← Back to the site

GDPR & Data Processing


The privacy policy covers this website. This page covers the different and more consequential question your procurement or legal team will ask: what happens to your data when we build or audit a system for you.

The roles

In a client engagement you are the controller of your own data and Koderna s.r.o. acts as a processor, acting only on your documented instructions. That relationship is set out in a written data-processing agreement forming part of the engagement contract, meeting the requirements of Article 28 GDPR.

During an audit

  • Access is read-only. No configuration is altered and no records are modified in your systems.
  • An NDA is signed as standard before access is granted, on our paper or yours.
  • We work with the minimum data required to answer the question. Where aggregate or pseudonymised extracts are sufficient, we ask for those instead of raw records.
  • Interview notes record roles and processes, not personal opinions attributed to named individuals.
  • Working copies of any client data are deleted on delivery of the report, and we confirm the deletion in writing on request.

During a build

  • Development and testing use synthetic or anonymised data wherever the work permits it.
  • Where production data is genuinely required — typically for a migration or a parallel run — it is processed inside your own infrastructure whenever possible, rather than copied to ours.
  • Access is granted per person and per environment, and is revoked when the phase that needed it ends.
  • Sub-processors are named in the agreement, and none is engaged without your prior written approval.

Security measures

Encryption in transit and at rest, multi-factor authentication on every account with access to client systems, least-privilege access granted per engagement, encrypted developer workstations, and separation between client environments. Specific technical and organisational measures are listed in the DPA annex for each engagement, because what is appropriate depends on what is being processed.

Location

Work is performed from the Czech Republic. Our own infrastructure is hosted within the European Union. Where an engagement requires a sub-processor outside the EEA, it is identified in the agreement in advance and covered by Standard Contractual Clauses.

On handover

When a system is handed over, the infrastructure and the data are yours and are held in accounts in your name. Our access is removed. Any residual working copies on our side are deleted, and we will confirm that in writing.

Audit rights and breach notification

The DPA provides for information and audit rights under Article 28(3)(h), and commits us to notifying you without undue delay — and in any event within 24 hours of becoming aware — of any personal data breach affecting your data.

Requesting the paperwork

Our standard DPA, sub-processor list and technical and organisational measures are available on request before any contract is signed. Write to hello@koderna.com.