1. Who is responsible for your data?
For the Codepine website, Codepine-operated products and direct business communications, the controller is Codepine Labs s.r.o., K Brance 1173/15, 155 00 Prague 13, Czech Republic. Privacy questions and data requests can be sent to privacy@codepine.org.
Company ID (IČO): 25183460
Tax / VAT ID (DIČ): CZ25183460
Codepine Labs s.r.o. is registered with the Municipal Court in Prague, Commercial Register, Section C, Insert 291046. Further company and consumer-information details are available in our Legal Notice.
For custom software developed or operated on behalf of a client, the client may be the controller and Codepine may act as a processor under the client's instructions. In that situation, the client's privacy notice and the applicable data-processing agreement determine the relevant roles and purposes.
2. What data may we process?
The categories depend on how you interact with Codepine and on the features of the particular product:
- Contact and support data — name, email address, telephone number, company, support-request content and information you choose to provide when asking for help or discussing a project.
- Account and authentication data — where a product uses accounts, this may include your name, email address, account settings, authentication records and security-related account events. Passwords are intended to be stored only in protected, non-reversible form where Codepine controls the authentication system.
- Product content — information, files, notes, photos, records or other content that you intentionally create, upload, synchronise or share in a Codepine-operated product.
- App and device data — depending on the product, operating-system version, device type, app version, language, coarse device characteristics and technical identifiers needed for functions such as authentication, synchronisation or push notifications.
- Diagnostics and security data — IP addresses, timestamps, request logs, crash or error information, security events and similar technical information may be generated by hosting infrastructure, app backends or Codepine-operated systems.
- Device permissions — an app may request access to functions such as camera, photos, files, notifications, calendar, location or other device capabilities only where those functions are relevant to the product. The operating system normally allows you to review or revoke permissions.
- Commercial and app-store data — where a product offers paid features or subscriptions, Codepine may receive transaction identifiers, purchase or subscription status and related records from an app store or payment provider. Full payment-card details are normally handled by the relevant payment provider rather than by Codepine.
- Publicly shared content — in products that offer a public-sharing feature, content you deliberately make public may be accessible to others as described below.
3. Why do we use personal data?
Depending on the situation, personal data may be processed to provide requested services, create and administer accounts, synchronise product data, deliver app functionality, send service-related notifications, respond to enquiries, provide support, operate and secure systems, diagnose faults, prevent abuse, maintain software, process purchases or subscriptions, comply with legal obligations and improve reliability.
Under the GDPR, the legal basis will generally be one or more of the following: performance of a contract or steps requested before entering a contract; our legitimate interests in operating, securing and improving Codepine services; compliance with a legal obligation; or consent where consent is specifically requested, for example for an optional device permission or feature where applicable law requires it.
4. Website analytics and cookies
The public Codepine website does not use analytics cookies, advertising cookies or browser-based analytics identifiers.
We use a small first-party, server-side statistics function to understand basic use of the website. It immediately aggregates page requests by calendar day. The stored statistics contain only the requested page path without query strings, the referrer hostname where available, and a coarse device category such as desktop, mobile or tablet.
The analytics function does not store IP addresses, full user-agent strings, query strings, persistent or rotating visitor identifiers, and it does not create user profiles. No analytics JavaScript is executed in your browser and nothing is written to or read from your browser storage for this purpose. Aggregate analytics data is automatically removed after 90 days.
Independent of these aggregate statistics, our hosting infrastructure may process ordinary connection and server-log data, including IP addresses, as technically necessary to deliver, secure and troubleshoot the website. Such operational logs are separate from the aggregate analytics described above.
5. Apps, permissions and notifications
Codepine develops mobile, web and cross-platform applications. The data used by an app depends on its actual functions. Where an app needs access to a device capability, the permission request should identify that capability through the operating system, and access should be limited to what is reasonably necessary for the feature.
If an app uses push notifications, a push token or comparable delivery identifier may be processed by Codepine and by the platform notification service, such as Apple Push Notification service or Firebase Cloud Messaging, solely to deliver the relevant notifications. Product-specific notices may provide further detail.
Codepine does not use advertising identifiers or behavioural advertising in a product unless that use is expressly described in the product's own privacy notice.
