CEDX SYSTEMS Talk to sales

On this page

  • The short version
  • Who we are
  • Two roles: our data, and your data
  • What we collect, where it comes from, and why
  • Cookies, and why there is no banner
  • Do Not Track, and Global Privacy Control
  • We do not sell or share your personal information
  • Who we disclose information to, and why
  • AI features and the AI gateway
  • How long we keep things
  • Sensitive personal information
  • Your rights
  • How to make a request
  • Complaints and appeals
  • Security
  • Where your data is processed
  • Marketing email, and calls
  • Children
  • Notes for particular places
  • Getting to this policy, and reading it
  • Changes to this policy
  • Change log
  • How to reach us

CEDX Systems · Legal

Privacy Policy

Full replacement privacy policy for CEDX Corporation, drafted to the California standard and applied to everyone. Adds the network provider as a disclosed recipient, corrects the breach trigger to "become aware", replaces the absolute no-tracking and no-inference claims with verifiable ones, states rete

Last updated: 8 August 2026 · Version 1.0

This document replaces the previous privacy page on this site in full.

The short version

This box is a summary, not the policy. The sections below are what govern.

  • This website runs no tracking. No analytics, no tag manager, no session recorder, no advertising pixel, no A/B testing tool, no chat widget. Loading a page here contacts no other company's servers except the network provider that sits in front of the site to deliver and protect it. The only outside sites we link to are cedx.org, linkedin.com and x.com, and nothing is sent to them unless you click.
  • There is no cookie banner because there is nothing here to consent to. Every cookie in play — what sets it, what it does and how long it lasts — is listed in our Cookie Policy, which is the authoritative list.
  • We have not sold personal information, and we have not shared it for cross-context behavioural advertising — not in the twelve months this policy is required to cover, and not at any point we have any record of. We do not have the advertising technology that would make either possible, and we are not a data broker.
  • Two different kinds of data, two different sets of rules. Data about you — a visitor, a prospect, an account admin, a job applicant — is ours to answer for, and this policy covers it. Data your company puts into CEDX apps belongs to your company, and we only touch it on your company's instructions. That is governed by our Data Processing Addendum, not by this policy.
  • We do not profile you for advertising and we do not segment you behaviourally.
  • Everyone gets at least the rights listed below, wherever you live, whether or not a law where you live requires it. Some laws add more on top; the section on Europe, the United Kingdom and Switzerland sets those out.
  • We're straight about scope. We don't hold a SOC 2 report or an ISO 27001 certificate, and we don't commission third-party penetration tests. The security section says so plainly, and sets out what we do run instead.

Who we are

CEDX Corporation is a for-profit New York corporation, doing business as CEDX Systems ("CEDX Corporation", "we", "us"). Our registered office is at 307 W 38th St, 16th Floor, New York, NY 10018. We build connected business software — a platform plus a catalogue of applications including CEDX CRM, CEDX Desk and CEDX Invoicing — for small and mid-sized companies.

CEDX Corporation is a separate company from CEDX (the 501(c)(3) research institution at cedx.org). Separate entity, separate books, separate marks. Nothing in this policy applies to the CEDX 501(c)(3), and it has no obligations under it. It publishes its own privacy policy.

Throughout this policy, "CEDX" used on its own is our product house-mark — the CEDX platform, CEDX CRM, CEDX Desk, CEDX Invoicing. The nonprofit is always named in full.

Two roles: our data, and your data

Almost every complaint about a software company's privacy policy comes from the same confusion, so we are explicit about it up front.

Role 1 — we decide (this policy applies). For some information, we choose what to collect and why: people who visit this website, people we contact about buying our software, people who fill in a form here, the administrators and billing contacts on a customer account, people who write to support, and people who apply for jobs with us. In privacy law we are the "controller" or "business" for that information. This policy is about that information.

Role 2 — our customer decides (the Data Processing Addendum applies). When a company buys CEDX and starts putting records into CEDX CRM, tickets into CEDX Desk, invoices into CEDX Invoicing, files into the platform and prompts into the AI gateway, that information belongs to that company. It may include personal information about that company's own customers, staff and contacts. We hold it and process it on that company's written instructions and for no other purpose. In privacy law we are the "service provider" or "processor" for it, and our customer is the controller.

