Skip to content

BusinessIntents privacy

How personal data is handled in BusinessIntents.

This notice explains how codbex ltd, the company that operates BusinessIntents, collects, uses, shares, and retains personal data, and how you can exercise your rights.

It covers website visitors, people who contact us, customer representatives, and the authorized users of customer accounts. Data that customers enter into their own BusinessIntents environment is processed on the customer's instructions.

Security and privacy enquiries: privacy@codbex.com. All other enquiries: office@codbex.com.

IdentityPurposesRightsRetentionSharing

Notice governance

The accountable owner and applicable version.

This notice is maintained by codbex ltd and should be read together with the Terms of Service and any Data Processing Agreement concluded with a customer.

Notice owner
Legal Advisor, codbex ltd
Effective date
17 September 2026
Last reviewed
24 September 2026
Review frequency
At least once a year, and whenever a new purpose, provider, hosting location, product feature, or legal requirement affects personal data.

Scope of the notice

codbex ltd has different roles in different relationships.

codbex ltd is the data controller for personal data about website visitors, people who contact us, customer representatives, and authorized users, to the extent needed to run the website, manage the customer relationship, and provide and secure the service. For the business data that a customer enters into its own BusinessIntents environment, such as employee, expense, timesheet, payroll, or sales records, the customer is the controller and codbex ltd processes that data as a processor on the customer's instructions.

Product-level privacy boundaries

How the product limits who sees personal data.

The product guide describes the following visibility rules. They support, but do not replace, the contractual and organizational measures described in this notice.

01

Personal workspace

The product guide states that personal surfaces show only the signed-in person’s own records, such as expenses, vacation requests, timesheets, payslips, and leads.

Review personal workspaces
02

Group permissions

Visibility and permitted actions depend on group membership. Read-only users are documented as having no create, edit, or delete controls.

Review permissions
03

Recorded responsibility

Administration views include created and changed timestamps and responsible users. Acting for another employee retains the administrator’s identity in the log.

Review administrative records

Who this notice covers

Find the relationship that applies to you.

The data we hold, the reason we hold it, and the person to contact depend on how you interact with BusinessIntents.

01

Visitors and enquiries

If you browse the website or write to us, we process technical request data and the contents of your message, as the controller.

02

Customers and users

If you represent a customer or sign in to a customer account, we process your contact, account, and usage data to provide, bill, support, and secure the service, as the controller.

03

People in customer data

If your employer or another customer holds records about you in BusinessIntents, that customer decides how they are used. Address your request to that customer; we will assist it.

Privacy notice

What we process, why, for how long, and your rights.

The sections below describe the processing for which codbex ltd is the controller. Processing of customer data on behalf of a customer is additionally governed by the Data Processing Agreement with that customer.

Legal identity and data roles

For personal data processed in connection with the BusinessIntents website, customer accounts, subscriptions, the customer relationship and the provision of the service, the data controller is codbex ltd, EIK 206886587, VAT ID BG206886587, 160 Tsar Boris III Blvd., 5-11, Sofia 1618, Bulgaria. codbex ltd determines the purposes and means of that processing in accordance with the General Data Protection Regulation (EU) 2016/679 and applicable Bulgarian legislation. Where BusinessIntents processes personal data on behalf of a customer in functionality that the customer configures or uses, the customer may act as data controller and codbex ltd as data processor; the respective roles depend on the nature and purpose of the processing and are described in the applicable contractual and data protection arrangements. codbex ltd has not appointed a Data Protection Officer or an EU representative, having determined that neither appointment is required for its processing activities. Privacy contact: privacy@codbex.com.

