Privacy Policy, Codixio Product Downloads
Last updated: 27 August 2026
1. Controller
The controller responsible for data processing within the meaning of Art. 4 No. 7 GDPR is:
Matthias Jakisch Hauptstr. 34, OT Etingen 39359 Oebisfelde-Weferlingen Germany
- Phone: +49 39059 974988
- E-mail (general):
support@codixio.com - E-mail (data protection):
legal@codixio.com
Legal form: sole proprietorship (no commercial register entry), operating under the trade name Codixio. VAT identification number pursuant to Sec. 27a German VAT Act (UStG): DE296346917. Tax status: small business under Sec. 19 UStG.
2. Data Protection Officer
No data protection officer has been appointed. Reason: the requirements of Art. 37(1) GDPR and Sec. 38(1) German Federal Data Protection Act (BDSG) are not met. Codixio does not employ ten persons permanently engaged in processing personal data, does not carry out core activities involving extensive processing of special categories of data, and does not systematically monitor data subjects on a large scale. For any data protection enquiries, please contact legal@codixio.com.
3. Scope
This privacy policy applies to:
- the Shopware app "Codixio Product Downloads" in all functions and plans (Standard, Pro, Max, Enterprise)
- the legal pages at
https://legal.codixio.com/(this privacy policy, DPA, imprint, terms, each in German and English) - the app backend domain
https://sw-codixioproductdownloadsapp.api.codixio.com/including the app endpoints and the admin module rendering
Distinction from the Codixio marketing website: The marketing website https://codixio.com (and its language versions) is operated on a separate instance and is subject to its own privacy policy linked there.
Distinction from Shopware: The use of the Shopware shop into which the app is installed, and of the merchant's Shopware account, is subject to the privacy provisions of Shopware AG (https://www.shopware.com/en/privacy/). This privacy policy only covers data processed by Codixio in the course of app usage.
4. Categories of Data Processed
The app is built on the principle of data minimisation. Core of the architecture: personal data of end customers is evaluated exclusively within the merchant's Shopware instance and never leaves it. No end-customer data is transmitted to the Codixio backend.
4.1. End-Customer Data, Processed Exclusively Within the Shopware Context
For download access control, the app evaluates the following data server-side within the merchant's Shopware instance:
- Customer login status (whether a customer is logged in to the shop), for downloads the merchant has marked as "logged-in customers only" (login gate, Max plan)
- Order history of the logged-in customer (mapping of order line items to products), for downloads the merchant has marked as "after purchase only" (purchase gate, Enterprise plan)
- Shopware Rule Builder context (which rules are satisfied in the current shopping context), for rule-based download visibility (Enterprise plan)
Personal reference: yes. This evaluation takes place exclusively server-side within the merchant's Shopware environment (Shopware App Scripts). This data is not transmitted to Codixio, not stored on Codixio systems, and not passed to third parties. The controller for this processing is the merchant as operator of the shop; the app merely provides the technical function within his Shopware instance.
4.2. Merchant Data (Shop Operators)
When a merchant installs the app in his Shopware shop, Codixio processes the following data on the app backend:
- Shop domain and shop ID (technical identifier of the Shopware instance, from app registration)
- Registration and authentication data of the app registration under the Shopware app system (shop secret for signature verification, stored access-protected)
- Active plan (Standard, Pro, Max or Enterprise) per shop, determined via the Shopware in-app purchase interface
- Language setting (locale) when calling the greeting endpoint
- Billing data: managed exclusively by Shopware AG via the merchant's Shopware account and the in-app purchase processing of the Shopware Store. Codixio only receives signed purchase information for plan determination, no payment instrument data (credit card, IBAN).
Personal reference: minor; affected at most are sole-proprietor merchants whose shop domain identifies the person.
4.3. Aggregated Usage Data (Download Statistics, Max and Enterprise Plans)
With the statistics feature enabled, the merchant's storefront sends the following data to the app backend upon a download click:
- Shop ID, download ID, product ID
From this, the backend maintains only an aggregated counter per download (total number of clicks). No customer data, no IP addresses in the application data store, no time profiles of individual persons and no other personal attributes are stored. Personal reference: no. Recording is protected against manipulation by a shop context check and rate limiting; retrieval is only possible via signed requests from the respective shop's admin module.