Our Data Processing Addendum governs Role 2 and is available pre-signed at a permanent URL. If you are an individual whose information is inside a CEDX customer's account and you want it accessed, corrected or deleted, the company that put it there is the right place to ask. Tell us and we will point you to them and help them respond, but we will not change or delete their records on our own initiative.

One line between the two roles is worth drawing explicitly. Service logs that record how a customer's users interact with the product — sign-in events, request and error logs, feature-usage counts — are data we control in our own right, for security, fault diagnosis and product development. They are covered by this policy. The content of a customer's records, tickets, invoices and files is Customer Personal Data under the Addendum, and we do not analyse it for product development or for anything else of our own.

What we collect, where it comes from, and why

We use the category names from California law rather than inventing our own, so this table can be compared with other companies' policies. We list only categories we actually collect.

Category What it is, for us Where it comes from Why we have it
Identifiers Name, work email address, work phone number, company name, account ID, IP address, session and device identifiers set by our own systems You, directly; the customer that named you as an administrator or billing contact; our own server logs; publicly available business sources when we research a prospect To create and secure your account; to reply when you contact us; to send service and billing messages; to detect and stop abuse
Personal information under Cal. Civ. Code §1798.80(e) Name, address, telephone number, employer, and billing information (we never hold your full card number) You, directly; your employer; our payment processor, JPMorgan Chase Bank, N.A. (Chase Payment Solutions) To bill you and keep the tax and accounting records the law requires us to keep
Commercial information Which plan you bought, seat counts, subscription and renewal history, what you asked about in a demo You, directly; our own records of your account To run your subscription; to take payment; to answer questions about your plan
Internet or other electronic network activity information Server logs of requests to our site and product, sign-in and sign-out events, error reports, which features an account uses Our own service logs To keep the service running; to investigate errors and security events; and to count which features an account uses, at the level of the feature and the account, so we know what to build next. We do not analyse the content of the records, tickets, invoices or files inside a customer's workspace for any of this
Geolocation data Coarse location only — the country or city that can be inferred from an IP address in our logs. We do not collect precise location Our own server logs Security: spotting sign-ins from places an account has never signed in from
Professional or employment-related information Job title, department, employer, and for applicants, the work history in a CV You, directly; your employer; publicly available business sources To address you correctly; to decide whether our software fits your company; to consider a job application
Education information Only what a job applicant chooses to put in a CV or application Job applicants, directly To consider a job application
Audio, electronic, visual or similar information Call recordings, if we make them — Where we record a call, we say so at the start of it. We do not record a call without telling you first, and you can ask us not to record. You, if you are on a recorded call To train our own team and keep an accurate record of what was agreed
Sensitive personal information Account log-in credentials in combination with a password You, directly, when you set up or reset your account To authenticate you and secure the service. Nothing else. See the section below

We do not collect characteristics of protected classifications, biometric information, precise geolocation, or health information.

Inferences. We do not profile you for advertising, we do not segment you behaviourally, and we do not sell or share any assessment of you. Yes. We score and rank prospect and contact records in our own sales systems to prioritise who we contact. That score is an inference under California law. We use it only to decide who our team contacts and in what order. We do not sell or share it, and it plays no part in pricing, in credit decisions, or in anything that affects the service you receive..

"To provide and improve our services" is not a real answer, so we have not written it. Every purpose above is the actual reason the data is on our systems.

Cookies, and why there is no banner

Storing or reading information on your device needs your consent unless it is strictly necessary to deliver the thing you asked for. Everything we set falls inside that exemption, which is why you are not interrupted by a banner.

Every cookie in play — what sets it, what it does and how long it lasts — is listed in our Cookie Policy, which is the authoritative list. We link to it rather than repeat it here so the two cannot drift apart.

If we ever add a cookie or tracker that is not strictly necessary, we will ask for your consent before it loads, not after. That is a commitment, not an aspiration.

