Skip to main content
Cordeo logoCordeoRDC Partner

Cordeo Privacy Notice

Last updated

Applies to: cordeo.io, Cordeo booking and contact forms, Cordeo customer accounts, and the Cordeo platform

Purpose and scope

This Privacy Notice explains how personal data is handled when you:

  • visit the Cordeo website;
  • submit a “Book a Meeting”, contact, demo, or similar request;
  • communicate with us;
  • act as a customer contact, account administrator, user, supplier, partner, or prospective customer; or
  • use, access, or are represented in data processed through the Cordeo platform.

Cordeo is a business-to-business product. The platform may process broad categories of corporate information. Corporate information is personal data only where it relates to an identified or identifiable individual. This Notice applies to that personal-data element.

Third-party websites, customer systems, and integrations are governed by their own privacy notices.

Who we are and which role we perform

Cordeo is jointly operated by:

EU entity

Cordeo IO (EU entity)

info@cordeo.io

Türkiye entity

Cordeo IO (Türkiye entity)

info@cordeo.io

Joint-controller activities

To the extent the two entities jointly determine why and how personal data is processed for the following activities, they act as joint controllers:

  • operating and securing the public website;
  • handling booking, demo, contact, and business-enquiry forms;
  • managing customer and partner relationships;
  • administering user accounts and access;
  • billing, legal compliance, fraud and abuse prevention;
  • service improvement using data that the entities are independently entitled to use; and
  • handling privacy requests, complaints, disputes, and legal claims.

The entities will maintain an arrangement allocating their respective responsibilities. The essence of that arrangement will be made available on request. You may exercise your rights against either entity, irrespective of the designated contact point.

The primary privacy contact is: info@cordeo.io.

Processor activities on the Cordeo platform

For personal data contained in information that a customer uploads, connects, transmits, generates, or otherwise makes available through the Cordeo platform (“Customer Data”):

  • the customer normally determines the purposes and essential means of processing and acts as the controller;
  • the Cordeo entities act as processors, processing Customer Data only on documented customer instructions and under the applicable Data Processing Agreement; and
  • where the customer itself acts as a processor, the Cordeo entities normally act as subprocessors.

For these activities, the customer is responsible for establishing a lawful basis, providing required notices, respecting data-subject rights, and ensuring that its instructions are lawful. Cordeo assists the customer as required by law and contract.

The same legal entity can be a controller for one activity and a processor for another. The role depends on the specific processing activity, not merely on the Cordeo product name.

Personal data we process

Website, booking, and business-enquiry data

We may process:

  • name and surname;
  • work email address and telephone number;
  • organisation, department, role, or job title;
  • the subject and content of your request;
  • preferred meeting date, time, time zone, and language;
  • communications and meeting-related records;
  • consent and communication-preference records, where applicable;
  • IP address, browser and device information, user-agent data, timestamps, security events, and rate-limit records; and
  • language, session, and necessary cookie preferences.

We do not use data submitted through the booking form for unrelated electronic marketing unless a separate lawful basis and any required opt-in have been established.

Account, customer, and support data

We may process:

  • account-holder and authorised-user information;
  • login, authentication, role, and permission information;
  • organisation and tenant information;
  • contract, order, invoicing, and payment-administration information;
  • support requests, service communications, and feedback;
  • audit records, feature usage, configuration, and security logs; and
  • records necessary to establish, exercise, or defend legal claims.

Customer Data processed through the platform

The categories depend on the customer’s configuration, use case, integrations, and instructions. They may include:

  • identity, contact, demographic, and professional information;
  • employee, candidate, customer, supplier, stakeholder, or user records;
  • organisational structures, roles, responsibilities, and access information;
  • correspondence, meeting content, messages, notes, and collaboration data;
  • documents, files, forms, reports, contracts, policies, and knowledge-base content;
  • audio, video, images, transcripts, and speaker information;
  • operational, commercial, financial, accounting, procurement, project, and service data;
  • system, device, application, usage, and event data;
  • information derived from connected systems or customer-authorised integrations; and
  • special categories of personal data or criminal-conviction/offence data, but only where the customer has expressly instructed such processing, has a valid legal basis, and the applicable agreement and safeguards permit it.

