Privacy Policy

Effective date: 8 September 2026
Last updated: 8 September 2026

CodeAce IT Solutions LLP (“CodeAce”, “we”, “us”, “our”) respects your privacy. This Privacy Policy explains what personal data we collect when you visit codeace.com (the “Website”), why we collect it, how we use and protect it, and the rights you have over it.

This Policy is written to comply with the Digital Personal Data Protection Act, 2023 (India) (“DPDP Act”), the EU General Data Protection Regulation and UK GDPR (“GDPR”), and the California Consumer Privacy Act as amended by the CPRA (“CCPA”). Where a law grants you rights beyond those described here, those rights apply.

Scope. This Policy covers the codeace.com Website only. It does not cover:

  • Personal data we process on behalf of clients while delivering our services. That processing is governed by the agreement with the client, who is responsible for its own privacy practices.
  • Our products — Writto AI (writto.ai), Momenza (momenza.ai) and RoamJoy — each of which publishes its own privacy policy.

1. Who we are

CodeAce brings together digital experience, performance marketing, and engineering & AI to help businesses build, automate and scale.

Data Fiduciary / ControllerCodeAce IT Solutions LLP (LLPIN AAN-4420), a limited liability partnership registered in India
OfficeUnit 4B, Second Floor, Sahya Building, Government Cyberpark, Nellikode PO, Kozhikode, Kerala 673016, India
Group officesCodeAce LLC, Austin, Texas, United States · IFZA Business Park, Dubai Silicon Oasis, United Arab Emirates
Contact for all privacy mattershello@codeace.com
Grievance Officer (DPDP Act)Reachable at hello@codeace.com with the subject line “Grievance”

CodeAce IT Solutions LLP is the Data Fiduciary under the DPDP Act, the Data Controller under the GDPR, and the Business under the CCPA for personal data collected through the Website. Our United States and United Arab Emirates offices may access Website data as part of the CodeAce group, under the safeguards described in Section 5.

2. What personal data we collect

2.1 Data you give us directly

Contact and enquiry forms. When you use a contact form, “Book a call”, “Start a project”, “Let’s Connect” or similar form, we collect what you enter: typically your name, business email, phone number, company name, job title, country, and the content of your message, including any brief or requirements you describe.

Acey, our website assistant. The Website includes an AI-powered chat assistant (“Acey”) that answers general questions about our services. When you use it, we collect the messages you type, Acey’s responses, and basic session data (time, page, device). Acey is a guide, not a quote: its responses are generated automatically and are not offers or advice. Do not enter sensitive personal data, passwords, personal data about other people, or confidential business information into the chat. Chat inputs are processed by a third-party AI model provider acting on our behalf (Section 4).

Careers. If you apply for a role through our Careers page, we collect the details you submit: name, contact information, CV or résumé, portfolio links, work history, and anything else you choose to include.

Email. If you email us at hello@codeace.com or any other CodeAce address, we retain the email and your contact details so we can respond.

Please do not send us sensitive personal data (health information, financial account numbers, government identification numbers, and similar) through the Website. We do not request it and do not need it.

2.2 Data collected automatically

When you browse the Website, our servers and analytics tools automatically record:

  • IP address, anonymised where our analytics configuration allows
  • Browser type and version, operating system, device type and screen size
  • Referring website or source, pages viewed, time on page, clicks and scroll depth
  • Approximate location (city or country level) derived from IP address
  • Cookie identifiers and similar technologies (Section 6)

2.3 Social media and embedded content

The Website links to our Facebook, LinkedIn, Instagram and YouTube pages and may embed video from those platforms. Interacting with those platforms, or viewing embedded content, may cause them to set cookies and collect data under their own privacy policies, which we do not control.

2.4 Children

The Website is intended for businesses and adults. We do not knowingly collect personal data from anyone under 18. If you believe a child has submitted data to us, email hello@codeace.com and we will delete it.

