Privacy Notice
We collect only the personal information needed to run our website, respond to you, and deliver the IRIS application security platform. We do not sell your data. This notice explains what we collect, why, who we share it with, and how to exercise your rights.
Effective July 1, 2026
Who we are and what this notice covers
CodeEye Solutions Inc. ("CodeEye", "we") is a Canadian corporation with its head office at 110 Cumberland Street, Suite 313, Toronto, Ontario, Canada. We have an operations team in El Salvador.
This notice applies to:
-
Visitors to codeeye.ai and any CodeEye-operated landing pages
-
People who submit a form on our website or through a LinkedIn Lead Gen Form
-
Business contacts at prospects, customers, partners and suppliers
-
Users of IRIS where CodeEye is the service provider
It does not apply to personal information our customers upload into IRIS, such as data inside scanned repositories. For that data CodeEye acts as a service provider under the customer's contract, and the customer's own privacy notice applies.
This notice is CodeEye's public privacy notice under our internal Privacy Policy, which is part of our SOC 2 control set. The internal policy is available to customers under NDA on request.
What personal information we collect
We collect business contact information you give us, and limited technical data about your visit. We do not collect sensitive personal information (health, financial account, government ID, biometrics) through our website or ads.
Source | Information | Collected how |
|---|---|---|
Website forms (demo request, contact, download) | Name, work email, company, job title, phone (optional), message | You type it in |
LinkedIn Lead Gen Forms | Name, work email, company, job title, country, and any field shown on the form, pre-filled from your LinkedIn profile | LinkedIn passes it to us when you click Submit |
LinkedIn Insight Tag and analytics | IP address, device and browser type, pages viewed, referring URL, LinkedIn member attributes in aggregate | Automatically, by cookies and similar technology |
Business relationship | Contact details, role, correspondence, meeting notes, contract and billing contacts | From you, your employer, or public professional sources such as LinkedIn |
IRIS user accounts | Name, work email, role, login and activity logs | Created by your organization's IRIS administrator |
Support and sales calls | Your questions, call notes, recordings where you are told at the start | From you |
We do not buy personal information from data brokers.
Why we use it
We use your information only for the purposes below, and only as far as a reasonable person would expect for a B2B software company.
Purpose | Examples | Basis |
|---|---|---|
Respond to your request | Book a demo, send a datasheet, answer a question | Your request (consent) |
Sales and marketing | Follow up on a form or LinkedIn lead, send product updates, invite you to events | Consent, or an existing business relationship under Canada's Anti-Spam Legislation (CASL) |
Deliver IRIS and services | Create accounts, provide support, bill, secure the platform | Our contract with your organization |
Improve the website and ads | Measure page visits, conversion of LinkedIn campaigns, test content | Legitimate business interest; analytics cookies only with your consent where required |
Security and fraud prevention | Detect abuse, investigate incidents, protect our systems | Legitimate business interest and legal duty |
Legal compliance | Tax, accounting, responding to lawful requests | Legal obligation |
Marketing email. Every marketing email we send includes an unsubscribe link. Opting out stops marketing but not transactional messages such as invoices or security notices.
No automated decisions. We do not use your personal information to make decisions with legal or similarly significant effects on you by automated means.
Cookies, analytics and the LinkedIn Insight Tag
Our website uses cookies and similar technologies. Strictly necessary cookies run without consent. Analytics and advertising cookies run only after you accept them in the cookie banner, where the law requires consent.
Category | What it does | Provider |
|---|---|---|
Strictly necessary | Keeps the site working, remembers your cookie choice | CodeEye |
Analytics | Counts visits and pages viewed so we can improve the site | Wix (our website platform) |
Advertising | Measures whether our LinkedIn ads led to a visit or a form submission, and lets us show relevant ads to people who visited | LinkedIn Insight Tag |
LinkedIn Insight Tag. This website uses the LinkedIn Insight Tag, a piece of code from LinkedIn Corporation (and LinkedIn Ireland Unlimited Company for members in the EEA, UK and Switzerland). It sets a cookie and collects URL, referrer, IP address, device and browser characteristics, and timestamp. LinkedIn does not share your personal data with CodeEye; it gives us aggregated reports about our website audience and ad performance. LinkedIn members can control the use of their data for advertising in their LinkedIn account settings, and anyone can opt out at LinkedIn's opt-out page. LinkedIn's privacy policy describes how LinkedIn handles this data.
