Scope of this policy
This policy explains how Codivo Labs (“Codivo Labs”, “we”, “us”) handles personal information in connection with the website at codivolabs.com and our business correspondence. Codivo Labs is the data controller for that information.
Our published applications are covered by their own policies, because they behave differently from a website. For Storage Optimizer, see the Storage Optimizer Privacy Policy.
When we process data on behalf of a client during an engagement, we act as a data processor under that client's instructions and our contract with them, not as a controller. See client code and confidentiality below.
No cookies, no analytics
To be specific about what this website does not do:
- It sets no cookies, and uses no local storage or session storage to identify you
- It runs no analytics or tag manager, and reports no page views, events or sessions to any third party
- It contains no advertising, retargeting or conversion pixels
- It embeds no third-party fonts, scripts, videos or social media widgets, so no third party learns that you visited
- It does not fingerprint your browser or device
- It has no contact form, so nothing you type is transmitted anywhere
Because we do not track you, features such as “Do Not Track” and Global Privacy Control signals require no action on our part — we already behave as though they were set.
Information we process
Information you send us
The website invites you to email us. If you do, we receive your email address, your name if your mail client includes it, your message, and any attachments — for example a repository link, a code sample or a document. If we go on to work together, we will also hold ordinary business contact and billing details for your organisation.
Technical information from hosting
Serving a web page necessarily involves your device's IP address. See hosting and server logs.
What we never ask for
We do not ask for, and would prefer not to receive, special category data (such as health, biometric, political or religious information), government identity numbers, or payment card details by email.
Hosting and server logs
This website is a set of static pages hosted on Cloudflare's global network. Like any web host, Cloudflare processes your IP address, the requested URL, your user agent string and the timestamp in order to route and serve the request, and to protect against attacks and abuse.
These logs are generated and retained by Cloudflare as our hosting provider and processor, for a limited period, for security and operational purposes. We do not use them to build audience statistics or to identify individual visitors, and we do not combine them with any other information. Cloudflare's privacy documentation is available at cloudflare.com/privacypolicy.
Our email is handled by a third-party email provider, which processes messages in order to deliver and store them.
Why we process it, and on what basis
| What | Why | Lawful basis (UK / EU GDPR) |
|---|---|---|
| Your email and message | To answer your enquiry and scope possible work | Legitimate interests — responding to someone who contacted us; or steps prior to entering a contract |
| Business contact and billing details | To deliver an engagement, invoice for it and keep records | Performance of a contract; and legal obligation for tax records |
| IP address in server and email logs | To serve the site, and to prevent abuse and attacks | Legitimate interests — security and availability of our systems |
We do not use your information for automated decision-making or profiling, and we do not send marketing email to people who have not asked for it.
Who we share it with
We do not sell, rent or trade personal information, and we do not share it for cross-context behavioural advertising. We disclose it only to:
- Service providers who process it on our behalf under contract — our hosting provider, our email provider, and our accounting software
- Professional advisers such as accountants or lawyers, where necessary and under a duty of confidence
- Authorities, where we are legally required to do so, and after satisfying ourselves that the request is valid
If our business were ever transferred to another party, personal information could transfer with it; we would tell affected clients before that happened.
How long we keep it
- Enquiries that do not become work: up to 12 months, then deleted
- Support and client correspondence: up to 24 months after our last exchange
- Contracts and invoices: as long as tax and company law require, currently up to 8 years
- Client code and repository access: access is revoked and local copies deleted at the end of an engagement, unless the contract says otherwise
International transfers
We work with clients worldwide, and our hosting and email providers operate globally. Personal information may therefore be processed in countries other than your own, including the United States. Where information is transferred out of the UK, the EEA or India, we rely on the safeguards our providers have in place — typically the European Commission's Standard Contractual Clauses, the UK Addendum, or an adequacy decision — and we will describe the applicable mechanism on request.
Your rights
Subject to the conditions in the applicable law, you may ask us to give you access to the personal information we hold about you, correct it, delete it, restrict how we use it, or provide it in a portable form. You may object to processing we carry out on the basis of legitimate interests, and withdraw consent where we relied on consent.
We do not sell personal information or share it for targeted advertising, so California opt-out rights have nothing to act on. We will not discriminate against you for exercising any right.
Write to privacy@codivolabs.com and we will respond within 30 days. We may need to verify your identity first, which usually means replying from the address we already hold.
If you are unhappy with our response you can complain to your data protection authority — in the UK the Information Commissioner's Office, in the EEA your national authority, and in India the Data Protection Board. We would appreciate the chance to put things right first.
Security
We keep our attack surface deliberately small: a static website with no database, no user accounts and no third-party scripts. Internally we use multi-factor authentication, full-disk encryption on work machines, a password manager, and least-privilege access to client systems.
No system is perfectly secure. If you believe you have found a vulnerability in anything we run or publish, please tell us privately at security@codivolabs.com before disclosing it publicly. We will acknowledge within 48 hours and credit you once the issue is fixed, if you would like us to.
Children
This website and our services are aimed at businesses and are not directed at children. We do not knowingly collect personal information from children under 13, or under the higher minimum age that applies where you live. If you believe a child has sent us personal information, contact us and we will delete it.
Client code and confidentiality
Auditing software means being trusted with it. Our standing commitments to clients are:
- Written confidentiality terms, signed before we are given repository access
- Least-privilege access — read-only where read-only is enough, scoped to the repositories in question, and revoked at the end of the engagement
- Client code is never used to train machine learning models, ours or anybody else's, and is not submitted to third-party services except tools named in the engagement documentation
- Findings and reports are shared only with the people the client nominates. We do not publish client names or case studies without written permission
- Intellectual property in delivered work is assigned to the client on delivery
- Where an engagement gives us access to personal data held by a client, we act as their processor under a data processing agreement and follow their instructions
Changes to this policy
We will update the “Last updated” date at the top of this page whenever this policy changes, and we will describe material changes prominently. Because we hold no accounts, we cannot notify visitors individually; if you rely on this policy, please check back periodically.
Contact us
If any part of this document is unclear, or you want to exercise a right described in it, write to us and a person will reply.
Email: privacy@codivolabs.com