This document governs the GlobalCodio application.
It applies to your account, immigration case data, documents, and integrations — not to the public marketing website, which has its own Website Privacy Policy. This page reproduces the Platform Privacy Policy in full from its canonical source at app.globalcodio.ai/privacy.
Overview & scope
This Privacy Policy explains how Medicodio Inc., the operator of the GlobalCodio platform ("GlobalCodio", "we", "us", or "our"), handles information within the GlobalCodio application — the authenticated product at app.globalcodio.ai and its associated portals. Medicodio Inc. is a Delaware corporation.
This policy is separate from the privacy policy that governs our public marketing website (www.globalcodio.ai). The marketing-site policy covers visitors, contact forms, and website analytics only. This policy governs accounts, immigration case data, documents, and integrations within the product. Where the two differ, this policy controls for the application.
Our roles: controller and processor
GlobalCodio serves law firms, corporate HR teams, service providers, and applicants. Our privacy role depends on the data:
| Data | Our role | What it means |
|---|---|---|
| Account, profile, billing, and usage telemetry | Controller | We decide why and how this data is processed. |
| Client matter / immigration case data, foreign-national PII, uploaded documents | Processor | Our law-firm or business customer is the controller. We process this data only on their documented instructions, under our agreement with them. |
| Google user data (sign-in profile, Gmail send) | Controller (limited) | We act as controller for the limited Google data we receive, bound by Google’s Limited Use requirements (see “Google user data”). |
If you are an applicant or employee whose data was entered by a law firm or employer, that organization is the controller of your case data. Requests about that data are routed to them (see “Your rights & choices”).
Information we collect
Account & profile information
- Name, work email, phone number, role, and the firm/organization you belong to.
- Authentication data — password hashes, multi-factor authentication (MFA) settings, and single sign-on (SSO) identifiers.
Client & immigration case data (processed as a processor)
- Immigration case details, beneficiary and petitioner information, and foreign-national personal data.
- Uploaded documents (e.g. passports, identity documents, supporting evidence, forms, and letters).
- Communications, notes, questionnaires, and case-status history.
Integration data
- Google account data when you connect Google sign-in or Gmail send (see “Google user data”).
- Calendar and meeting data when you connect Google Meet scheduling.
Usage, device & log data
- Product usage and feature telemetry used to operate, secure, and improve the service.
- Information collected automatically, such as IP address, browser type, operating system, device identifiers, referring pages, and date/time stamps, gathered via cookies and similar technologies.
- Diagnostic and error logs (including crash and performance data captured for reliability monitoring).
- Essential cookies for authentication, session, and security (see “Cookies & analytics”).
Sensitive information
Because GlobalCodio supports immigration case work, the case data our customers submit can include the following categories of sensitive information:
- Health & medical information — for example, Form I-693 civil-surgeon results and vaccination records attached to a case.
- Biometric-adjacent data — appointment records and identity photos submitted as supporting evidence.
- Criminal history — police clearance certificates and background-check results submitted as part of a case.
- National origin & immigration/citizenship status — the core subject matter of an immigration case.
- Family relationships — information about spouses, dependents, and other relatives named in a case.
- Financial & billing information — invoicing and payment details for firm and organization accounts.
- Coarse IP-based location — inferred from request metadata for security and fraud prevention.
This information is submitted by our law-firm and business customers as case data. We process it as a processor, on their documented instructions — see “Our roles: controller and processor” above.
Aggregated & de-identified data
We may aggregate or de-identify information so that it no longer identifies you. We use aggregated data only for internal purposes — operating, securing, and improving the platform, and understanding product usage trends — and only in a form that is not treated as personal information.
Google user data
Scopes we request and why
| Google scope | Purpose | Access level |
|---|---|---|
| Sign-in — `openid`, `email`, `profile` | Authenticate your account and display your identity (name, email, profile photo). | Read basic profile/email only. |
| `.../auth/gmail.send` | Send case-status updates and notification emails from your own Gmail mailbox, on your behalf. | Send only. We cannot read, search, modify, or delete any message in your mailbox. |
| `.../auth/calendar.events`, `.../auth/meetings.space.settings` | Create and manage Google Meet meetings and calendar events you schedule through GlobalCodio. | Create/manage events you initiate in the product. |
Limited Use
What we never do with Google user data
- We never use Google user data to train or improve any AI/ML models — ours or any third party’s.
- We never use Google user data for advertising or remarketing.
- We never sell Google user data.
- We do not transfer Google user data except as needed to provide or improve the user-facing feature you enabled, or to comply with applicable law. A transfer as part of a merger or acquisition is possible, with notice, as described in “How we share.”
Token storage & retention
- Google access and refresh tokens are encrypted at rest using AES-256-GCM and transmitted only over TLS 1.2+.
- When you unlink your Google account or close your account, we revoke the tokens with Google immediately and delete them from our systems within 30 days.
- We do not retain the contents of emails sent through the `gmail.send` integration beyond standard delivery logs (metadata such as recipient, timestamp, and delivery status) needed to operate and audit the service.
Human access
We do not access Gmail-scope data for any routine purpose. A human at GlobalCodio may access this data only in an aggregated or de-identified form, or in one of these specific cases:
- With your explicit consent.
- For security purposes or to investigate abuse.
- To comply with applicable law.
How we use information
- To provide, operate, secure, and maintain the GlobalCodio platform and its portals.
- To process immigration cases on the documented instructions of our customer (the controlling firm or organization).