Customers must not provide personal data that is unnecessary for their use case. Customers should apply data minimisation, access restrictions, and, where appropriate, anonymisation or pseudonymisation.

Generated and derived data

Depending on enabled features, Cordeo may generate or process:

  • structured extractions;
  • classifications, labels, topics, and metadata;
  • summaries, transcripts, translations, and redacted versions;
  • embeddings, search indexes, and semantic representations;
  • scores, indicators, recommendations, forecasts, and model outputs;
  • workflow and audit records; and
  • quality, performance, security, and error telemetry.

Generated data may itself constitute personal data where it relates to an identifiable person.

How we obtain personal data

We may obtain personal data:

  • directly from you;
  • from your employer, organisation, or the Cordeo customer;
  • from users authorised by the customer;
  • from systems and integrations connected by or for the customer;
  • automatically from your device or interaction with the service;
  • from our hosting, security, communications, and support providers; and
  • from public sources only where this is lawful and relevant to a customer-authorised or independently lawful purpose.

Purposes and legal bases for controller activities

Where the Cordeo entities act as controllers, personal data may be processed as follows:

PurposeTypical legal basis under GDPRTypical basis under KVKK
Responding to a meeting, demo, contact, or commercial requestSteps requested before entering a contract; legitimate interestsNecessary for establishing or performing a contract; legitimate interests where applicable
Managing customer, user, supplier, and partner relationshipsContract; legitimate interests; legal obligationEstablishment or performance of a contract; legal obligation; legitimate interests
Creating and administering accounts and permissionsContract; legitimate interestsEstablishment or performance of a contract; legitimate interests
Providing service communications and supportContract; legitimate interestsEstablishment or performance of a contract; legitimate interests
Invoicing, accounting, tax, and record keepingContract; legal obligationLegal obligation; establishment, exercise, or protection of a right
Securing systems, preventing abuse, detecting incidents, and maintaining logsLegitimate interests; legal obligationLegal obligation; legitimate interests
Establishing, exercising, or defending legal claimsLegitimate interests; legal obligationEstablishment, exercise, or protection of a right
Remembering language, session, and necessary preferencesNecessary service functionality; legitimate interestsNecessary for service functionality; legitimate interests
Optional marketing communicationsConsent or another basis permitted by applicable electronic-marketing lawExplicit consent or another basis permitted by applicable law

The precise basis may vary by jurisdiction and circumstance. Where consent is relied upon, it may be withdrawn at any time without affecting processing already carried out lawfully.

Where Cordeo acts as a processor, the customer determines the purposes and lawful basis of the processing.

Artificial intelligence and automated processing

Depending on the features selected by the customer, Cordeo may use automated and AI-assisted techniques for functions such as transcription, OCR, extraction, classification, redaction, translation, summarisation, semantic search, scoring, forecasting, recommendation generation, and workflow support.

Cordeo does not independently use Customer Data to make decisions that produce legal or similarly significant effects on individuals. Outputs are intended to support customer-controlled workflows and, where appropriate, human review. The customer is responsible for assessing whether its particular use constitutes automated decision-making or profiling and for applying any required safeguards.

Proposed policy commitment — confirm before publication: Cordeo does not use Customer Data to train general-purpose or shared models made available to other customers unless the customer has expressly agreed to that use in writing. Where external AI providers are used as subprocessors, their processing must be governed by contract, documented instructions, and the current subprocessor list.

Cookies and similar technologies

The website currently uses only technologies required to provide and secure the service, including:

TechnologyPurposeProviderRetention
Language-preference cookieRemember the selected website languageCordeo365 days
Session or security storage, if usedMaintain the requested session and protect the serviceCordeoN/A
Turnstile or equivalent bot protectionDetect automated abuse of public formsCloudflare or replacement providerAccording to configured service and provider terms

We do not currently use advertising or behavioural-tracking cookies. We do not currently use website analytics unless expressly identified in an updated cookie notice and, where required, activated only after consent.

