Cordeo Privacy Notice
Last updated
Applies to: cordeo.io, Cordeo booking and contact forms, Cordeo customer accounts, and the Cordeo platform
Purpose and scope
This Privacy Notice explains how personal data is handled when you:
- visit the Cordeo website;
- submit a “Book a Meeting”, contact, demo, or similar request;
- communicate with us;
- act as a customer contact, account administrator, user, supplier, partner, or prospective customer; or
- use, access, or are represented in data processed through the Cordeo platform.
Cordeo is a business-to-business product. The platform may process broad categories of corporate information. Corporate information is personal data only where it relates to an identified or identifiable individual. This Notice applies to that personal-data element.
Third-party websites, customer systems, and integrations are governed by their own privacy notices.
Who we are and which role we perform
Cordeo is jointly operated by:
Joint-controller activities
To the extent the two entities jointly determine why and how personal data is processed for the following activities, they act as joint controllers:
- operating and securing the public website;
- handling booking, demo, contact, and business-enquiry forms;
- managing customer and partner relationships;
- administering user accounts and access;
- billing, legal compliance, fraud and abuse prevention;
- service improvement using data that the entities are independently entitled to use; and
- handling privacy requests, complaints, disputes, and legal claims.
The entities will maintain an arrangement allocating their respective responsibilities. The essence of that arrangement will be made available on request. You may exercise your rights against either entity, irrespective of the designated contact point.
The primary privacy contact is: info@cordeo.io.
Processor activities on the Cordeo platform
For personal data contained in information that a customer uploads, connects, transmits, generates, or otherwise makes available through the Cordeo platform (“Customer Data”):
- the customer normally determines the purposes and essential means of processing and acts as the controller;
- the Cordeo entities act as processors, processing Customer Data only on documented customer instructions and under the applicable Data Processing Agreement; and
- where the customer itself acts as a processor, the Cordeo entities normally act as subprocessors.
For these activities, the customer is responsible for establishing a lawful basis, providing required notices, respecting data-subject rights, and ensuring that its instructions are lawful. Cordeo assists the customer as required by law and contract.
The same legal entity can be a controller for one activity and a processor for another. The role depends on the specific processing activity, not merely on the Cordeo product name.
Personal data we process
Website, booking, and business-enquiry data
We may process:
- name and surname;
- work email address and telephone number;
- organisation, department, role, or job title;
- the subject and content of your request;
- preferred meeting date, time, time zone, and language;
- communications and meeting-related records;
- consent and communication-preference records, where applicable;
- IP address, browser and device information, user-agent data, timestamps, security events, and rate-limit records; and
- language, session, and necessary cookie preferences.
We do not use data submitted through the booking form for unrelated electronic marketing unless a separate lawful basis and any required opt-in have been established.
Account, customer, and support data
We may process:
- account-holder and authorised-user information;
- login, authentication, role, and permission information;
- organisation and tenant information;
- contract, order, invoicing, and payment-administration information;
- support requests, service communications, and feedback;
- audit records, feature usage, configuration, and security logs; and
- records necessary to establish, exercise, or defend legal claims.
Customer Data processed through the platform
The categories depend on the customer’s configuration, use case, integrations, and instructions. They may include:
- identity, contact, demographic, and professional information;
- employee, candidate, customer, supplier, stakeholder, or user records;
- organisational structures, roles, responsibilities, and access information;
- correspondence, meeting content, messages, notes, and collaboration data;
- documents, files, forms, reports, contracts, policies, and knowledge-base content;
- audio, video, images, transcripts, and speaker information;
- operational, commercial, financial, accounting, procurement, project, and service data;
- system, device, application, usage, and event data;
- information derived from connected systems or customer-authorised integrations; and
- special categories of personal data or criminal-conviction/offence data, but only where the customer has expressly instructed such processing, has a valid legal basis, and the applicable agreement and safeguards permit it.
Customers must not provide personal data that is unnecessary for their use case. Customers should apply data minimisation, access restrictions, and, where appropriate, anonymisation or pseudonymisation.
Generated and derived data
Depending on enabled features, Cordeo may generate or process:
- structured extractions;
- classifications, labels, topics, and metadata;
- summaries, transcripts, translations, and redacted versions;
- embeddings, search indexes, and semantic representations;
- scores, indicators, recommendations, forecasts, and model outputs;
- workflow and audit records; and
- quality, performance, security, and error telemetry.
Generated data may itself constitute personal data where it relates to an identifiable person.
How we obtain personal data
We may obtain personal data:
- directly from you;
- from your employer, organisation, or the Cordeo customer;
- from users authorised by the customer;
- from systems and integrations connected by or for the customer;
- automatically from your device or interaction with the service;
- from our hosting, security, communications, and support providers; and
- from public sources only where this is lawful and relevant to a customer-authorised or independently lawful purpose.