Website visitors and enquiries

Website visitors: IP address, browser and device information, requested pages, and timestamps, processed to deliver the website and protect it against abuse, based on our legitimate interest (Art. 6(1)(f) GDPR). The website uses Google Analytics (Google Ireland Limited) only after you accept it in the consent banner, based on your consent (Art. 6(1)(a) GDPR), with IP addresses not stored and data possibly transferred to the United States under the EU–U.S. Data Privacy Framework; it uses no advertising or social-media tracking. Your browser may store a display preference, such as light or dark mode, and your consent choice locally on your device. People who contact us: name, email address, company, role, and the content of the message, processed to answer the enquiry and prepare an offer, based on steps taken at your request before a contract (Art. 6(1)(b)) or our legitimate interest in responding to business enquiries (Art. 6(1)(f)). Providing information in an enquiry is voluntary. Where we send business contacts information about BusinessIntents, we do so on the basis of legitimate interest, or consent where the law requires it, and every message includes a way to opt out.

Customers and authorized users

Customer representatives and billing contacts: name, business email, telephone, company, role, billing and payment details, subscription, and invoice history, processed to conclude and perform the contract, invoice, and communicate about the service, based on the contract with the customer (Art. 6(1)(b)), our legitimate interest in managing the relationship with the customer's representatives (Art. 6(1)(f)), and legal obligations under accounting and tax law (Art. 6(1)(c)). Authorized users: name, email or username, authentication data, group membership, IP address, access and security logs, records of who created or changed an entry, and support correspondence, processed to provide the service, verify identity, prevent fraud, investigate incidents, and provide support, based on the contract with the customer and our legitimate interest in running a secure service (Art. 6(1)(b) and (f)). This data comes from you, from the customer that invited you, or is generated when you use the service. Contract, billing, and sign-in data are required to conclude the contract and use the service; without them we cannot provide it.

Recipients, sharing, and sale

Personal data is accessible only to codbex ltd staff who need it for their role. We share it with service providers that act as our processors under written data protection terms: Amazon Web Services EMEA SARL for hosting and system emails, and Google Cloud EMEA Limited for Google Workspace email; the current list is published on the Subprocessors page. Subscription payments are processed by Stripe Payments Europe, Limited, which acts as an independent controller for payment processing. We may also disclose data to professional advisers bound by confidentiality, to public authorities where the law requires it, to third-party services that a customer chooses to connect, and to a successor in a merger, acquisition, or sale of the service. codbex ltd does not sell personal data, does not share it for targeted advertising, and does not use customer data for purposes unrelated to providing, maintaining, securing, and improving the service.

International transfers

The BusinessIntents service, including production data, backups, and service logs, is hosted by Amazon Web Services in the Frankfurt region, Germany, and service data is not transferred outside the European Economic Area. The public website businessintents.com is served by GitHub Pages, a service of GitHub, Inc. in the United States, which processes visitors' IP addresses and request data to deliver the pages; that transfer relies on the EU–U.S. Data Privacy Framework. Email correspondence with office@codbex.com and privacy@codbex.com is handled in Google Workspace, and payments are processed by Stripe; both providers may process data outside the EEA, including in the United States, relying on the EU–U.S. Data Privacy Framework and Standard Contractual Clauses. If another transfer outside the EEA becomes necessary, it will take place only under an adequacy decision or Standard Contractual Clauses approved by the European Commission, and this notice will be updated first. You can request information about the applicable safeguards at privacy@codbex.com.

Retention and deletion

Customer data in a BusinessIntents environment is kept for the duration of the subscription. After termination or expiration, the customer has 30 days to export it; the data is then deleted from production systems, and residual copies in daily backups are deleted automatically within a further 30 days, so the data is fully removed within 60 days. Account and contract data is kept for the duration of the contract and afterwards for the general five-year limitation period for claims under Bulgarian law. Invoices and accounting records are kept for the periods required by Bulgarian accounting and tax legislation, generally up to ten years. Enquiries that do not lead to a contract are deleted within 24 months of the last communication. Security and access logs are kept only as long as needed to protect the service and investigate incidents, and are then deleted or anonymized. Data may be kept longer only where required by law or needed to establish, exercise, or defend a legal claim.

