Privacy policy

Privacy policy

Privacy Policy

https://www.codexnova.com

EestBIK OÜ

Effective date: 20 June 2025 | Last updated: 20 June 2025

1. Who We Are (Data Controller)

EestIBIK OÜ (“Codexnova” / “we” / “us”), Pärnu mnt 139c, Kesklinn, 11317 Tallinn, Estonia, operates the digital-content marketplace at https://www.codexnova.com/ .

2. What Personal Data We Collect

CategoryExamplesSource
Identity Datafull name, date of birth, national ID/passportuser-supplied (account or KYC)
Contact Dataemail, telephone, billing & payout addressuser-supplied
Account Credentialshashed password, two-factor tokensuser-supplied
Financial & Transaction Datacard BIN, IBAN, on-chain wallet, invoices, VAT IDpayment service provider / user
Creator Content Dataassets uploaded, EXIF metadata, model releasesuser-supplied
Usage & Technical DataIP, device type, browser, pages viewed, clicksautomated via logs & cookies
Marketing Preferencesnewsletter opt-in/opt-out, communication historyuser-supplied
Compliance DataPEP/sanctions screening results, risk scoresthird-party KYC / AML vendors

We do not intentionally collect data from children under 16. If we learn that a minor has provided personal data, we will delete it promptly.

3. Why We Process Your Data & Legal Bases

PurposeLegal Basis (GDPR)Key Data
Account creation & contract performanceArt 6 (1)(b) ContractIdentity, Contact, Credentials
Processing Pay In / Pay OutArt 6 (1)(b) ContractFinancial & Transaction
KYC / AML & sanctions screeningArt 6 (1)(c) Legal obligationIdentity, Compliance
Customer support & dispute resolutionArt 6 (1)(b)/(f) Contract / Legitimate interestIdentity, Contact, Transaction
Marketing communicationsArt 6 (1)(a) ConsentContact, Marketing Prefs
Site security & fraud preventionArt 6 (1)(f) Legitimate interestUsage, Technical, Compliance
Analytics & product improvementArt 6 (1)(f) Legitimate interestUsage & Technical

Where legitimate interest is relied upon, we balance our interests with your fundamental rights and expect minimal privacy impact.

4. Cookies & Tracking Technologies

We use:

  • Essential cookies – session management, secure login.
  • Analytics cookies – page-view metrics (Matomo self-hosted).
  • Marketing cookies – only with prior consent (e.g., Meta Pixel).

Detailed cookie lifetimes, purposes, and opt-out mechanisms are set out in our Cookie Policy shown in the consent banner.

5. Marketing & Opt-Out

  • Newsletters are sent only if you tick “Subscribe”.
  • You may withdraw consent at any time via the “Unsubscribe” link or your dashboard settings.
  • We commit to no more than two promotional emails per month.

6. Disclosures & International Transfers

We share data only as necessary with:

  1. Payment processors (PCI-DSS–certified) for card and SEPA transactions.
  2. KYC/AML service providers for identity verification and sanctions checks.
  3. Cloud hosting & CDN providers (EU data centres by default).
  4. Analytics platform (EU-hosted instance).
  5. Law-enforcement or regulators when legally required.

Whenever processors are outside the EEA, we rely on:

  • Adequacy decisions (e.g., UK), or
  • Standard Contractual Clauses (SCCs) with supplementary security measures.

7. Data Retention

Data TypeRetention PeriodRationale
Account & Transaction7 years after account closureEstonian Accounting Act §12
KYC & AML records5 years after last transactionEstonian MLTFP Act §47
Marketing consent recordsUntil withdrawal + 1 yearProof of consent
Analytics logs26 months (aggregated thereafter)Trend analysis
Archived backups35 days rollingDisaster recovery

8. Security Measures

  • TLS 1.3 encryption in transit; AES-256 at rest.
  • ISO 27001-aligned policies; quarterly penetration tests.
  • Role-based access control (RBAC) and hardware MFA for admin panels.
  • Continuous monitoring & automated anomaly detection.

9. Your Rights

Under GDPR you may, at no cost:

  1. Access your personal data.
  2. Rectify inaccurate or incomplete data.
  3. Erase data (“right to be forgotten”) where Art 17 applies.
  4. Restrict processing in certain circumstances.
  5. Port data to another controller.
  6. Object to processing based on legitimate interest or direct marketing.
  7. Withdraw consent at any time (does not affect legality of prior processing).

How to exercise: email info@codexnova.com or use the web-form in your dashboard. We respond within 30 days (extendable by 60 days for complex requests).

You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): https://www.aki.ee, +372 627 4135.

10. Automated Decision-Making

We do not make solely automated decisions with legal or similarly significant effects.
Note: AML risk scoring is automated but reviewed by staff before any adverse action.

11. Changes to This Policy

We may update this Privacy Policy to reflect legal or operational changes.

  • Notice period: 14 days via dashboard banner and email.
  • The “Last updated” date at the top indicates the current version.

12. Contact

EestIBIK OÜ – Privacy Desk
Pärnu mnt 139c, Kesklinn, 11317 Tallinn, Estonia
Email: info@codexnova.com
Business hours: Mon–Fri 09:00–18:00 EET/EEST