Skip to content
CodexaCloud

Privacy Policy

Last updated:

This policy explains what personal data CodexaCloud collects, why, and what you can do about it. It covers our website and the services we provide to customers.

1. What we collect

DataWhy we hold it
Name, email, postal address, phoneTo create your account, issue invoices, and contact you about the service
Company name and tax numberTo issue compliant invoices where you ask us to
Payment detailsHandled by our payment providers. We store only the last four digits and card type — never the full number
IP address, browser and device informationSecurity, fraud screening, and diagnosing support issues
Support tickets and correspondenceTo answer you and to keep a history of your account
Server and access logsOperating the service, investigating abuse, and capacity planning
Domain registrant detailsRequired by registries and ICANN to register a domain on your behalf

2. Content you store with us

Files, databases and email that you host with us may contain personal data about your own users. That data is yours; we process it only to provide the service to you, and we do not access it except where necessary for support you have asked for, for security, or where legally required.

Where data-protection law applies, you are the controller of that content and we act as your processor. We can enter a data processing agreement on request — contact legal@codexacloud.com.

3. Legal bases

  • Contract — to provide the service you have ordered and to bill for it
  • Legal obligation — tax and accounting records, and responses to lawful requests
  • Legitimate interests — network security, fraud prevention, and improving the service
  • Consent — marketing email, and any non-essential analytics. Withdrawable at any time

4. Who we share it with

We do not sell personal data, and we do not share it for anyone else’s marketing. We share it only with the parties needed to run the service:

  • Payment processors, to take payment and to prevent fraud
  • Domain registries and registrars, where registration requires it
  • Certificate authorities, when you order an SSL certificate
  • Infrastructure and data centre providers hosting the servers your service runs on
  • Law enforcement or regulators, where we receive a valid legal order

Each processor is bound by contract to handle the data only on our instructions and to keep it secure.

5. International transfers

Our infrastructure and some of our processors are located outside your country. Where personal data is transferred internationally we rely on appropriate safeguards, such as standard contractual clauses or an adequacy decision, depending on the jurisdictions involved.

6. How long we keep it

  • Account and billing records — for the life of the account and then as long as tax law requires, typically six to seven years
  • Hosted content — deleted 30 days after termination
  • Backups — cycled out within 30 days
  • Server and access logs — typically 90 days, longer where an abuse or security investigation is open
  • Support tickets — three years after the ticket is closed

7. Cookies and analytics

This website uses cookies that are strictly necessary to remember your theme preference and to keep you signed in to the client area. We use privacy-respecting, aggregate analytics that do not set advertising cookies, do not track you across sites and do not build a profile of you. We do not run advertising or behavioural tracking pixels.

8. Your rights

Subject to the law that applies to you, you may request access to your personal data, a copy of it in a portable format, correction of anything inaccurate, deletion of data we no longer need, restriction of or objection to certain processing, and withdrawal of consent where we relied on it.

Email privacy@codexacloud.com. We respond within 30 days. We will ask you to verify your identity before acting on a request. If you are unhappy with our response you may complain to your local data protection authority.

9. Security

We encrypt data in transit with TLS, restrict administrative access to named staff on the principle of least privilege, require two-factor authentication on internal systems, keep systems patched, and store backups encrypted and off-site. No system is perfectly secure, but we will notify affected customers and, where required, the relevant authority without undue delay if a breach occurs.

10. Children

Our services are not directed at children and we do not knowingly collect data from anyone under 18. If you believe we have, contact us and we will delete it.

11. Changes

We will post any update here and change the date above. Material changes will be notified to your account email before they take effect.

12. Contact

CodexaCloudprivacy@codexacloud.com. Our registered company details and postal address appear on every invoice we issue.