CEDX Systems · Legal
Cookie Policy and Acceptable Use Policy
Two separately versioned policies on one page. The cookie table is replaced with markers to be filled from a real page load rather than vendor documentation, the "remember this device" feature is written conditionally to match the Privacy Policy, and the AUP now defers to the Terms' precedence ranki
Last updated: 8 August 2026 · Version 1.0
In short. This website sets no analytics, advertising or tracking cookies, which is why you never see a consent banner. The only cookies in play are the ones needed to keep the site reachable, keep you signed in to the product, and take a payment. If we ever add a cookie that is not strictly necessary, we will ask you before it loads.
Who this covers
This policy covers cedxsystems.com and the CEDX apps you sign in to — CEDX CRM, CEDX Desk, CEDX Invoicing and the rest of the platform. They are operated by CEDX Corporation, a for-profit New York corporation doing business as CEDX Systems ("CEDX Corporation", "we", "us") — CEDX Corporation is the legal entity, CEDX Systems is the name it trades under and the name on this site, and the rest of this page uses the trading name. It is a separate organisation from CEDX (the 501(c)(3) research institution at cedx.org), with separate books and separate systems. This policy does not cover cedx.org, and nothing here should be read as describing that organisation's practices.
What a cookie is, and what "strictly necessary" means
A cookie is a small piece of data a website asks your browser to store and hand back on later requests. Related technologies — local storage, session storage — work the same way for this purpose, and everything below applies to them too.
The rule in the EU and the UK (Article 5(3) of the ePrivacy Directive, and regulation 6 of the UK's PECR) is that storing or reading anything on your device needs your consent, unless it is strictly necessary to deliver the thing you actually asked for. That exemption is narrow on purpose. Keeping you signed in is strictly necessary. Measuring how you move around a site, remembering you for an advertiser, or recording your session is not.
Everything listed below falls in the first category. That is the whole reason there is no banner on this site: there is nothing to ask you about.
What this website sets
Our pages are served through a network provider that sits in front of the site and protects it from bots and abuse. That provider sets cookies on our domain.
Cloudflare sits in front of the site and the product as CDN, DNS and reverse proxy, terminating TLS at its edge and serving from the Cloudflare network globally. Verified against response headers on 8 August 2026.
Whatever that list turns out to be, these are bot-management and rate-limiting cookies set to keep the site reachable and to apply rate limits fairly. They are strictly necessary, and none of them is used to profile you. We will publish the names and lifetimes here before this page goes live, because a cookie table is the one thing on this page a visitor can check against the live site in ten seconds — and we would encourage you to.
That provider is also listed in Annex 3 of our Data Processing Addendum, because it terminates TLS and therefore handles request content in transit.
Apart from that provider, this site loads no analytics, no tag manager, no session recorder, no advertising or conversion pixel, no A/B testing tool and no chat widget. There is no third-party script on these pages collecting anything about you.
The only outside hosts named on these pages are cedx.org, linkedin.com and x.com, and they are link destinations in our footer, not resources the page loads — your browser contacts them only if you click. Following one of those links takes you to a site with its own cookies and its own policy, over which we have no control.
What the product sets when you sign in
Signing in requires a cookie. There is no way to run an authenticated session without one, and it is the textbook example of strictly necessary.
| Session / authentication cookie | Keeps you signed in as you move between pages and apps, so you are not asked for your password on every click | A single session cookie is set when you sign in. It is removed when you sign out, and expires on its own if the session is left idle. | | "Remember this device" cookie | If offered, keeps you signed in after you close the browser — only if you choose it | We do not offer a "remember this device" option. |
One distinction matters here, and we would rather spell it out than gloss it. The session cookie is strictly necessary and needs no consent. A cookie that keeps you signed in across browser sessions is a convenience, not a necessity. If we offer one, it will be set only when you actively ask for it by ticking an unticked box at sign-in, and leaving the box unticked will leave the cookie unset.
What our payment processor sets on payment pages
Payments are processed by JPMorgan Chase Bank, N.A., through Chase Payment Solutions. On the pages where you enter or manage payment details, the processor's code loads and may set cookies of its own.
What those cookies do is governed by the processor's own cookie and privacy policies rather than this one. They should load only on payment pages and never on the marketing site —
The table that previously stood here listed cookies set by a different processor and did not describe this site.
What we do not do
We do not use cookies to build a profile of you, to measure your behaviour, to retarget you with advertising, or to share anything about your visit with an advertising network. We have not built the machinery to do it, and we are not planning to.
We do not sell personal information, and we do not share it for cross-context behavioural advertising — which is the specific meaning California gives the word "share". So there is no "Do Not Sell or Share My Personal Information" link on this site, and there is nothing for an opt-out preference signal such as Global Privacy Control to switch off. We would rather say that than publish a link that does nothing.