6. Contact, support and remote support
If you email or call Codepine, we use the information you provide to answer the enquiry and, where relevant, prepare or perform a business relationship. Support requests may contain diagnostic information needed to investigate a problem.
If a remote-support session is required, it should only be started after direct coordination with Codepine. We access only what is reasonably necessary for the support task and expect customers to close unrelated confidential material before a session where practical. Do not send passwords, recovery codes, payment-card data or unnecessary sensitive information through ordinary email.
7. Client projects and data processing on behalf of clients
Codepine may design, develop, host, maintain or support software for business clients. Where personal data in such a system is processed solely on a client's instructions, Codepine acts as a processor and the client remains responsible for deciding why and how the data is used.
In processor situations, Codepine seeks to process personal data only on documented instructions, apply appropriate security measures, limit access to personnel and service providers who need it, assist the client with applicable data-protection obligations where agreed, and return or delete data as required by the relevant contract or data-processing agreement.
8. Public sharing features
Some Codepine products may allow users to intentionally publish or share selected content. Content is not meant to become public merely because it is stored or synchronised with a Codepine service.
If you activate a public-sharing feature, the selected content may be accessible to other users or to anyone on the web, depending on the product. Removing public access later cannot undo copies, screenshots, search-engine caches or other copies already made by third parties.
9. Service providers, app stores and recipients
We may use technical service providers for functions such as hosting, infrastructure, email, storage, monitoring, remote support, push notifications, app distribution or payment processing. They may process personal data only to the extent needed to provide those services and are expected to handle it under appropriate contractual and security safeguards.
Apps distributed through platforms such as Apple's App Store or Google Play are also subject to the platform provider's own processing and privacy terms. Codepine does not control the independent processing performed by those platform providers.
We may also disclose information where required by law, to establish or defend legal claims, or where necessary to protect users, Codepine or others from security threats or abuse.
10. Website resources and maps
The fonts, decorative images and social-sharing images used by the public Codepine website are served locally from Codepine's own website rather than being loaded from public font or image CDNs.
The contact map displayed on the website is requested by our server and delivered to your browser from the Codepine domain. Your browser therefore does not need to contact Google merely to display the static map image. If you actively click the “Open in Google Maps” link, you leave the Codepine website and Google receives the data normally transmitted when you visit its service.
11. International transfers
Some service providers used for particular Codepine services may process data outside the European Economic Area. Where this occurs and the destination is not covered by an adequacy decision, we seek to rely on an appropriate transfer mechanism such as the European Commission's Standard Contractual Clauses together with any additional safeguards that are reasonably required.
12. How long do we keep data?
We keep personal data only for as long as it is needed for the purpose for which it was collected, including active service delivery, account operation, support history, security, contractual requirements, legal obligations and the establishment or defence of claims. Retention periods can differ by product and data type. Data may remain for a limited period in backups after deletion from active systems.
Where Codepine acts as a processor, retention is also governed by the client's instructions and the applicable agreement. The aggregate website statistics described above are retained for up to 90 days.
13. Security
We use technical and organisational measures appropriate to the nature of the service and the risks involved. These can include access controls, encryption in transit, secure authentication practices, least-privilege access, software updates, logging, backups and separation of production credentials from public source code. No internet-connected system can be guaranteed to be completely secure.
Security concerns can be reported privately to support@codepine.org.
14. Your rights
Subject to the conditions set by applicable law, you may have the right to request access to your personal data, correction, deletion, restriction of processing, data portability, or to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw that consent for the future.
If Codepine processes your data solely on behalf of a client, your request may need to be handled by that client as controller. Codepine will assist the controller where required by the applicable agreement and law.
You also have the right to lodge a complaint with the competent data-protection authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů).
15. Children
Codepine's general business website and professional software services are not directed at children. If a particular product is intended for younger users, it should provide product-specific information and age-appropriate safeguards where required.
16. Product-specific notices and changes
A Codepine product may provide its own privacy notice where its features, data categories, service providers, permissions or retention rules require more specific information. The product-specific notice supplements this policy and takes precedence for those specific details.
We may update this policy when services, providers or legal requirements change. The current version is identified by the date at the top of this page. Material changes may also be communicated within an affected product where appropriate.
17. Contact
For privacy questions or requests, email privacy@codepine.org or write to Codepine Labs s.r.o., K Brance 1173/15, 155 00 Prague 13, Czech Republic.