Skip to content

BusinessIntents trust center

Put every trust question in one reviewable place.

Review how BusinessIntents controls access inside the application, how codbex ltd operates and secures the service, and the legal terms and notices that apply.

Product documentation shows how permissions and records behave. The linked pages describe the infrastructure, operations, and legal commitments behind the service.

Security and privacy enquiries: privacy@codbex.com. All other enquiries: office@codbex.com.

SecurityPrivacyData hostingLegal termsSubprocessors

Document governance

The accountable owner and applicable version.

Each linked page carries its own owner and dates; this record covers the Trust Center itself.

Document owner
Legal Advisor, codbex ltd
Effective date
24 September 2026
Last reviewed
24 September 2026
Review frequency
At least once a year, and whenever a linked security, privacy, hosting, legal, cookie, or subprocessor page changes.

Evidence before reassurance

Documented behavior and operational commitments, kept apart.

Controls inside the application are described in the product guide and summarized below. Commitments about production infrastructure, company procedures, legal roles, and contractual remedies are made by codbex ltd on the linked pages, each with its own owner and review date. No certification or audit is claimed beyond what those pages state.

Documented application controls

Start with behavior the product guide already explains.

These statements describe application behavior documented in the current BusinessIntents guide. They are not certifications or infrastructure guarantees.

01

Group-based access

What a person can see and do depends on their group. The guide states that read-only users can see permitted lists but cannot create, edit, or delete records.

Read how the apps work
02

Administrator boundaries

The Administration workspace is restricted to administrators. System-owned fields remain protected, and final or posted records stay locked.

Review Administration
03

Recorded responsibility

Administration views include created and changed timestamps and the person responsible for the change. Acting for another employee retains the administrator’s real identity in the log.

Review recorded identity

Buyer review paths

Move from the trust question to the relevant detail.

Each page has a narrow purpose so buyers and reviewers can find an answer without treating silence as assurance.

01

Security

Amazon Cognito sign-in with MFA, encryption in transit and at rest, restricted staff access, monitoring, vulnerability reporting, and incident handling.

Open Security
02

Privacy

The privacy notice names codbex ltd as controller and sets out purposes, legal bases, recipients, transfers, retention, and rights.

Open Privacy
03

Data hosting

Service data is hosted by AWS in Frankfurt, with a separate database per customer and daily EU backups kept for 30 days.

Open Data Hosting

Company commitments

What buyers cannot verify from product documentation.

Who is responsible, what assurance exists, how requests are handled, and how changes are communicated.

Company identity and responsibility

BusinessIntents is operated and provided by codbex ltd, a Bulgarian single-member limited liability company (EOOD), EIK 206886587, VAT ID BG206886587, registered in Bulgaria at 160 Tsar Boris III Blvd., 5-11, Sofia 1618, Bulgaria. codbex ltd operates the service and is the contracting party for BusinessIntents subscriptions. The company is incorporated and registered under the laws of the Republic of Bulgaria. Security and privacy enquiries: privacy@codbex.com. Commercial, contractual and procurement enquiries: office@codbex.com.

Assurance and certifications

BusinessIntents does not currently claim any certification, such as ISO 27001 or SOC 2, any independent audit, or any penetration-test report. The security measures on the Security page are codbex ltd's own description of how the service is operated. The underlying infrastructure is provided by Amazon Web Services, whose independent assurance reports are available through AWS Artifact; those reports cover AWS's infrastructure, not the BusinessIntents application.

Request handling

Security questions, security questionnaires, and vulnerability reports: privacy@codbex.com; acknowledged within 5 working days, with a completion date agreed for questionnaires based on their scope. Privacy and data-subject requests: privacy@codbex.com; answered within one month, as described in the privacy notice. Contract documents, such as the Data Processing Agreement, an Order, or a support schedule, and all commercial and procurement questions: office@codbex.com. If a request is not answered within the stated time, reply to the original message or write to office@codbex.com with the request details.

Change communication

Material changes to the Terms of Service and the privacy notice are announced to customer account administrators through the service or by email before they take effect. New or replaced subprocessors are published on the Subprocessors page before they begin processing customer personal data. Changes to security, hosting, or cookie practices are published on the relevant page with a new review date. Security incidents that affect customer data are notified by email to the customer's registered contact without undue delay.

Supporting documents

Documents and how to obtain them.

Documents that are not published on this site are provided on request.

Data Processing AgreementWhere applicable law requires one, codbex ltd and the customer enter into a Data Processing Agreement. No standard document is published on this site. Request the applicable terms from office@codbex.com.
Security questionnaireSend your questionnaire to privacy@codbex.com. We acknowledge it within 5 working days and agree a completion date based on its scope.
Subprocessor listPublished on the Subprocessors page. Changes are published there before a new provider begins processing customer personal data.

Trust and legal library

Review each topic at the right level.

Use the focused pages for technical, privacy, hosting, contractual, cookie, and supplier questions.

Trust center questions

Short answers to common trust questions.

Does this Trust Center claim ISO 27001 or SOC 2 certification?

No. BusinessIntents does not currently claim ISO 27001, SOC 2, or any other certification or independent audit. AWS's own assurance reports cover the underlying infrastructure only.

Which controls are already documented?

The current product guide documents group-based permissions, administrator-only access, protected system fields, locked final records, personal-record visibility, and created or changed responsibility fields.

Where are infrastructure controls described?

On the Security page (sign-in, encryption, staff access, monitoring, vulnerability handling, and incident response) and the Data Hosting page (AWS Frankfurt, separate customer databases, backups, recovery, logs, and deletion).

How can a buyer request more information?

Write to privacy@codbex.com for security and privacy questions, or to office@codbex.com for contract documents and commercial questions. Security questions and questionnaires are acknowledged within 5 working days; privacy requests are answered within one month, and we may ask for the minimum information needed to confirm the requester's identity.

Continue the review

Bring the questions your organization must answer.

Send due-diligence questions to privacy@codbex.com and contract requests to office@codbex.com.

Security and privacy enquiries: privacy@codbex.com. All other enquiries: office@codbex.com.

The BusinessIntents Business Suite - end-user guide.