Privacy Policy

craiready.com, craiready.ch, accounts.craiready.com, platform.craiready.ch and tenant subdomains · codAIx GmbH · Version 6.5 · As at: 07.09.2026

Convenience translation. This English version is provided for information only. The German version is the legally binding one.

1. Controller

The controller for our own processing operations described in this policy is:

codAIx GmbH
c/o JULITH GmbH
Erlengasse 3
8240 Thayngen, Switzerland
UID CHE-249.882.147, Commercial Register of the Canton of Schaffhausen
Managing directors: Dr. Judith Behr, Thomas Riehn
Email: datenschutz@codaix.ch
Contact: via the contact form

2. Representative in the European Union

Where Art. 27 GDPR applies, the representative in the EU is:

JULITH UG (haftungsbeschränkt)
Rennbahnstrasse 72
60528 Frankfurt am Main, Germany
Frankfurt am Main Local Court (Amtsgericht), HRB 138446

The representative is an additional point of contact for data subjects and supervisory authorities. It is neither the controller for the platform nor the data protection officer of codAIx.

3. Scope and roles

This policy applies to the public website, the Quick Check, the contact and purchase process, the account portal, the crAIready platform and customer-specific tenant subdomains.

For the website, the Quick Check, contact, user account, contract, payment, our own security logs and abuse prevention, codAIx acts as controller. For personal content that a business customer processes in a product file, codAIx generally acts as processor under the data processing agreement (DPA) concluded with the customer.

The offering is aimed at businesses in Germany and Switzerland. Because services are specifically directed at Germany, the GDPR applies in addition to the Swiss Federal Act on Data Protection (FADP).

4. Hosting and technical operation

The core systems operated by codAIx itself – marketing website, account portal, platform, tenants, database, Umami, local AI and local backups – run on our own infrastructure at the operating site Erlengasse 3, 8240 Thayngen, Switzerland.

From the EU's perspective, Switzerland provides an adequate level of data protection. External processing by Stripe and by selectable AI providers is described separately in sections 11 and 12. Operating our own infrastructure in Thayngen therefore does not mean that, for every optional function, all data without exception remains in Thayngen.

The legal basis for technical operation is Art. 6(1)(f) GDPR or Art. 31(1) FADP, as applicable; our legitimate interest lies in secure, stable and traceable operation.

5. Server log files and technical security

When you access our services, the IP address, date and time, requested URL, HTTP status, volume of data transferred, referrer and user agent may be processed. This processing serves delivery, error analysis, protection against attacks and the evidencing of security events.

The legal basis is Art. 6(1)(f) GDPR or Art. 31(1) FADP, as applicable. Access logs are generally stored for 14 days and then deleted or anonymised, unless a specific security event requires longer, purpose-bound retention.

6. Cookies and local storage

We use technically necessary cookies or comparable local storage for language, session, login, security and basket/checkout control. They are not used for profile-based advertising. Session cookies generally expire at the end of the session; under the current configuration, the login session cookie has a lifetime of up to 24 hours.

The legal bases are Art. 6(1)(b) or (f) GDPR and the applicable rules on access to terminal equipment. Non-essential cookies are set only after valid consent.

7. Audience measurement with Umami

The platform uses the cookie-free software Umami, operated by codAIx itself. Umami runs on the codAIx infrastructure in Thayngen; no external analytics provider receives any data. Under the current configuration, no complete IP addresses are stored permanently and no cross-site user profiles are created.

The processing is based on Art. 6(1)(f) GDPR or Art. 31(1) FADP, as applicable. Our interest is the aggregated measurement of usage and errors. Aggregated measurement data is generally consolidated or deleted after approximately 90 days.

8. Public Quick Check

The Quick Check provides a non-binding initial assessment without login and runs entirely rule-based in the browser. The answers may contain product, scope and role data; they are processed exclusively locally in the browser and should not contain any special categories of personal data or confidential customer data.

The individual answers entered are neither transmitted to codAIx or the crAIready platform nor stored. No email address is required to use the Quick Check or to obtain the result. The answers are not carried over into a later product file; registration and invitation work without handoff or result tokens. After a purchase, product details are captured afresh in the platform's onboarding wizard.

When the Quick Check is accessed, technical server log data may be processed in accordance with section 5, irrespective of the content of the answers. If a user actively contacts codAIx or starts a purchase process, only the data newly entered there is processed in accordance with sections 9 and 11.

