Back to home

Privacy and personal data

Privacy policy

This policy explains what data Codenergy processes, why it is used, and what choices people have when they visit the website, request a demo, or use the platform.

Last updated: August 18, 2026

1. Who processes the data

Codenergy is the brand and service through which the platform is offered. The provider identified in each customer's proposal, order form, or agreement is responsible for account, contact, security, and business relationship data processed by Codenergy.

Privacy inquiries are received at hola@cod.energy. This policy applies to cod.energy, the demo, and the application; it does not cover third-party websites linked from them.

2. Data we process

We process only the data reasonably needed to provide, protect, and improve the service. Depending on how Codenergy is used, this may include:

  • Account and access data: name, corporate email, organization, role, language, and authentication records.
  • Customer-uploaded project data: assets, contractors, personnel and resources subject to accreditation, protocols, results, signatures, evidence, documents, punch items, and acceptance decisions.
  • Technical and security data: IP address, browser, device, date, normalized route, error events, and records needed to prevent abuse and maintain the service.
  • Information voluntarily submitted through forms or support: name, company, email, project type, and any context the person chooses to share.

3. How we use data

Processing supports the requested or contracted relationship, the consent given, legal obligations, and legitimate interests compatible with individual rights. Specifically, we use data to:

  • Create accounts, authenticate users, and provide accreditation, execution, handover, and traceability features.
  • Protect organizations, projects, and users, and investigate errors, fraud, abuse, or unauthorized access.
  • Respond to inquiries, arrange demos, provide support, and send operational service communications.
  • Measure limited feature usage and improve performance and experience without session recordings or automatic content capture.
  • Meet legal obligations, preserve contractual evidence, and establish, exercise, or defend rights.

4. Codenergy's and the customer's roles

For visitor, prospect, account, and service security data, Codenergy determines the purposes described in this policy. For project data an organization uploads to manage its site, the customer determines what is included and why, while Codenergy processes it to provide the service under the customer's instructions and the applicable agreement.

Each customer must have a valid basis for uploading data about employees, contractors, suppliers, and third parties, provide any required notices, and configure access according to its own obligations.

5. Providers and recipients

We do not sell personal data. We may share it with providers operating required infrastructure or communication channels under their contracts and security measures, or where required by law. Current main categories include:

  • Supabase and Vercel for databases, authentication, storage, execution, and application hosting.
  • Sentry and PostHog for errors and limited product analytics, and Google Analytics for acquisition on public pages when the visitor accepts it. Analytics is not used for advertising and is not loaded within authenticated routes.
  • Resend and Slack for transactional email, forms, and internal coordination of inquiries. A person's message may reach those channels so the team can respond.

6. International transfers

Some providers may process data outside Chile. Codenergy assesses each provider's function, location, and contractual safeguards and applies the requirements in force for international transfers. The specific region may depend on the contracted service and available technical configuration.

7. Retention

We retain data while the account or relationship is active and then for the time needed to perform the agreement, address requests, maintain backups, prevent fraud, and meet legal periods. Commercial inquiries are retained while a request or reasonable business interest remains; a person may ask for deletion where no obligation requires retention.

8. Security

We use database-level organization isolation, role-based access controls, authentication, encryption in transit, logging of sensitive actions, and backups. No system is infallible; if you detect a possible incident, avoid adding further sensitive information and report it immediately to hola@cod.energy.

9. Individual rights

Under applicable law, you may request information about your data, access, correction, deletion or cancellation, blocking, and any other available rights. Once the rules recognizing them take effect, this will include objection and portability in the cases provided by law.

To exercise a right, write to hola@cod.energy and describe your request and relationship with Codenergy. We may request limited information to verify identity and avoid disclosing data to someone else. If your employer or principal uploaded the data, we will coordinate the response with that customer when needed.

10. Children

Codenergy is a business service and is not directed to children. We do not seek to deliberately collect children's or teenagers' data through the public website.

11. Changes to this policy

We may update this policy when the service, providers, or laws change. We will publish the new date on this page and communicate material changes through an appropriate channel when needed.