How the GlobalCodio application collects, uses, shares, and protects information — including data processed on behalf of our law-firm customers.
This Privacy Policy explains how Medicodio Inc., the operator of the GlobalCodio platform ("GlobalCodio", "we", "us", or "our"), handles information within the GlobalCodio application — the authenticated product at app.globalcodio.ai and its associated portals. Medicodio Inc. is a Delaware corporation.
This policy is separate from the privacy policy that governs our public marketing website (www.globalcodio.ai). The marketing-site policy covers visitors, contact forms, and website analytics only. This policy governs accounts, immigration case data, documents, and integrations within the product. Where the two differ, this policy controls for the application.
GlobalCodio serves law firms, corporate HR teams, service providers, and applicants. Our privacy role depends on the data:
| Data | Our role | What it means |
|---|---|---|
| Account, profile, billing, and usage telemetry | Controller | We decide why and how this data is processed. |
| Client matter / immigration case data, foreign-national PII, uploaded documents | Processor | Our law-firm or business customer is the controller. We process this data only on their documented instructions, under our agreement with them. |
| Google user data (sign-in profile, Gmail send) | Controller (limited) | We act as controller for the limited Google data we receive, bound by Google’s Limited Use requirements (see “Google user data”). |
If you are an applicant or employee whose data was entered by a law firm or employer, that organization is the controller of your case data. Requests about that data are routed to them (see “Your rights & choices”).
Because GlobalCodio supports immigration case work, the case data our customers submit can include the following categories of sensitive information:
This information is submitted by our law-firm and business customers as case data. We process it as a processor, on their documented instructions — see “Our roles: controller and processor” above.
We may aggregate or de-identify information so that it no longer identifies you. We use aggregated data only for internal purposes — operating, securing, and improving the platform, and understanding product usage trends — and only in a form that is not treated as personal information.
| Google scope | Purpose | Access level |
|---|---|---|
| Sign-in — `openid`, `email`, `profile` | Authenticate your account and display your identity (name, email, profile photo). | Read basic profile/email only. |
| `.../auth/gmail.send` | Send case-status updates and notification emails from your own Gmail mailbox, on your behalf. | Send only. We cannot read, search, modify, or delete any message in your mailbox. |
| `.../auth/calendar.events`, `.../auth/meetings.space.settings` | Create and manage Google Meet meetings and calendar events you schedule through GlobalCodio. | Create/manage events you initiate in the product. |
We do not access Gmail-scope data for any routine purpose. A human at GlobalCodio may access this data only in an aggregated or de-identified form, or in one of these specific cases:
Where the GDPR / UK GDPR applies, we process personal data on one or more of the following legal bases:
For immigration case data we process as a processor, the legal basis is determined by the controlling firm or organization, and we act on their documented instructions under our agreement with them.
| Data | Retention |
|---|---|
| Account & profile data | 365 days after account closure or a deletion request, then permanently deleted. |
| Client / immigration case data (processor data) | 365 days by default, subject to any legal hold; returned or deleted per the customer’s instructions on termination of the customer’s agreement. |
| Logs & diagnostics | 365 days, then deleted or anonymized. |
| Google OAuth tokens | Revoked and deleted from our systems within 30 days of unlink or account closure (see “Google user data”). |
| Dormant / inactive accounts | Not deleted or anonymized for inactivity alone — an account is retained until you close it or request deletion. |
| Deletion request SLA | Up to 365 days from your request to permanent deletion. |
You can close your account or request deletion of your account data at any time. This is currently an email-driven process — we do not yet offer a self-serve “Delete my account” control in the product.
You can also request an export of the account data we control by emailing the same address.
If you are an applicant or beneficiary whose case is managed through GlobalCodio, you can choose how much of your case history is visible to people the controlling firm gives access to.
For example, this controls what a corporate HR contact or a co-applicant can see about your case.
