Personal workspace
The product guide states that personal surfaces show only the signed-in person’s own records, such as expenses, vacation requests, timesheets, payslips, and leads.
Review personal workspacesBusinessIntents privacy
This notice explains how codbex ltd, the company that operates BusinessIntents, collects, uses, shares, and retains personal data, and how you can exercise your rights.
It covers website visitors, people who contact us, customer representatives, and the authorized users of customer accounts. Data that customers enter into their own BusinessIntents environment is processed on the customer's instructions.
Security and privacy enquiries: privacy@codbex.com. All other enquiries: office@codbex.com.
Notice governance
This notice is maintained by codbex ltd and should be read together with the Terms of Service and any Data Processing Agreement concluded with a customer.
Scope of the notice
codbex ltd is the data controller for personal data about website visitors, people who contact us, customer representatives, and authorized users, to the extent needed to run the website, manage the customer relationship, and provide and secure the service. For the business data that a customer enters into its own BusinessIntents environment, such as employee, expense, timesheet, payroll, or sales records, the customer is the controller and codbex ltd processes that data as a processor on the customer's instructions.
Product-level privacy boundaries
The product guide describes the following visibility rules. They support, but do not replace, the contractual and organizational measures described in this notice.
The product guide states that personal surfaces show only the signed-in person’s own records, such as expenses, vacation requests, timesheets, payslips, and leads.
Review personal workspacesVisibility and permitted actions depend on group membership. Read-only users are documented as having no create, edit, or delete controls.
Review permissionsAdministration views include created and changed timestamps and responsible users. Acting for another employee retains the administrator’s identity in the log.
Review administrative recordsWho this notice covers
The data we hold, the reason we hold it, and the person to contact depend on how you interact with BusinessIntents.
If you browse the website or write to us, we process technical request data and the contents of your message, as the controller.
If you represent a customer or sign in to a customer account, we process your contact, account, and usage data to provide, bill, support, and secure the service, as the controller.
If your employer or another customer holds records about you in BusinessIntents, that customer decides how they are used. Address your request to that customer; we will assist it.
Privacy notice
The sections below describe the processing for which codbex ltd is the controller. Processing of customer data on behalf of a customer is additionally governed by the Data Processing Agreement with that customer.
For personal data processed in connection with the BusinessIntents website, customer accounts, subscriptions, the customer relationship and the provision of the service, the data controller is codbex ltd, EIK 206886587, VAT ID BG206886587, 160 Tsar Boris III Blvd., 5-11, Sofia 1618, Bulgaria. codbex ltd determines the purposes and means of that processing in accordance with the General Data Protection Regulation (EU) 2016/679 and applicable Bulgarian legislation. Where BusinessIntents processes personal data on behalf of a customer in functionality that the customer configures or uses, the customer may act as data controller and codbex ltd as data processor; the respective roles depend on the nature and purpose of the processing and are described in the applicable contractual and data protection arrangements. codbex ltd has not appointed a Data Protection Officer or an EU representative, having determined that neither appointment is required for its processing activities. Privacy contact: privacy@codbex.com.
Website visitors: IP address, browser and device information, requested pages, and timestamps, processed to deliver the website and protect it against abuse, based on our legitimate interest (Art. 6(1)(f) GDPR). The website uses Google Analytics (Google Ireland Limited) only after you accept it in the consent banner, based on your consent (Art. 6(1)(a) GDPR), with IP addresses not stored and data possibly transferred to the United States under the EU–U.S. Data Privacy Framework; it uses no advertising or social-media tracking. Your browser may store a display preference, such as light or dark mode, and your consent choice locally on your device. People who contact us: name, email address, company, role, and the content of the message, processed to answer the enquiry and prepare an offer, based on steps taken at your request before a contract (Art. 6(1)(b)) or our legitimate interest in responding to business enquiries (Art. 6(1)(f)). Providing information in an enquiry is voluntary. Where we send business contacts information about BusinessIntents, we do so on the basis of legitimate interest, or consent where the law requires it, and every message includes a way to opt out.
Customer representatives and billing contacts: name, business email, telephone, company, role, billing and payment details, subscription, and invoice history, processed to conclude and perform the contract, invoice, and communicate about the service, based on the contract with the customer (Art. 6(1)(b)), our legitimate interest in managing the relationship with the customer's representatives (Art. 6(1)(f)), and legal obligations under accounting and tax law (Art. 6(1)(c)). Authorized users: name, email or username, authentication data, group membership, IP address, access and security logs, records of who created or changed an entry, and support correspondence, processed to provide the service, verify identity, prevent fraud, investigate incidents, and provide support, based on the contract with the customer and our legitimate interest in running a secure service (Art. 6(1)(b) and (f)). This data comes from you, from the customer that invited you, or is generated when you use the service. Contract, billing, and sign-in data are required to conclude the contract and use the service; without them we cannot provide it.
Personal data is accessible only to codbex ltd staff who need it for their role. We share it with service providers that act as our processors under written data protection terms: Amazon Web Services EMEA SARL for hosting and system emails, and Google Cloud EMEA Limited for Google Workspace email; the current list is published on the Subprocessors page. Subscription payments are processed by Stripe Payments Europe, Limited, which acts as an independent controller for payment processing. We may also disclose data to professional advisers bound by confidentiality, to public authorities where the law requires it, to third-party services that a customer chooses to connect, and to a successor in a merger, acquisition, or sale of the service. codbex ltd does not sell personal data, does not share it for targeted advertising, and does not use customer data for purposes unrelated to providing, maintaining, securing, and improving the service.
