Last updated: December 2024
Codalyx ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our proxy infrastructure services.
Privacy is fundamental to our service architecture. We operate on a zero-knowledge model where your data never touches our servers in an unencrypted state. This policy outlines our comprehensive privacy practices, your rights regarding your personal information, and how we maintain the highest standards of data protection in compliance with GDPR, CCPA, and other applicable privacy regulations.
By using Codalyx services, you acknowledge that you have read, understood, and agree to the collection and use of information in accordance with this Privacy Policy. We reserve the right to modify this policy at any time, and such modifications will be effective immediately upon posting.
We collect only the minimum information necessary to provide and maintain our services. Our data collection practices are designed to respect your privacy while ensuring service quality and security.
When you are invited and approved for Codalyx services, we collect:
We automatically collect certain technical information to ensure service quality:
Due to our zero-knowledge architecture, we explicitly do not collect:
Our proxy infrastructure operates on a zero-knowledge architecture, meaning we have no access to your actual traffic data. This is not a policy choice—it's a fundamental technical design of our infrastructure.
How Zero-Knowledge Works: All traffic passing through Codalyx proxies is encrypted end-to-end using AES-256 encryption with perfect forward secrecy. Our infrastructure routes encrypted packets without decrypting or inspecting the contents. We cannot see, log, or access:
Technical Implementation: Our zero-knowledge architecture is enforced at the network level. Even if we wanted to access your traffic (which we don't), our infrastructure design makes it technically impossible. Encryption keys are generated client-side and never transmitted to our servers. This ensures that even in the event of a security breach, your traffic data remains protected.
What We Can See: We can only see aggregate, anonymized metrics such as total bandwidth usage, connection counts, and performance statistics. These metrics are used solely for billing, capacity planning, and service optimization. They contain no personally identifiable information or traffic content.
We use the information we collect solely for legitimate business purposes related to providing and improving our services. We never sell your personal information or use it for marketing purposes without your explicit consent.
We implement comprehensive, multi-layered security measures to protect your information. Our security practices exceed industry standards and are continuously updated to address emerging threats.
In the unlikely event of a data breach affecting your personal information, we will:
We retain personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements.
Upon your request or after the retention period expires, we will securely delete your personal information using industry-standard secure deletion methods. However, we may retain certain information if:
You have comprehensive rights regarding your personal information under GDPR, CCPA, and other applicable privacy laws. We are committed to facilitating the exercise of these rights.
You have the right to request access to your personal information. We will provide you with a copy of your personal data, including account information, billing records, and communication logs. Requests will be fulfilled within 30 days.
You can request correction of inaccurate or incomplete personal information. We will update your information promptly and notify you of the changes. You can also update certain information directly through your account dashboard.
You can request deletion of your personal information, subject to legal and contractual obligations. We will delete your data unless we have a legitimate reason to retain it (e.g., legal requirements, dispute resolution, fraud prevention).
You can request that we limit how we use your personal information in certain circumstances, such as when you contest the accuracy of the data or object to processing.
You can request a copy of your personal data in a structured, machine-readable format. We will provide your account data, usage statistics, and communication records in a standard format (e.g., JSON or CSV).
You can object to processing of your personal information for certain purposes, such as direct marketing or legitimate interests. We will respect your objection unless we have compelling legitimate grounds for processing.
Where processing is based on consent, you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. Note that withdrawing consent may affect our ability to provide certain services.
To exercise any of these rights, please contact us through your dedicated account manager or through the secure communication channels provided after account approval. We will respond to your request within 30 days and may request verification of your identity to protect your privacy.
Note: Due to our invitation-only access model, all privacy-related requests must be made through established secure channels. We do not accept privacy requests through public contact methods.
We work with trusted third-party service providers to deliver our infrastructure and services. All third-party relationships are governed by strict data protection agreements that require them to protect your information to the same standards we maintain.
We use PCI DSS Level 1 certified payment processors for handling transactions. These processors receive only the minimum payment information necessary to process transactions. We never store full credit card numbers on our servers.
Our infrastructure is hosted on tier-1 cloud providers and data centers. These providers have no access to your traffic data due to our zero-knowledge architecture. They only see encrypted data packets with no ability to decrypt or inspect contents.
We use third-party analytics tools for aggregate service metrics and performance monitoring. These tools only receive anonymized, aggregate data that cannot identify individual users or their activities.
All third-party service providers are contractually required to:
Third-party services have their own privacy policies governing their use of information. We encourage you to review these policies. However, our data protection agreements ensure that third parties cannot use your information in ways that violate this Privacy Policy.
Codalyx operates a global infrastructure network spanning multiple countries. Your personal information may be transferred to and processed in countries other than your country of residence, including countries that may have different data protection laws.
We ensure that international data transfers comply with applicable laws through:
Your account and billing information may be processed in:
Important: Your proxy traffic data is never transferred internationally in a way that could be accessed, as our zero-knowledge architecture ensures it cannot be decrypted or inspected by any party, including ourselves.
Codalyx services are designed exclusively for enterprise and business use. Our services are not intended for, and we do not knowingly collect personal information from, individuals under 18 years of age.
Age Verification: During the account approval process, we verify that account holders are authorized representatives of legitimate businesses. This verification process includes confirming that the organization is a registered business entity and that the account holder has authority to bind the organization.
No Personal Use: Our invitation-only, enterprise-focused model means we do not provide services to individuals for personal use, including minors. All accounts must be associated with verified business entities.
If we become aware that we have collected personal information from a minor, we will immediately delete such information and terminate the associated account. If you believe we have collected information from a minor, please contact us immediately through your account manager.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes that affect your rights or how we use your information.
When we make material changes to this Privacy Policy, we will:
If you do not agree with changes to this Privacy Policy, you may:
Continued use of our services after changes become effective constitutes acceptance of the updated Privacy Policy.
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how we handle your personal information, please contact us through your dedicated account manager or through the secure communication channels established after account approval.
Important: Due to our invitation-only access model and security requirements, we do not accept privacy-related inquiries through public contact methods. All privacy requests must be made through established secure channels to protect your information and verify your identity.
For Verified Clients: Contact your dedicated account manager or use the secure messaging platform provided after approval. Your account manager can facilitate all privacy-related requests, including data access, correction, deletion, and portability requests.
Response Times: We will respond to privacy requests within 30 days as required by GDPR and other applicable laws. Complex requests may require additional time, and we will notify you if an extension is needed.
Data Protection Officer: For EU-based clients, our Data Protection Officer can be reached through your account manager. All communications are handled through secure, encrypted channels.
Regulatory Complaints: If you believe we have not adequately addressed your privacy concerns, you have the right to file a complaint with your local data protection authority. However, we encourage you to contact us first so we can resolve the matter directly.