PurposeData usedLegal basis under GDPRBasis under DPDP Act
Respond to your enquiry, call request or project briefForm and email dataPre-contractual steps (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f))Consent; legitimate use where you voluntarily provide data for a specified purpose
Operate Acey and answer your chat questionsChat messages, session dataLegitimate interest (Art. 6(1)(f)); consent where requiredConsent
Evaluate job applications and communicate with candidatesCareers dataPre-contractual steps (Art. 6(1)(b)); legitimate interestConsent; legitimate use for employment purposes
Send marketing emails or newsletters you have signed up forName, emailConsent (Art. 6(1)(a))Consent
Operate, secure and debug the WebsiteAutomatic data, server logsLegitimate interest (Art. 6(1)(f))Legitimate use
Understand how the Website is used and improve itAnalytics cookiesConsent (Art. 6(1)(a))Consent
Improve the accuracy of Acey’s answers about our servicesChat transcripts, de-identified where practicableLegitimate interest (Art. 6(1)(f))Consent
Comply with legal obligations and respond to lawful requestsAny relevant dataLegal obligation (Art. 6(1)(c))Legitimate use for legal compliance
Establish, exercise or defend legal claimsAny relevant dataLegitimate interest (Art. 6(1)(f))Legitimate use

We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you. Acey does not make decisions about you, and job applications are reviewed by people.

4. Who we share your data with

We do not sell personal data. We do not share personal data for cross-context behavioural advertising. We share data only with:

  • Service providers (Data Processors) acting on our documented instructions under written contracts: our web hosting and content delivery providers, email delivery service, CRM and form-storage tools, web analytics provider, applicant-tracking tool, and the AI model provider that powers Acey.
  • CodeAce group companies — CodeAce LLC in the United States and our Dubai office — where an enquiry relates to their market or staff in those offices handle the work.
  • Professional advisers such as lawyers, auditors and accountants, where necessary.
  • Authorities, regulators and courts where required by law or to protect our rights.
  • A successor entity in the event of a merger, acquisition or restructuring, subject to this Policy.

A current list of our processors is available on request from hello@codeace.com.

5. International transfers

CodeAce is headquartered in India and has offices in the United States and the United Arab Emirates. Your data may be transferred to, stored in and accessed from any of these countries, and by service providers located elsewhere, including the United States and the European Union.

  • EU and UK users. Transfers outside the EEA or UK are made under the European Commission’s Standard Contractual Clauses and, where relevant, the UK International Data Transfer Addendum, or another mechanism permitted under Chapter V of the GDPR. You may request a copy of the relevant safeguards.
  • Indian users. Data may be processed outside India in accordance with Section 16 of the DPDP Act and any restrictions notified by the Central Government.
  • UAE users. Transfers are made in accordance with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) where it applies.

6. Cookies and analytics

The Website uses cookies and similar technologies.

CategoryPurposeConsent required
Strictly necessarySecurity, load balancing, remembering your cookie preferences, keeping an Acey chat session openNo
AnalyticsMeasuring traffic, pages viewed and Website performance through third-party web analytics tools such as Google AnalyticsYes
Third-party embedsSet by YouTube, Facebook or other platforms when embedded content loadsYes

When you first visit, a cookie banner lets you accept or reject non-essential cookies. You can change your choice at any time through the Cookie Settings link in the Website footer, or through your browser settings. Rejecting non-essential cookies does not affect your ability to use the Website.

Where Google Analytics is used, IP anonymisation is enabled and data is shared with Google under its data processing terms. You can also opt out using Google’s browser add-on.

We honour Global Privacy Control (GPC) signals as an opt-out of the sale or sharing of personal data where required by law. The Website does not otherwise respond to browser “Do Not Track” signals, for which no common standard exists.

