Privacy Policy, Codixio Product Downloads

Last updated: 27 August 2026

1. Controller

The controller responsible for data processing within the meaning of Art. 4 No. 7 GDPR is:

Matthias Jakisch Hauptstr. 34, OT Etingen 39359 Oebisfelde-Weferlingen Germany

Legal form: sole proprietorship (no commercial register entry), operating under the trade name Codixio. VAT identification number pursuant to Sec. 27a German VAT Act (UStG): DE296346917. Tax status: small business under Sec. 19 UStG.

2. Data Protection Officer

No data protection officer has been appointed. Reason: the requirements of Art. 37(1) GDPR and Sec. 38(1) German Federal Data Protection Act (BDSG) are not met. Codixio does not employ ten persons permanently engaged in processing personal data, does not carry out core activities involving extensive processing of special categories of data, and does not systematically monitor data subjects on a large scale. For any data protection enquiries, please contact legal@codixio.com.

3. Scope

This privacy policy applies to:

Distinction from the Codixio marketing website: The marketing website https://codixio.com (and its language versions) is operated on a separate instance and is subject to its own privacy policy linked there.

Distinction from Shopware: The use of the Shopware shop into which the app is installed, and of the merchant's Shopware account, is subject to the privacy provisions of Shopware AG (https://www.shopware.com/en/privacy/). This privacy policy only covers data processed by Codixio in the course of app usage.

4. Categories of Data Processed

The app is built on the principle of data minimisation. Core of the architecture: personal data of end customers is evaluated exclusively within the merchant's Shopware instance and never leaves it. No end-customer data is transmitted to the Codixio backend.

4.1. End-Customer Data, Processed Exclusively Within the Shopware Context

For download access control, the app evaluates the following data server-side within the merchant's Shopware instance:

Personal reference: yes. This evaluation takes place exclusively server-side within the merchant's Shopware environment (Shopware App Scripts). This data is not transmitted to Codixio, not stored on Codixio systems, and not passed to third parties. The controller for this processing is the merchant as operator of the shop; the app merely provides the technical function within his Shopware instance.

4.2. Merchant Data (Shop Operators)

When a merchant installs the app in his Shopware shop, Codixio processes the following data on the app backend:

Personal reference: minor; affected at most are sole-proprietor merchants whose shop domain identifies the person.

4.3. Aggregated Usage Data (Download Statistics, Max and Enterprise Plans)

With the statistics feature enabled, the merchant's storefront sends the following data to the app backend upon a download click:

From this, the backend maintains only an aggregated counter per download (total number of clicks). No customer data, no IP addresses in the application data store, no time profiles of individual persons and no other personal attributes are stored. Personal reference: no. Recording is protected against manipulation by a shop context check and rate limiting; retrieval is only possible via signed requests from the respective shop's admin module.

4.4. Technical Data

When accessing the legal pages (legal.codixio.com) and the app backend (sw-codixioproductdownloadsapp.api.codixio.com), the following technical data is processed:

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technical operational security, error diagnosis, abuse prevention).

5. Legal Bases of Processing

5.1. Art. 6(1)(b) GDPR, Performance of a Contract

The processing of merchant data (shop domain, shop ID, registration data, active plan) is based on the usage contract concluded between Codixio and the merchant upon app installation. Without this data the app cannot be provided, the booked plan cannot be determined, and the admin module cannot be delivered.

5.2. Art. 6(1)(f) GDPR, Legitimate Interest

Technical access logs, rate limiting and signature verification serve operational security and abuse prevention (protection of counter integrity, defence against automated attacks). The aggregated, non-personal download statistics serve the merchant's legitimate interest in evaluating the usage of his own content.

Balancing of interests (Art. 6(1)(f) GDPR, second half-sentence): processing is limited to technically necessary minimal data without lasting personal reference (IP anonymisation after 7 days, aggregated counters without personal attributes). No overriding interests of data subjects are apparent given this data situation.

5.3. Processing Within the Shopware Context (Merchant Responsibility)

The evaluation of login status, order history and rule context (Section 4.1) takes place exclusively within the merchant's Shopware instance. The merchant is the controller for this; the legal basis arises from his relationship with his customers (typically Art. 6(1)(b) GDPR, performance of the usage or purchase contract including the promised download provision). The merchant informs his customers about this in his own privacy policy.

6. Recipients / Sub-Processors

6.1. Recipients

No personal data is disclosed to third parties for their own purposes. The only recipient in the technical sense is the sub-processor listed below within the meaning of Art. 28 GDPR.

6.2. Active Sub-Processors

6.3. Codixio-Owned Infrastructure

No further service providers are used. In particular, the app does not send e-mails via external delivery services and does not use external AI services.

7. Third-Country Transfer

No third-country transfer takes place. The only sub-processor (Hetzner Online GmbH) is located in Germany; all processing takes place within the EU.

8. Retention Periods

8.1. Merchant and Plan Data

Shop registration, shop secret and plan assignment are stored for the duration of the app installation. Upon uninstallation of the app, the Shopware lifecycle mechanism triggers the automatic deletion of the shop data on the app backend.

8.2. Aggregated Download Counters

The aggregated counters are bound to the shop registration and are automatically deleted together with the shop record (database-level cascading deletion). At no time do they contain personal data.

8.3. Technical Access Logs

Access logs at the reverse proxy are automatically IP-anonymised after 7 days and fully deleted after 90 days.

9. Rights of Data Subjects

Under the GDPR, data subjects have the following rights:

You can exercise these rights by e-mail to legal@codixio.com. End customers of a merchant shop can additionally contact the respective merchant directly, since his Shopware instance holds the end-customer data; no end-customer data is stored on Codixio systems.

Response time: We respond to requests within the statutory period of one month pursuant to Art. 12(3) GDPR. For complex requests, this period may be extended by two further months; you will be informed of this within the first month.

10. Right to Lodge a Complaint With a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for Codixio is:

Landesbeauftragter für den Datenschutz Sachsen-Anhalt (State Commissioner for Data Protection Saxony-Anhalt) Leiterstraße 9 39104 Magdeburg, Germany

11. AI Features

The app "Codixio Product Downloads" contains no AI functions. No data is transmitted to AI providers, no AI-generated content is produced, and no automated decisions within the meaning of Art. 22 GDPR are made. Transparency obligations under Art. 50 of Regulation (EU) 2024/1689 (AI Act) therefore do not apply.

12. Cookies and Similar Technologies (Sec. 25 TDDDG)

The app and the legal pages operate cookie-free. No cookies are set, no information is stored on the end device, and no information stored on the end device is read beyond what is strictly technically necessary for transmission. Language selection on the legal pages is purely URL-based.

No marketing cookies, no tracking pixels, no Google Analytics, no Facebook pixel and no other third-party tracking are used. Consent under Sec. 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG) is not required in the absence of access to terminal equipment; no cookie consent banner is needed.

13. Security Measures (TOMs Under Art. 32 GDPR)

13.1. Data Minimisation as an Architectural Principle

The most effective protective measure of this app is its architecture: personal end-customer data is neither stored on nor transmitted to Codixio systems. Access control (login gate, purchase gate, rule visibility) runs entirely server-side within the merchant's Shopware instance.

13.2. Encryption

13.3. Access Control

13.4. Network Security

13.5. Backup, Monitoring and Review

14. Personal Data Breaches (Art. 33/34 GDPR)

In the event of a personal data breach:

15. Changes to This Privacy Policy

We reserve the right to amend this privacy policy to keep it in line with current legal requirements or to reflect changes to our services. Material changes will be announced with 30 days' notice via the app's store page and, where a contact address is available, by e-mail. The current version is available at https://legal.codixio.com/apps/product-downloads-shopware/privacy.

Historical versions are available on request at legal@codixio.com.

16. Date and Contact

Last updated: 27 August 2026

For questions about data protection or to exercise your rights, please contact:

legal@codixio.com

Matthias Jakisch, Hauptstr. 34, OT Etingen, 39359 Oebisfelde-Weferlingen, Germany.