Privacy Policy
Last updated: 2026-08-10
This policy explains what personal data flows.codebar.ch processes, why, where it is held, and who else receives it.
1. Controller
For your account, authentication, and billing data, the controller is codebar Solutions AG, Hauptstrasse 91, CH-4455 Zunzgen, Switzerland.
For the documents your workspace processes through flows.codebar.ch (DocuWare documents, OCR output, extracted index fields), your organisation — the customer that operates the workspace — is the controller, and codebar Solutions AG acts as its processor under the Data Processing Agreement. If you are a member of a workspace, direct document-related requests to your workspace owner first.
2. Contact
3. What flows.codebar.ch does
flows.codebar.ch connects to your DocuWare document management system and lets you build automated "flows" that read documents, extract data from them (using OCR and, optionally, AI models), and write results back to DocuWare or to other systems through a hosted MCP (Model Context Protocol) gateway. Some flow steps are deterministic (webhook triggers, field transforms, scheduled runs); others hand document content to an AI model to interpret it. Accounts are passwordless: you sign in with a one-time link sent to your email address.
4. Accounts and how they are created
Entering an email address on the sign-in page and accepting this policy and the Terms of Service produces a one-time sign-in link; an address we do not recognise is registered as a new account. Accounts are also created when a workspace member invites someone by email, and an invited user goes through the same acceptance step on first sign-in. Sign-in links are single-use and expire after 15 minutes; the link record itself carries no IP address or browser information.
5. Personal data we process
- Account data — name, email address, locale, workspace membership, and the timestamp of your privacy-policy acceptance.
- Authentication & session data — your browser session is tracked server-side and includes your IP address and user-agent string, so that a session can be recognised and, if needed, investigated.
- Workspace & billing data — workspace name, billing company name, billing contact person, billing email, billing address, and tax/VAT identifier. This data is stored for invoicing purposes; flows.codebar.ch does not itself integrate a payment processor, so no card or bank details pass through the application.
- Invitations — an invitee's email address, an invitation token, and the identities of the inviter and (once accepted) the accepter.
- Audit log — account and workspace actions are logged: sign-in attempts (successful, failed, expired, throttled), self-registration, changes to records, and who made them, each with the IP address and user-agent of the request and the old and new value of whatever changed. We keep this record for the life of the account on the basis of our legitimate interest in account security and accountability, and it is not erased piecemeal on request — an audit trail that could be edited would not be one. See §8.
- Notifications — the content of emails we send you (for example the sign-in link or an invitation) is stored until it has been delivered.
- Integration credentials — your DocuWare username and password, API keys for any AI provider you configure, bearer tokens for any MCP server you connect, and similar secrets are stored encrypted at rest.
- Flow configuration — the automation rules you build: DocuWare search filters (which can encode names, customer numbers, or other identifiers you chose to filter on), prompts, JSON schemas, and agent instructions you or an AI model authored.
- Document data — see §6. This is usually the largest category by volume and the one most likely to contain personal data about people who are not flows.codebar.ch users at all (for example names and details on an invoice or contract your workspace processes).
6. Document content — what we store
flows.codebar.ch processes and stores the content of the documents your workspace runs through it, in three places:
- Original document files are stored in your workspace's own Azure Blob Storage container. A read-only, time-limited link to a specific file can be generated when needed (by default valid for 24 hours).
- Extracted text and structured data — the OCR output, the raw response from the OCR/extraction model, the fields extracted from it, DocuWare's own text layer, and the input and output of each automation step — are stored in our application database, on rows that belong to your workspace.
- Document metadata and DocuWare index fields — titles and the full set of index-field values from DocuWare (which can include names, amounts, dates, and customer numbers) — plus the raw inbound webhook payload that triggered a flow, are stored the same way. Credential-bearing headers are removed from a webhook payload before it is stored.
7. Where your data is hosted
The application and its database run on Laravel Cloud infrastructure in the EU (Amazon Web Services, Frankfurt). Workspaces share that database, and each workspace's data is kept separate from every other's.
Each workspace additionally has its own dedicated set of Microsoft Azure resources, created when the workspace is set up: a Storage Account holding document files and inbound webhook payloads, a Key Vault holding that workspace's integration secrets, an Application Insights instance for operational telemetry, a Function App receiving inbound webhooks, and an AI Foundry account with the model deployments used for OCR and AI steps. See §9 for where AI inference is processed.
8. Retention
- Sign-in links
- Superseded by each new request; removed once expired.
- Inbound webhook payloads buffered before processing
- 7 days.
- Scheduled-flow dispatch history
- 30 days.
- Application performance and error telemetry
- 30 days.
- Document files, extraction output, flow-run history, billing usage records
- For the duration of the workspace relationship; deleted or returned on request as described in the DPA.
- Audit log
- For the life of the account — see §5.
9. Sub-processors and other recipients
The following vendors process personal data on our behalf, or on your organisation's behalf as a sub-processor under the DPA, for which this list is the authoritative one. Vendors marked "customer-controlled" are not our sub-processors: you, not we, decide whether and how to use them, and they receive data directly from actions your workspace configures.