Rights and complaints

Under the GDPR you have the right to access your personal data, have it corrected, have it erased, restrict its processing, receive it in a portable format, and object to processing based on legitimate interests, including direct marketing. Where processing is based on consent, you can withdraw consent at any time without affecting earlier processing. codbex ltd does not make decisions with legal or similarly significant effects about you based solely on automated processing. To exercise a right, write to privacy@codbex.com. We may ask for information needed to confirm your identity, but no more than necessary. We respond within one month; for complex or numerous requests this may be extended by two further months, and we will tell you why. Requests are free of charge unless they are manifestly unfounded or excessive. If your request concerns data that a customer holds in its BusinessIntents environment, we will forward it to that customer and assist it in responding. You may lodge a complaint with the Bulgarian Commission for Personal Data Protection (2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, www.cpdp.bg) or with the supervisory authority in the EU country where you live or work.

Security

codbex ltd implements reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, and misuse, including group-based permissions and records of who created or changed data. No internet-based service can be guaranteed to be completely secure. If a personal data breach occurs, we notify the supervisory authority and affected people where the GDPR requires it, and customers in accordance with the Data Processing Agreement.

Children and sensitive data

BusinessIntents is a service for businesses and organizations and is not directed at children. We do not knowingly collect personal data from anyone under 16. As controller, codbex ltd does not intentionally collect special categories of personal data. Customers that use HR or payroll functions may record such data about their employees, for example absence reasons; in that case the customer is the controller and is responsible for having a lawful basis and for limiting access to it.

Changes to the notice

We update this notice when our processing, providers, or legal obligations change. The updated version is published on this page with a new effective date. Material changes are also announced to customer account administrators through the service or by email before they take effect. Earlier versions are available on request from privacy@codbex.com.

Privacy documents

Documents behind the privacy relationship.

Documents that are not published here are provided on request.

Data Processing AgreementWhere applicable law requires one, codbex ltd and the customer enter into a Data Processing Agreement. No standard document is published on this site. Request the applicable terms from office@codbex.com.
Data-subject requestsSend requests to privacy@codbex.com. No form is required: say which right you want to exercise and which relationship with BusinessIntents applies to you.
Earlier notice versionsThis is the first published version. Superseded versions and their effective periods will be available on request from privacy@codbex.com.

Related privacy information

Connect the notice to hosting, cookies, suppliers, and contract terms.

These pages describe the infrastructure, technologies, providers, and contract terms referred to in this notice.

Privacy questions

Short answers to common privacy questions.

Who controls personal data in BusinessIntents?

codbex ltd is the controller for website, enquiry, customer-relationship, account, billing, support, and security data. For the business records a customer enters into its own BusinessIntents environment, the customer is the controller and codbex ltd processes that data on the customer's instructions under a Data Processing Agreement.

How long is personal data retained?

Customer data is kept for the subscription and deleted 30 days after it ends; backup copies expire within a further 30 days. Contract data is kept for the five-year limitation period, accounting records generally for up to ten years as Bulgarian law requires, and enquiries that do not lead to a contract for up to 24 months.

How can a person request deletion or access?

Write to privacy@codbex.com. We confirm your identity with no more information than necessary and respond within one month, which may be extended by two months for complex requests. Requests about data a customer holds in BusinessIntents are forwarded to that customer. You can also complain to the Bulgarian Commission for Personal Data Protection or your local supervisory authority.

Does BusinessIntents transfer data internationally?

Service data, including backups and logs, is hosted by AWS in Frankfurt and is not transferred outside the EEA. The public website is served by GitHub Pages, and email and payments are handled by Google Workspace and Stripe; these providers may process data in the United States under the EU–U.S. Data Privacy Framework and Standard Contractual Clauses.

Privacy requests

Ask about your data.

Send access, correction, deletion, and other privacy requests to privacy@codbex.com. We respond within one month.

Security and privacy enquiries: privacy@codbex.com. All other enquiries: office@codbex.com.

The BusinessIntents Business Suite - end-user guide.