Do Not Track, and Global Privacy Control

Do Not Track. This site does not track you across other websites, so there is nothing for a Do Not Track signal to switch off. We do not respond to DNT signals, because we do not do the tracking they were designed to stop. Other than the network provider that sits in front of the site, no third party collects personal information about your activity over time and across different websites through this site.

Global Privacy Control. GPC and similar opt-out preference signals exist to tell a business to stop selling or sharing your personal information. We do not sell or share it, so there is nothing for the signal to switch off, and we do not process these signals. We are telling you this rather than claiming to honour a signal we do not read.

We do not sell or share your personal information

We have not sold personal information in the preceding 12 months, and we have not shared it in the preceding 12 months.

Those two words have specific meanings and we are using them in their legal sense. Sell means disclosing personal information to another business for money or other valuable consideration. Share means disclosing it for cross-context behavioural advertising — advertising to you on other websites based on what you did here. We do neither, and we do not have the advertising technology that would make either possible.

One disclosure deserves naming here, because it is the one a regulator would test. Chase acts as an independent controller for its own payment, fraud-prevention and anti-money-laundering purposes, not only as our service provider. We disclose your billing contact details and transaction records to Chase because that disclosure is necessary to complete the transaction you asked us to process and to meet our own legal obligations, and we receive no money and no other valuable consideration for making it. That is not a sale within Cal. Civ. Code § 1798.140(ad), and it is not a share within § 1798.140(ah), because none of it is for cross-context behavioural advertising. We name it rather than leave it for you to find in the table below.

Because we do not sell or share, we do not publish a "Do Not Sell or Share My Personal Information" link. That link is a legal duty for businesses that sell or share; for us it would be decoration in front of a mechanism with nothing to do. The statement above is the substance the link is supposed to point to.

We are not a data broker and are not registered as one, because we do not collect and sell personal information about people we have no relationship with.

Who we disclose information to, and why

This is a different thing from selling or sharing. To run a business at all we have to let a small number of service providers handle information on our behalf, under contract, for the purposes we specify and nothing else.

Who What they do What they can see
Cloudflare sits in front of the site and the product as CDN, DNS and reverse proxy, terminating TLS at its edge and serving from the Cloudflare network globally. Verified against response headers on 8 August 2026. Sits in front of our website and our product: delivers pages, terminates TLS, and blocks bots and denial-of-service traffic Request metadata for every request, including IP address, user agent and requested URL, and the content of requests and responses as they pass through
Customer data is hosted on dedicated virtual infrastructure provided by Hostinger International Limited, in a data centre in Vilnius, Lithuania. The servers run in UTC. Runs the servers and the Postgres database the product sits on Everything stored in the service, at the infrastructure level
None. CEDX Corporation operates its own mail server; product and transactional email is not handed to a third-party delivery provider. Delivers our transactional and marketing email Names and email addresses, and the content of the messages we send you
Application errors are logged on our own infrastructure in the same region as the Services. We do not send error data to a third-party monitoring service. Receives error reports when something breaks Technical details of the error, which can incidentally include identifiers
CEDX AI is CEDX Corporation's own assistant layer. It is not trained or fine-tuned on customer content. It calls third-party frontier models — Anthropic (Claude) and OpenAI — which process in the United States. Content you send to AI features reaches those providers, and what they may retain or train on is governed by their terms, which we name in Annex 3 rather than paraphrase. Runs the models behind AI features Only the content sent to a model when an AI feature is used. See the AI section below
Supabase is not in use for the Services covered by this agreement. Appears once in our architecture notes; we are confirming its status rather than guessing at it here To be confirmed
Our accountants and lawyers Advise us Only what a specific matter requires

A third party that is not our service provider. Chase processes payment and billing data as an independent controller for its own payment, fraud-prevention, anti-money-laundering and identity-verification purposes — see Chase's own privacy terms. It receives billing contact details and transaction records. We never receive or store your full card number. We name it separately because the contractual position is genuinely different from the rows above.

We also disclose information where the law compels it — a subpoena, a court order, a lawful request from a regulator — and where it is necessary to investigate fraud or protect someone's safety. We will tell the affected customer before we do, unless we are legally forbidden from telling them.

