top of page
CodeEye New Logo-Dark_2x.png

Privacy Notice

We collect only the personal information needed to run our website, respond to you, and deliver the IRIS application security platform. We do not sell your data. This notice explains what we collect, why, who we share it with, and how to exercise your rights.

Effective July 1, 2026

Who we are and what this notice covers

CodeEye Solutions Inc. ("CodeEye", "we") is a Canadian corporation with its head office at 110 Cumberland Street, Suite 313, Toronto, Ontario, Canada. We have an operations team in El Salvador.

This notice applies to:

  • Visitors to codeeye.ai and any CodeEye-operated landing pages

  • People who submit a form on our website or through a LinkedIn Lead Gen Form

  • Business contacts at prospects, customers, partners and suppliers

  • Users of IRIS where CodeEye is the service provider

It does not apply to personal information our customers upload into IRIS, such as data inside scanned repositories. For that data CodeEye acts as a service provider under the customer's contract, and the customer's own privacy notice applies.

This notice is CodeEye's public privacy notice under our internal Privacy Policy, which is part of our SOC 2 control set. The internal policy is available to customers under NDA on request.

What personal information we collect

We collect business contact information you give us, and limited technical data about your visit. We do not collect sensitive personal information (health, financial account, government ID, biometrics) through our website or ads.

Source
Information
Collected how
Website forms (demo request, contact, download)
Name, work email, company, job title, phone (optional), message
You type it in
LinkedIn Lead Gen Forms
Name, work email, company, job title, country, and any field shown on the form, pre-filled from your LinkedIn profile
LinkedIn passes it to us when you click Submit
LinkedIn Insight Tag and analytics
IP address, device and browser type, pages viewed, referring URL, LinkedIn member attributes in aggregate
Automatically, by cookies and similar technology
Business relationship
Contact details, role, correspondence, meeting notes, contract and billing contacts
From you, your employer, or public professional sources such as LinkedIn
IRIS user accounts
Name, work email, role, login and activity logs
Created by your organization's IRIS administrator
Support and sales calls
Your questions, call notes, recordings where you are told at the start
From you

We do not buy personal information from data brokers.

Why we use it

We use your information only for the purposes below, and only as far as a reasonable person would expect for a B2B software company.

Purpose
Examples
Basis
Respond to your request
Book a demo, send a datasheet, answer a question
Your request (consent)
Sales and marketing
Follow up on a form or LinkedIn lead, send product updates, invite you to events
Consent, or an existing business relationship under Canada's Anti-Spam Legislation (CASL)
Deliver IRIS and services
Create accounts, provide support, bill, secure the platform
Our contract with your organization
Improve the website and ads
Measure page visits, conversion of LinkedIn campaigns, test content
Legitimate business interest; analytics cookies only with your consent where required
Security and fraud prevention
Detect abuse, investigate incidents, protect our systems
Legitimate business interest and legal duty
Legal compliance
Tax, accounting, responding to lawful requests
Legal obligation

Marketing email. Every marketing email we send includes an unsubscribe link. Opting out stops marketing but not transactional messages such as invoices or security notices.

No automated decisions. We do not use your personal information to make decisions with legal or similarly significant effects on you by automated means.

Cookies, analytics and the LinkedIn Insight Tag

Our website uses cookies and similar technologies. Strictly necessary cookies run without consent. Analytics and advertising cookies run only after you accept them in the cookie banner, where the law requires consent.

Category
What it does
Provider
Strictly necessary
Keeps the site working, remembers your cookie choice
CodeEye
Analytics
Counts visits and pages viewed so we can improve the site
Wix (our website platform)
Advertising
Measures whether our LinkedIn ads led to a visit or a form submission, and lets us show relevant ads to people who visited
LinkedIn Insight Tag

LinkedIn Insight Tag. This website uses the LinkedIn Insight Tag, a piece of code from LinkedIn Corporation (and LinkedIn Ireland Unlimited Company for members in the EEA, UK and Switzerland). It sets a cookie and collects URL, referrer, IP address, device and browser characteristics, and timestamp. LinkedIn does not share your personal data with CodeEye; it gives us aggregated reports about our website audience and ad performance. LinkedIn members can control the use of their data for advertising in their LinkedIn account settings, and anyone can opt out at LinkedIn's opt-out page. LinkedIn's privacy policy describes how LinkedIn handles this data.