Laravel Cloud (on Amazon Web Services)
- Purpose
- Hosting of the application and its database.
- Receives
- All data described in this policy.
- Location
- EU (Frankfurt).
Microsoft Azure
- Purpose
- Per-workspace document storage, Key Vault, webhook intake, telemetry, and the AI Foundry model deployments used for OCR and AI steps.
- Receives
- Document files and inbound payloads; the document content sent for OCR and the content sent to AI steps.
- Location
- Storage, Key Vault, and telemetry resources are created in the workspace's configured region. AI inference — including OCR, which sends the full document — runs on globally routed model deployments and may be processed by Microsoft in any Azure region.
Postmark (or an alternative mail provider your deployment is configured to use)
- Purpose
- Delivering sign-in and invitation emails.
- Receives
- Recipient email address, the sign-in or invitation link, workspace and inviter name.
- Location
- US, under Swiss/EU-compliant transfer safeguards.
Laravel Nightwatch
- Purpose
- Application performance and error monitoring.
- Receives
- Request metadata, the acting user's identifier, and exception details including the surrounding source code; request payloads are not captured.
- Location
- EU/US, under Swiss/EU-compliant transfer safeguards.
Oh Dear
- Purpose
- Uptime and health monitoring of the application.
- Receives
- No personal data.
- Location
- EU.
Userback
- Purpose
- In-app feedback widget, loaded only on our staging and production environments.
- Receives
- Your user id, name, and email address; if you use the widget to submit feedback, also a screenshot, console log, and browser/OS information.
- Location
- EU.
Fathom Analytics
- Purpose
- Cookie-free page-view analytics, on staging and production only.
- Receives
- Page URL and your IP address, processed by Fathom and not stored by us; no cookies are set and no account identifier is passed.
- Location
- EU.
Automattic (Gravatar)
- Purpose
- Avatar images next to member names in the interface.
- Receives
- A one-way hash of the email address, plus your IP address and the page you were on, each time an avatar is requested — this happens for every workspace member visible on a page, not only your own.
- Location
- US.
Zefix (Swiss Central Business Names Index)
- Purpose
- Company look-up during workspace onboarding.
- Receives
- The company name you type while searching.
- Location
- Switzerland.
DigitalOcean
- Purpose
- Hosting of the application's own front-end asset files.
- Receives
- No personal data.
- Location
- EU (Frankfurt).
Your DocuWare system — customer-controlled
- Purpose
- The document management system a flow reads from and writes back to.
- Status
- Not our sub-processor — this is your own infrastructure.
AI providers you configure — customer-controlled
- Purpose
- Interpreting document content in an "agent" flow step, at your instruction. This covers OpenAI, Anthropic, Google, Mistral, OpenRouter, any OpenAI-compatible endpoint, and your own Azure AI Foundry deployment.
- Receives
- Whatever the flow step sends it, which can include extracted document text.
- Status
- Not our sub-processor: you choose the vendor and supply the API key. Your organisation is the one authorising that vendor to process this data, and we cannot warrant a third party's safeguards on your behalf.
MCP servers you configure — customer-controlled
- Purpose
- External tools a flow can call in a "tool" step.
- Receives
- Whatever the tool call sends it.
- Status
- Not our sub-processor — customer-controlled.
Where a vendor above processes data outside Switzerland or the EU/EEA, the safeguard we rely on is described in §11.
10. Cookies and tracking
flows.codebar.ch itself sets one cookie: the session cookie that keeps you signed in. It is strictly necessary and is not used for tracking or advertising.
On our staging and production environments (not in local development), two third-party scripts also load:
- Fathom Analytics — cookie-free page-view counting. It does not set a cookie and does not receive your name, email, or account id.
- Userback — an in-app feedback widget that becomes active after a short delay or when you interact with the page. Unlike Fathom, it does receive identifying information (your user id, name, and email) so that feedback can be matched to an account, and it can capture a screenshot and console log if you choose to submit feedback.
11. International transfers
Where a sub-processor listed in §9 processes data outside Switzerland or the EU/EEA, we rely on Standard Contractual Clauses, an applicable adequacy decision, or (for the US) certification under the Swiss-U.S. or EU-U.S. Data Privacy Framework, as the safeguard for that transfer.
12. Your rights
Depending on where you are, you may have the right to access, correct, or request erasure of your personal data, to object to or restrict certain processing, and to receive your data in a portable format. To exercise any of these, or to close a workspace, contact info@codebar.ch. As explained in §5, the audit-log record of your account activity is an exception we do not erase on request while your account exists, because it is the record we rely on for account security.
13. Security
We apply technical and organisational measures appropriate to the risk, covering authentication and access control, separation of each workspace's data, encryption of credentials and secrets at rest, encryption of data in transit, and logging of security-relevant events. These measures are reviewed as the service changes. Customers who need them described in more detail for their own assessment can request that in writing.
No security measure is perfect; if you believe you have found a vulnerability, please report it to helpdesk@codebar.ch.
14. Changes to this policy
When we materially change this policy, we update the "Last updated" date above and — since account holders must accept this policy — every signed-in user is asked to review and re-accept it the next time they use flows.codebar.ch.