LinkedIn Lead Gen Forms. When you submit a LinkedIn Lead Gen Form for a CodeEye ad, LinkedIn sends us the fields on that form. We use them only to respond to the offer you requested and, if you agree, for follow-up marketing. LinkedIn keeps a copy under its own privacy policy.
You can change or withdraw your cookie choices at any time through the cookie settings link in the website footer, or by clearing cookies in your browser.
Who we share it with
We do not sell personal information, and we do not share lead data from LinkedIn with third parties for their own marketing.
We share personal information only with service providers that process it on our instructions under written contracts with confidentiality, security and audit terms, and with authorities when the law requires.
Category | Purpose | Examples |
|---|---|---|
Cloud hosting | Run IRIS and internal systems; host our website | Microsoft Azure (Canada Central); Wix |
Business productivity | Email, documents, calendars, collaboration | Microsoft 365 |
CRM and marketing | Track leads and send marketing email | Microsoft Dynamics 365 Customer Insights |
Advertising and analytics | Measure website and ad performance | LinkedIn, Wix |
Payments and accounting | Invoice and collect payment | Our bank and accounting software; we do not use a third-party card processor |
Professional advisers | Legal, accounting, audit (including our SOC 2 auditor) | Under professional confidentiality |
Corporate transactions | If CodeEye is sold or merges, to the buyer under confidentiality | Only as needed to complete the transaction |
We keep an inventory of all service providers that handle personal information and review their privacy and security practices at least annually. A current list of sub-processors for IRIS is available to customers on request.
Where your information is stored
Our primary systems run on Microsoft Azure in the Canada Central region (Toronto). Some service providers, including LinkedIn and Microsoft, process data in the United States and other countries. Our team in El Salvador may access personal information to provide sales, support and operations.
When personal information leaves Canada we use contractual safeguards, including Standard Contractual Clauses or equivalent terms, and we document and approve any exception. Information held outside Canada may be subject to lawful access by the authorities of that country.
How long we keep it
We keep personal information only as long as needed for the purpose we collected it, then delete or anonymize it under our Data Retention Schedule.
Information | Retention |
|---|---|
Website and LinkedIn form submissions that do not become a customer | Until you unsubscribe or ask us to delete them, and no longer than 36 months after your last interaction with us |
Marketing contacts | Until you unsubscribe, then suppressed to honour the opt-out |
Customer and contract records | Term of the contract plus 7 years for tax and legal requirements |
IRIS account and activity logs | Term of the contract plus 90 days, or as the contract states |
Website analytics and advertising cookies | Up to 13 months, or as set by the provider |
Privacy requests and related records | 3 years minimum |
How we protect it
CodeEye maintains a SOC 2 control environment. Personal information is encrypted in transit and at rest, access is limited to staff with a business need and protected by multi-factor authentication, networks are segmented, and access to personal information is logged and reviewed. All staff and contractors complete privacy and security training at onboarding and every year.
If a security incident affects your personal information and creates a real risk of significant harm, we will notify you and the relevant privacy regulator within the timelines the law requires.
No system is completely secure. If you believe your information has been compromised, contact us at the address below.
Your rights
You can ask us to:
-
Tell you what personal information we hold about you and how we use it
-
Correct information that is inaccurate or incomplete
-
Delete your information, unless we must keep it by law or contract
-
Stop or limit how we use it, including withdrawing consent
-
Give you a copy in a portable format
-
Object to marketing at any time
To make a request, email our Privacy Officer at the address below. We will confirm your identity, respond within 30 days, and tell you if we need more time or cannot fully comply. There is no fee for a reasonable request. We record every request and its outcome.
If you are not satisfied with our response you may complain to the Office of the Privacy Commissioner of Canada, to the Commission d'accès à l'information du Québec if you are in Quebec, or to the data protection authority in your country.
If your personal information is in IRIS because your employer is a CodeEye customer, please contact your employer first. We will support them in responding to you.
Children
Our website, ads and services are for businesses and their staff. We do not knowingly collect personal information from anyone under 18. If you believe a minor has given us information, contact us and we will delete it.
Changes to this notice
We review this notice at least once a year and whenever our practices change. We will post the new version here with a new effective date, and tell you directly if a change materially affects how we use information we already hold about you.
Contact
Privacy Officer, CodeEye Solutions Inc.
110 Cumberland Street, Suite 313, Toronto, Ontario, Canada
Email: contact@codeeye.ai (subject line: Privacy)
