Legal

Privacy Notice

Last updated 11 October 2026

In short
  • Citadel AI reads metadata from your AWS accounts: resource settings, utilization metrics and billing totals. It never reads the contents of your files, databases or applications.
  • Your data is stored on AWS in the EU (Frankfurt, eu-central-1).
  • We do not sell personal data and do not use advertising or tracking cookies.

1Who is responsible

The controller of personal data processed through Citadel AI is CODENEX SRL, Republic of Moldova, IDNO 1024600018769. Contact: andrei@code-nex.tech.

2What we collect

DataWhyLegal basis
Account data: email address, password (stored only as a one-way hash), name and company if you provide themTo create and secure your account and to contact you about itContract
AWS metadata: account ids and names, resource ids, names, tags, configuration, utilization metrics, cost and usage totalsTo produce your recommendations and findingsContract
Usage and security logs: sign-ins, IP address, browser, actions in the ServiceTo keep the Service secure, investigate problems and prevent abuseLegitimate interest
Billing data: plan, invoices, country for tax. Card details are handled by Paddle and never reach usTo bill your subscription and meet tax obligationsContract, legal obligation
Messages you send usTo answer youLegitimate interest

AWS metadata can contain personal data if you put it there, for example a person's name in a resource tag or an IAM user name. We treat it with the same care as the rest of your account data.

3Who we share it with

We share data only with service providers who help us run the Service, under contracts that protect it:

  • Amazon Web Services EMEA SARL: hosting and storage, in the EU (Frankfurt).
  • Paddle.com Market Ltd: our reseller and Merchant of Record. Paddle processes payments, invoices, taxes and refunds as an independent controller under its own privacy notice.
  • Email providers: to send account and service emails.

We may disclose data when the law requires it. We never sell personal data.

4International transfers

Your data is stored in the EU. CODENEX SRL operates from the Republic of Moldova, so our team may access data from outside the EU. Where EU or UK law requires it, such access is covered by the European Commission's Standard Contractual Clauses or another lawful transfer mechanism.

5How long we keep it

  • Account and AWS data: while your account is active. Detailed resource-level cost data is kept for 90 days, daily cost totals for 12 months.
  • After you close your account, we delete your data within 30 days. Encrypted backups are overwritten within a further 35 days.
  • Billing records: as long as tax law requires.
  • Security logs: up to 12 months.

6How we protect it

Access to your AWS accounts uses a read-only role and short-lived credentials (at most one hour). We never ask for or store AWS access keys. Each customer's role is protected by a unique ExternalId. Data is encrypted in transit and at rest, and every record is tied to your organization so no other customer can see it.

7Cookies

This website does not use advertising or analytics cookies. The Service uses one essential cookie to keep you signed in. Your theme choice (light or dark) is stored in your browser's local storage.

8Your rights

Depending on where you live, including under the EU and UK GDPR and Moldovan Law No. 195/2024 on personal data protection, you can ask to access, correct, delete or export your personal data, object to or restrict its processing, and withdraw consent where we rely on it. Write to andrei@code-nex.tech; we reply within 30 days. You can also complain to your local data protection authority.

9Children

The Service is for people aged 18 and over. We do not knowingly collect data from children.

10Changes

If we change this notice in a material way, we will tell you by email or in the Service before the change applies.