The current, authoritative list is Annex 3 of our Data Processing Addendum, which carries each company's name, what it does, the data it can reach, and where it processes. We give customers at least 30 days' notice before adding a new one, and 15 days from that notice to object on reasonable data protection grounds.

AI features and the AI gateway

Our platform includes an AI gateway: features that send content to a third-party language model and return a result. It is the part of the stack buyers ask about most, so here is the whole of it.

  • It runs on a trigger, not in the background. Content is sent to a model when someone uses an AI feature — asks for a draft, a summary, a suggested reply.
  • What is sent is what the feature needs: the prompt and the specific records the feature is operating on.
  • The model provider is a subprocessor and is named in Annex 3 of the Data Processing Addendum.
  • Training. CEDX Corporation does not use customer content to train or fine-tune models. Whether the model provider is contractually barred from training on what we send is a question about their terms, not ours, and we state their position rather than a comfortable version of it: CEDX AI is CEDX Corporation's own assistant layer. It is not trained or fine-tuned on customer content. It calls third-party frontier models — Anthropic (Claude) and OpenAI — which process in the United States. Content you send to AI features reaches those providers, and what they may retain or train on is governed by their terms, which we name in Annex 3 rather than paraphrase..
  • Output is generated text. It can be wrong. It should be read by a person before anyone relies on it. You must not use AI features as the sole basis for a decision about a person's legal rights, finances, employment, credit, housing, insurance, education, immigration status or medical care. A person must meaningfully review the output before the decision is made.
  • If a model call is processed outside the region where the rest of your data sits, that is a cross-border transfer and it is described in the section on where your data is processed.

How long we keep things

We do not keep personal information for longer than is reasonably necessary for the purpose we collected it for.

Where a period below has not yet been fixed, these are the criteria that determine it: how long the account or business relationship lasts; the minimum periods that tax, accounting, employment and limitation-of-actions law require us to keep a record; how long a record is still needed to investigate a billing dispute or a security event; and, for logs, the shortest period that still allows an incident to be investigated after the fact. We will not publish this page with a row left blank — each row will carry either a period or the specific criterion that sets it.

What How long we keep it
Account and profile records For the life of the account, and for 60 days after it closes.
Billing and tax records Seven years, which is the period tax law requires us to keep them for., subject to the minimum periods tax law requires
Support correspondence Two years from the close of the conversation.
Security and server logs 12 months.
Security incident records Six years from the close of the incident.
Prospect and marketing records 24 months from the last interaction, unless you ask us to delete them sooner.. If you opt out, we keep the minimum needed to remember not to contact you again
Job applicant records 12 months from the close of the role, unless you ask us to delete them sooner.
Customer content inside the apps Kept while the subscription is live. After it ends, exportable for 30 days from the end of the subscription, during which you can export your data through the account portal or ask us to produce an export., deleted from live systems within Within 30 days of the end of the export window, so no later than 60 days after termination. of that window closing, and persisting in a backup for no more than 30 days, after which backups are deleted automatically. from the date that backup was taken

Deletion is not instantaneous and we are not going to pretend it is. Backups are not deleted on demand — they age out on a rotation, so a record deleted from the live system persists in a backup until that backup expires, and the row above says by when. Backup integrity is verified weekly and the most recent verification passed. A full restore-to-a-clean-host drill has not been recorded.. Whether backups are encrypted at rest, and by what mechanism, is stated on our Security page — we will not describe them as encrypted here until that line is confirmed.

Sensitive personal information

We hold one thing that California classes as sensitive personal information: your account log-in credentials in combination with a password.

We use them to authenticate you and to secure the service. Both are purposes the regulations permit without a limitation right, so we do not offer — and are not required to offer — a "Limit the Use of My Sensitive Personal Information" link. We do not use credentials to infer anything about you, and we do not disclose them to anyone.

We are saying this rather than writing "we do not collect sensitive personal information", which would be false and would be disproved by our own sign-up page.

Your rights

These are the baseline rights we give everyone who deals with us, wherever you live, whether or not a law where you live requires them. Some laws — the GDPR and the UK GDPR in particular — add rights on top of this baseline, and the section on Europe, the United Kingdom and Switzerland sets those out.