The BusinessIntents service, including production data, backups, and service logs, is hosted by Amazon Web Services in the Frankfurt region, Germany, and service data is not transferred outside the European Economic Area. The public website businessintents.com is served by GitHub Pages, a service of GitHub, Inc. in the United States, which processes visitors' IP addresses and request data to deliver the pages; that transfer relies on the EU–U.S. Data Privacy Framework. Email correspondence with office@codbex.com and privacy@codbex.com is handled in Google Workspace, and payments are processed by Stripe; both providers may process data outside the EEA, including in the United States, relying on the EU–U.S. Data Privacy Framework and Standard Contractual Clauses. If another transfer outside the EEA becomes necessary, it will take place only under an adequacy decision or Standard Contractual Clauses approved by the European Commission, and this notice will be updated first. You can request information about the applicable safeguards at privacy@codbex.com.
Customer data in a BusinessIntents environment is kept for the duration of the subscription. After termination or expiration, the customer has 30 days to export it; the data is then deleted from production systems, and residual copies in daily backups are deleted automatically within a further 30 days, so the data is fully removed within 60 days. Account and contract data is kept for the duration of the contract and afterwards for the general five-year limitation period for claims under Bulgarian law. Invoices and accounting records are kept for the periods required by Bulgarian accounting and tax legislation, generally up to ten years. Enquiries that do not lead to a contract are deleted within 24 months of the last communication. Security and access logs are kept only as long as needed to protect the service and investigate incidents, and are then deleted or anonymized. Data may be kept longer only where required by law or needed to establish, exercise, or defend a legal claim.
Under the GDPR you have the right to access your personal data, have it corrected, have it erased, restrict its processing, receive it in a portable format, and object to processing based on legitimate interests, including direct marketing. Where processing is based on consent, you can withdraw consent at any time without affecting earlier processing. codbex ltd does not make decisions with legal or similarly significant effects about you based solely on automated processing. To exercise a right, write to privacy@codbex.com. We may ask for information needed to confirm your identity, but no more than necessary. We respond within one month; for complex or numerous requests this may be extended by two further months, and we will tell you why. Requests are free of charge unless they are manifestly unfounded or excessive. If your request concerns data that a customer holds in its BusinessIntents environment, we will forward it to that customer and assist it in responding. You may lodge a complaint with the Bulgarian Commission for Personal Data Protection (2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, www.cpdp.bg) or with the supervisory authority in the EU country where you live or work.
codbex ltd implements reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, and misuse, including group-based permissions and records of who created or changed data. No internet-based service can be guaranteed to be completely secure. If a personal data breach occurs, we notify the supervisory authority and affected people where the GDPR requires it, and customers in accordance with the Data Processing Agreement.
BusinessIntents is a service for businesses and organizations and is not directed at children. We do not knowingly collect personal data from anyone under 16. As controller, codbex ltd does not intentionally collect special categories of personal data. Customers that use HR or payroll functions may record such data about their employees, for example absence reasons; in that case the customer is the controller and is responsible for having a lawful basis and for limiting access to it.
We update this notice when our processing, providers, or legal obligations change. The updated version is published on this page with a new effective date. Material changes are also announced to customer account administrators through the service or by email before they take effect. Earlier versions are available on request from privacy@codbex.com.
Privacy documents
Documents that are not published here are provided on request.
Related privacy information
These pages describe the infrastructure, technologies, providers, and contract terms referred to in this notice.
Review the complete trust and legal library.
Open page →InfrastructureConfirm where service data, backups, and operational logs are stored.
Open page →WebsiteInventory cookies and related technologies used by the website.
Open page →Service providersIdentify processors, locations, services, and transfer arrangements.
Open page →ContractAlign account, service, termination, and customer-responsibility terms.
Open page →Privacy questions
codbex ltd is the controller for website, enquiry, customer-relationship, account, billing, support, and security data. For the business records a customer enters into its own BusinessIntents environment, the customer is the controller and codbex ltd processes that data on the customer's instructions under a Data Processing Agreement.
Customer data is kept for the subscription and deleted 30 days after it ends; backup copies expire within a further 30 days. Contract data is kept for the five-year limitation period, accounting records generally for up to ten years as Bulgarian law requires, and enquiries that do not lead to a contract for up to 24 months.
Write to privacy@codbex.com. We confirm your identity with no more information than necessary and respond within one month, which may be extended by two months for complex requests. Requests about data a customer holds in BusinessIntents are forwarded to that customer. You can also complain to the Bulgarian Commission for Personal Data Protection or your local supervisory authority.
Service data, including backups and logs, is hosted by AWS in Frankfurt and is not transferred outside the EEA. The public website is served by GitHub Pages, and email and payments are handled by Google Workspace and Stripe; these providers may process data in the United States under the EU–U.S. Data Privacy Framework and Standard Contractual Clauses.
Privacy requests
Send access, correction, deletion, and other privacy requests to privacy@codbex.com. We respond within one month.
Security and privacy enquiries: privacy@codbex.com. All other enquiries: office@codbex.com.