This Privacy Policy explains how we collect and use personal data when you visit codezen.tech, contact us, or interact with our LinkedIn page through our LinkedIn application (see section 2.4). It is provided in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”), the Italian Personal Data Protection Code (Legislative Decree 196/2003, as amended) and the ePrivacy Directive 2002/58/EC.
1. Data controller
The controller of your personal data is:
Codezen S.r.l.
Via Traiana 10, 00037 Segni (RM), Italy
VAT: IT16941791002
Email: info@codezen.tech
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. For any privacy-related request, write to the email address above.
2. Personal data we process, purposes and legal bases
2.1 Audit requests and email correspondence
When you fill in the “Request an audit” form or email us, we process your name, email address, project or protocol name and any information you include in your message.
- Purpose: responding to your enquiry, scoping an engagement and preparing a quote.
- Legal basis: steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR) and, for general enquiries, our legitimate interest in answering the messages we receive (Art. 6(1)(f) GDPR).
Name and email are required to reply to you. Please do not include sensitive personal data or confidential secrets such as private keys in the form.
2.2 Technical data (server logs)
When you load the site, our hosting provider automatically processes technical data such as your IP address, browser type, requested URL, referrer and timestamp.
- Purpose: delivering the website and keeping it secure and available.
- Legal basis: our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).
2.3 Analytics
With your consent, we use Google Analytics 4 and Microsoft Clarity to understand how visitors use the site: pages viewed, time on page, clicks, scrolling, approximate location, device and browser information. Microsoft Clarity may also record anonymised session replays and heatmaps; text entered in form fields is masked.
- Purpose: measuring traffic and improving the content and usability of the site.
- Legal basis: your consent (Art. 6(1)(a) GDPR and Art. 122 of the Italian Privacy Code). You can withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
2.4 LinkedIn application
We operate an internal application that connects to the LinkedIn API to manage the Codezen company page. Only authorised Codezen staff sign in to it with their LinkedIn accounts. The application is used to:
- publish posts on the Codezen LinkedIn page;
- read aggregated analytics for our page and posts (followers, impressions, engagement);
- read comments, reactions and mentions relating to our page and posts, so we can respond to them.
Through the application we process:
- Codezen staff: the LinkedIn member ID, name and access token needed to authenticate and act on behalf of the company page;
- LinkedIn members who interact with our page: the public profile information LinkedIn returns with a comment, reaction or mention (such as name, headline, profile picture and member ID) and the content of the comment or post. Page analytics are received from LinkedIn in aggregated form and do not identify individual members.
- Purpose: managing our company page, measuring the performance of our content and responding to people who engage with it.
- Legal basis: our legitimate interest in managing our professional presence on LinkedIn and communicating with our audience (Art. 6(1)(f) GDPR).
- Source: this data is obtained from LinkedIn Ireland Unlimited Company via the LinkedIn API (Art. 14 GDPR). It is limited to what you have made visible on our page and to what LinkedIn's API permissions allow.
- Storage: the application does not store LinkedIn data or access tokens. Data is retrieved from LinkedIn when needed, displayed to authorised staff and discarded when the request ends.
We use LinkedIn data only for the purposes above and in line with the LinkedIn API Terms of Use . We do not sell it, share it with third parties, combine it with other data, use it for advertising or profiling, or use it to train machine-learning models. Staff can revoke the application's access at any time in their LinkedIn settings under Data privacy › Permitted services. The processing of your data by LinkedIn itself is governed by the LinkedIn Privacy Policy .
2.5 Legal obligations and legal claims
If we enter into a contract with you, we process the data needed for invoicing, accounting and tax purposes (Art. 6(1)(c) GDPR), and we may process data where necessary to establish, exercise or defend legal claims (Art. 6(1)(f) GDPR).
3. Cookies and similar technologies
Our site does not set any first-party cookies needed for it to work. The analytics tools described above set the following cookies only after you have given consent:
| Cookie | Provider | Purpose | Duration |
|---|---|---|---|
_ga | Distinguishes unique visitors | 2 years | |
_ga_<ID> | Maintains session state | 2 years | |
_clck | Microsoft | Stores the Clarity user ID and preferences | 1 year |
_clsk | Microsoft | Groups page views into a single session | 1 day |
You can change your choice at any time using “Cookie settings” in the footer of every page; withdrawing consent deletes these cookies. You can also delete cookies through your browser settings. Refusing analytics cookies has no effect on your ability to use the site.
4. Recipients and processors
We do not sell your personal data. We share it only with service providers that process it on our behalf under a data processing agreement (Art. 28 GDPR):
- GitHub, Inc. (USA): website hosting via GitHub Pages.
- EmailJS: delivery of contact form submissions to our inbox.
- Google Ireland Ltd. / Google LLC: Google Analytics.
- Microsoft Ireland Operations Ltd. / Microsoft Corporation: Microsoft Clarity.
- Our email and productivity software providers, accountants and legal advisers.
LinkedIn Ireland Unlimited Company is not our processor: it is an independent controller and the source of the data described in section 2.4. We do not share LinkedIn data with any of the recipients above.
We may also disclose data to public authorities where required by law.
5. Transfers outside the European Economic Area
Some of the providers above are based in, or may access data from, the United States. Where this happens, transfers rely on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, for recipients certified under it, or on Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR). You can request a copy of the relevant safeguards by writing to us.
6. How long we keep your data
- Enquiries that do not lead to an engagement: up to 24 months after our last exchange, then deleted.
- Client data and invoices: for the duration of the contract and then for 10 years, as required by Italian accounting and tax law (Art. 2220 of the Italian Civil Code).
- Analytics data: up to 14 months in Google Analytics; Microsoft Clarity keeps session recordings for 30 days and aggregated data for up to 13 months.
- LinkedIn data: not stored by us; it is held only in memory for the duration of the request in which it is retrieved.
- Server logs: according to the hosting provider's retention policy, normally no longer than 90 days.
7. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy of it (Art. 15);
- have inaccurate data rectified (Art. 16);
- have your data erased (Art. 17);
- restrict processing (Art. 18);
- receive your data in a portable format (Art. 20);
- object at any time to processing based on our legitimate interests (Art. 21);
- withdraw your consent at any time (Art. 7(3)).
To exercise these rights, email info@codezen.tech. We will reply within one month, which may be extended by two further months for complex requests. We may ask you to verify your identity.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state where you live or work or where the alleged infringement took place. In Italy this is the Garante per la protezione dei dati personali .
8. Automated decision-making
We do not use your personal data for decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).
9. Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss or alteration, including encrypted connections (HTTPS) and restricted access to our mailboxes and systems.
10. Children
Our services are aimed at businesses. We do not knowingly collect personal data from anyone under 16 years of age.
11. Changes to this policy
We may update this Privacy Policy from time to time. The latest version is always available on this page, with the date of the last update shown at the top. If a change is significant, we will notify you by other means where appropriate.