LinkedIn Lead Gen Forms. When you submit a LinkedIn Lead Gen Form for a CodeEye ad, LinkedIn sends us the fields on that form. We use them only to respond to the offer you requested and, if you agree, for follow-up marketing. LinkedIn keeps a copy under its own privacy policy.

You can change or withdraw your cookie choices at any time through the cookie settings link in the website footer, or by clearing cookies in your browser.

Who we share it with

We do not sell personal information, and we do not share lead data from LinkedIn with third parties for their own marketing.

We share personal information only with service providers that process it on our instructions under written contracts with confidentiality, security and audit terms, and with authorities when the law requires.

Category
Purpose
Examples
Cloud hosting
Run IRIS and internal systems; host our website
Microsoft Azure (Canada Central); Wix
Business productivity
Email, documents, calendars, collaboration
Microsoft 365
CRM and marketing
Track leads and send marketing email
Microsoft Dynamics 365 Customer Insights
Advertising and analytics
Measure website and ad performance
LinkedIn, Wix
Payments and accounting
Invoice and collect payment
Our bank and accounting software; we do not use a third-party card processor
Professional advisers
Legal, accounting, audit (including our SOC 2 auditor)
Under professional confidentiality
Corporate transactions
If CodeEye is sold or merges, to the buyer under confidentiality
Only as needed to complete the transaction

We keep an inventory of all service providers that handle personal information and review their privacy and security practices at least annually. A current list of sub-processors for IRIS is available to customers on request.

Where your information is stored

Our primary systems run on Microsoft Azure in the Canada Central region (Toronto). Some service providers, including LinkedIn and Microsoft, process data in the United States and other countries. Our team in El Salvador may access personal information to provide sales, support and operations.

When personal information leaves Canada we use contractual safeguards, including Standard Contractual Clauses or equivalent terms, and we document and approve any exception. Information held outside Canada may be subject to lawful access by the authorities of that country.

How long we keep it

We keep personal information only as long as needed for the purpose we collected it, then delete or anonymize it under our Data Retention Schedule.

Information
Retention
Website and LinkedIn form submissions that do not become a customer
Until you unsubscribe or ask us to delete them, and no longer than 36 months after your last interaction with us
Marketing contacts
Until you unsubscribe, then suppressed to honour the opt-out
Customer and contract records
Term of the contract plus 7 years for tax and legal requirements
IRIS account and activity logs
Term of the contract plus 90 days, or as the contract states
Website analytics and advertising cookies
Up to 13 months, or as set by the provider
Privacy requests and related records
3 years minimum

How we protect it

CodeEye maintains a SOC 2 control environment. Personal information is encrypted in transit and at rest, access is limited to staff with a business need and protected by multi-factor authentication, networks are segmented, and access to personal information is logged and reviewed. All staff and contractors complete privacy and security training at onboarding and every year.

If a security incident affects your personal information and creates a real risk of significant harm, we will notify you and the relevant privacy regulator within the timelines the law requires.

No system is completely secure. If you believe your information has been compromised, contact us at the address below.

Your rights

You can ask us to:

  • Tell you what personal information we hold about you and how we use it

  • Correct information that is inaccurate or incomplete

  • Delete your information, unless we must keep it by law or contract

  • Stop or limit how we use it, including withdrawing consent

  • Give you a copy in a portable format

  • Object to marketing at any time

To make a request, email our Privacy Officer at the address below. We will confirm your identity, respond within 30 days, and tell you if we need more time or cannot fully comply. There is no fee for a reasonable request. We record every request and its outcome.

If you are not satisfied with our response you may complain to the Office of the Privacy Commissioner of Canada, to the Commission d'accès à l'information du Québec if you are in Quebec, or to the data protection authority in your country.

If your personal information is in IRIS because your employer is a CodeEye customer, please contact your employer first. We will support them in responding to you.

Children

Our website, ads and services are for businesses and their staff. We do not knowingly collect personal information from anyone under 18. If you believe a minor has given us information, contact us and we will delete it.

Changes to this notice

We review this notice at least once a year and whenever our practices change. We will post the new version here with a new effective date, and tell you directly if a change materially affects how we use information we already hold about you.

Contact

Privacy Officer, CodeEye Solutions Inc.
110 Cumberland Street, Suite 313, Toronto, Ontario, Canada
Email: contact@codeeye.ai (subject line: Privacy)

bottom of page