This choice is set in-product and can be changed at any time.
| Level | What it shares |
|---|---|
| Full history | Your complete case history and status updates. |
| Current status only | Your case’s current status, without historical detail. |
| Declined | No case information is shared beyond what the firm itself already has direct access to as case controller. |
This setting controls sharing with people the firm designates as having limited access. It does not limit the controlling firm’s own access to the case data it submitted — the firm is the controller of that data.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a personal-data breach likely to present a risk to affected individuals, we will notify the relevant data-protection authorities without undue delay. Where feasible under the GDPR, we will do so within 72 hours, and will notify affected individuals where required.
A breach notice we send you will describe what happened, what categories of information were involved, and the steps we are taking in response. We will send it to the email address on file for your account, or route it through the controlling firm or organization where we act as processor for the affected data.
We are actively working toward recognized security certifications, including SOC 2 and ISO 27001. We do not currently claim to hold these certifications and will update this policy as any are formally achieved.
Depending on where you live, you may have rights over your personal data. Under the GDPR / UK GDPR, these include:
We do not charge for responding to a request and aim to respond within 30 days. We may decline or charge for requests that are manifestly unfounded or excessive, and will explain why if we do. You also have the right to lodge a complaint with your local data-protection supervisory authority.
If you are a California resident, the CCPA / CPRA gives you rights over your personal information:
The table below is our Notice at Collection: the categories of personal information we collect, why, and how long we keep them. See “Information we collect” and “Data retention” above for the full detail behind each row.
| CCPA category | Examples we collect | Purpose | Retention |
|---|---|---|---|
| Identifiers | Name, email, phone number | Account creation & authentication | 365 days post-closure |
| Customer records | Billing and payment details | Invoicing your firm/organization | 365 days post-closure |
| Protected classifications | National origin, immigration status (case data only) | Immigration case processing, as a processor | Per the retention table |
| Commercial information | Product usage and feature telemetry | Operating and improving the platform | 365 days |
| Internet/network activity | IP address, device, and log data | Security, reliability, troubleshooting | 365 days |
| Professional/employment info | Role, firm/organization affiliation | Access control and account administration | While account is active |
| Sensitive personal information | Health, criminal history, precise case details (case data only) | Immigration case processing, as a processor | Per the retention table |
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
To exercise your California rights, contact us at info@globalcodio.ai, or by mail at 2603 Camino Ramon #200, San Ramon, CA 94583, USA. You may also designate an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your authorization, and may still require you to directly verify your own identity. We will verify your request and respond within the timeframe required by law (generally 45 days).
GlobalCodio operates in the United States and India, and may process information in both. Where we transfer personal data across borders, we rely on appropriate safeguards, including the EU/UK Standard Contractual Clauses (SCCs) where applicable.
The application may link to or integrate with third-party services (for example, Google sign-in, Gmail send, and Google Meet). This policy does not cover the practices of those third parties, and we are not responsible for their privacy practices. Your use of a linked third-party service is governed by that party’s own terms and privacy policy.
GlobalCodio is a business platform and is not directed to children. The GDPR sets the age of consent at up to 16, and the U.S. Children’s Online Privacy Protection Act (COPPA) sets its own protections for children under 13. We do not knowingly create accounts for or collect personal information directly from children. If you believe a child has provided us personal information through an account, contact us at info@globalcodio.ai and we will take appropriate steps.
Immigration cases may include information about minor beneficiaries (for example, dependents) provided by our customers as part of a case. Such data is processed as case data on the customer’s instructions (we act as a processor), not collected from the minor directly.
We may update this policy from time to time. Every update revises the effective date and version number shown above, so you can always tell whether you are looking at the current version.
For a material change, we will email you a plain-language summary of what changed and ask you to acknowledge it before you continue using the application. Non-material changes (clarifications, formatting) take effect on posting, without a separate notice.
For privacy questions or to exercise your rights, contact us at info@globalcodio.ai. We aim to respond within 30 days.
Medicodio Inc. (operator of GlobalCodio) Delaware (registered office): 16192 Coastal Hwy, Lewes, DE 19958, USA · California: 2603 Camino Ramon #200, San Ramon, CA 94583, USA · India (operations): B-Block, 8th Floor, Brigade Tech Park, 134/1, Whitefield, Bangalore – 560 066, India