Effective date: 31 July 2026 — Version 2026-07-31.1
Codelynx, LLC, at 8 The Green STE B, Dover, Delaware 19901, United States, is the controller for account, order, contract, support and website data described below. Email melvyn@melvynx.com for privacy requests.
For personal data inside a Customer application that we access solely to perform an authorized audit, Customer is normally the controller and Codelynx is its processor under the Data Processing Addendum.
1. Data we collect
- Account and contact: name, business email, organization, role and authentication records.
- Order and payment: Stripe session and payment references, amount, currency, status, accepted legal-document versions and refund records. Stripe receives card details directly.
- Authorization evidence: verified target, verification method, signer identity and role, timestamps, user agent, document version, document hash and consent record.
- Scope: primary target, included assets, environment, exclusions, special instructions and provider-authorization confirmations.
- Audit access: dedicated test-account identifier and secret when voluntarily supplied. Never provide a reused or personal password.
- Audit material: minimum evidence required to prove findings, report files, remediation notes and delivery records.
- Technical and security: IP and request metadata available in infrastructure logs, device/browser information, rate-limit records and security events.
- Communications: support requests and other messages you send.
We do not use advertising pixels, behavioral advertising or third-party marketing analytics on this service.
2. Purposes and legal bases
We process data to enter into and perform the business contract; verify authority and retain lawful-testing evidence; operate, secure and prevent abuse of the service; process payment and refunds; perform and deliver the audit; comply with accounting, tax and legal duties; and establish or defend legal claims.
The corresponding legal bases, where GDPR applies, are performance of a contract, compliance with legal obligations, and legitimate interests in security, fraud prevention, service administration and legal defence. Consent is used only where the law specifically requires it and may be withdrawn prospectively.
3. Recipients
Authorized Codelynx personnel and the providers necessary to run the service may receive data. The current list, purpose and transfer information appear on the Subprocessors page. We may also disclose information to professional advisers, insurers, authorities or courts where legally required or necessary to protect legal rights.
Reports are available only to authorized members of the Customer organization and Codelynx personnel who need access. We do not publish findings without separate written permission.
4. International transfers
Codelynx, LLC is established in the United States. Where EEA, UK or Swiss personal data is transferred, we use an applicable adequacy framework, the European Commission's Standard Contractual Clauses, the UK Addendum, or another lawful safeguard. Our DPA incorporates the relevant SCC module. Provider-specific mechanisms are linked on the Subprocessors page.
5. Retention
- Unsigned checkout reservations expire automatically; unpaid session metadata follows Stripe's retention rules.
- Test-account secrets are removed when the report is delivered, when the authorization expires, when a pre-signature refund is completed, or earlier on request when no longer needed.
- Reports and finding evidence remain available while the business account is active and are deleted within 30 days of a valid deletion request, unless a legal hold applies.
- Signed authorizations, accepted contract versions, delivery evidence, refunds and payment/accounting records are retained for up to seven years after the order closes, or longer only when required for an active claim or legal duty.
- Support records are normally retained for three years after the last exchange.
- Infrastructure and security logs follow provider schedules and are kept only as long as reasonably necessary for security and incident investigation.
Backups may retain deleted data for a limited rolling period, during which it is isolated from ordinary use.
6. Security
We use access controls, least privilege, multi-factor authentication where available, TLS in transit, provider encryption at rest, private report storage, signed download URLs, audit logs, data minimization and credential deletion. No internet service can guarantee absolute security.
If you discover a security or privacy incident involving this service, email melvyn@melvynx.com immediately.
7. Your rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, objection or portability, and may complain to a competent supervisory authority. We verify identity and normally respond within 30 days. Some contract, fraud-prevention and accounting records must be retained despite a deletion request.
For data controlled by a Customer SaaS, submit the request to that Customer first; we will assist it as processor.
8. Business service and children
The service is for business representatives aged 18 or older and is not directed to children. Do not place children's data or special-category data in scope notes or test credentials.
9. Cookies
Only cookies and local storage strictly necessary for authentication, security and checkout are used. See the Cookie Notice.
10. Changes
Material changes receive a new version and effective date. The privacy version accepted with an existing order remains in its evidence record, although current processing is also governed by applicable law.