  • Know and access. Ask what personal information we hold about you, where it came from, why we have it, who we disclosed it to, and get a copy of the specific pieces in a portable format.
  • Delete. Ask us to delete personal information we hold about you. We will, unless we are required to keep it — for example, a paid invoice we have to retain for tax.
  • Correct. Tell us something is wrong and we will fix it.
  • Opt out of sale or sharing. There is nothing to opt out of, because we do neither. The right exists and we honour it; it simply has no work to do here.
  • Limit the use of sensitive personal information. As explained above, we use credentials only for permitted purposes, so this right has nothing to bite on either.
  • Opt out of marketing. Every marketing email has an unsubscribe link, and you can also just tell us. Opting out of marketing does not stop transactional and service messages — invoices, security notices, downtime notifications — because those are part of the service you bought.
  • Appeal. If we refuse a request, you can ask us to look again. See the complaints section.
  • No retaliation. We will not deny you service, charge you a different price, give you a lower quality of service, or penalise you in any way for exercising any of these rights.

How to make a request

Email privacy@cedxsystems.com, or CEDX Corporation, 307 W 38th St, 16th Floor, New York, NY 10018 with what you want. That is the only address you need, and it is monitored by a person.

How we verify you. If you have an account, sign in and make the request from the address on the account — that is the verification. If you do not have an account, we will ask you to confirm two or three pieces of information we already hold, so we can be reasonably sure we are not handing your data to somebody else. We will not ask for a government ID to answer a routine request. If we cannot verify you, we will tell you why rather than ignoring you.

Authorised agents. Someone can make a request on your behalf. Send us written permission signed by you. We may still contact you directly to confirm it, and to confirm the agent's authority.

Timing. We confirm receipt within 10 business days. We give you a substantive answer within 45 calendar days. If a request is genuinely complex we can take one further 45-day extension, and if we do, we will tell you before the first 45 days are up and explain why. Nevada requests not to sell information are answered within 60 days, extendable by 30 with notice — although as set out above, we do not sell.

Reviewing and changing your own information. You do not need to file a request for most of this. Administrators can export account data and request deletion through the account portal. Where an app has no self-service export, we produce one on written request within 10 business days.. Where an app has no self-service route, email us and we will do it for you within Within 10 business days of a written request..

Requests about data inside a customer's account. If your information is in a CEDX customer's CRM, help desk or invoicing records, that company decides what happens to it. Write to them. If you write to us instead, we will tell you who they are where we are permitted to, and we will help them respond.

Complaints and appeals

If you are unhappy with how we handled a request, reply to our answer and say so, or write to the same address with "appeal" in the subject line. Where the size of our team allows, a different person from the one who handled the original request reviews it; where it does not, the reviewer reconsiders the request from the beginning against the original evidence and says so in the answer. We will respond within 45 days with the outcome and our reasons.

Several state privacy laws — Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware and others — require a controller within their scope to operate an appeals process, on a defined timetable and with a route to the state Attorney General if the appeal is refused. California does not. Which of them reaches us turns on where you live, on their volume and revenue thresholds, and on the commercial-context exclusion described under "Notes for particular places". It does not turn on where we are incorporated: those laws reach a business that does business in the state or targets its residents, and none of them asks what state a company is chartered in. New York, where we are incorporated, has no such law at all. Our customers are principally in the United States and Canada. We do not offer the Services in the EEA, the United Kingdom or Switzerland.. We do not ask you to rely on our analysis: we run an appeals process for everyone, whether or not a law obliges us to, because a company that cannot explain a refusal probably should not have refused.

If you are still not satisfied, you can complain to your state Attorney General, to the California Privacy Protection Agency, to the Office of the Privacy Commissioner of Canada, or to your data protection authority if you are in the EEA, the UK or Switzerland.

Security

Here is what we can say and stand behind.

