Skip to main content

Legal

Privacy Policy

Privacy Policy

This Privacy Policy explains how Codepixel collects, uses, and protects personal data when you visit codepixel.me, submit a form, or book a discovery call through our website.

We try to keep this readable. If something is unclear, contact us at privacy@codepixel.me.

1. Who we are

The Codepixel group operates through two related entities:

  • Codepixel d.o.o. — registered at Branka Miljkovića 32, 81000 Podgorica, Montenegro; registration number 5-0839589/005; PIB 03200116; VAT 30/31-20004-8. Primary data controller for personal data processed through codepixel.me.
  • Codepixel Canada — 1561844 B.C. Ltd. operating as Codepixel Canada; BC incorporation number BC1561844; CRA Business Number 760795633; registered office at 65-2838 Livingstone Ave, Abbotsford BC V2T 0J1, Canada. Canadian subsidiary of Codepixel d.o.o. (90% owned by Codepixel d.o.o.); supports local commercial activities for Canadian customers.

Codepixel d.o.o. is the primary data controller for personal data processed via codepixel.me, regardless of the visitor's location. Where a visitor enters a commercial relationship with Codepixel Canada, personal data may be shared between the two entities under an intercompany data sharing arrangement aligned with EU GDPR, Canada PIPEDA, and BC PIPA.

Contact:

We do not currently designate a formal Data Protection Officer (DPO) under GDPR Article 37 because the scale of our processing does not require it. The named contact for all privacy matters is privacy@codepixel.me.

2. Scope

This policy covers personal data processed by Codepixel through:

  • The codepixel.me website (including all subdomains and embedded scheduler).
  • The lead-capture form at /contact and equivalent forms on service pages.
  • Gated resource downloads (playbooks) at /playbooks/*.
  • The Pipedrive Scheduler iframe used to book discovery calls.
  • Email correspondence initiated from the site.

This policy does not cover personal data processed under a signed client engagement (Master Services Agreement / Statement of Work). Such processing is governed by the engagement contract and, where applicable, a separate Data Processing Agreement (DPA) available to clients on request.

3. What data we collect

3.1 Data you provide directly

When you submit a form or book a meeting, we collect:

  • Name (first, last).
  • Work email address.
  • Company name (optional).
  • Phone number (optional).
  • Free-text message describing your project or inquiry.
  • Role / persona (e.g., founder, product, engineering).
  • Project timeline (e.g., within 30 days, 1–3 months, exploring).
  • Indicative budget range (optional) — a broad band you can set on a slider, never an exact figure, and the form submits without it.
  • How you heard about us (optional) — a source such as Clutch, LinkedIn, web search or a referral, plus a short free-text answer if you pick "Other".
  • Links to project assets (optional).
  • The URL of the page you submitted the form from.

When you request a gated resource (e.g. a playbook), we collect: name (first, last), work email address, company name, and role.

3.2 Data we collect automatically

  • IP address — collected briefly to enforce rate limiting on our form endpoints (contact/lead, newsletter, gated resource requests) and the article-reaction endpoint (see retention below).
  • Browser user-agent string — for server-side request logging and bot detection.
  • UTM campaign parameters — captured from the URL query string if you arrived via a tracked campaign link.
  • Aggregate analytics data — only if you accept analytics cookies (see Cookie Policy).

3.3 Data we do NOT collect

  • We do not collect special-category data under GDPR Article 9 (health, biometric, religious, political, etc.) through this website.
  • We do not knowingly collect data from children under 18.
  • We do not use intrusive fingerprinting or cross-device tracking.