Purposes and legal bases for controller activities
Where the Cordeo entities act as controllers, personal data may be processed as follows:
| Purpose | Typical legal basis under GDPR | Typical basis under KVKK |
|---|---|---|
| Responding to a meeting, demo, contact, or commercial request | Steps requested before entering a contract; legitimate interests | Necessary for establishing or performing a contract; legitimate interests where applicable |
| Managing customer, user, supplier, and partner relationships | Contract; legitimate interests; legal obligation | Establishment or performance of a contract; legal obligation; legitimate interests |
| Creating and administering accounts and permissions | Contract; legitimate interests | Establishment or performance of a contract; legitimate interests |
| Providing service communications and support | Contract; legitimate interests | Establishment or performance of a contract; legitimate interests |
| Invoicing, accounting, tax, and record keeping | Contract; legal obligation | Legal obligation; establishment, exercise, or protection of a right |
| Securing systems, preventing abuse, detecting incidents, and maintaining logs | Legitimate interests; legal obligation | Legal obligation; legitimate interests |
| Establishing, exercising, or defending legal claims | Legitimate interests; legal obligation | Establishment, exercise, or protection of a right |
| Remembering language, session, and necessary preferences | Necessary service functionality; legitimate interests | Necessary for service functionality; legitimate interests |
| Optional marketing communications | Consent or another basis permitted by applicable electronic-marketing law | Explicit consent or another basis permitted by applicable law |
The precise basis may vary by jurisdiction and circumstance. Where consent is relied upon, it may be withdrawn at any time without affecting processing already carried out lawfully.
Where Cordeo acts as a processor, the customer determines the purposes and lawful basis of the processing.
Artificial intelligence and automated processing
Depending on the features selected by the customer, Cordeo may use automated and AI-assisted techniques for functions such as transcription, OCR, extraction, classification, redaction, translation, summarisation, semantic search, scoring, forecasting, recommendation generation, and workflow support.
Cordeo does not independently use Customer Data to make decisions that produce legal or similarly significant effects on individuals. Outputs are intended to support customer-controlled workflows and, where appropriate, human review. The customer is responsible for assessing whether its particular use constitutes automated decision-making or profiling and for applying any required safeguards.
Proposed policy commitment — confirm before publication: Cordeo does not use Customer Data to train general-purpose or shared models made available to other customers unless the customer has expressly agreed to that use in writing. Where external AI providers are used as subprocessors, their processing must be governed by contract, documented instructions, and the current subprocessor list.
Who receives personal data
Personal data may be disclosed, strictly as necessary, to:
- the two Cordeo operating entities and authorised personnel;
- the relevant customer and its authorised users;
- hosting, infrastructure, communications, email-delivery, security, support, and AI-service providers acting under contract;
- integration providers selected or enabled by the customer;
- accountants, auditors, insurers, legal advisers, and professional consultants;
- public authorities, courts, regulators, or law-enforcement bodies where disclosure is legally required or necessary to protect rights; and
- a prospective purchaser, investor, or successor in connection with a merger, financing, reorganisation, or sale, subject to appropriate confidentiality and legal safeguards.
We do not sell personal data. We do not disclose personal data for third-party behavioural advertising.
Service providers and subprocessors
The current service architecture may include:
| Provider | Function | Processing location / transfer note |
|---|---|---|
| DigitalOcean | Website, application, database, storage, or infrastructure hosting | Frankfurt, Germany, subject to confirmation of the contracted entity and support-access arrangements |
| Resend and its email-delivery infrastructure, which may include Amazon SES | Transactional and confirmation email delivery | Ireland (eu-west-1) sending region; provider-side retention follows the active Resend configuration |
| Cloudflare | Network security, content delivery, and Turnstile bot protection | May involve processing from multiple locations under the applicable transfer safeguards |
The current subprocessors are listed in Section 9 of this Notice. Where contractually required, customers will receive notice of material subprocessor changes and may exercise the rights stated in their agreement.
International data transfers
Cordeo’s operating model may involve:
- access to EEA-hosted data by authorised personnel in Türkiye;
- transfers between the EU entity and the Türkiye entity;
- transfers from Türkiye to providers or systems located abroad; and
- processing by global service providers and their approved subprocessors.
International transfers are carried out only where the requirements of GDPR Chapter V, KVKK Article 9, and other applicable law are met.
Depending on the transfer, safeguards may include:
- an applicable adequacy decision;
- European Commission Standard Contractual Clauses and, where required, a transfer assessment and supplementary measures;
- standard contracts, binding corporate rules, undertakings, or other appropriate safeguards recognised under Turkish data-protection law;
- contractual restrictions, encryption, access controls, data minimisation, and regional hosting; or
- a legally permitted derogation for a specific and non-repetitive situation.
Information about the applicable transfer safeguard may be requested from info@cordeo.io, subject to lawful redactions.
Retention and deletion
We retain personal data only for as long as reasonably necessary for the stated purpose, contractual obligations, legal requirements, security, and the establishment or defence of claims.
