Legal

Privacy Policy

How Codeaex handles personal data across the AMS platform and this website.

Last updated 24 September 2026

1. Who we are

Codeaex ("we", "us", "our") operates the Accreditation Management System ("AMS", "the platform"). This policy explains what personal data we handle, why, and what rights you have over it.

For any privacy question or request, write to corp@codeaex.com.

2. Controller and processor

Where you visit this website or contact us, Codeaex acts as the data controller.

Where your organization uses the platform, your organization is the controller of the records it holds — assessors, trainers, applicants, cases and evidence — and Codeaex acts as a processor, handling that data on your documented instructions under our Data Processing Addendum.

3. Data we collect

Depending on how you interact with us, we handle:

  • Enquiry data: the name, work email, organization, phone number and message you send us.
  • Account data: the name, email address and role of users provisioned into a workspace.
  • Google sign-in data: if you choose to sign in with Google, the name, email address and Google account identifier that Google shares with us (see section 4).
  • Operational data: the records your organization enters — assessors, trainers, applications, assessments, documents, certificates and invoices.
  • Technical data: server logs, including IP address, request time and user agent, retained for security and reliability.

4. Signing in with Google

Assessors can create an account or sign in with their Google account instead of a password. When you do, Google shares three things with us, and only with your permission: your name, your email address (with confirmation that Google has verified it), and a Google account identifier.

  • We use them only to create your assessor account, recognise you when you sign in again, and pre-fill the name on your application.
  • We do not request access to your Gmail, Google Drive, contacts, calendar or any other Google service, and we never receive your Google password.
  • We do not sell this data, use it for advertising, or share it with anyone outside the accreditation body you applied to, except the service providers described in section 8.
  • Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can stop using Google sign-in at any time: set a password with "Reset Password" on the assessor sign-in page, and remove our access from your Google Account under Security, Third-party apps. To have the account itself deleted, see section 10.

5. How we use it

We use personal data to:

  • Provide, operate and secure the platform.
  • Respond to enquiries and provide support.
  • Provision workspaces and manage user access.
  • Meet legal, contractual and accounting obligations.
  • Diagnose faults and improve reliability.

We do not sell personal data, and we do not share it with third parties for their own marketing.

Where the GDPR or equivalent legislation applies, we rely on: performance of a contract (operating the platform for your organization); legitimate interests (securing the service, responding to enquiries you initiate); and legal obligation (accounting and statutory record-keeping).

7. Retention

Enquiry correspondence is retained while it remains commercially relevant. Operational data is retained for the term of your organization's agreement and any period specified in it. Technical logs are retained for a limited period for security and reliability purposes.

On termination, operational data is returned or deleted in line with the agreement in force.

8. Service providers

We use a small number of infrastructure and communication providers to host and operate the platform. They act on our instructions, under contract, and are not permitted to use the data for their own purposes.

A current list of subprocessors is available on request from corp@codeaex.com.

9. Security

Each organization operates in an isolated workspace. Access is role-based, onboarding is invite-only, credentials are stored hashed, and actions across the platform are recorded in an audit trail.

No system is perfectly secure, but we design for containment: a problem in one area should not expose another organization's records.

10. Your rights

Subject to applicable law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, or object to processing.

If your data sits inside an organization's workspace, direct the request to that organization first; we will support them in fulfilling it. Otherwise write to corp@codeaex.com. You also have the right to complain to your local supervisory authority.

11. Changes to this policy

We may update this policy as the platform develops. Material changes will be communicated to organization administrators, and the revision date above will be updated.

12. Contact

Privacy questions, requests and complaints: corp@codeaex.com.