Privacy Policy
How we collect, use, and protect personal data on the Codat.pro platform.
Last updated: June 15, 2026
What we collect: only what is necessary for your account, IMEI checks, payments, contact, and security. We do not sell data.
How long we keep it: account until deletion or 3 years of inactivity; checks 2 years (with account) or as needed to deliver the report (without account); contact 3 years; payments 10 years; logs 1 year.
What we do with it: service delivery, invoicing, support, security, technical improvement. We do not sell data to third parties.
Transparent summary: what data, how long we keep it, what we do with it
We collect: Name, email, password (hashed), optional: phone, company, tax ID, billing address
We keep: Until account deletion or 3 years of inactivity
Purpose: Authentication, invoicing, verification history
We collect: IMEI/serial, check result, account ID
We keep: 2 years
Purpose: History, reports, support
We collect: IMEI/serial, result, email, name, phone (if provided)
We keep: As needed to deliver the report (report accessible for 30 days)
Purpose: Report delivery, refunds
We collect: Name, email, subject, message; on submission: IP, user agent
We keep: 3 years
Purpose: Responding to inquiries, support
We collect: We do not store card data; Viva.com processes payments. We keep transaction references (ID, amount, date)
We keep: 10 years (tax obligations)
Purpose: Invoicing, refunds, disputes
We collect: As set out in the Cookie Policy
We keep: As set out in the Cookie Policy
Purpose: Site operation, performance
We collect: IP, security-relevant actions
We keep: 1 year
Purpose: Security, debugging
Cookies: details in Cookie Policy.
1. Our Commitment
At Codat.pro, we are committed to protecting the privacy of your data. This policy explains what information we collect, how we use it, and what rights you have regarding it, in accordance with Regulation (EU) 2016/679 (GDPR).
2. What Data We Collect
We only collect information that is strictly necessary. Here is exactly what we store:
- Account: name, email, password (stored hashed); optional: phone, company, tax ID, billing address, avatar. We do not collect card data.
- IMEI checks: IMEI or serial number, check result; for checks without an account: email, name, phone (if provided).
- Contact: messages submitted through the contact form are stored in our ticketing system (email, name, subject, message). Upon submission we automatically record the IP address and browser type (user agent) for abuse prevention and support.
- Cookies and analytics: as set out in the Cookie Policy (link below).
- Payments: we do NOT store card data; our partner Viva.com processes payments. We only keep transaction references (ID, amount, date).
3. Purpose and Legal Basis for Processing
We process your data for the following purposes and on the following legal bases:
- Provision of Services (Art. 6(1)(b) GDPR): To create and manage your account, process IMEI checks, and generate reports.
- Communication (Art. 6(1)(f) GDPR): To respond to contact messages and send essential notifications (account confirmation, password reset). Our legitimate interest is maintaining good communication with users.
- Security and Improvement (Art. 6(1)(f) GDPR): To monitor and secure the platform and to analyze usage in order to optimize the user experience. Our legitimate interest is ensuring the functionality and performance of the service.
- Consent (Art. 6(1)(a) GDPR): For the use of non-essential cookies, where we will request your explicit consent.
4. Sharing Data with Third Parties
We do not sell or rent your personal data. We share data only with essential service providers, under strict confidentiality agreements:
- IMEI Database Providers: To carry out the requested checks.
- Payment Processors (Viva.com): To process transactions securely.
- Hosting and Infrastructure Providers (e.g. Vercel, AWS): To run the platform.
- Analytics Services (Vercel Analytics): To monitor site performance and improve loading speed.
5. Your Rights
Under the GDPR, you have the following rights:
- Right of Access: You may request a copy of the data we hold about you.
- Right to Rectification: You may correct inaccurate data in your account.
- Right to Erasure ("Right to be Forgotten"): You may request deletion of your account and associated data, a process you can start from your account and confirm by email.
- Right to Restriction of Processing: You may request that we limit how we process your data.
- Right to Object: You may object to processing based on legitimate interest.
- Right to Data Portability: You may request the transfer of your data to another controller.
- Right to lodge a complaint with the supervisory authority (ANSPDCP).
6. Data Security
We implement advanced security measures, including SSL encryption, password hashing, and email confirmations for sensitive actions, to protect your data against unauthorized access.
7. Data Retention Period
We retain data only as long as necessary:
- Account data: Until deletion is requested or 3 years of inactivity.
- Checks with account: 2 years for verification history.
- Checks without account (guest): data is kept as needed to deliver the report (report accessible for 30 days).
- Contact messages / support tickets: 3 years for responding to inquiries.
- Payment data (transaction references): 10 years under tax legislation.
- Security logs: 1 year.
- Cookies: as set out in the Cookie Policy.
8. Cookie Policy
We use cookies to ensure the site functions properly and to provide you with a personalized experience. For full details, please see our dedicated Cookie Policy page.
9. Changes to This Policy
We reserve the right to update this policy. Any changes will be published on this page, together with the date of the last update. We encourage you to review this page periodically.
10. Contact
To exercise your rights or for any questions about this policy, you can contact us using the details on the Contact page.
Protecting your personal data is a priority for us. For more information, please do not hesitate to contact us.