The following retention schedule reflects the current implementation where a period is specified. Items marked N/A remain to be defined:
| Data category | Current retention / status |
|---|---|
| Booking, demo, and business-enquiry records | 730 days (24 months), measured from the record's most recent update (updated_at) |
| IP address and user-agent attached to briefing/demo requests | 730 days, because they are stored in the same briefing-request record and currently have no separate deletion rule |
| Customer-contract, billing, tax, and legal records | For the contract term and the applicable statutory limitation and record-retention periods |
| Account and authorised-user data | For the active account period, followed by a limited closure and recovery period |
| Customer Data in the active platform | For the contract term and as instructed by the customer |
| Customer Data after termination | N/A — a separate platform-wide post-termination retention period has not yet been specified |
| Access and application logs | No fixed retention period is currently configured because log rotation is not yet defined |
| Rate-limit and temporary anti-abuse data | 1 hour in memory; the state is cleared on application restart |
| Database backups | Approximately 35 days (7 daily backups plus 4 weekly backups); deleted live data may therefore remain in backup copies until those copies expire |
| Language-preference cookie | 365 days |
| Provider-held email and delivery logs | According to the configured retention and the provider contract |
The periods above reflect the currently provided implementation details. Items marked N/A must be defined before publication. Where Cordeo acts as processor, deletion and return are governed by the customer’s instructions and Data Processing Agreement.
Security
We apply technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Depending on the service and risk, these measures include:
- encryption in transit;
- restricted administrative access through encrypted channels;
- role-based and least-privilege access controls;
- private-network separation of databases and internal services;
- strong authentication and cryptographic-key-based administration;
- firewalling, logging, monitoring, and abuse prevention;
- controlled backups and recovery procedures;
- vulnerability, patch, and dependency management;
- personnel confidentiality and security responsibilities;
- supplier and subprocessor due diligence; and
- incident-response and breach-management procedures.
No system can be guaranteed completely secure. Customers are also responsible for configuring access, integrations, retention, and use of the platform in a secure and lawful manner.
Personal-data breaches
Where Cordeo acts as a processor, it will notify the relevant customer without undue delay after becoming aware of a personal-data breach, in accordance with the Data Processing Agreement, and will provide reasonable assistance with investigation and legally required notifications.
Where the Cordeo entities act as controllers, they will notify the competent authority and affected individuals where and within the period required by applicable law.
Your rights
Rights under GDPR
Subject to the applicable conditions and exceptions, you may have the right to:
- access your personal data and obtain a copy;
- correct inaccurate or incomplete data;
- request erasure;
- restrict processing;
- object to processing based on legitimate interests or to direct marketing;
- receive certain data in a portable format;
- withdraw consent at any time;
- request safeguards relating to qualifying automated decisions; and
- lodge a complaint with a competent data-protection supervisory authority.
Rights under KVKK
Under Article 11 of Law No. 6698, you may have the right to:
- learn whether your personal data is processed;
- request information about the processing;
- learn the purpose of processing and whether data is used consistently with that purpose;
- know the third parties to whom data is transferred domestically or abroad;
- request correction of incomplete or inaccurate data;
- request deletion or destruction where the legal conditions are met;
- request notification of correction, deletion, or destruction to recipients;
- object to a result against you arising from analysis exclusively by automated systems; and
- claim compensation for damage caused by unlawful processing.
How to exercise your rights
For data Cordeo processes as controller, send your request to info@cordeo.io or use the application method stated at info@cordeo.io.
We may request information necessary to verify identity and locate the relevant records. We will respond without undue delay and within the applicable statutory period—normally within one month under GDPR and no later than 30 days under KVKK, subject to lawful extensions or exceptions.
For Customer Data that Cordeo processes as processor, please contact the organisation that provided or controls your access to Cordeo. That organisation is normally the controller. Cordeo will assist it in responding as required by law and contract.
Complaints
You may complain to:
- the data-protection supervisory authority in the EU/EEA country of your habitual residence, place of work, or the alleged infringement;
- N/A, where applicable; and
- the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu), subject to the application and complaint procedure under Turkish law.
We encourage you to contact info@cordeo.io first so that we can try to address the concern directly. This does not limit your right to approach a supervisory authority.
Children
Cordeo is intended for organisations and business users and is not directed to children. Customers must not use the platform to process children’s personal data unless this is lawful, necessary for the authorised use case, contractually permitted, and protected by appropriate safeguards.
Changes to this Notice
We may update this Notice where our services, providers, processing activities, or legal obligations change. The updated version will be posted with a revised “Last updated” date. Where required, we will provide additional notice of material changes.
Language versions
This Notice may be made available in English, German, Dutch, and Turkish. The versions are intended to have the same meaning. In the event of an inconsistency, English will be the reference version to the extent permitted by mandatory law. No translation limits rights granted by applicable law.
Contact
Primary privacy contact: info@cordeo.io
EU entity: Cordeo IO (EU entity), info@cordeo.io
Türkiye entity: Cordeo IO (Türkiye entity), info@cordeo.io
Data Protection Officer, if appointed: bilal.naci.yilmaz@rdc.com.tr