Privacy Policy

Last Updated: 12th June 2026


Who we are

Codebii is a limited company registered in Guernsey, Channel Islands (Company No. 77918).

We are the data controller for the personal data collected through this website and in the course of our client relationships, and we are registered as a data controller with the Office of the Data Protection Authority (ODPA), Registration No. DPA11576. We also act as a data processor on behalf of our clients in certain circumstances - see "Personal data we process on behalf of clients" below.


What this policy covers

This policy explains what personal data we collect when you visit our website or engage our services, how we use it, and your rights in relation to it.

We are committed to protecting your privacy and handling your data responsibly in accordance with the Data Protection (Bailiwick of Guernsey) Law, 2017.

Guernsey has been granted adequacy status by both the European Union and the United Kingdom, meaning our data protection standards are recognised as equivalent to those of the EU and UK respectively.


The data protection principles we follow

Under the Data Protection (Bailiwick of Guernsey) Law, 2017 we are committed to ensuring that personal data is:


What data we collect and why

Contact form submissions

When you submit an enquiry via our contact form we collect:

Why we collect this

To respond to your enquiry and assess how we can help with your project. Enquiry details may also be recorded in our project management tool (Trello) to manage our response and any follow-up.

Legal basis

Legitimate interests; processing the information you provide is necessary to respond to your enquiry and take steps at your request prior to entering into a contract.

How long we keep it

Contact form submissions are retained for up to 2 years from the date of submission, after which they are automatically and permanently deleted from our database. Automated deletion runs on the first of every month. Notification emails received in our inbox are also retained for up to 2 years and reviewed periodically for deletion. You may request deletion at any time by contacting us at privacy@codebii.dev.

Where does this data come from?

The personal data described above is provided to us directly by you, when you contact us, use our website, or engage our services, or by someone acting on your behalf. We do not collect personal data about website visitors, enquirers, or clients from any other source.

Personal data we process on behalf of clients

Separately from the data we collect through this website, we provide web and software development services to client organisations. In the course of that work, we may have access to, or process, personal data held within a client's own systems or software - for example, details of their customers, users or staff.

Where this happens, the client organisation is the data controller for that personal data and we act only as a data processor, processing it solely on the client's documented instructions. This processing is governed by a written data processing agreement between us and the client, as required by sections 34 and 35 of the Data Protection (Bailiwick of Guernsey) Law, 2017.

We do not store our clients' customer or user data, databases, or system backups in our own storage - that data remains within the client's own systems at all times, and we access it there only as needed to perform our services.

We do not use any such data for our own purposes, and this privacy policy does not govern it - the relevant client organisation's own privacy information applies to those individuals. If you believe your personal data is held within a client's system that we work on and you wish to exercise your rights, please contact that organisation, who will direct any instructions to us as their processor.


Cookies

We do not set any cookies on this website. However Cloudflare, which provides security and performance services for this site, may set a cookie named __cf_build for the purpose of identifying trusted web traffic and protecting against bots. This is a strictly necessary cookie and does not track you for advertising purposes. For more information, see Cloudflare's privacy policy at www.cloudflare.com/en-gb/privacypolicy.


Analytics

We do not use any dedicated analytics tools on this website and do not actively track visitor behaviour.

However, as part of providing website security and performance services, Cloudflare automatically processes certain technical data about visitors - including IP addresses, request metadata and geographic location. This data is processed by Cloudflare in accordance with their privacy policy, available at www.cloudflare.com/en-gb/privacypolicy.

Aggregated and anonymised visitor location data - which cannot identify individual visitors - may be used to inform our marketing strategy, such as identifying regions where our services are in demand.


How we store and protect your data

Contact form data

Contact form submissions are stored securely in a database provided by Supabase, hosted within the European Union. Access is strictly limited and protected by technical security controls including encryption at rest and in transit.

Email notifications

When you submit the contact form, a notification email containing your enquiry details is sent to us via Amazon Web Services Simple Email Service (AWS SES) and stored in our Microsoft 365 business inbox. These emails are retained for up to 2 years and reviewed periodically for deletion in line with our data retention policy. Emails are only accessible to the individual operating this business.

Client and contract data

Contracts, proposals, and engagement records - including scanned copies of signed contracts - are stored in encrypted cloud storage (Microsoft OneDrive for Business), with access limited and protected by multi-factor authentication. Enquiry and client relationship information may also be recorded in Trello for project management purposes.

Security measures

We take reasonable technical and organisational steps to protect your personal data against unauthorised access, loss or destruction. These include encrypted data storage, access controls and secure data transmission over HTTPS. Automated data deletion is enforced at the database level and an audit log is maintained recording every deletion run for accountability purposes.


Third parties we use

We use the following third party services to operate this website. Each acts as a data processor on our behalf and is bound by contractual obligations to protect your data:

Service: Supabase

Purpose: Data storage

Location: EU

Privacy Policy: supabase.com/privacy

Service: AWS SES

Purpose: Email notification delivery

Location: EU

Privacy Policy: aws.amazon.com/privacy

Service: AWS Amplify / CloudFront

Purpose: Website hosting and delivery

Location: Global CDN

Privacy Policy: aws.amazon.com/privacy

Service: Cloudflare

Purpose: DNS, security, performance and bot protection

Location: Global

Privacy Policy: www.cloudflare.com/en-gb/privacypolicy

Service: Microsoft 365 / OneDrive

Purpose: Business email, storage of contracts, proposals, and engagement records

Location: EU

Privacy Policy: www.microsoft.com/en-gb/privacy/privacystatement

Service: Atlassian

Purpose: Project management, client work tracking, source code management and version control

Location: Global (US)

Privacy Policy: www.atlassian.com/legal/privacy-policy

Service: Github (Owned By Microsoft)

Purpose: Public (non-client) source code management

Location: Global (US)

Privacy Policy: docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement

We do not sell your personal data to any third party. We do not use your personal data for advertising purposes.


International data transfers

Some of our third-party service providers operate globally, meaning your data may be processed outside of Guernsey. Where this occurs, we ensure that appropriate safeguards are in place in accordance with the Data Protection (Bailiwick of Guernsey) Law, 2017 to protect your data to an equivalent standard.


Data breach notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms we will notify the Office of the Data Protection Authority (ODPA) without undue delay and, where required, notify you directly.


Your rights

Under the Data Protection (Bailiwick of Guernsey) Law, 2017 you have the following rights:

To exercise any of these rights please contact us at privacy@codebii.dev. We will respond within 30 days of receiving your request. In complex cases we may extend this by a further 60 days and will notify you accordingly. Please note that we may need to retain certain data where the law requires or permits it - for example, executed contracts retained for limitation purposes.

There is no charge for making a Subject Access Request. We reserve the right to charge a reasonable administrative fee where a request is manifestly unfounded or manifestly excessive, particularly where it is repetitive in nature. We will notify you of any applicable fee before proceeding.


Complaints

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with The Office of the Data Protection Authority (ODPA):

We would appreciate the opportunity to address your concerns before you approach the ODPA - please contact us first at privacy@codebii.dev.


Changes to this policy

We may update this policy from time to time to reflect changes in our practices or legal requirements. The date at the top of this page will always reflect when this policy was last updated. We recommend checking this page periodically. Continued use of this website following any changes constitutes acceptance of the updated policy. Where a change materially affects how we handle your personal data, we will take reasonable steps to bring it to your attention.


Contact us

If you have any questions about this privacy policy or how we handle your data, please contact us at: privacy@codebii.dev