Codbip
Back to home
EU Regulation 2016/679

GDPR

The principles we apply to protect your data and respect your rights.

Last updated: March 16, 2026

1

Our commitment

Codbip processes personal data with care, transparency and data minimization in mind. Only data strictly necessary to deliver the service is collected.

For any data protection request: [email protected]. We respond within 30 days.

2

Legal bases

  • - Contract performance: client accounts, quotes/devis, project delivery
  • - Legitimate interest: security, fraud prevention, logging, product analytics
  • - Consent: newsletter, marketing communications, Google Analytics 4 cookies
  • - Legal obligation: invoicing, retention of accounting records
3

Sub-processors and data sharing

Codbip uses the following sub-processors, each providing appropriate GDPR safeguards:

  • - Directus CMS: content and user data storage — self-hosted, EU servers
  • - Brevo: transactional emails and newsletter — EU servers
  • - Vercel: hosting and CDN — edge functions may process data in multiple regions with adequate safeguards
  • - Cloudflare Turnstile: bot protection — minimal processing, no personal data retained
  • - Rybbit Analytics: privacy-focused audience measurement — self-hosted, no personally identifiable information (PII)
  • - Google Analytics 4: audience measurement — activated only after explicit consent, data retained for 14 months
4

Data retention

  • - Contact requests: 3 years
  • - Newsletter subscribers: until unsubscribe
  • - Client accounts: duration of contract + 3 years
  • - Analytics data: 14 months (Google Analytics 4), indefinite for anonymized data (Rybbit)
  • - Logs: 12 months
5

Data location

All primary data is stored within the European Union via our self-hosted Directus infrastructure.

Vercel edge functions may process requests in multiple regions; adequate safeguards (Standard Contractual Clauses or adequacy decisions) are in place for any transfer outside the EU.

6

Your rights

Under the GDPR, you have the following rights over your personal data:

  • - Access: obtain a copy of the data we hold about you
  • - Rectification: correct inaccurate or incomplete data
  • - Erasure: request deletion of your data (right to be forgotten)
  • - Portability: receive your data in a structured, machine-readable format
  • - Restriction: limit the processing of your data in certain circumstances
  • - Objection: object to processing based on legitimate interest

To exercise your rights, contact: [email protected]. We respond within 30 days. If you are unsatisfied, you may lodge a complaint with the CNIL (cnil.fr).

7

Security

We apply appropriate technical and organizational measures: encryption of data in transit and at rest, strict access control, logging of sensitive actions and regular review of sub-processor access.

Questions about this document?

[email protected]