Codyco
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.
Watch: Data retention
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Imposes an obligation on the data controller to store personal data only for the duration necessary to fulfill the stated purposes, establishing a necessity-based retention limit.
Discloses that online data partners or vendors may use cookies and similar technologies to associate website activity with personal information including email, and that marketing communications may be sent; provides an opt-out mechanism for users, establishing both a data-sharing practice and a user right to opt out.
Describes the use of cookies and similar technologies by data partners to associate website activity with personal information, discloses marketing communications, provides an opt-out right for advertising, and references an option to opt out of personal data collection in compliance with an external data protection framework, establishing both data-sharing practices and user opt-out rights.
How to read this page: Overall risk rates what Codyco's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Partially verified — Privacy Policy — Verified (read in full, 57 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Terms not yet captured
AIRIN has not yet captured a gate-verified Terms of Service document for this platform.
- Privacy PolicyVerified - read in full - 57 citationsLast captured 2026-07-20
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
States the legal basis for collecting server log files as the operator's legitimate interest in technically error-free presentation and optimization of the website, incorporating an external legal framework by article reference to justify the data collection obligation.
" The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of their website – for this purpose, the server log files must be recorde..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" We store your data only for as long as necessary to fulfill the purposes mentioned:"
Imposes an obligation on the data controller to store personal data only for the duration necessary to fulfill the stated purposes, establishing a necessity-based retention limit.
AI-generated interpretation, not legal advice.
" When you visit or log in to our website from the US, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email. You may opt out of receiving this advertising by visiting https://app.retention.com/optout . "
Discloses that online data partners or vendors may use cookies and similar technologies to associate website activity with personal information including email, and that marketing communications may be sent; provides an opt-out mechanism for users, establishing both a data-sharing practice and a user right to opt out.
AI-generated interpretation, not legal advice.
" When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email. You may opt out of receiving this advertising by visiting https://app.retention.com/optout . You also have the option to opt out of the collection of your personal data in compliance with GDPR. To exercise this option, please visit https://www.rb2b.com/rb2b-gdpr-opt-out . "
Describes the use of cookies and similar technologies by data partners to associate website activity with personal information, discloses marketing communications, provides an opt-out right for advertising, and references an option to opt out of personal data collection in compliance with an external data protection framework, establishing both data-sharing practices and user opt-out rights.
AI-generated interpretation, not legal advice.
" For the technical operation of "Mia," we engage a specialized service provider as a processor, who processes your data strictly according to our instructions:"
Establishes that a specialized service provider is engaged as a processor for the technical operation of 'Mia', and that this processor handles data strictly according to the controller's instructions, defining the subprocessor relationship and imposing an instruction-bound processing obligation.
AI-generated interpretation, not legal advice.
" Additionally, our service provider CODYCO engages further technical sub-processors to provide the service. A current list of these providers can be provided upon request. All service providers are based within the EU/EEA or are bound by appropriate safeguards to comply with European data protection standards."
Discloses that the named service provider engages further technical sub-processors, commits to providing a current list upon request, and states that all service providers are located within the EU/EEA or bound by appropriate safeguards to meet European data protection standards, establishing both a transparency obligation and a data-transfer safeguard requirement.
AI-generated interpretation, not legal advice.
" This data will not be combined with data from other sources."
Imposes a restriction prohibiting the combination of server log file data with data from other sources, which is user-protective and limits the operator's data processing activities.
AI-generated interpretation, not legal advice.
" Should you send us questions via the contact form, we will collect the data entered on the form, including the contact details you provide, to answer your question and any follow-up questions. We do not share this information without your permission."
States the legal basis for processing contact form data, citing contract fulfillment, legitimate interest, and consent as applicable legal grounds, incorporating external legal framework references to justify processing.
AI-generated interpretation, not legal advice.
" Data subject to statutory retention obligations (e.g., from invoices) is stored in accordance with the respective legal retention periods."
Carves out an exception to standard retention limits for data subject to statutory retention obligations (e.g., from invoices), specifying that such data is stored in accordance with the applicable legal retention periods rather than the general policy.
AI-generated interpretation, not legal advice.
" Within the hotel, only authorized employees have access to the information relevant to them."
Restricts internal access to personal data to only authorized hotel employees and only to information relevant to their role, limiting the scope of internal data sharing — user-favorable restriction.
AI-generated interpretation, not legal advice.
" The provider of the website automatically collects and stores information that your browser automatically transmits to us in "server log files". These are:"
Describes the automatic collection and storage of browser-transmitted data into server log files, establishing the procedure by which the operator collects technical data from website visitors.
AI-generated interpretation, not legal advice.
" The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of their website – for this purpose, the server log files must be recorded."
States the legal basis for collecting server log files as the operator's legitimate interest in technically error-free presentation and optimization of the website, incorporating an external legal framework by article reference to justify the data collection obligation.
AI-generated interpretation, not legal advice.
" IF THE DATA PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA AT ANY TIME FOR REASONS ARISING FROM YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING IS FOR THE PURPOSE OF ASSERTING, EXERCISING, OR DEFENDING LEGAL CLAIMS (OBJECTION UNDER ART. 21(1) GDPR)."
This segment (continuation of index 30) sets out the right to object to processing for direct marketing purposes, including related profiling, and imposes a restriction on the controller to cease using data for direct marketing upon such objection.
AI-generated interpretation, not legal advice.
" The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you could be personally identified. Detailed information on the subject of data protection can be found in our privacy policy listed below this text."
This segment defines the scope and nature of the privacy policy document, explaining that it covers what happens to personal data when visiting the website, and provides a working definition of personal data as any data with which a person could be personally identified.
AI-generated interpretation, not legal advice.
" The data processing on this website is carried out by the website operator. The operator's contact details can be found in the website's Imprint (Legal Notice)."
This segment identifies the website operator as the party responsible for data processing and directs users to the Imprint for contact details, defining the controller relationship for data processing on the website.
AI-generated interpretation, not legal advice.
" Some data is collected when you provide it to us. This could, for example, be data you enter into a contact form."
This segment describes one method of data collection — user-provided data such as contact form entries — defining the voluntary input pathway for personal data collection.
AI-generated interpretation, not legal advice.
" Other data is collected automatically by our IT systems when you visit the website. This data is primarily technical data such as the browser and operating system you are using or the time you accessed the page. This data is collected automatically as soon as you enter our website."
This segment describes automatic collection of technical data (browser, operating system, access time) by IT systems upon website entry, defining the automatic data collection pathway.
AI-generated interpretation, not legal advice.
" Part of the data is collected to ensure the proper functioning of the website. Other data can be used to analyze how visitors use the site."
This segment defines two purposes for which collected data is used: ensuring proper website functioning and analyzing visitor usage patterns.
AI-generated interpretation, not legal advice.
" You have the right at any time to request information about your stored data, its origin, its recipients, and the purpose of its collection at no charge. You also have the right to request that it be corrected, blocked, or deleted. If you have given your consent to data processing, you may revoke this consent at any time for the future. You also have the right to request the restriction of the processing of your personal data under certain circumstances. You also have the right to lodge a complaint with the competent supervisory authority."
This segment enumerates multiple user rights regarding their stored personal data, including the right to request information, correction, blocking, deletion, restriction of processing, revocation of consent, and lodging a complaint with a supervisory authority, all at no charge.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Codyco's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in Codyco's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in Codyco's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat Codyco requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Codyco's published policies yet.
What the policies actually cover
0 topicsNone of Codyco's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Cross-clause notes
Verified retention clauses point in different directions: the Privacy Policy, § 4 (Storage Duration) describes broad or open-ended retention, while the Privacy Policy, Privacy Policy › “Storage Duration” describes deletion or erasure. Which clause controls in a given situation is not resolved by the documents' text alone — this is surfaced as an ambiguity, treated as Caution.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause allows indefinite, perpetual, or necessity-based retention.
“We store your data only for as long as necessary to fulfill the purposes mentioned:”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“When you visit or log in to our website from the US, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email. You may opt out of receiving this advertising ...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email. You may opt out of receiving this advertising by visiting ...”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“For the technical operation of "Mia," we engage a specialized service provider as a processor, who processes your data strictly according to our instructions:”Open source citation
The clause permits disclosure or sharing with third parties, affiliates, vendors, or subprocessors.
“Additionally, our service provider CODYCO engages further technical sub-processors to provide the service. A current list of these providers can be provided upon request. All service providers are based within the EU/EEA or are bound by appropriate safeguards to comply with European data protection standards.”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | data retention | conditional | MEDIUM | 1 |
| All applicable tiers | subprocessors data sharing | conditional | MEDIUM | 4 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: third party or vendor sharing on subprocessors data sharing
“When you visit or log in to our website from the US, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email. You may opt out of receiving this advertising by visiting https://app.retention.com/optout .”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email. We (or service providers on our behalf) may then send communications and marketing to these email. You may opt out of receiving this advertising by visiting https://app.retention.com/optout . You also have the option to opt out of the collection of your personal data in compliance with GDPR. To exercise this option, please visit https://www.rb2b.com/rb2b-gdpr-opt-out .”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“For the technical operation of "Mia," we engage a specialized service provider as a processor, who processes your data strictly according to our instructions:”Open timeline citation
Latest stance: third party or vendor sharing on subprocessors data sharing
“Additionally, our service provider CODYCO engages further technical sub-processors to provide the service. A current list of these providers can be provided upon request. All service providers are based within the EU/EEA or are bound by appropriate safeguards to comply with European data protection standards.”Open timeline citation
Latest stance: indefinite or necessity based on data retention
“We store your data only for as long as necessary to fulfill the purposes mentioned:”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
57 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Codyco's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Codyco's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Codyco's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.