Under the EU GDPR (and equivalent provisions in PIPEDA / BC PIPA), we rely on the following legal bases:

PurposeLegal basis (GDPR Article 6)
Responding to your contact-form or scheduler submissionPre-contractual measures (Art. 6(1)(b)) + consent for any follow-up marketing communication (Art. 6(1)(a))
Analytics (Google Analytics 4, Hotjar)Consent (Art. 6(1)(a)) — only after you accept analytics cookies
Rate-limiting (storing IP address for up to 10 minutes)Legitimate interest (Art. 6(1)(f)) — fraud and abuse prevention
Error monitoring in your browser (Sentry)Consent (Art. 6(1)(a)) — the browser SDK is only loaded after you accept analytics cookies
Error monitoring on our servers (Sentry)Legitimate interest (Art. 6(1)(f)) — keeping the site working. Server-side error events are minimized: they contain no form contents, IP addresses, or cookies
Sending an internal lead notification to our sales team (email and our internal team chat)Legitimate interest (Art. 6(1)(f)) — operating our business
Storing your lead in our CRM (Pipedrive) for sales follow-upLegitimate interest (Art. 6(1)(f)) and, where relevant, pre-contractual measures (Art. 6(1)(b))
Sending you our newsletter / insights emailsConsent (Art. 6(1)(a)) — confirmed double opt-in; you can unsubscribe at any time
Delivering a gated resource you requested (emailing a time-limited download link)Performance of your request / pre-contractual measures (Art. 6(1)(b))

Newsletter & marketing emails

If you subscribe to our newsletter, we use a double opt-in process: after you enter your email we send a confirmation email, and we only add you to the list once you click the confirmation link. We store your email address in our email platform (Resend), which is the list our newsletter is sent from. We send insights and occasional product updates — nothing else. Every email includes a one-click unsubscribe, and you can withdraw consent at any time (see Section 9) or by emailing privacy@codepixel.me. Until you confirm, we do not store your email anywhere — an unconfirmed address only ever lives inside the (time-limited) confirmation link.

Gated resources (playbooks)

Some resources on this site (e.g. our delivery playbooks) are free but require a short form: name, work email, company, and role. When you submit it, we email you a signed download link valid for 7 days, and we store your details in our CRM (Pipedrive) where they may prompt a one-to-one follow-up from our team (legitimate interest, Art. 6(1)(f)). Requesting a resource does not sign you up to any automated marketing list. The form includes an optional newsletter checkbox — if you tick it, your subscription activates only when you use the emailed download link (an opt-in confirmation equivalent to double opt-in). You can withdraw consent or object to follow-up at any time (see Section 9).

You can withdraw any consent at any time (see Section 9).

5. Sub-processors

We work with the following third parties ("sub-processors") to deliver this website and follow up on your inquiry. Each is bound by a Data Processing Agreement (DPA) and, where applicable, EU Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914.

ProviderPurposeData categoriesLocationSafeguards
Pipedrive OÜCRM — stores Person, Lead, Note, and Organization recordsAll form fields (name, email, phone, company, message, role, timeline, budget range, how you heard about us, project links, UTM, page URL)EU (Estonia) — region selectableGDPR DPA + SCCs
Resend (Drip Resends Inc.)Transactional email (internal lead notifications to info@codepixel.me, newsletter confirmation emails, resource download links) + newsletter audience / send listEmail address; for internal notifications, the form contents (name, company, email, role, timeline, budget range, service interest, industry, how you heard about us, full message, project links, UTM, page URL)US (with Cloudflare edge)GDPR DPA + SCCs
Slack Technologies, LLC (a Salesforce company)Internal team chat — a new-lead notification is posted to our sales channel so the team can respond quicklyName, company, role, industry, project timeline, budget range, service interest, how you heard about us (category only), the resource or meeting you requested, newsletter preference, whether you have contacted us before, the page you were on, and a link to the CRM record. Your email address, phone number, message, project links, and booking notes are not posted to SlackUSGDPR DPA + SCCs
Upstash Inc.Serverless Redis — short-term IP rate-limit countersIP address (up to 10 min sliding window)EU (Ireland) — region selectableGDPR DPA + SCCs
Cloudflare, Inc.Bot mitigation (Turnstile) on our forms (contact, newsletter, and resource download), edge CDNIP address, request metadata, Turnstile challenge tokensGlobal edgeGDPR DPA + SCCs
Functional Software, Inc. (Sentry)Error monitoringError stack traces and technical request metadata (no form contents, IP addresses, or cookies)EU (Frankfurt) regionGDPR DPA + SCCs
Vercel Inc.Hosting and edge runtime for codepixel.meAll HTTP request metadata transiting our siteUS headquarters, EU edgeGDPR DPA + SCCs
Amazon Web Services EMEA SARL (S3)Object storage for the images, illustrations and article audio shown on this site; your browser fetches those files directly from the bucketIP address and request metadata of the file request (no form contents, no cookies)EU (Frankfurt, eu-central-1)GDPR DPA + SCCs
Codepixel-operated Strapi CMSContent delivery for marketing pagesNo personal dataCodepixel-hosted infrastructureSame controllers as this policy
Google LLC (Tag Manager + GA4)Web analytics (only if you accept analytics cookies)Cookie identifiers, page URLs, aggregate metricsUS + EU regionsGDPR DPA + SCCs; GA4 does not log or store IP addresses
Hotjar Ltd.UX heatmaps and session sampling (only if you accept analytics cookies)Cookie identifiers, click coordinates, session recording fragmentsEU (Malta / Ireland)GDPR DPA + SCCs

We review this list periodically and update it on changes. If a new sub-processor materially changes the data flow described in this policy, we update the policy and reset the cookie-consent banner where applicable.

A Codepixel-issued DPA is available to clients and partners on request via privacy@codepixel.me.

6. International data transfers

Some of our sub-processors operate in or transfer data to countries outside the EU/EEA (notably the United States). Where this happens, transfers are covered by:

  • The EU Commission's Standard Contractual Clauses (SCCs) under Decision 2021/914.
  • The Codepixel intercompany data sharing arrangement aligned with PIPEDA and BC PIPA for transfers between Codepixel d.o.o. (Montenegro) and Codepixel Canada (British Columbia).
  • Where applicable, certifications such as the EU–US Data Privacy Framework (Vercel, Cloudflare, Google, Sentry, Slack/Salesforce).

We choose EU regions for our sub-processors where the option is available.

7. Retention

We keep personal data only as long as necessary for the purposes described in this policy:

Data categoryRetention period
Lead data stored in Pipedrive (your contact + message)24 months from last contact; then anonymized or deleted on review
Internal notification email logs (Resend)30 days
Lead notification messages in our internal chat (Slack)Kept as a working notification only; the CRM record is the system of record. Subject to the retention of our Slack workspace plan
IP address for rate limiting (Upstash)Up to 10 minutes sliding window (1 minute for article reactions)
Web server access logs (Vercel)30 days
Media request logs (AWS S3)Not enabled; we do not keep S3 access logs
Error events (Sentry)90 days
Cookies on your deviceSee Cookie Policy

If you ask us to delete your data sooner, we'll honor the request (see Section 9), except where we're legally required to keep it (e.g., tax records for invoices already issued).

8. Security

We take security seriously. See our Security Statement for the controls we apply, including:

  • Multi-factor authentication on all production systems.
  • Encryption at rest and in transit (TLS 1.2+).
  • Centralized secret management (no hardcoded credentials in source code).
  • Two AI-assisted code review gates before any deliverable ships.
  • Incident notification within 24 hours of confirmation.

9. Your rights

If you are in the EU/EEA, the UK, Switzerland, Montenegro, or a Canadian province with equivalent rights, you have the following rights regarding your personal data:

  • Right of access (GDPR Art. 15 / PIPEDA Principle 9) — request a copy of what we hold about you.
  • Right to rectification (Art. 16) — correct inaccurate data.
  • Right to erasure (Art. 17, "right to be forgotten") — delete your data.
  • Right to restriction (Art. 18) — limit how we use it.
  • Right to data portability (Art. 20) — receive your data in a machine- readable format.
  • Right to object (Art. 21) — including objecting to processing based on legitimate interest.
  • Right to withdraw consent (Art. 7) — for any processing based on consent, with no effect on prior processing.
  • Right to lodge a complaint with a supervisory authority:

To exercise any right, email privacy@codepixel.me with the subject "DSAR". We respond within 30 days. We may ask for proof of identity to prevent unauthorized disclosure.

