Privacy Policy
Last updated: 15 June 2026 | Effective: 15 June 2026
This Privacy Policy explains how Langbridge Digital Ltd ("we", "us", "our") collects, uses, and protects your personal data when you use Codex IQ. We are committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data Controller: Langbridge Digital Ltd, Bath, England
ICO Registration: Registered under the Data Protection Act 2018
Contact: privacy@codex-iq.co.uk
1. Data We Collect
| Category | Data | Source |
| Account data | Name, email address, password (hashed) | You, on registration |
| Business data | Company name, address, registration numbers, PAYE/UTR refs, bank details | You, during setup |
| Employee data | Names, NI numbers, addresses, salaries, tax codes | You, when adding employees |
| Financial data | Invoices, expenses, accounts, payroll records | You, during use |
| Industry-specific data | Where applicable to your business type, e.g. driver records, compliance documents and compliance dates for taxi/private hire operators | You, during use |
| Usage data | Login timestamps, module usage, audit logs | Automatically collected |
| Technical data | Browser type, device info, fraud prevention headers (HMRC requirement) | Automatically collected |
2. Legal Basis for Processing
- Contract performance — to provide the Codex IQ service you subscribe to.
- Legal obligation — processing employee payroll data to enable HMRC RTI compliance.
- Legitimate interests — fraud prevention, security monitoring, service improvement.
- Consent — marketing communications (you can opt out at any time).
3. How We Use Your Data
- Providing and improving the Codex IQ platform.
- Generating payslips, invoices, RTI XML files, and other documents.
- Sending account notifications and billing emails.
- HMRC fraud prevention header generation (required by HMRC API specifications).
- Customer support.
- Security monitoring and fraud prevention.
4. Data Sharing
We do not sell your data. We share data only with:
- Google Firebase — cloud storage and authentication (EU data centres, GDPR compliant).
- Stripe — payment processing (PCI DSS Level 1, does not see your business or payroll data).
- Resend — transactional email delivery (email addresses only).
- Cloudflare — DNS and edge security (no access to content).
- HMRC — when you generate and submit RTI payroll files (data you choose to submit).
All processors are under data processing agreements ensuring GDPR compliance.
5. Data Storage and Security
- All data is stored in Google Firebase Firestore in the europe-west2 (London) region.
- Data is encrypted at rest (AES-256) and in transit (TLS 1.3).
- Access is controlled by Firebase Authentication and role-based Firestore security rules.
- All sensitive operations are recorded in an immutable audit log.
- Passwords are hashed by Firebase Authentication and never stored in plaintext.
6. Data Retention
- Active accounts: Data retained while account is active.
- Closed accounts: Data retained for 30 days, then permanently deleted unless you request earlier deletion.
- Payroll records: HMRC requires payroll records to be kept for a minimum of 3 years. We recommend 6 years. You can export these before closing your account.
- Audit logs: Retained for 6 years to meet statutory requirements.
- Backups: Encrypted backups are retained for 30 days.
7. Your Rights (UK GDPR)
- Right of access — request a copy of your personal data.
- Right to rectification — correct inaccurate data.
- Right to erasure — request deletion (subject to legal retention obligations).
- Right to portability — export your data via Settings > Data & Audit.
- Right to object — object to processing based on legitimate interests.
- Right to restrict processing — request we limit how we use your data.
To exercise any of these rights, email privacy@codex-iq.co.uk. We will respond within 30 days.
8. Cookies
Codex IQ is a single-page Progressive Web App. We use:
- Essential cookies — Firebase Authentication session tokens (necessary for the app to function).
- Local storage — device ID for HMRC fraud prevention (no personal data).
We do not use advertising, tracking, or analytics cookies.
9. Children's Data
Codex IQ is a business application intended for adults. We do not knowingly collect data from persons under 18. If you believe a minor has registered, contact us immediately.
10. Changes to This Policy
We will notify you of material changes by email at least 14 days in advance. The current policy is always available at this URL.
11. Complaints
If you are unhappy with how we handle your data, you can: