Privacy Policy
Last Updated: December 27, 2025
1. Introduction
QODRYX ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI DevOps Command Center platform at qodryx.com.
We comply with the General Data Protection Regulation (GDPR) and Swedish data protection laws. By using QODRYX, you consent to the data practices described in this policy.
2. Data Controller
Company: QODRYX
Location: Ystad, Sweden
Email: privacy@qodryx.com
General Contact: hello@qodryx.com
3. Information We Collect
3.1 Information You Provide
- Account Information: Name, email address, password (hashed)
- Profile Information: Avatar, preferences, settings
- Payment Information: Processed securely via Lemon Squeezy (we don't store card details)
- Repository Access: GitHub repository data you authorize
- Support Communications: Messages you send to our support team
3.2 Information Collected Automatically
- Usage Data: Features used, actions taken, time spent
- Device Information: Browser type, operating system, device type
- Log Data: IP address, access times, pages viewed
- Cookies: As described in our Cookie Policy
3.3 Code and Repository Data
When you connect your GitHub repositories, we access your code solely for the purpose of providing our services (security scanning, code review, etc.). We do not store your code permanently - it is processed in memory and results are stored separately.
4. How We Use Your Information
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide our services | Contract performance |
| Process payments | Contract performance |
| Send service updates | Contract performance |
| Improve our services | Legitimate interest |
| Security monitoring | Legitimate interest |
| Marketing (newsletter) | Consent |
| Analytics | Consent |
5. Third-Party Services
We share data with the following third-party services to provide our platform:
| Service | Purpose | Data Shared |
|---|---|---|
| Vercel | Hosting | IP address, usage data |
| GitHub | Repository scanning | Authorized repository data |
| AI Providers (OpenAI, Anthropic, etc.) | Code analysis | Code snippets for analysis |
| Lemon Squeezy | Payments | Payment information |
| PostgreSQL (Neon/Railway) | Database | All user data (encrypted) |
6. Your Rights (GDPR)
Under GDPR, you have the following rights:
Right to Access
Request a copy of your personal data
Right to Rectification
Correct inaccurate personal data
Right to Erasure
Request deletion of your data ("right to be forgotten")
Right to Data Portability
Export your data in machine-readable format
Right to Restrict Processing
Limit how we use your data
Right to Object
Object to certain processing activities
Right to Withdraw Consent
Revoke consent at any time
Right to Lodge Complaint
File complaint with supervisory authority (IMY in Sweden)
To exercise these rights, contact us at privacy@qodryx.com. We will respond within 30 days.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion + 30 days |
| Usage logs | 90 days |
| Security audit logs | 1 year |
| Payment records | 7 years (legal requirement) |
| Support communications | 2 years |
8. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit (TLS 1.3) and at rest
- Secure password hashing (bcrypt)
- Two-factor authentication support
- Regular security audits
- Access controls and logging
- Regular backups with encryption
9. International Data Transfers
Some of our service providers are located outside the EU/EEA. When we transfer data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or adequacy decisions by the European Commission.
10. Children's Privacy
QODRYX is not intended for users under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through our platform. The "Last Updated" date at the top of this page indicates when the policy was last revised.
12. Contact Us
For privacy-related questions or to exercise your rights:
Email: privacy@qodryx.com
General: hello@qodryx.com
Location: Ystad, Sweden
13. Supervisory Authority
If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection: