PRIVACY
What we hold about you.
Written to be read, not to be survived. If anything below is unclear, ask us and we will explain it in plain words.
Last updated 1 September 2026
Who we are
CodiVibes provides software that lets small and mid-sized businesses across Europe build and run their own business systems, and a launch service where we build the first version with you. We operate from Bulgaria and serve customers throughout the European Union.
The controller of your personal data is Intellect Consulting Ltd, a company registered in Bulgaria, VAT number BG207537396, at 2 Preslav, Sofia, Bulgaria. CodiVibes is the trading name it operates this platform under.
For anything in this policy — a question, a request, a complaint — write to office@codivibes.com or use the contact form. Either reaches us directly and we answer it ourselves. If you believe we have handled your data wrongly you may also complain to the Bulgarian Commission for Personal Data Protection (КЗЛД), or to the supervisory authority in the EU country where you live.
What we collect, and why
If you only read the site
We count page views, language switches, clicks on the main buttons and which template pages get opened, so we know which parts of the site are worth keeping. Each browser is given a random identifier that we store in your browser's own storage. It is not linked to a name, and we never send it anywhere else.
We run one advertising cookie, and only if you agree to it. The first time you arrive, a bar at the bottom of the page asks whether we may load the Meta (Facebook) pixel. It tells Meta that a page was opened, and if you go on to create an account, that an account was created — no name, no email, no message you typed. It also stores a cookie in your browser called _fbp. We use it for one thing: to see which of our ads bring people here, so we can stop paying for the ones that do not. If you decline, nothing is requested from Meta at all — not the script, not the cookie, not a single connection. There is no Google Analytics and no session recorder either way, and we do not store your IP address alongside the counts above.
Saying yes means data goes to Meta Platforms Ireland Ltd, which may move it to the United States under the EU–US Data Privacy Framework. Meta also uses it for its own purposes, so for that one step the two of us are joint controllers and Meta's terms for it are public. Your answer is remembered in your browser and nowhere else, and you can change it whenever you like — declining after having accepted also deletes the cookie.
If you arrive from a campaign or a partner link, we keep the campaign tags from the address for as long as your browser holds them, so that if you later become a customer we can tell which channel or partner brought you. You can clear all of this at any time by clearing site data for codivibes.com in your browser.
If you ask us to get in touch
The enquiry form asks for your name, email, phone if you give one, your company, what your business does and what you need. We use it to reply to you and to prepare a proposal, and we may follow up about that enquiry once or twice over the following days. Every one of those messages carries a one-click stop link, and one click is all it takes — we do not ask you to confirm. We do not add you to a newsletter and we do not pass your details to anyone else.
If you talk to the voice consultant
Vera is an AI assistant, not a person. You are told this before the microphone is ever asked for, and you can type instead of speaking at any time.
While the conversation is running, your microphone audio is sent to the AI service that answers you. It is processed to produce the reply and is not recorded. We do not store the audio at any point, and there is no way to play a conversation back.
We do keep the written words. What you and Vera said is stored for 90 days and then deleted automatically. We read it for one reason: to find the questions she answered badly or could not answer at all, and correct her. She is not trained on it — there is no learning from your conversation happening in the background — and it is never used to advertise to you, never passed to anyone else, and never linked to your name unless you gave it to her yourself. If you would rather it were deleted sooner, ask us through the contact form and it will be.
What we do keep is one line per conversation: when it started and ended, which language it was in, which page you started from, what it cost us to run and why it ended. That is what stops one visitor running up an unlimited bill, so it also includes the random browser identifier described above and a one-way hash of your IP address — a fingerprint we cannot turn back into an address, and which is used only for counting.
If you ask Vera to have someone call you back, the details you give her are stored exactly like an enquiry from the form above, and nothing else from the conversation goes with them.
If you open an account
To run your account we hold your email address, your name if you give one, the country and language you chose, when you registered, and — if you were referred — the partner who referred you. If you sign in with a password we store it hashed, never in readable form. If you sign in with Google we store the account identifier Google gives us instead, and no password at all.
If you buy credits or a plan
We hold what you bought, what you paid, and the state of your subscription. For a company invoice we hold the billing details you enter: company name, EIK, VAT number, address, city, country and the person representing the company. Where you give a VAT number we check it against the EU VIES register and keep the result and the date, so we can show why an invoice was charged the way it was.
Your card details never reach us. Payment happens on Stripe's own pages; we receive only a reference, the amount and whether it succeeded.
What you build
The systems you build, and the data you put into them, are yours. We do not read them, mine them, or use them to train anything. We can reach them only when you ask us to — for support, or during a launch-service build — and only for as long as that takes.
Why we are allowed to hold it
- To give you what you asked for — running your account, your projects and your payments. Without this data there is no service.
- Because the law requires it — invoices and the accounting record behind them.
- Because we have a legitimate interest — the site counts above, keeping accounts secure, and answering an enquiry you sent us. This is the one ground you can object to, and you can object using the contact form.
Who else touches it
These are the only companies involved in running the service. Each one gets the minimum it needs, and none of them may use it for their own purposes.
| Who | What they do | What they see |
|---|---|---|
| Our platform and AI infrastructure provider | Runs the studio you build in, the hosting behind it, and the AI service the voice consultant speaks through | Your account on the platform, the projects you create, and — while a conversation is running — the audio you speak to the consultant |
| Stripe | Takes the payment | Your card details and email — held by Stripe, not by us |
| Signs you in, if you choose the Google button; also serves the fonts this site uses | That you signed in here, and your email and name from your Google account | |
| Amazon Web Services | Hosts the site, the platform and the database | Stores the data described above, in the EU (Frankfurt) |
We name our platform and AI infrastructure provider to any customer who asks, and it is named in the data processing agreement we sign with business customers. Ask through the contact form and we will tell you who it is.
We do not sell data, and we do not share it for advertising. Where a provider processes data outside the EU, that transfer runs on the European Commission's standard contractual clauses.
How long we keep it
- Your account — while it is open, and up to 90 days after you close it, in case you come back.
- Invoices and payment records — 10 years, because Bulgarian accounting law says so.
- Enquiries — 24 months from your last message, then deleted.
- Site counts — 24 months, then deleted.
- Voice conversations — no audio is kept at all. The written words are kept for 90 days, then deleted automatically. The one line per conversation described above is kept for 24 months, and the browser identifier and IP fingerprint are stripped from it after the first 90 days.
Your rights
Under the GDPR you can ask us to show you what we hold, correct it, delete it, restrict what we do with it, hand it to you in a portable form, or object to the processing we do on legitimate interest. Ask through the contact form. We answer within 30 days, and it costs nothing.
If you think we have handled your data badly, tell us first — we would rather fix it. You also have the right to complain to the Bulgarian Commission for Personal Data Protection (cpdp.bg), or to the supervisory authority in the country where you live.
Security
Everything runs over HTTPS. Passwords are stored hashed and salted, never readable. Access to the customer database is limited to the people who need it to run the service. No system is perfect; if something goes wrong that puts your data at risk, we will tell you and the regulator within the time the law allows.
Changes
If we change this policy in a way that matters, we will say so on this page and date it. The date at the top is always the date of the current version.