9. Contact and technical support

For contact enquiries, we process name, business email address, company, message and, where applicable, telephone number in order to answer the enquiry and take steps prior to entering into a contract. The legal basis is Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR, as well as Art. 31 FADP.

Enquiries that do not lead to a contract are deleted once they have been dealt with and no legitimate evidentiary or limitation-period interests stand in the way. Contract-relevant communication is stored for the statutory retention and evidence periods.

On request, we can pass contact details on to an independent law firm in order to establish contact. This is done only upon express request and on the basis of Art. 6(1)(b) GDPR. The law firm processes any further data under its own responsibility.

10. Account, registration and platform

For user accounts, we process business email address, password hash, role, company, login times and security events. The legal basis is Art. 6(1)(b) GDPR and, for security data, Art. 6(1)(f) GDPR.

Company, product, SBOM, component, vulnerability, supply chain, documentation, role, task, approval and reporting data may be processed in the platform. Where such data relates to identified or identifiable persons and the customer determines the purposes and means, codAIx processes it on the customer's behalf under the DPA.

Account and contract data is stored for the term of the contract and thereafter in accordance with statutory retention and limitation criteria. Customer data is exported and deleted after the end of the contract in accordance with the DPA. Audit and security logs are stored for the period required for traceability, security and contractual evidence and are then deleted or anonymised.

11. Purchase and Stripe

For paid orders, we process company name, name, billing address, tax/UID details, plan, number of products, contract versions, order status and transaction reference. Payment details are processed via Stripe.

Depending on the active Stripe product, Stripe Payments Europe, Ltd. and its affiliates act as independent controllers for parts of the payment processing and as processors for other processing steps. Stripe processes data in particular for payment, billing, fraud prevention and legal obligations. Processing may take place outside Switzerland and the EEA; Stripe describes the safeguards in its Data Processing Agreement.

The legal basis is Art. 6(1)(b) GDPR; for invoicing and tax data required by law, additionally Art. 6(1)(c) GDPR. Complete card data is not stored on codAIx systems but processed by Stripe. Invoicing records are stored in accordance with the applicable statutory retention periods.

12. AI-supported functions

crAIready may use AI for triage, structuring, risk indications, chat and document drafts. AI outputs are suggestions and are reviewed and approved by humans before any legally or technically significant decision. No decision based solely on automated processing which produces legal or similarly significant effects takes place.

12.1 Local AI via OnLumis

The local AI software OnLumis is provided by JULITH GmbH and runs on codAIx infrastructure in Thayngen. The model processes only the respective prompt. Prompts, outputs and customer content are not transmitted to JULITH or other external recipients and are not used for model training. JULITH has no remote maintenance access and cannot view any customer data.

If the server is connected to the internet, it establishes an outbound connection to the deployment server for licence verification and to obtain software updates. In doing so, technically necessary connection, licence and version information is processed; prompts and customer content are not transmitted. This technical connection is not remote maintenance and does not give JULITH access to the local instance.

12.2 Selectable cloud AI

The customer may – where enabled in the selected plan – choose OpenAI or Anthropic. In that case, the respective prompt and the product information required for the function are transmitted to the selected provider. Passwords, authentication data, API keys and complete audit logs are not intentionally transmitted.

For customers from Switzerland or the EEA, under the current OpenAI DPA the contracting party is generally OpenAI Ireland Ltd.; OpenAI may pass data on to affiliates and sub-processors in accordance with its DPA. OpenAI states that, by default, it does not use API inputs and outputs for training unless expressly opted in; standard abuse logs may be stored for up to 30 days unless a different configuration has been agreed.

For commercial API use, Anthropic provides a DPA, incorporated into its Commercial Terms, that includes standard contractual clauses and states that, by default, it does not use inputs and outputs of commercial offerings for training unless expressly opted in or feedback is reported. The specific retention period depends on the account, function and agreed configuration.

The legal basis for processing activated by the customer is Art. 6(1)(b) GDPR; where codAIx acts as processor, the choice of provider constitutes a documented instruction under the DPA. The customer should not transmit any personal or confidential content that is not required for the function.

13. Technical data sources and APIs

For vulnerability, package, licence and lifecycle information, the platform may query public sources such as NVD/NIST, OSV, CISA KEV, EUVD/ENISA, package registries and GitHub on the server side. Only technical identifiers such as CVE numbers, package names, versions or public repository names are transmitted, not user IP addresses or customer names.

Should an activated function transmit personal or customer-identifying data, the service concerned will be added to this policy and to the DPA before activation.

