1. Overview and Commitment
TheCodexThrill ("we", "our", "us") provides high-performance software engineering, enterprise web applications, AI solutions, and digital product consulting. This Privacy Policy details how we handle information collected through our public website (thecodexthrill.com) and our client portal and administrative workspaces.
We operate on principles of data minimization and least privilege: we collect only information necessary to deliver, secure, and improve our services, and we never sell, rent, or trade client or user personal information.
2. Information We Collect
Public Visitors and Enquiries: When you submit a project enquiry or contact form, we collect your name, business email address, company name, and details of your project requirements.
Authenticated Platform Users: For invited client members and staff, we collect authenticated profile details (email address, full name, avatar if provided), session metadata, multifactor authentication factor registrations, and security audit logs required to ensure workspace integrity.
Technical and Usage Data: Standard server access logs including IP addresses, browser user-agents, request timestamps, and referrers to monitor platform security, protect against automated abuse, and guarantee uptime.
3. How We Use Your Information
We use collected information solely for legitimate business and engineering operations:
- Responding to project enquiries and commercial consultations.
- Provisioning secure, invitation-only tenant organizations and user workspaces.
- Enforcing enterprise authentication boundaries, including mandatory multi-factor authentication (MFA) for privileged accounts.
- Maintaining immutable audit event trails for security and governance.
- Complying with contractual obligations and applicable regulatory standards.
4. Client Data Isolation and Security Architecture
All client tenant data is protected by PostgreSQL Row-Level Security (RLS) in our Supabase Cloud infrastructure. Organization records, memberships, projects, and documents are strictly compartmentalized by organization identifiers. Staff access is bounded by explicit role-based access controls (RBAC) and audited.
5. Data Retention and Erasure
We retain operational project data for the duration of the commercial engagement and for a reasonable period thereafter to fulfill warranty and legal obligations. Security audit events are preserved according to our governance baseline. You may request data access, export, or deletion at any time by contacting our engineering team.
6. Third-Party Infrastructure
Our core platform is hosted on enterprise cloud providers: Vercel for application delivery and edge network routing, and Supabase Cloud (AWS) for database, authentication, and encrypted storage. All data is encrypted in transit using TLS 1.3/1.2 and encrypted at rest using AES-256.
7. Contact and Rights Inquiries
If you have questions regarding this Privacy Policy or wish to exercise your rights under GDPR, CCPA, or applicable data protection regulations, please reach out directly:
TheCodexThrill Engineering & Governance
Email: contact@thecodexthrill.com
Security: security@thecodexthrill.com