Our site also does not track you across other websites, so a Do Not Track signal has nothing to disable here. Our Privacy Policy sets this out in full, including the one qualifier that belongs on it: the network provider in front of the site sees requests to it.
Controlling cookies
Every browser lets you see, block and delete cookies, usually under Settings, Privacy. Because we set nothing optional, there is no preference centre of ours to visit — there is nothing to turn off that would change what we know about you.
Blocking cookies on this site has one practical effect: the sign-in cookie is what keeps you signed in, so blocking it means the product will not work.
If this ever changes
If we ever want to add a cookie or similar technology that is not strictly necessary — an analytics tool, for example — we will ask for your consent before it loads, not after, and we will update this page first. This page is the authoritative list of what we set, and our Privacy Policy links here rather than repeating it, so the two cannot drift apart.
Material changes are notified the same way as changes to our Privacy Policy: by email to account administrators, with the change taking effect no sooner than 30 days later.
Questions
Write to privacy@cedxsystems.com, or CEDX Corporation, 307 W 38th St, 16th Floor, New York, NY 10018.
Change log
| Effective | Version | What changed | | 8 August 2026 | 1.0 | First publication. Replaces the cookie language carried in our earlier privacy page. |
Acceptable Use Policy
Last updated: 8 August 2026 · Version 1.0
In short. Use the CEDX Corporation platform to run your business. Do not use it to break the law, to send mail nobody asked for, to attack anything, or to get around what you paid for. You are responsible for the people you give access to. If something goes wrong, we will normally talk to you before we act, take the narrowest action that fixes it, and give you a route to appeal.
Who this applies to, and where
This policy applies to every CEDX Corporation product — the platform, CEDX CRM, CEDX Desk, CEDX Invoicing and every other CEDX app — including the API and the AI gateway. All of them are operated by CEDX Corporation, a New York corporation doing business as CEDX Systems ("CEDX Corporation", "we", "us"), and the rest of this policy uses the corporate name.
It applies to you as the customer and to everyone you give access to: your staff, your contractors, and anyone using your account. You are responsible for what they do here, the same as if you had done it yourself.
This policy is part of our Terms of Service. Breaking it is a breach of that contract.
It does not cover cedx.org. That is a separate organisation — the CEDX 501(c)(3) research institution — and its systems are outside the scope of this document.
The rule behind the rules
Use the platform for your own business, within the plan you bought, and do not use it to harm anyone — including us, other customers, and the people whose data you put into it. Everything below is a specific application of that. If something is not listed but clearly falls foul of it, treat it as covered.
Content and the law
Do not use the platform to store, send or process anything unlawful where you are, where we are, or where the recipient is.
Do not upload or distribute material you have no right to — someone else's copyrighted work, trade secrets, or confidential material you were not given permission to hold. We respond to copyright notices under the DMCA, and section 5A of the Terms of Service says how to send one, how to counter-notice, and what our repeat-infringer policy is.
Do not use the platform to harass, threaten, stalk or intimidate anyone, or to publish a private individual's personal details in order to expose them to harm.
Child sexual abuse material is treated separately from everything else in this policy. If we find it, or it is reported to us and confirmed, we disable access to it immediately with no notice and report it to the CyberTipline at the National Center for Missing & Exploited Children, as 18 U.S.C. § 2258A requires. We then preserve the report and the material it concerns for at least 90 days, as § 2258A(h) requires — in a secure place that nobody can reach in the ordinary course — and for longer if law enforcement asks us to. Account termination follows once that preservation is in place, immediately and without notice, under section 10 of the Terms of Service. Nothing in this policy obliges us to monitor or search customer content for this material, and § 2258A(f) says the same.
Email, messages and calls sent through the platform
Several CEDX apps can send mail on your behalf. The rules below apply to all of it, and they exist because a shared sending reputation is exactly that — shared. One customer's bad list damages delivery for everyone.
Only send commercial mail to people who agreed to hear from you or have a genuine, current business relationship with you. Do not use lists you bought, rented, scraped or harvested.
Every commercial message must identify you honestly. Real sender name, working reply address, a valid physical postal address, an accurate subject line, and a working unsubscribe link. Honour unsubscribes promptly — within 10 business days at the outside, which is what both US and Canadian law require, and sooner is better. Never charge for an unsubscribe or demand extra information to process one.
Do not use the platform to route around a suspension somewhere else, to relay mail for a third party, or to send messages whose content or destination you have not disclosed to us when asked.
If you use a CEDX app to make calls or send text messages, consent, do-not-call registries, calling-hours limits and call-recording law are your responsibility — including all-party consent states, where everyone on the call must be told it is being recorded before it starts.
Security
Do not attempt to access any account, tenant or data that is not yours. Do not attempt to defeat authentication, entitlements, seat limits or rate limits, or to escalate your own permissions.