  • Traffic between your browser and both our website and our product is served over HTTPS.
  • Card details go to Chase. Card details are entered into Chase's own payment components and go to Chase directly. We do not store, process or transmit full card numbers, so we are not the party that holds the card-network attestation for that processing. We do not store or transmit full card numbers through the payment path. One caveat we would rather state than have you find: nothing stops a user typing a card number into a free-text field such as a note or a ticket. Our Acceptable Use Policy forbids it, and We do not run automated detection or redaction of card numbers typed into free-text fields. Do not put them there..
  • Our data store is Postgres. Customer workspaces are separated logically within it rather than by running separate infrastructure per customer: every record is scoped to the customer account it belongs to, and we do not run a separate database or a separate instance per customer. Tenant separation is enforced in the application layer, which scopes every query to the signed-in account..
  • Staff access to customer data is limited to the people who need it for a specific task, such as investigating a support ticket you raised. Reading customer data is not routine work here.
  • Customer data is stored on the server's own filesystem. There is no full-disk or volume-level encryption layer in place today, and backups are compressed rather than encrypted. Data is encrypted in transit..
  • Production access is by SSH to a single host, restricted to two registered public keys. Key-based authentication is in use and access is limited to the root account..

Here is what we have not done, stated plainly because you would find out on the diligence call anyway:

  • We do not hold a SOC 2 report.
  • We are not ISO 27001 certified.
  • We don't commission third-party penetration tests today.
  • We do not run a 24/7 staffed on-call rotation.
  • We don't appoint a Data Protection Officer: our processing isn't the large-scale monitoring or special-category processing Article 37 requires one for. We name an accountable person instead, below.
  • We have not appointed an EU or UK representative under Article 27 — see the section on Europe, the United Kingdom and Switzerland.

We are not going to write "bank-level", "military-grade" or "enterprise-grade" anywhere on this page. Those phrases mean nothing, and every one of them is a statement we could be held to.

If something goes wrong. If personal information is breached, we notify the people affected in the most expedient time possible and without unreasonable delay, and in no case later than thirty days after we discover the breach. That thirty days is New York's outside limit under General Business Law § 899-aa, and we work to it whichever state you live in rather than running a different clock for each one. We treat ourselves as having discovered a breach once we have a reasonable degree of certainty that a security incident has occurred and that personal information was compromised — not once the investigation has finished. The only delay New York permits is one requested by law enforcement because notice would impede a criminal investigation. Our notice tells you what categories of information were involved, what we know, what we do not yet know and what we are doing, and it carries our contact details and the telephone numbers and websites of the state and federal agencies that publish guidance on breach response and identity theft, which New York requires us to include. Where the law requires it we also notify regulators: the New York Attorney General, the Department of State and the Division of State Police where New York residents are notified; the attorney general of your own state on that state's timetable where its law reaches us; the consumer reporting agencies where more than five thousand New York residents are notified at once; and the Office of the Privacy Commissioner of Canada where a breach creates a real risk of significant harm. Where you are our customer and the data is yours, we notify you immediately following discovery and you decide what to report; our Data Processing Addendum says so in those terms. We keep a record of every breach, whether or not it required notification.

Where we act as a processor, the 72-hour clock for notifying a regulator belongs to our customer, not to us. Our job is to tell our customer immediately following discovery — and in no case later than thirty days after discovery, which is what New York General Business Law § 899-aa requires of a business holding data it does not own — and give them what they need to make that call. Our Data Processing Addendum says so in those terms.

Reporting a vulnerability. See our vulnerability disclosure policy. Researchers acting in good faith under it are welcome here.

Where your data is processed

Customer data is stored and processed at Customer data is hosted on dedicated virtual infrastructure provided by Hostinger International Limited, in a data centre in Vilnius, Lithuania. The servers run in UTC.. Our staff may access data from other countries when providing support. Some of the service providers listed above process data outside that primary region — most obviously the network provider in front of the site, error monitoring and, where applicable, the AI gateway.

Information processed in another country is subject to that country's laws, including laws that allow courts, law enforcement and national security authorities of that country to obtain access to it. We are telling you that because you are entitled to know it, not because we are asking your permission — under Canadian law, transferring information to a service provider for processing is a use, not a disclosure, and it is our accountability for that provider that protects you, not a consent box. We remain responsible for personal information we hand to a processor, and we require them by contract to protect it to a comparable standard.

