1. Who we are
Codified Studio ("we", "us", "our") is an independent software development studio. We operate remotely, and our operational base is at House no L-495, Universal Town, Karachi 74900, Pakistan. We work with clients in the United Kingdom, United States, United Arab Emirates and Pakistan.
Codified Studio is a trading name. Nothing in this policy should be read as a statement that we are incorporated, registered, licensed, certified or established as a business in any particular country.
This policy applies to personal data we handle through codifiedstudio.com and through direct enquiries made to us by email, telephone or messaging. It does not apply to third-party websites we link to, which operate under their own policies.
Questions about this policy, or about any personal data we hold, can be sent to admin@codifiedstudio.com or +92 345 276 2600. We aim to respond personally, and promptly.
2. Our role: controller and processor
Data protection law distinguishes between the party that decides why and how personal data is used (the controller) and the party that handles it on someone else's instructions (the processor). Which role we occupy depends on the data in question.
- Website visitors and enquirers — we act as controller. We decide what the contact form asks for, what analytics we run, and how long we keep an enquiry.
- Client project data — where we handle personal data belonging to a client's own users, customers or staff in the course of delivering a project, we generally act as processor on that client's instructions. In that case the client remains the controller, and the terms governing that processing are set out in a separate written data processing agreement rather than in this policy.
- Where the two overlap, the written project agreement takes precedence over this policy for the data it covers.
3. What we collect, and when
We aim to collect as little personal data as is reasonably necessary. There is no account system on this site, no newsletter sign-up wall, and no advertising or remarketing pixel.
- Contact form — your name, email address, optional company or website, the service selected, an optional budget range, and the content of your project description. You control what goes into the free-text field. Please do not include confidential material, special category data, or personal data belonging to your own customers before a confidentiality agreement is in place.
- Booking a call — if you use the Calendly scheduler embedded on our contact page, Calendly collects your name, email address and chosen time directly from you. That processing is carried out by Calendly under its own privacy policy, and the booking details are shared with us so that we can attend.
- Direct correspondence — if you email, call or message us (including via WhatsApp), we hold the content of that correspondence and the contact details it carries, in the relevant inbox or thread.
- Analytics — aggregated usage data collected through Google Analytics 4 where you have consented: which pages were viewed, approximate geographic region, device category, and the referring source. We do not use it to identify individuals, and we do not combine it with contact form submissions.
- Server logs — our hosting provider records standard technical information such as IP address, timestamp, requested URL and user agent, for security, diagnostics and abuse prevention.
- Client engagement records — where you become a client, we hold the contact, project, billing and correspondence records needed to deliver the work and to meet our record-keeping obligations.
4. Cookies and similar technologies
This site uses a small amount of browser storage, and — with your consent — analytics cookies. It sets no advertising cookies and no social tracking pixels.
A complete inventory of what is set, what each item does and how long it lasts is maintained in our Cookie Policy, which also lets you review or withdraw your analytics choice at any time. Where consent is required, analytics scripts are not loaded until that consent is given.
5. Analytics
We use Google Analytics 4 to understand which pages are useful and where visitors encounter difficulty. It is configured to report on usage patterns rather than to identify individuals, and we have not enabled advertising or remarketing features.
Analytics runs only where you have accepted it, or where consent is not required under the law applicable to you. You may withdraw consent at any time through our Cookie Policy, and analytics cookies will cease to be set. Google acts as our service provider for this purpose and processes the data under its own terms, which we do not control.
6. Why we are permitted to hold it (lawful basis)
Where UK or EU data protection law applies to a particular processing activity, we rely on the following bases. Where other laws apply, we aim to apply equivalent standards.
- Enquiries and correspondence — legitimate interests. You have approached us about a possible engagement, and responding to you is the expected use of that information. You may object at any time, and we will stop unless we have a compelling reason not to, in which case we will explain it.
- Analytics cookies — consent, where consent is required. You can withdraw it at any time; withdrawal does not affect processing carried out beforehand.
- Client engagements — performance of a contract, or steps taken at your request before entering into one.
- Accounting, tax and financial records — compliance with legal obligations to which we are subject, and our legitimate interest in maintaining accurate business records.
- Security, abuse prevention and defence of legal claims — legitimate interests in operating the site safely and protecting our position.
7. What we do with it
We use the information you provide to understand what you need, respond to you, prepare a scope and quotation, and — where you proceed — deliver and support the project.
We do not sell personal data. We do not rent or trade it, and we do not add enquirers to marketing lists they did not ask to join. We do not send unsolicited marketing email. If you send an enquiry and we do not hear back, we may follow up a small number of times and will then stop.
8. Third-party services and recipients
We use a limited number of third-party service providers to operate the site and the business. Each receives only what it needs for its function, and each processes data under its own terms and security arrangements, which we do not control.
- Google (Gmail / Google Workspace) — delivery and storage of contact form submissions and email correspondence.
- Google Analytics 4 — aggregated usage statistics, where consented.
- Calendly — scheduling, where you choose to book through the embedded scheduler.
- Hosting and infrastructure providers — serving the website and retaining standard server access logs.
