Privacy Policy
1. Information We Collect
Depending on your interactions across the Coderyx ecosystem, we collect the following categories of information:
- Account Credentials: Full name, verified email address, cryptographically hashed authentication credentials, multi-factor authentication secrets (TOTP), and phone numbers for SMS verification.
- Transactional & Subscription Records: Invoices, payment transaction references (processed via PCI-DSS Level 1 compliant processors; raw credit card numbers are never stored on Coderyx infrastructure), and subscription status.
- Security & SIEM Telemetry (Coderyx Guard): System audit logs, fleet endpoint telemetry, process execution audits, network socket connections, and auto-isolation event records.
- Business Operations Data (Coderyx LeadFlow): Invoices, CRM contacts, deals, accounting ledgers, HR personnel profiles, and Team Chat Space messages and attachments.
- Wireframes & UX Assets (Coderyx ProtoStudio): Vector layout data, UI wireframes, variable simulation models, exported package code, and collaborator comments.
- Payment Information: Transaction references, plan tiers, and billing receipts. Raw payment card details are tokenized directly by PCI-DSS Level 1 compliant processors (Paystack) and are never stored on Coderyx application servers.
2. Unified Profile Avatar Synchronization
To deliver a seamless, cohesive user experience while maintaining unified identity across our multi-product ecosystem, Coderyx utilizes a centralized avatar synchronization system:
- When you upload a profile picture in Coderyx Central (via
/dashboard/profile), the image is securely stored in centralized encrypted cloud storage. - This single profile image is automatically propagated and synchronized across all active product instances—including Coderyx Guard, LeadFlow ERP, and ProtoStudio.
- No individual product maintains a discordant or detached profile picture. If you update or remove your avatar in Central, the change immediately takes effect across the entire ecosystem.
3. How We Process Your Data
We process your data strictly under the lawful bases of contractual necessity, compliance with legal obligations, and legitimate enterprise security interests:
- To authenticate users and verify verified email addresses before permitting platform access.
- To enforce step-up security protocols on sensitive account actions.
- To detect, mitigate, and neutralize cybersecurity attacks via Coderyx Guard's SOC Co-Pilot AI and automated host isolation mechanisms.
- To facilitate real-time team collaboration, messaging, and project wireframing.
- To dispatch transactional invoices, billing notifications, and critical security alerts.
4. Security & Encryption Standards
All data processed within Coderyx is protected using industry-leading defensive controls:
- Encryption in Transit: 256-bit TLS 1.3 enforced across all public endpoints and internal SSO communication channels.
- Encryption at Rest: Database volumes, backup archives, and user file uploads are encrypted with AES-256.
- Multi-Factor Authentication (MFA): Time-based one-time passwords (TOTP) supported for all account tiers.
- Strict Network Segmentation: Zero-trust network access between Guard telemetry nodes, ERP databases, and public web servers.
5. Data Retention & Erasure
We retain account data for as long as your subscription is active. Upon explicit account deletion or termination, all associated personal records across Coderyx Central, LeadFlow, and Guard are permanently purged from production databases within 30 days, subject to mandatory statutory tax and accounting retention requirements.
6. Your Privacy Rights
Under the Nigeria Data Protection Act (NDPA) and General Data Protection Regulation (GDPR), you have the right to:
- Access: Request a full export of your personal data and activity records.
- Rectification: Correct inaccurate or incomplete account information directly in your profile settings.
- Erasure (Right to be Forgotten): Request the permanent deletion of your account and personal identifiers.
- Restriction & Objection: Object to processing of telemetry data where applicable.
- Data Portability: Export your ERP data, ProtoStudio projects, and audit logs in machine-readable JSON/CSV formats.
7. Telemetry & Cookies
We use strictly necessary session cookies to preserve authenticated state and prevent Cross-Site Request Forgery (CSRF). We do not deploy third-party advertising cookies or cross-site tracking pixels.
8. NDPR, GDPR & International Data Transfers
Coderyx complies with the Nigeria Data Protection Regulation (NDPR) and aligns with international standards including GDPR and ISO/IEC 27001. Where data is transferred across borders, we implement standard contractual clauses (SCCs) and rigorous technical safeguards to ensure adequate data protection.
9. Contact Our Data Protection Officer (DPO)
If you have questions, complaints, or wish to exercise your data privacy rights, please contact our Data Protection Officer:
Coderyx Global Technologies Ltd
Email: dpo@coderyx.com
Security Escalations: security@coderyx.com