Who receives personal data

Personal data may be disclosed, strictly as necessary, to:

  • the two Cordeo operating entities and authorised personnel;
  • the relevant customer and its authorised users;
  • hosting, infrastructure, communications, email-delivery, security, support, and AI-service providers acting under contract;
  • integration providers selected or enabled by the customer;
  • accountants, auditors, insurers, legal advisers, and professional consultants;
  • public authorities, courts, regulators, or law-enforcement bodies where disclosure is legally required or necessary to protect rights; and
  • a prospective purchaser, investor, or successor in connection with a merger, financing, reorganisation, or sale, subject to appropriate confidentiality and legal safeguards.

We do not sell personal data. We do not disclose personal data for third-party behavioural advertising.

Service providers and subprocessors

The current service architecture may include:

ProviderFunctionProcessing location / transfer note
DigitalOceanWebsite, application, database, storage, or infrastructure hostingFrankfurt, Germany, subject to confirmation of the contracted entity and support-access arrangements
Resend and its email-delivery infrastructure, which may include Amazon SESTransactional and confirmation email deliveryIreland (eu-west-1) sending region; provider-side retention follows the active Resend configuration
CloudflareNetwork security, content delivery, and Turnstile bot protectionMay involve processing from multiple locations under the applicable transfer safeguards

The current subprocessors are listed in Section 9 of this Notice. Where contractually required, customers will receive notice of material subprocessor changes and may exercise the rights stated in their agreement.

International data transfers

Cordeo’s operating model may involve:

  • access to EEA-hosted data by authorised personnel in Türkiye;
  • transfers between the EU entity and the Türkiye entity;
  • transfers from Türkiye to providers or systems located abroad; and
  • processing by global service providers and their approved subprocessors.

International transfers are carried out only where the requirements of GDPR Chapter V, KVKK Article 9, and other applicable law are met.

Depending on the transfer, safeguards may include:

  • an applicable adequacy decision;
  • European Commission Standard Contractual Clauses and, where required, a transfer assessment and supplementary measures;
  • standard contracts, binding corporate rules, undertakings, or other appropriate safeguards recognised under Turkish data-protection law;
  • contractual restrictions, encryption, access controls, data minimisation, and regional hosting; or
  • a legally permitted derogation for a specific and non-repetitive situation.

Information about the applicable transfer safeguard may be requested from info@cordeo.io, subject to lawful redactions.

Retention and deletion

We retain personal data only for as long as reasonably necessary for the stated purpose, contractual obligations, legal requirements, security, and the establishment or defence of claims.

The following retention schedule reflects the current implementation where a period is specified. Items marked N/A remain to be defined:

Data categoryCurrent retention / status
Booking, demo, and business-enquiry records730 days (24 months), measured from the record's most recent update (updated_at)
IP address and user-agent attached to briefing/demo requests730 days, because they are stored in the same briefing-request record and currently have no separate deletion rule
Customer-contract, billing, tax, and legal recordsFor the contract term and the applicable statutory limitation and record-retention periods
Account and authorised-user dataFor the active account period, followed by a limited closure and recovery period
Customer Data in the active platformFor the contract term and as instructed by the customer
Customer Data after terminationN/A — a separate platform-wide post-termination retention period has not yet been specified
Access and application logsNo fixed retention period is currently configured because log rotation is not yet defined
Rate-limit and temporary anti-abuse data1 hour in memory; the state is cleared on application restart
Database backupsApproximately 35 days (7 daily backups plus 4 weekly backups); deleted live data may therefore remain in backup copies until those copies expire
Language-preference cookie365 days
Provider-held email and delivery logsAccording to the configured retention and the provider contract

The periods above reflect the currently provided implementation details. Items marked N/A must be defined before publication. Where Cordeo acts as processor, deletion and return are governed by the customer’s instructions and Data Processing Agreement.

