How the GlobalCodio application collects, uses, shares, and protects information — including data processed on behalf of our law-firm customers.
This Privacy Policy explains how Medicodio Inc., the operator of the GlobalCodio platform ("GlobalCodio", "we", "us", or "our"), handles information within the GlobalCodio application — the authenticated product at app.globalcodio.ai and its associated portals. Medicodio Inc. is a Delaware corporation.
This policy is separate from the privacy policy that governs our public marketing website (www.globalcodio.ai). The marketing-site policy covers visitors, contact forms, and website analytics only. This policy governs accounts, immigration case data, documents, and integrations within the product. Where the two differ, this policy controls for the application.
GlobalCodio serves law firms, corporate HR teams, service providers, and applicants. Our privacy role depends on the data:
| Data | Our role | What it means |
|---|---|---|
| Account, profile, billing, and usage telemetry | Controller | We decide why and how this data is processed. |
| Client matter / immigration case data, foreign-national PII, uploaded documents | Processor | Our law-firm or business customer is the controller. We process this data only on their documented instructions, under our agreement with them. |
| Google user data (sign-in profile, Gmail send) | Controller (limited) | We act as controller for the limited Google data we receive, bound by Google’s Limited Use requirements (see “Google user data”). |
If you are an applicant or employee whose data was entered by a law firm or employer, that organization is the controller of your case data. Requests about that data are routed to them (see “Your rights & choices”).
We may aggregate or de-identify information so that it no longer identifies you. We may use and share such aggregated data (for example, total usage trends) for lawful business purposes; it is not treated as personal information.
| Google scope | Purpose | Access level |
|---|---|---|
| Sign-in — `openid`, `email`, `profile` | Authenticate your account and display your identity (name, email, profile photo). | Read basic profile/email only. |
| `.../auth/gmail.send` | Send case-status updates and notification emails from your own Gmail mailbox, on your behalf. | Send only. We cannot read, search, modify, or delete any message in your mailbox. |
| `.../auth/calendar.events`, `.../auth/meetings.space.settings` | Create and manage Google Meet meetings and calendar events you schedule through GlobalCodio. | Create/manage events you initiate in the product. |
We do not access Gmail-scope data for any routine purpose. A human at GlobalCodio may access this data only: (a) with your explicit consent; (b) for security purposes or to investigate abuse; (c) to comply with applicable law; or (d) in an aggregated or de-identified form.
Where the GDPR / UK GDPR applies, we process personal data on one or more of the following legal bases:
For immigration case data we process as a processor, the legal basis is determined by the controlling firm or organization, and we act on their documented instructions under our agreement with them.
| Data | Retention |
|---|---|
| Account & profile data | Kept while your account is active, and afterward only as needed to meet legal, tax, and contractual obligations, resolve disputes, and enforce our agreements. |
| Client / immigration case data (processor data) | Per the customer’s instructions, subject to any legal hold; returned or deleted on termination of the customer’s agreement. |
| Logs & diagnostics | Retained for a limited period for security, reliability, and troubleshooting, then deleted or anonymized. |
| Google OAuth tokens | Revoked and deactivated on unlink/closure; deleted within 30 days (see “Google user data”). |
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a personal-data breach likely to present a risk to affected individuals, we will notify the relevant data-protection authorities without undue delay — and, where feasible under the GDPR, within 72 hours — and will notify affected individuals where required.
We are actively working toward recognized security certifications, including SOC 2 and ISO 27001. We do not currently claim to hold these certifications and will update this policy as any are formally achieved.
Depending on where you live, you may have rights over your personal data. Under the GDPR / UK GDPR, these include:
We do not charge for responding to a request and aim to respond within 30 days. We may decline or charge for requests that are manifestly unfounded or excessive, and will explain why if we do. You also have the right to lodge a complaint with your local data-protection supervisory authority.
If you are a California resident, the CCPA / CPRA gives you the right to know what personal information we collect, use, and disclose; to request access to and deletion of your personal information; to correct inaccurate information; and to not be discriminated against for exercising these rights.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. To exercise your California rights, contact us at info@globalcodio.ai. We will verify your request and respond within the timeframe required by law (generally 45 days).
GlobalCodio operates in the United States and India, and may process information in both. Where we transfer personal data across borders, we rely on appropriate safeguards, including the EU/UK Standard Contractual Clauses (SCCs) where applicable.
The application may link to or integrate with third-party services (for example, Google sign-in, Gmail send, and Google Meet). This policy does not cover the practices of those third parties, and we are not responsible for their privacy practices. Your use of a linked third-party service is governed by that party’s own terms and privacy policy.
GlobalCodio is a business platform and is not directed to children. Consistent with the U.S. Children’s Online Privacy Protection Act (COPPA) and the GDPR (which sets the age of consent at up to 16), we do not knowingly create accounts for or collect personal information directly from children. If you believe a child has provided us personal information through an account, contact us at info@globalcodio.ai and we will take appropriate steps.
Immigration cases may include information about minor beneficiaries (for example, dependents) provided by our customers as part of a case. Such data is processed as case data on the customer’s instructions (we act as a processor), not collected from the minor directly.
We may update this policy from time to time. We will revise the effective date above and, for material changes, provide notice through the application or by email.
For privacy questions or to exercise your rights, contact us at info@globalcodio.ai. We aim to respond within 30 days.
Medicodio Inc. (operator of GlobalCodio) Delaware (registered office): 16192 Coastal Hwy, Lewes, DE 19958, USA · California: 2603 Camino Ramon #200, San Ramon, CA 94583, USA · India (operations): B-Block, 8th Floor, Brigade Tech Park, 134/1, Whitefield, Bangalore – 560 066, India