Europe, the United Kingdom and Switzerland. Whether we offer the Services to customers established in the EEA, the UK or Switzerland today is set out here: No. CEDX Corporation offers the Services worldwide with the exception of the European Economic Area, the United Kingdom and Switzerland. We do not target, market to, or accept customers established in those territories, and the Services are not offered to data subjects there.. Where the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection applies to processing we carry out, our lawful bases are: performance of a contract, for creating and running your account and billing you; legitimate interests, for keeping the service secure, for keeping logs, and for business-to-business prospecting, balanced against your interests and always with a working objection route; legal obligation, for tax and accounting records; and consent, where we ask for it, which you can withdraw at any time. You have the additional rights those laws give you, including the right to object to processing based on legitimate interests, the right to restrict processing, and the right to lodge a complaint with your supervisory authority.

CEDX Corporation has no establishment in the European Union or the United Kingdom. Where Article 27 requires us to appoint a representative, we will appoint one and publish its name and address in this section before we take such a customer. We will not name a representative we have not retained, and we will not assert that one is unnecessary until the question above is settled.

Where you are in the EEA, the UK or Switzerland, or you use our services to process the personal data of people located there, our Data Processing Addendum and the Standard Contractual Clauses attached to it — as adapted for Swiss transfers — apply to that processing by their own terms. We do not rely on the EU–US Data Privacy Framework and we do not display a Data Privacy Framework badge, because we are not self-certified to it.

Marketing email, and calls

We send commercial email to business contacts about our software. If you get one from us:

  • It will identify CEDX Corporation and carry our mailing address: 307 W 38th St, 16th Floor, New York, NY 10018.
  • It will have a working unsubscribe link. Unsubscribing costs nothing, requires no login, and we will not ask you to tell us why.
  • We honour opt-outs within 10 business days, which is the outside limit both US and Canadian law allow, and sooner in practice. The unsubscribe link keeps working for at least 30 days after the message was sent, as the law requires. None. CEDX Corporation operates its own mail server; product and transactional email is not handed to a third-party delivery provider..
  • We do not sell, rent or trade our contact list.

California's "Shine the Light" law, Cal. Civ. Code § 1798.83, gives a right to customers who provide personal information to a business primarily for personal, family or household purposes. We sell business software to businesses, so on our facts it does not reach us. Independently of that, we have adopted and disclosed here a policy of not disclosing personal information to third parties for those third parties' own direct marketing purposes — which is itself a route to compliance under § 1798.83(c)(2). If you want that answer in writing anyway, write to the privacy address above and we will send it, free of charge, within 30 days.

Under Canadian anti-spam law we send commercial messages only where we have consent, express or implied — for example, because you published a business address relevant to your role, because we have an existing business relationship with your company, or because you enquired.

Calls. Where we record a call, we say so at the start of it. We do not record a call without telling you first, and you can ask us not to record.. Where calls are recorded, we say so at the start of the call and you can ask us not to record. California and several other states require every party's consent to record, and we follow the strictest rule rather than the one most convenient to us.

Children

We do not direct our services to anyone under 16, and we do not knowingly collect personal information from anyone under 16. We have no actual knowledge of selling or sharing the personal information of consumers under 16 — and as set out above, we do not sell or share anyone's. We do not knowingly collect personal information from children under 13. If you believe a child has given us information, write to the privacy address and we will delete it.

Notes for particular places

California. Everything above is written to California's standard, so the California disclosures are in the body of this policy rather than exiled to a box at the bottom. One point deserves calling out: business contact information is fully protected personal information in California. The temporary carve-out for business-to-business contacts expired on 1 January 2023 and was never renewed. Your work email, your job title, your employer and any notes a salesperson wrote about you are personal information about you, and you have the complete set of rights over them.

Other US states. Virginia, Colorado, Connecticut, Texas, Delaware and the other state privacy laws define "consumer" to exclude a person acting in a commercial or employment context. Under those laws, information about you in your capacity as an employee, owner, officer or contractor of a business is outside their scope. This matters to us because most of the personal information we hold as a controller is exactly that. We have drafted to California and let the rest follow, so in practice you get the same treatment either way.