Security

We apply technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Depending on the service and risk, these measures include:

  • encryption in transit;
  • restricted administrative access through encrypted channels;
  • role-based and least-privilege access controls;
  • private-network separation of databases and internal services;
  • strong authentication and cryptographic-key-based administration;
  • firewalling, logging, monitoring, and abuse prevention;
  • controlled backups and recovery procedures;
  • vulnerability, patch, and dependency management;
  • personnel confidentiality and security responsibilities;
  • supplier and subprocessor due diligence; and
  • incident-response and breach-management procedures.

No system can be guaranteed completely secure. Customers are also responsible for configuring access, integrations, retention, and use of the platform in a secure and lawful manner.

Personal-data breaches

Where Cordeo acts as a processor, it will notify the relevant customer without undue delay after becoming aware of a personal-data breach, in accordance with the Data Processing Agreement, and will provide reasonable assistance with investigation and legally required notifications.

Where the Cordeo entities act as controllers, they will notify the competent authority and affected individuals where and within the period required by applicable law.

Your rights

Rights under GDPR

Subject to the applicable conditions and exceptions, you may have the right to:

  • access your personal data and obtain a copy;
  • correct inaccurate or incomplete data;
  • request erasure;
  • restrict processing;
  • object to processing based on legitimate interests or to direct marketing;
  • receive certain data in a portable format;
  • withdraw consent at any time;
  • request safeguards relating to qualifying automated decisions; and
  • lodge a complaint with a competent data-protection supervisory authority.

Rights under KVKK

Under Article 11 of Law No. 6698, you may have the right to:

  • learn whether your personal data is processed;
  • request information about the processing;
  • learn the purpose of processing and whether data is used consistently with that purpose;
  • know the third parties to whom data is transferred domestically or abroad;
  • request correction of incomplete or inaccurate data;
  • request deletion or destruction where the legal conditions are met;
  • request notification of correction, deletion, or destruction to recipients;
  • object to a result against you arising from analysis exclusively by automated systems; and
  • claim compensation for damage caused by unlawful processing.

How to exercise your rights

For data Cordeo processes as controller, send your request to info@cordeo.io or use the application method stated at info@cordeo.io.

We may request information necessary to verify identity and locate the relevant records. We will respond without undue delay and within the applicable statutory period—normally within one month under GDPR and no later than 30 days under KVKK, subject to lawful extensions or exceptions.

For Customer Data that Cordeo processes as processor, please contact the organisation that provided or controls your access to Cordeo. That organisation is normally the controller. Cordeo will assist it in responding as required by law and contract.

Complaints

You may complain to:

  • the data-protection supervisory authority in the EU/EEA country of your habitual residence, place of work, or the alleged infringement;
  • N/A, where applicable; and
  • the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu), subject to the application and complaint procedure under Turkish law.

We encourage you to contact info@cordeo.io first so that we can try to address the concern directly. This does not limit your right to approach a supervisory authority.

Children

Cordeo is intended for organisations and business users and is not directed to children. Customers must not use the platform to process children’s personal data unless this is lawful, necessary for the authorised use case, contractually permitted, and protected by appropriate safeguards.

Changes to this Notice

We may update this Notice where our services, providers, processing activities, or legal obligations change. The updated version will be posted with a revised “Last updated” date. Where required, we will provide additional notice of material changes.

Language versions

This Notice may be made available in English, German, Dutch, and Turkish. The versions are intended to have the same meaning. In the event of an inconsistency, English will be the reference version to the extent permitted by mandatory law. No translation limits rights granted by applicable law.

Contact

Primary privacy contact: info@cordeo.io

EU entity: Cordeo IO (EU entity), info@cordeo.io

Türkiye entity: Cordeo IO (Türkiye entity), info@cordeo.io

Data Protection Officer, if appointed: bilal.naci.yilmaz@rdc.com.tr