4.4. Technical Data
When accessing the legal pages (legal.codixio.com) and the app backend (sw-codixioproductdownloadsapp.api.codixio.com), the following technical data is processed:
- Access logs at the reverse proxy (Coolify/Traefik): IP address (anonymised to the first 3 octets for IPv4 or the 64-bit subnet for IPv6 after 7 days), user agent, HTTP method, URL, response status, timestamp
- Application-side error logs: error messages without personal data, stack traces
- Language preference when accessing the legal pages: the Accept-Language HTTP header is evaluated to serve the appropriate language version (DE or EN). No language cookies are set, language selection is purely URL-based.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in technical operational security, error diagnosis, abuse prevention).
5. Legal Bases of Processing
5.1. Art. 6(1)(b) GDPR, Performance of a Contract
The processing of merchant data (shop domain, shop ID, registration data, active plan) is based on the usage contract concluded between Codixio and the merchant upon app installation. Without this data the app cannot be provided, the booked plan cannot be determined, and the admin module cannot be delivered.
5.2. Art. 6(1)(f) GDPR, Legitimate Interest
Technical access logs, rate limiting and signature verification serve operational security and abuse prevention (protection of counter integrity, defence against automated attacks). The aggregated, non-personal download statistics serve the merchant's legitimate interest in evaluating the usage of his own content.
Balancing of interests (Art. 6(1)(f) GDPR, second half-sentence): processing is limited to technically necessary minimal data without lasting personal reference (IP anonymisation after 7 days, aggregated counters without personal attributes). No overriding interests of data subjects are apparent given this data situation.
5.3. Processing Within the Shopware Context (Merchant Responsibility)
The evaluation of login status, order history and rule context (Section 4.1) takes place exclusively within the merchant's Shopware instance. The merchant is the controller for this; the legal basis arises from his relationship with his customers (typically Art. 6(1)(b) GDPR, performance of the usage or purchase contract including the promised download provision). The merchant informs his customers about this in his own privacy policy.
6. Recipients / Sub-Processors
6.1. Recipients
No personal data is disclosed to third parties for their own purposes. The only recipient in the technical sense is the sub-processor listed below within the meaning of Art. 28 GDPR.
6.2. Active Sub-Processors
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany Activity: hosting provider for application servers and Postgres database Processing location: data centres Falkenstein (DE) and Nuremberg (DE) Third-country transfer: no
6.3. Codixio-Owned Infrastructure
- Coolify (open-source software), self-hosted container orchestration on Hetzner, not an external service provider.
No further service providers are used. In particular, the app does not send e-mails via external delivery services and does not use external AI services.
7. Third-Country Transfer
No third-country transfer takes place. The only sub-processor (Hetzner Online GmbH) is located in Germany; all processing takes place within the EU.
8. Retention Periods
8.1. Merchant and Plan Data
Shop registration, shop secret and plan assignment are stored for the duration of the app installation. Upon uninstallation of the app, the Shopware lifecycle mechanism triggers the automatic deletion of the shop data on the app backend.
8.2. Aggregated Download Counters
The aggregated counters are bound to the shop registration and are automatically deleted together with the shop record (database-level cascading deletion). At no time do they contain personal data.
8.3. Technical Access Logs
Access logs at the reverse proxy are automatically IP-anonymised after 7 days and fully deleted after 90 days.
9. Rights of Data Subjects
Under the GDPR, data subjects have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure / "right to be forgotten" (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR; in particular against processing based on Art. 6(1)(f))
- Right not to be subject to automated decision-making including profiling (Art. 22 GDPR), Codixio does not carry out automated individual decisions with legal effect.
You can exercise these rights by e-mail to legal@codixio.com. End customers of a merchant shop can additionally contact the respective merchant directly, since his Shopware instance holds the end-customer data; no end-customer data is stored on Codixio systems.