New York. We are a New York corporation. New York has no comprehensive consumer privacy law in force, so there are no New York access, deletion, correction, portability, opt-out or appeal rights for us to describe. Bills to create one have been introduced in successive legislative sessions. We do not describe pending bills as law, and we will update this section if one is enacted. What New York does have, and what does reach us, is the SHIELD Act: General Business Law § 899-bb requires us to maintain reasonable administrative, technical and physical safeguards over the private information of New York residents — the programme is described on our Security page — and § 899-aa requires us to notify people of a breach within thirty days of discovering it. Both of those reach any business holding New York residents' private information wherever it happens to be incorporated, so being incorporated here changes nothing about what we owe you, and incorporating somewhere else would not have changed it either. New York's Child Data Protection Act also applies to online services directed to under-18s or where the operator knows a user is under eighteen; we do not direct our services to minors and do not knowingly collect their information, as set out under "Children".

Nevada. Nevada residents may submit a verified request directing us not to sell covered information about them. Send it to the privacy address above — the same one, deliberately, because a second inbox is a second inbox to forget about. We will respond within 60 days, and may take a further 30 days where reasonably necessary, in which case we will tell you. We do not sell covered information, so our answer will normally be to confirm that.

Washington and consumer health data. Washington's My Health My Data Act and Nevada's equivalent apply regardless of a company's size, and require a separate, linked Consumer Health Data Privacy Policy. If any application in our catalogue processes consumer health data, we will publish that separate policy before it is offered to residents of those states.

Canada. The person accountable for privacy compliance at CEDX Corporation is Mukesh Thakur, Chief Executive Officer, reachable at the privacy address above. Quebec customers: where we are asked to communicate personal information outside Quebec on your instructions, the arrangements required by Law 25 are handled in our Data Processing Addendum.

Getting to this policy, and reading it

Where a notice is not yet in place, we are adding it; this paragraph will describe only what is actually shipped. A point-of-collection notice says what that form collects, why, that we do not sell it, how long we keep it, and links to the section here that covers it.

We build this page to be readable on a phone and usable with a screen reader, and we aim at WCAG 2.1 AA. If you cannot access it in the format published, email us and we will send it in another one. We publish it in English; if we begin providing contracts or notices in another language, we will publish this policy in that language too.

Changes to this policy

We review this policy at least once every 12 months, whether or not anything has changed, and update the date at the top when we do.

If we make a material change — a new purpose, a new category of information, a new kind of recipient, a change to your rights or to how you exercise them — we will:

  1. post the updated policy here with a new date and version number;
  2. record what changed in the change log below;
  3. email account administrators and billing contacts at least 30 days before the change takes effect; and
  4. We notify account administrators by email. We do not rely on an in-app banner for notices that matter..

Non-material changes — clearer wording, a corrected typo, a fixed link — go live when posted and are recorded in the change log. Adding a new subprocessor follows the separate 30-day notice and objection process described in the Data Processing Addendum.

We do not treat your continued use of the site or the product as your agreement to a material change you were never told about. From this version onwards we keep every superseded version at a stable URL, listed in the change log, so you can see exactly what changed and when. This is version 1.0, so there is nothing yet to link to.

Change log

Effective Version What changed
8 August 2026 1.0 First publication of this policy. It replaces the previous privacy page in full. The page it replaces was adapted from another company's document and did not describe CEDX Corporation; nothing from it has been carried over.

How to reach us

  • Privacy requests, questions and complaints: privacy@cedxsystems.com, or CEDX Corporation, 307 W 38th St, 16th Floor, New York, NY 10018
  • Security reports: security@cedxsystems.com, or CEDX Corporation, 307 W 38th St, 16th Floor, New York, NY 10018, and see our vulnerability disclosure policy
  • Legal notices: CEDX Corporation, Attn: Legal, 307 W 38th St, 16th Floor, New York, NY 10018, or legal@cedxsystems.com
  • Everything else: hello@cedxsystems.com, sales@cedxsystems.com, support@cedxsystems.com, press@cedxsystems.com
  • Post: 307 W 38th St, 16th Floor, New York, NY 10018

Related documents: Terms of Service · Data Processing Addendum · Subprocessors — DPA Annex 3 · Security · Service Level Agreement · Cookie Policy and Acceptable Use Policy