10. Use of AI in our services

Codepixel is an AI-augmented development studio. We use enterprise AI tools (Anthropic Claude, OpenAI ChatGPT Business, GitHub Copilot Business) to help us deliver client work and operate our business. These tools are configured so that:

  • They do not train on customer data by default.
  • They have restricted retention (per-vendor configuration).
  • Their outputs are always reviewed by a human before delivery.

For the full breakdown, see our AI Use Policy.

For data submitted through this website (e.g., contact-form messages), we do not feed your free-text content into AI tools as part of automated lead processing. Sales staff may, with judgment, use AI assistance to draft a reply to your inquiry — but only via Tier A enterprise tools that do not retain your data for training.

11. Cookies

This website uses cookies and similar technologies, in three categories (necessary, analytics, marketing). For the full inventory, durations, and how to manage your preferences, see our Cookie Policy.

You can change your consent at any time via the "Manage cookies" link in the site footer.

12. Children

Codepixel's services are directed at businesses, not individuals under 18. We do not knowingly collect personal data from children. If we learn that we have inadvertently collected data from a child, we will delete it promptly. If you are a parent or guardian and believe your child has provided us with personal data, contact privacy@codepixel.me.

13. Changes to this policy

We update this policy when our data practices change (for example, when we add a new sub-processor, change retention periods, or introduce a new feature). Material changes are highlighted at the top of this page for at least 30 days after the change date. The "Last updated" date in the header always reflects the most recent change.

If a change materially affects how we process data you've already given us, we'll email the address on file for active leads where practicable.

14. Contact

For all privacy-related questions, requests, or complaints:

  • Email: privacy@codepixel.me (subject: "Privacy" or "DSAR")
  • General company contact: info@codepixel.me
  • Phone: +382 69 192 118
  • Post (EU/EEA): Codepixel d.o.o., Branka Miljkovića 32, 81000 Podgorica, Montenegro
  • Post (North America): Codepixel Canada (1561844 B.C. Ltd.), 65-2838 Livingstone Ave, Abbotsford BC V2T 0J1, Canada

Change log

  • v1.6 — August 2026. Added Amazon Web Services (S3, eu-central-1) as a sub-processor: images, illustrations and article audio are served straight from the bucket to your browser, so AWS sees the request metadata for those files. Documents moved from draft to active for the launch of this website.
  • v1.5 — August 2026. Added Slack (Salesforce) as a sub-processor for internal new-lead notifications posted to our sales channel, with a reduced data set (no email address, phone number, message, project links, or booking notes). Broadened the internal-notification legal-basis row accordingly and aligned the Resend data categories with what the notification email carries.
  • v1.4 — August 2026. Clarified error monitoring: the browser Sentry SDK remains consent-gated, while server-side error monitoring runs under legitimate interest with minimized events (no form contents, IP addresses, or cookies). Broadened the rate-limiting disclosure to cover all form endpoints and the article-reaction endpoint, and updated the GA4 safeguards wording (GA4 does not log or store IP addresses).
  • v1.3 — August 2026. Added two optional contact-form fields to the collected-data list and the Pipedrive sub-processor entry: an indicative budget range and how you heard about us.
  • v1.2 — June 2026. Added gated resources (playbook downloads): data collected, time-limited download links, CRM follow-up basis, and the optional newsletter opt-in flow.
  • v1.1 — June 2026. Added a newsletter subscription section (confirmed double opt-in; email stored in Resend as the send list) covering what we store and how to unsubscribe, and updated the Resend sub-processor entry accordingly.
  • v1.0 — Initial publication (May 2026).