- Professional advisers, payment providers and accounting services — where reasonably necessary for billing, record-keeping or obtaining advice.
- Successors in the business — if the studio or its assets are transferred or restructured, relevant records may transfer with it, subject to equivalent protections.
- Legal disclosures — where we are required to disclose information by applicable law, regulation, court order or a valid request from a competent authority, or where disclosure is reasonably necessary to establish, exercise or defend legal claims.
9. International transfers
We operate from Pakistan, some of the people we work with are based in other countries, and our service providers are largely established in the United States. If you are located in the United Kingdom or the EEA, this means your personal data will be accessed from, and may be stored in, a country outside your own.
Some of those countries have not been the subject of an adequacy decision by the UK or EU authorities. Where we transfer personal data internationally, we take steps we consider appropriate in the circumstances, including relying on the transfer mechanisms published by our providers — such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum — and limiting what is transferred to what is reasonably necessary.
You can ask us which mechanism applies to a specific provider and we will point you to it. Where a project involves personal data belonging to your own customers, transfer arrangements are dealt with in the separate data processing agreement for that project.
10. How long we keep it
We retain personal data for as long as it is needed for the purpose it was collected for, and then delete it or reduce it to an anonymised form. The periods below are our normal practice; they may be extended where a longer period is required by applicable law or where the data is relevant to an actual or anticipated dispute.
- Enquiries that do not become projects — normally up to 24 months from the last contact. Business conversations frequently resume, and keeping the context avoids asking you to repeat yourself.
- Client project and engagement records — for the duration of the engagement and normally up to 6 years afterwards, reflecting financial record-keeping obligations and limitation periods for claims.
- Analytics data — retained by Google Analytics on a rolling basis, currently configured to 14 months.
- Server logs — retained by our hosting provider for a short period under its own retention settings.
- You may ask us to delete your data sooner at any time. We will do so unless we are required to retain a specific record, or need it to establish, exercise or defend a legal claim — in which case we will tell you.
11. Security
We take technical and organisational measures that we consider appropriate to the risk. The site is served over HTTPS. Contact form submissions are transmitted over an authenticated, encrypted connection to our mail provider. Access to the inbox holding enquiries is restricted to those who need it and protected by multi-factor authentication. Devices used for client work are access-controlled.
No method of transmission or storage is entirely secure, and we do not represent that our systems, or those of our providers, cannot be compromised. We do not accept responsibility for the security of information while it is in transit to us over networks we do not control.
Please do not send passwords, payment card details, identity documents or other sensitive material through the contact form. If credentials need to be shared during a project, we will agree a suitable method with you.
12. Personal data breaches
We maintain internal procedures for identifying and responding to suspected personal data breaches, and we aim to investigate any incident as soon as reasonably practicable after becoming aware of it.
Where a breach affects personal data we control and applicable law requires notification, we will notify the relevant supervisory authority and, where required, affected individuals, without undue delay and within the timeframes that law prescribes. Where we act as a processor for a client, we will inform that client without undue delay so that they can meet their own obligations as controller.
13. Automated decision-making and profiling
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not build marketing profiles about individual visitors.
Analytics reporting is aggregated and used to improve the site, not to evaluate individuals. If this changes, we will update this policy and, where required, seek your consent or provide the additional information the law requires before doing so.
14. Your rights
Subject to the law applicable to you, you may have the right to request access to the personal data we hold about you, to have inaccurate data corrected, to have data erased, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent where our processing relies on it. As a matter of practice, we aim to make these rights available to anyone who contacts us, wherever they are located.
To make a request, email admin@codifiedstudio.com. You do not need to give a reason. We may need to verify your identity or ask for further detail before we can act, particularly where a request is broad. We aim to respond within one month, and will tell you if a request is complex and we need longer, to the extent applicable law allows.
There is normally no charge. Where a request is manifestly unfounded or excessive, we may charge a reasonable fee or decline to act, and we will explain why. Some rights are qualified: for example, we may not be able to erase records we are required to keep.
If you believe we have handled your personal data poorly, we would welcome the opportunity to put it right first. You may also have the right to lodge a complaint with the data protection authority in your country of residence or place of work. In the United Kingdom that is the Information Commissioner's Office (ico.org.uk).
15. Children's privacy
This is a business-to-business website. It is not directed at children, and we do not knowingly collect personal data from anyone under 16 (or the equivalent age of digital consent where you live).
If you believe a child has provided us with personal data, please contact us and we will take reasonable steps to delete it.
16. Changes to this policy
We may update this policy from time to time to reflect changes in how we work, in the services we use, or in applicable law. The current version is always the one published on this page, and the date at the top shows when it was last revised.
Where a change is material, we may aim to draw attention to it on the site.
17. Contact
Data protection enquiries, rights requests and complaints: admin@codifiedstudio.com, or +92 345 276 2600. Written correspondence can be sent to House no L-495, Universal Town, Karachi 74900, Pakistan.
We are not required to appoint a data protection officer and have not appointed one. Enquiries sent to the address above are handled by the individual or individuals responsible for privacy and compliance matters within Codified Studio.