7. How long we keep your data

DataRetention period
Enquiry and contact form submissionsUp to 24 months after our last interaction, unless a client relationship begins, in which case per the client agreement
Acey chat transcriptsUp to 12 months, then deleted or de-identified
Job applicationsUp to 12 months after the role closes, so we can consider you for future roles, unless you ask us to delete sooner
Marketing and newsletter subscriptionsUntil you unsubscribe, after which your address is suppressed to honour your opt-out
Server and security logsUp to 12 months
Analytics data14 months
Records needed for legal, tax or dispute purposesFor the applicable statutory limitation period

Under the DPDP Act, we erase personal data when the purpose is served or when you withdraw consent, unless retention is required by law. At the end of the retention period, data is deleted or irreversibly anonymised.

8. How we protect your data

We apply reasonable technical and organisational safeguards appropriate to the risk, including HTTPS encryption in transit, access controls limiting data to staff who need it, encrypted storage with our hosting providers, and contractual security obligations on every processor. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

In the event of a personal data breach, we will notify the Data Protection Board of India and affected individuals as required by the DPDP Act, and supervisory authorities and individuals as required by the GDPR, within 72 hours where that applies.

9. Your rights

9.1 All users

Wherever you live, you can:

  • Access the personal data we hold about you and a summary of how it is processed
  • Correct inaccurate or incomplete data
  • Delete your data, subject to legal retention requirements
  • Withdraw consent at any time, as easily as you gave it, without affecting processing already carried out
  • Unsubscribe from marketing emails using the link in any email or by contacting us

9.2 Additional rights in India (DPDP Act)

  • Right to grievance redressal through our Grievance Officer at hello@codeace.com, who will respond within the period prescribed under the DPDP Rules
  • Right to nominate another person to exercise your rights in the event of your death or incapacity
  • If you are not satisfied with our response, you may approach the Data Protection Board of India

9.3 Additional rights in the EU, EEA and UK (GDPR)

  • Right to restrict processing and to object to processing based on legitimate interests
  • Right to data portability in a structured, commonly used, machine-readable format
  • Right to lodge a complaint with your local supervisory authority (for the UK, the Information Commissioner’s Office). We would appreciate the chance to address your concern first.

9.4 Additional rights in California (CCPA/CPRA)

To the extent the CCPA applies to CodeAce, California residents have the right to:

  • Know the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of third parties it is disclosed to
  • Delete and correct personal information
  • Opt out of the sale or sharing of personal information. CodeAce does not sell or share personal information as those terms are defined under the CCPA and has not done so in the preceding 12 months.
  • Limit use of sensitive personal information. We do not collect sensitive personal information through the Website.
  • Non-discrimination for exercising any of these rights

Categories collected in the last 12 months: identifiers (name, email, phone, IP address); commercial information (enquiry details); internet activity (browsing, chat and interaction data); approximate geolocation; and professional or employment information (company, job title, and CV data for applicants). Sources: you, and your device or browser. Disclosed for business purposes to the service-provider categories in Section 4.

You may designate an authorised agent to make a request on your behalf. We will require proof of authorisation and may verify your identity directly.

9.5 How to exercise your rights

Email hello@codeace.com with the subject line “Privacy Request”, or write to the address in Section 1. We may ask you to verify your identity. We will respond within 30 days, or sooner where the law requires; the GDPR allows one month, extendable by two further months for complex requests, and the CCPA allows 45 days, extendable by a further 45 days. There is no fee unless a request is manifestly unfounded or excessive.

The Website links to third-party sites — social platforms, client websites, media coverage — and to our own products Writto AI, Momenza and RoamJoy. Each has its own privacy policy. We are not responsible for the practices of third-party sites; review their policies before providing personal data.

11. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date at the top will change, and for material changes we will post a notice on the Website or, where we have your email, notify you directly. Continued use of the Website after changes take effect constitutes acceptance of the updated Policy, to the extent permitted by law.

12. Contact us

CodeAce IT Solutions LLP
Unit 4B, Second Floor, Sahya Building, Government Cyberpark, Nellikode PO, Kozhikode, Kerala 673016, India
hello@codeace.com

For privacy requests, use the subject line “Privacy Request”. For grievances under the DPDP Act, use the subject line “Grievance”.