Privacy Policy

This Privacy Policy explains how Codexal (“Codexal”, “we”, “us”, “our”) collects, uses, discloses, and protects information when you use our websites, products, and services (together, the “Services”). It also explains your choices and rights.

Last updated: September 24, 2025

Quick Navigation

1) Who We Are

Codexal is a software & AI company headquartered in Amman, Jordan, with presence in California, USA and Riyadh, Saudi Arabia. We build web/mobile applications, AI/OCR pipelines, automation, IoT integrations, design systems, and cloud deployments.

2) Scope & Roles (Controller / Processor)

This Policy applies to information we process when you visit our websites, communicate with us, or use our Services. Depending on the engagement:

  • Controller: We act as a controller for data we collect directly (e.g., website analytics, support communications, marketing).
  • Processor/Service Provider: When customers use our products to process their end users’ data (e.g., OCR intake, portals), we process such data on the customer’s documented instructions and our contract terms.

3) Information We Collect

A. Information you provide

  • Contact and account details.
  • Content you upload (OCR docs, images, forms).
  • Payment info via gateways.
  • Recruitment data.
  • Support communications.

B. Information collected automatically

  • Device/usage data (IP, browser/OS, pages, timestamps, language, coarse location).
  • Cookies/SDKs (sessions, preferences, analytics, marketing where applicable).
  • Diagnostics/telemetry from apps/APIs/IoT.

C. Information from third parties

  • Payment processors, identity providers, public sources, partners.

4) How We Use Information

  • Provide/secure/improve Services; support; configure AI/OCR; QA & incidents; comply with law; prevent abuse; and (with consent/legitimate interest) send updates (you can opt out).

5) AI, OCR & Automation

We integrate AI (OCR, NLP, CV) to automate workflows. We do not use customer content to train public models unless agreed in writing. Any third-party AI processors are contractually restricted.

6) Payments

Processed by PayTabs/MEPS/Stripe; we don’t store raw card data. We receive status and tokenized references for invoicing/refunds/fraud prevention.

7) Cookies, SDKs & Analytics

We use necessary cookies; analytics with consent where required (e.g., GA4). Blocking some cookies may affect functionality.

8) Sharing & Disclosures

  • Service providers (hosting/analytics/comms/gateways), advisors, corporate transactions, legal compliance. We don’t sell personal information.

9) Security

We apply appropriate technical/organizational measures (encryption in transit, least privilege, logging). No method is 100% secure; we’ll notify as required in case of breach.

10) Data Retention

Kept as needed for Services/purposes/legal duties. For processor roles, retention follows customer instructions, including deletion at contract end.

11) International Transfers

Processing may occur in JO/SA/US and other regions with appropriate safeguards where required.

12) Your Rights & Choices

  • Access/correct/delete data; object/restrict; withdraw consent; data portability; opt-out of marketing; appeal (where applicable). Contact info@codexal.co.

13) Children’s Privacy

Not directed to under-13s (or higher local age). If you believe a child provided data, contact us to delete it.

14) Do Not Track

We don’t respond to DNT signals currently.

15) Changes to this Policy

We may update periodically and post the new “Last updated” date.

16) Contact Us

Emails

Phone & WhatsApp

Branches

  • Jordan — Amman
  • USA — California
  • Saudi Arabia — Riyadh

This Policy is for transparency and not legal advice. If there’s a conflict with a signed customer agreement, that agreement controls to the extent allowed by law. English version governs.

18) Jurisdiction-Specific Addenda (Summary)

A. EEA/UK (GDPR/UK GDPR)

  • Legal bases: consent, contract, legitimate interests, legal obligation, vital interests. Rights include access, rectification, erasure, restriction, portability, objection, complaint.

B. California (CCPA/CPRA)

  • No “sale” of PI; rights to access/delete/correct/limit SPI; requests via info@codexal.co.

C. Saudi Arabia (PDPL)

  • Processed per PDPL where applicable; cross-border transfers follow PDPL rules.

D. Jordan & Other Regions

  • We follow applicable local requirements; contact us to exercise any additional rights.