14. Newsletter and voluntary customer emails

We currently offer no newsletter and no article or product update subscription. Opening an account, a Quick Check, a contact enquiry or a purchase is not used as consent to marketing.

Contract- and security-related service notifications may be sent regardless, insofar as they are necessary for the performance, protection or amendment of the contract. Advertising by email takes place only within the limits permitted by law.

15. Direct approach to business contacts

For permissible B2B business development, we may process business contact details obtained from direct contact, public company sources or from sales partners acting as independent controllers. The purposes are initial contact and management of a potential business relationship.

The legal basis is Art. 6(1)(f) GDPR or Art. 31(1) FADP, as applicable. Electronic advertising takes place only with the consent required under § 7 UWG or within the scope of a statutory exception. Data subjects may object to direct marketing at any time; thereafter, contact details are processed only in a suppression list to the extent necessary to honour the objection.

Prospect data is deleted as soon as there is no longer a demonstrable interest in initiating business, generally no later than 18 months after the last contact without a further business relationship.

16. Recipients and international transfers

Depending on the function actually used, recipients may include:

  • authorised persons within codAIx;
  • JULITH UG as EU representative for forwarded data subject and authority requests;
  • JULITH GmbH as software provider solely for technical licence verification and the provision of updates; without transmission of prompts or customer content and without remote maintenance access;
  • OpenAI or Anthropic where cloud AI has been selected by the customer;
  • Stripe and the payment companies involved for orders/payments;
  • an independent law firm only where a referral has been expressly requested;
  • authorities or courts where there is a legal obligation.

Transfers from the EU/EEA to Switzerland are based on the adequacy decision of the European Commission. For other third countries, adequacy decisions, standard contractual clauses and any necessary supplementary measures are used depending on the recipient. The provider DPAs actually concluded and the configurations in place remain decisive.

17. Data security

We implement technical and organisational measures appropriate to the risk. The documented measures include HTTPS/TLS, role-based permissions, separated customer environments, administrative access via VPN and additional password protection, a locked room at the operating site with access restricted to Judith Behr and Thomas Riehn, daily encrypted local backups, restore tests, security updates and monitoring. The platform logs key editing and approval operations so that decisions and changes remain traceable. Product-related logs are stored for the term of the contract and are thereafter handled together with the other customer data in accordance with the export and deletion rules described in section 18 and in the DPA. Technical server and access logs are generally stored for 14 days; in the event of a specific security event, longer purpose-limited retention may be necessary.

The last documented successful restore test took place on 2 September 2026. Administrative access is protected by VPN and additional password protection; comprehensive MFA is not claimed. Specific RTO/RPO, UPS/network redundancy, penetration tests or certifications are promised only where they have been expressly agreed or published.

18. Retention criteria

Data categoryDuration/criterion
Server and access logsgenerally 14 days; longer only in the event of a specific security event
Session datauntil the end of the session, or login session up to 24 hours
Umami datagenerally consolidated or deleted after approximately 90 days
Contacts/prospectsuntil dealt with; without a business relationship generally no later than 18 months after the last contact
Account and contract dataterm of the contract plus statutory retention/limitation periods
Customer/product dataterm of the contract; thereafter export and deletion in accordance with the DPA
Production data after the end of the contractgenerally within 30 days of export/end of contract
Backupsuntil overwritten in the regular backup cycle, at the latest within 30 days; restricted use for restoration only
AI prompts at cloud providersaccording to the respective DPA, endpoint and account configuration; displayed before activation
Quick Check individual answerslocal processing in the browser only; no transmission and no server-side storage

19. Rights of data subjects

Under the applicable rules, data subjects have in particular the rights of access, rectification, erasure, restriction of processing, data portability and objection. Consent may be withdrawn with effect for the future. Direct marketing may be objected to at any time. Please submit requests via the contact form at https://www.craiready.com/en/contact/?topic=privacy or to the EU representative. If a request relates to data that we process on behalf of a customer, we forward it to the customer acting as controller.

20. Right to lodge a complaint

In Switzerland, you may contact the Federal Data Protection and Information Commissioner (FDPIC). Under the GDPR, you may lodge a complaint with a data protection supervisory authority, in particular at your place of residence or at the place of the alleged infringement.

21. Changes

We update this policy when services, data flows or the legal situation change. The current version is available on the website. Registered users are informed of material changes where this is necessary.

22. Version date

This privacy policy is dated 7 September 2026.