Group-based access
What a person can see and do depends on their group. The guide states that read-only users can see permitted lists but cannot create, edit, or delete records.
Read how the apps workBusinessIntents trust center
Review how BusinessIntents controls access inside the application, how codbex ltd operates and secures the service, and the legal terms and notices that apply.
Product documentation shows how permissions and records behave. The linked pages describe the infrastructure, operations, and legal commitments behind the service.
Security and privacy enquiries: privacy@codbex.com. All other enquiries: office@codbex.com.
Document governance
Each linked page carries its own owner and dates; this record covers the Trust Center itself.
Evidence before reassurance
Controls inside the application are described in the product guide and summarized below. Commitments about production infrastructure, company procedures, legal roles, and contractual remedies are made by codbex ltd on the linked pages, each with its own owner and review date. No certification or audit is claimed beyond what those pages state.
Documented application controls
These statements describe application behavior documented in the current BusinessIntents guide. They are not certifications or infrastructure guarantees.
What a person can see and do depends on their group. The guide states that read-only users can see permitted lists but cannot create, edit, or delete records.
Read how the apps workThe Administration workspace is restricted to administrators. System-owned fields remain protected, and final or posted records stay locked.
Review AdministrationAdministration views include created and changed timestamps and the person responsible for the change. Acting for another employee retains the administrator’s real identity in the log.
Review recorded identityBuyer review paths
Each page has a narrow purpose so buyers and reviewers can find an answer without treating silence as assurance.
Amazon Cognito sign-in with MFA, encryption in transit and at rest, restricted staff access, monitoring, vulnerability reporting, and incident handling.
Open SecurityThe privacy notice names codbex ltd as controller and sets out purposes, legal bases, recipients, transfers, retention, and rights.
Open PrivacyService data is hosted by AWS in Frankfurt, with a separate database per customer and daily EU backups kept for 30 days.
Open Data HostingCompany commitments
Who is responsible, what assurance exists, how requests are handled, and how changes are communicated.
BusinessIntents is operated and provided by codbex ltd, a Bulgarian single-member limited liability company (EOOD), EIK 206886587, VAT ID BG206886587, registered in Bulgaria at 160 Tsar Boris III Blvd., 5-11, Sofia 1618, Bulgaria. codbex ltd operates the service and is the contracting party for BusinessIntents subscriptions. The company is incorporated and registered under the laws of the Republic of Bulgaria. Security and privacy enquiries: privacy@codbex.com. Commercial, contractual and procurement enquiries: office@codbex.com.
BusinessIntents does not currently claim any certification, such as ISO 27001 or SOC 2, any independent audit, or any penetration-test report. The security measures on the Security page are codbex ltd's own description of how the service is operated. The underlying infrastructure is provided by Amazon Web Services, whose independent assurance reports are available through AWS Artifact; those reports cover AWS's infrastructure, not the BusinessIntents application.
Security questions, security questionnaires, and vulnerability reports: privacy@codbex.com; acknowledged within 5 working days, with a completion date agreed for questionnaires based on their scope. Privacy and data-subject requests: privacy@codbex.com; answered within one month, as described in the privacy notice. Contract documents, such as the Data Processing Agreement, an Order, or a support schedule, and all commercial and procurement questions: office@codbex.com. If a request is not answered within the stated time, reply to the original message or write to office@codbex.com with the request details.
Material changes to the Terms of Service and the privacy notice are announced to customer account administrators through the service or by email before they take effect. New or replaced subprocessors are published on the Subprocessors page before they begin processing customer personal data. Changes to security, hosting, or cookie practices are published on the relevant page with a new review date. Security incidents that affect customer data are notified by email to the customer's registered contact without undue delay.
Supporting documents
Documents that are not published on this site are provided on request.
Trust and legal library
Use the focused pages for technical, privacy, hosting, contractual, cookie, and supplier questions.
Application controls, authentication, encryption, staff access, and incident handling.
Open page →Personal dataRoles, purposes, legal bases, transfers, retention, and rights.
Open page →InfrastructureAWS Frankfurt, separate customer databases, daily backups kept 30 days, deletion within 60 days.
Open page →ContractThe Terms of Service, effective 17 September 2026.
Open page →Website dataThe website uses Google Analytics only after your consent, and no advertising.
Open page →Service providersAWS and Google Workspace, with locations, safeguards, and the change process.
Open page →Trust center questions
No. BusinessIntents does not currently claim ISO 27001, SOC 2, or any other certification or independent audit. AWS's own assurance reports cover the underlying infrastructure only.
The current product guide documents group-based permissions, administrator-only access, protected system fields, locked final records, personal-record visibility, and created or changed responsibility fields.
On the Security page (sign-in, encryption, staff access, monitoring, vulnerability handling, and incident response) and the Data Hosting page (AWS Frankfurt, separate customer databases, backups, recovery, logs, and deletion).
Write to privacy@codbex.com for security and privacy questions, or to office@codbex.com for contract documents and commercial questions. Security questions and questionnaires are acknowledged within 5 working days; privacy requests are answered within one month, and we may ask for the minimum information needed to confirm the requester's identity.
Continue the review
Send due-diligence questions to privacy@codbex.com and contract requests to office@codbex.com.
Security and privacy enquiries: privacy@codbex.com. All other enquiries: office@codbex.com.