Response time: We respond to requests within the statutory period of one month pursuant to Art. 12(3) GDPR. For complex requests, this period may be extended by two further months; you will be informed of this within the first month.
10. Right to Lodge a Complaint With a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for Codixio is:
Landesbeauftragter für den Datenschutz Sachsen-Anhalt (State Commissioner for Data Protection Saxony-Anhalt) Leiterstraße 9 39104 Magdeburg, Germany
- Phone: +49 391 81803-0
- E-mail:
poststelle@lfd.sachsen-anhalt.de - Website:
https://datenschutz.sachsen-anhalt.de/
11. AI Features
The app "Codixio Product Downloads" contains no AI functions. No data is transmitted to AI providers, no AI-generated content is produced, and no automated decisions within the meaning of Art. 22 GDPR are made. Transparency obligations under Art. 50 of Regulation (EU) 2024/1689 (AI Act) therefore do not apply.
12. Cookies and Similar Technologies (Sec. 25 TDDDG)
The app and the legal pages operate cookie-free. No cookies are set, no information is stored on the end device, and no information stored on the end device is read beyond what is strictly technically necessary for transmission. Language selection on the legal pages is purely URL-based.
No marketing cookies, no tracking pixels, no Google Analytics, no Facebook pixel and no other third-party tracking are used. Consent under Sec. 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG) is not required in the absence of access to terminal equipment; no cookie consent banner is needed.
13. Security Measures (TOMs Under Art. 32 GDPR)
13.1. Data Minimisation as an Architectural Principle
The most effective protective measure of this app is its architecture: personal end-customer data is neither stored on nor transmitted to Codixio systems. Access control (login gate, purchase gate, rule visibility) runs entirely server-side within the merchant's Shopware instance.
13.2. Encryption
- Data transmission: TLS 1.2+ mandatory (HTTPS, Let's Encrypt, auto-renewal); HSTS header
- Credentials: shop secrets are stored access-protected and used exclusively for signature verification
13.3. Access Control
- Multi-factor authentication for all production access
- Least-privilege principle
- Signature verification (HMAC) for admin module calls and statistics retrieval; JWT verification against the Shopware keys for purchase information
13.4. Network Security
- Rate limiting on the statistics recording endpoint (30 requests per minute per shop)
- Search engine exclusion (X-Robots-Tag) on all app endpoints
- Security headers at the reverse proxy
13.5. Backup, Monitoring and Review
- Daily database backups on Hetzner infrastructure
- Health check endpoints for uptime monitoring, without disclosure of internal details in error cases
- Static code analysis and automated test suite with dedicated security regression tests
- Periodic security reviews along the Codixio Security Hardening Plan
14. Personal Data Breaches (Art. 33/34 GDPR)
In the event of a personal data breach:
- Notification to the supervisory authority without undue delay and where feasible within 72 hours of becoming aware, where the breach is likely to result in a risk to the rights and freedoms of natural persons (Art. 33(1) GDPR). No notification is made where the breach is unlikely to result in such a risk.
- Notification of affected data subjects without undue delay where there is a high risk (Art. 34(1) GDPR). Notification may be omitted where the data has been rendered inaccessible by appropriate measures (Art. 34(3)(a) GDPR), where subsequent measures eliminate the high risk (Art. 34(3)(b) GDPR), or where public communication would be more proportionate (Art. 34(3)(c) GDPR).
- Documentation of all incidents in the internal incident response log.
- Notification of the affected merchant for incidents touching shop data, in parallel with or before the supervisory notification.
15. Changes to This Privacy Policy
We reserve the right to amend this privacy policy to keep it in line with current legal requirements or to reflect changes to our services. Material changes will be announced with 30 days' notice via the app's store page and, where a contact address is available, by e-mail. The current version is available at https://legal.codixio.com/apps/product-downloads-shopware/privacy.
Historical versions are available on request at legal@codixio.com.
16. Date and Contact
Last updated: 27 August 2026
For questions about data protection or to exercise your rights, please contact:
legal@codixio.com
Matthias Jakisch, Hauptstr. 34, OT Etingen, 39359 Oebisfelde-Weferlingen, Germany.