Privacy Policy — Code Guardian Allow
This Privacy Policy explains how Code Guardian B.V. (“Code Guardian”, “we”, “us”) processes personal data in connection with Code Guardian Allow (“Allow”), our software-as-a-service platform for vetting and allowlisting software extensions. It covers the people who administer and use Allow on behalf of a customer organization. It sits alongside our Terms and Conditions, which govern how Customer Data is handled (see section 5).
1.Who we are
Code Guardian B.V., Barbusselaan 209, 1102 TT Amsterdam, the Netherlands, registered with the Dutch Chamber of Commerce under number 99122898, is responsible for the processing described in this policy. You can reach us at [email protected].
2.Controller and processor roles
Allow is a business tool. We act in two different roles depending on the data:
- Controller — for personal data about the customer’s representatives and Authorized Users that we need to operate the service, such as account, authentication, billing, support and security data. This policy describes that processing.
- Processor — for personal data that may be contained in Customer Data (the allowlists, extension requests and configurations a customer submits). We process that only on the customer’s documented instructions under the Agreement, and the customer is the controller (see section 5).
3.Personal data we process
| Category | Examples |
|---|---|
| Account & identity | Name, work email address and the identifier from your Microsoft account, obtained when you sign in with Microsoft single sign-on. |
| Organization & role | The organization you belong to, your role (owner, admin or member) and invitations you send or receive. |
| Billing | Subscription status, plan, renewal dates and the customer identifier we receive from our reseller, Paddle. Card and payment details are handled by Paddle, not stored by us. |
| Usage & technical | Server log data such as IP address, user agent, requested URLs and timestamps, and records of actions taken in the service (for example who submitted or approved an extension). |
| Communications | Messages you send us for support, and transactional emails we send you (invitations, account and subscription notices). |
4.Why we process it, and the legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service, creating and administering accounts and organizations, and authenticating users | Performance of a contract, or our and the customer’s legitimate interest in operating the service |
| Billing, subscriptions and preventing payment fraud | Performance of a contract; compliance with a legal obligation |
| Securing the service, detecting and preventing abuse, and troubleshooting | Legitimate interest in the security and reliability of the service |
| Support and service communications | Performance of a contract; legitimate interest |
| Complying with legal obligations and enforcing our terms | Legal obligation; legitimate interest |
5.Customer Data
The allowlists, extension requests, configurations and related records that a customer submits to Allow are Customer Data. Where these contain personal data, we process it only as a processor, on the customer’s documented instructions, to provide, secure, maintain and support the service, in accordance with the Agreement. The customer is the controller of that data and is responsible for the lawful basis of submitting it. Extension analysis is performed primarily through automated workflows; in exceptional cases our personnel may access the relevant records to resolve a request, subject to the confidentiality obligations in our Terms.
6.Service providers and subprocessors
We use a limited set of providers to run Allow. Each processes personal data only as needed to provide its service to us and under appropriate contractual safeguards. We do not sell personal data.
| Provider | Purpose |
|---|---|
| Microsoft (Microsoft Entra ID) | Single sign-on. You authenticate with your own Microsoft work or school account through an app registration; we receive your name and email. We do not host data or infrastructure with Microsoft |
| Paddle | Reseller and Merchant of Record: payment processing, invoicing and tax. Paddle acts as an independent controller for payment and tax data under its own terms |
| Hetzner Online GmbH (Germany) | Cloud hosting of the application and customer data, in the EU |
| Cloudflare | DNS, proxy and security in front of the application (traffic handling only; the application and data are stored at Hetzner) |
| Resend (Ireland) | Delivery of transactional email (invitations and account or subscription notices), on EU servers |
7.Where your data is processed
Your personal data is stored within the European Economic Area (EEA): the application and its database are hosted at Hetzner in Germany, and transactional email is delivered by Resend on servers in Ireland. Sign-in is provided by Microsoft — you authenticate with your own Microsoft account through our app registration, and we do not store data with Microsoft. Cloudflare, our DNS, proxy and security provider, routes connection traffic in transit across its global network before it reaches our EU servers; to the extent that involves processing outside the EEA, it takes place under Cloudflare’s data protection terms and the European Commission’s Standard Contractual Clauses. We do not otherwise transfer your personal data outside the EEA.
8.Retention
- Account, organization and billing data are kept for as long as the organization has an account and for a reasonable period afterwards to meet legal, accounting and security obligations.
- After a subscription ends, access may be limited to read-only for up to three months so data can be retrieved, after which Customer Data may be deleted in line with our Terms.
- Server access logs are retained for a short period (generally up to 14 days) and then deleted or aggregated.
- Support messages are kept as long as needed to handle your request and for reasonable follow-up.
9.Security
We apply technical and organizational measures appropriate to a security-focused service, including access controls, tenant isolation, encryption in transit and limiting personnel access to what is needed for a role. No service can be guaranteed completely secure; if a security incident materially affects your personal data we will act in accordance with our legal obligations and our Terms.
10.Cookies and local storage
Allow uses only what is necessary to run the application. After you sign in, an authentication token is stored in your browser’s local storage to keep you signed in. Our infrastructure provider may set strictly necessary cookies for security and routing. We do not use advertising or third-party tracking cookies in the application.
11.Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict or object to the processing of your personal data, and to data portability. Where our processing relies on legitimate interest, you may object on grounds relating to your situation.
If we process your data as a processor on behalf of a customer, please direct your request to that customer (your organization); we will assist them as required. For data we control, contact us at [email protected]. You also have the right to lodge a complaint with a supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens.
12.Changes to this policy
We may update this policy when our practices change. The latest version will be published on this page, and we will provide notice of material changes as required.
13.Contact
Code Guardian B.V.
Barbusselaan 209
1102 TT Amsterdam
The Netherlands
Email: [email protected]
Dutch Chamber of Commerce number: 99122898