Do not scan, probe, load-test, stress-test or penetration-test the platform without our written permission. We welcome security research, but it has to happen inside a set of rules — our vulnerability disclosure policy says what is in scope, what is off limits, and what protection you have when you follow it. Report anything you find to security@cedxsystems.com, or CEDX Corporation, 307 W 38th St, 16th Floor, New York, NY 10018 rather than to anyone else, and stop the moment you encounter another customer's data.
Do not upload or distribute malware, and do not use the platform as a staging point for an attack on anyone else.
Keep your own side secure: do not share logins, and do not leave credentials in a place where people outside your account can reach them.
The API and the AI gateway
Stay within the published rate limits for the API and the AI gateway — Rate limits are applied per account and published in the developer documentation.. Do not spread traffic across extra accounts to get around a limit, and do not build anything that hammers an endpoint in a retry loop when it should back off.
Do not bulk-export data other than your own, and do not use the API to scrape or mirror the platform.
For the AI gateway specifically: do not use it as a general-purpose model proxy for work unrelated to your use of the platform, do not try to extract system prompts or model internals, and do not use its outputs to train or evaluate a competing model.
Do not use AI features to generate content that targets a real person — impersonation, harassment, sexual content about an identifiable individual, or fabricated statements presented as that person's own.
You must not use AI features as the sole basis for a decision about a person's legal rights, finances, employment, credit, housing, insurance, education, immigration status or medical care. A person must meaningfully review the output before the decision is made. Generated output can be confidently wrong, and it is not unique to you — another customer can receive something similar from the same prompt.
Access, seats and resale
Your subscription is for your own internal business use, for the number of seats you bought. A seat belongs to one named person; do not share a login between several people.
Do not resell, sublicense, rent out or run a service bureau on top of the platform, and do not provide access to a third party as a service, unless we have agreed it with you in writing.
Do not copy, reverse engineer or decompile the platform, except where the law says you may despite this sentence.
Data you put into the platform
You must have the right to put the data there, and to let us process it on your behalf. Our Data Processing Addendum sets out what we do with it.
Do not put special category personal data — health, race or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation — or criminal offence data, or the personal data of children, into the platform unless we have agreed it with you in writing first. The platform is not built or contracted for that, and agreeing it in advance is how we make sure it does not arrive somewhere it should not. The same list appears in our Data Processing Addendum, which is where the contractual restriction lives.
Do not enter full payment card numbers into free-text fields such as notes, tickets or invoice descriptions. We do not store card numbers; the payment processor handles card data, and typing one into a note defeats that.
What we do if this policy is broken
We do not monitor what you put into the platform. We act on reports, on legal obligations, and on our own alerts about load, sending volume and abuse.
Our normal sequence is to contact you first and give you a chance to fix it. When we do act, we take the narrowest step that addresses the problem: removing or disabling specific content, disabling a single user, throttling a key, or suspending one feature — before we ever consider suspending an account.
We will act immediately and without prior notice only where there is active harm in progress, where the law compels us, or where the content is illegal on its face. We tell you as soon as we reasonably can afterwards, and we say what we did and why.
Suspension is not deletion. Your data stays where it is during a suspension, and access is restored once the problem is fixed. Termination, and what happens to your data after it, is governed by the Terms of Service.
Reporting a problem
If you think another customer is using the platform in a way this policy forbids — spam from a CEDX-sent address, abusive content, anything unlawful — tell us at abuse@cedxsystems.com. Include enough for us to identify it: the message, the headers, a URL, a timestamp. We aim to acknowledge a report within Abuse reports and appeals are acknowledged within 2 business days and actioned within 5 business days..
Appeals
If we suspend, restrict or remove something and you think we got it wrong, email abuse@cedxsystems.com with your account name, what was actioned, and why you think the decision was mistaken.
A person reviews every appeal — not an automated system. We aim to respond within Abuse reports and appeals are acknowledged within 2 business days and actioned within 5 business days., and we will tell you the outcome and the reason for it. If we were wrong, we restore what we took and say so. If we were not, we tell you exactly what has to change before we can restore access.
Changes to this policy
This policy sits apart from our Terms of Service so it can be updated as new kinds of abuse appear, without reopening your contract. Changes are posted here with a new date. If a change materially narrows what you are allowed to do, we will email account administrators at least 30 days before it takes effect.
How this fits with our other documents
The Terms of Service are the contract, and this policy is incorporated into them. Where this policy and another CEDX Corporation document conflict, the order of precedence in section 17 of the Terms of Service decides which one governs: your order or plan page first, then the Data Processing Addendum, then this policy, then the Service Level Agreement, then the Terms — except that the Data Processing Addendum governs the processing of personal data whatever else says, and the Standard Contractual Clauses attached to it prevail over the Addendum.
Change log
| Effective | Version | What changed | | 8 August 2026 | 1.0 | First publication. CEDX Corporation has not previously published an Acceptable Use Policy. |
CEDX SYSTEMS
Talk to sales