Privacy Policy
Last updated:
This policy explains what personal data CodexaCloud collects, why, and what you can do about it. It covers our website and the services we provide to customers.
1. What we collect
| Data | Why we hold it |
|---|---|
| Name, email, postal address, phone | To create your account, issue invoices, and contact you about the service |
| Company name and tax number | To issue compliant invoices where you ask us to |
| Payment details | Handled by our payment providers. We store only the last four digits and card type — never the full number |
| IP address, browser and device information | Security, fraud screening, and diagnosing support issues |
| Support tickets and correspondence | To answer you and to keep a history of your account |
| Server and access logs | Operating the service, investigating abuse, and capacity planning |
| Domain registrant details | Required by registries and ICANN to register a domain on your behalf |
2. Content you store with us
Files, databases and email that you host with us may contain personal data about your own users. That data is yours; we process it only to provide the service to you, and we do not access it except where necessary for support you have asked for, for security, or where legally required.
Where data-protection law applies, you are the controller of that content and we act as your processor. We can enter a data processing agreement on request — contact legal@codexacloud.com.
3. Legal bases
- Contract — to provide the service you have ordered and to bill for it
- Legal obligation — tax and accounting records, and responses to lawful requests
- Legitimate interests — network security, fraud prevention, and improving the service
- Consent — marketing email, and any non-essential analytics. Withdrawable at any time
4. Who we share it with
We do not sell personal data, and we do not share it for anyone else’s marketing. We share it only with the parties needed to run the service:
- Payment processors, to take payment and to prevent fraud
- Domain registries and registrars, where registration requires it
- Certificate authorities, when you order an SSL certificate
- Infrastructure and data centre providers hosting the servers your service runs on
- Law enforcement or regulators, where we receive a valid legal order
Each processor is bound by contract to handle the data only on our instructions and to keep it secure.
5. International transfers
Our infrastructure and some of our processors are located outside your country. Where personal data is transferred internationally we rely on appropriate safeguards, such as standard contractual clauses or an adequacy decision, depending on the jurisdictions involved.
6. How long we keep it
- Account and billing records — for the life of the account and then as long as tax law requires, typically six to seven years
- Hosted content — deleted 30 days after termination
- Backups — cycled out within 30 days
- Server and access logs — typically 90 days, longer where an abuse or security investigation is open
- Support tickets — three years after the ticket is closed
7. Cookies and analytics
This website uses cookies that are strictly necessary to remember your theme preference and to keep you signed in to the client area. We use privacy-respecting, aggregate analytics that do not set advertising cookies, do not track you across sites and do not build a profile of you. We do not run advertising or behavioural tracking pixels.
8. Your rights
Subject to the law that applies to you, you may request access to your personal data, a copy of it in a portable format, correction of anything inaccurate, deletion of data we no longer need, restriction of or objection to certain processing, and withdrawal of consent where we relied on it.
Email privacy@codexacloud.com. We respond within 30 days. We will ask you to verify your identity before acting on a request. If you are unhappy with our response you may complain to your local data protection authority.
9. Security
We encrypt data in transit with TLS, restrict administrative access to named staff on the principle of least privilege, require two-factor authentication on internal systems, keep systems patched, and store backups encrypted and off-site. No system is perfectly secure, but we will notify affected customers and, where required, the relevant authority without undue delay if a breach occurs.
10. Children
Our services are not directed at children and we do not knowingly collect data from anyone under 18. If you believe we have, contact us and we will delete it.
11. Changes
We will post any update here and change the date above. Material changes will be notified to your account email before they take effect.
12. Contact
CodexaCloud — privacy@codexacloud.com. Our registered company details and postal address appear on every invoice we issue.