- To authenticate users, enforce access controls, and protect against fraud and abuse.
- To provide customer support and respond to your requests.
- To monitor reliability and diagnose errors (using diagnostic/crash logs).
- To comply with legal obligations and enforce our agreements.
Legal bases for processing
Where the GDPR / UK GDPR applies, we process personal data on one or more of the following legal bases:
- Contract — to provide the service you or your organization have signed up for and to administer your account.
- Legitimate interests — to operate, secure, and improve the platform, prevent fraud and abuse, and communicate with you, where these interests are not overridden by your rights.
- Legal obligation — to comply with applicable laws, regulations, and lawful requests.
- Consent — where we ask for it (for example, before enabling an optional integration); you may withdraw consent at any time.
For immigration case data we process as a processor, the legal basis is determined by the controlling firm or organization, and we act on their documented instructions under our agreement with them.
Data retention
| Data | Retention |
|---|---|
| Account & profile data | 365 days after account closure or a deletion request, then permanently deleted. |
| Client / immigration case data (processor data) | 365 days by default, subject to any legal hold; returned or deleted per the customer’s instructions on termination of the customer’s agreement. |
| Logs & diagnostics | 365 days, then deleted or anonymized. |
| Google OAuth tokens | Revoked and deleted from our systems within 30 days of unlink or account closure (see “Google user data”). |
| Dormant / inactive accounts | Not deleted or anonymized for inactivity alone — an account is retained until you close it or request deletion. |
| Deletion request SLA | Up to 365 days from your request to permanent deletion. |
Deleting your data and closing your account
You can close your account or request deletion of your account data at any time. This is currently an email-driven process — we do not yet offer a self-serve “Delete my account” control in the product.
- Email info@globalcodio.ai from your registered account email and state that you want to close your account or delete your data.
- We verify the request and confirm receipt.
- We process the request within 365 days, per the retention table above.
You can also request an export of the account data we control by emailing the same address.
Your data-sharing choices
If you are an applicant or beneficiary whose case is managed through GlobalCodio, you can choose how much of your case history is visible to people the controlling firm gives access to.
For example, this controls what a corporate HR contact or a co-applicant can see about your case.
This choice is set in-product and can be changed at any time.
| Level | What it shares |
|---|---|
| Full history | Your complete case history and status updates. |
| Current status only | Your case’s current status, without historical detail. |
| Declined | No case information is shared beyond what the firm itself already has direct access to as case controller. |
This setting controls sharing with people the firm designates as having limited access. It does not limit the controlling firm’s own access to the case data it submitted — the firm is the controller of that data.
Security
- Encryption in transit (TLS 1.2+) and at rest; OAuth tokens encrypted with AES-256-GCM.
- Role-based access control (RBAC), multi-tenant isolation, and least-privilege access.
- Multi-factor authentication (MFA) support and audit logging of sensitive actions.
- Continuous monitoring and a documented incident-response process.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a personal-data breach likely to present a risk to affected individuals, we will notify the relevant data-protection authorities without undue delay. Where feasible under the GDPR, we will do so within 72 hours, and will notify affected individuals where required.
If we notify you of a breach
A breach notice we send you will describe what happened, what categories of information were involved, and the steps we are taking in response. We will send it to the email address on file for your account, or route it through the controlling firm or organization where we act as processor for the affected data.
- Change your account password and enable multi-factor authentication if you have not already.
- Review your recent account activity for anything you do not recognize.
- If the notice concerns case data, contact the law firm or organization that controls your case — they can advise on any case-specific steps.
- Contact us at info@globalcodio.ai with any questions about the notice.
We are actively working toward recognized security certifications, including SOC 2 and ISO 27001. We do not currently claim to hold these certifications and will update this policy as any are formally achieved.
Your rights & choices
Depending on where you live, you may have rights over your personal data. Under the GDPR / UK GDPR, these include:
- The right to be informed about how we store, use, and share your data.
- The right to access your data.
- The right to rectify (correct) your data.
- The right to erase your data.
- The right to restrict or object to our processing of your data.
- The right to data portability — to receive your data in a commonly used, machine-readable format.
- The right not to be subject to solely automated decision-making that produces legal or similarly significant effects.
We do not charge for responding to a request and aim to respond within 30 days. We may decline or charge for requests that are manifestly unfounded or excessive, and will explain why if we do. You also have the right to lodge a complaint with your local data-protection supervisory authority.
How to exercise your rights
- For data we control (account, profile, billing), contact us at info@globalcodio.ai.
- For immigration case data, the controlling firm or organization is responsible. We will route your request to them, or assist them in responding, as a processor.
- You can unlink your Google account at any time from your in-app integration settings, which revokes our access and our stored tokens.
- You can request export or deletion of your account data; account deletion purges or returns controller data within 365 days (see “Deleting your data and closing your account”).
California privacy rights
If you are a California resident, the CCPA / CPRA gives you rights over your personal information:
- The right to know what we collect, use, and disclose.
- The right to request access to and deletion of your personal information.
- The right to correct inaccurate information.
- The right not to be discriminated against for exercising these rights.
Notice at collection
The table below is our Notice at Collection: the categories of personal information we collect, why, and how long we keep them. See “Information we collect” and “Data retention” above for the full detail behind each row.
| CCPA category | Examples we collect | Purpose | Retention |
|---|---|---|---|
| Identifiers | Name, email, phone number | Account creation & authentication | 365 days post-closure |
| Customer records | Billing and payment details | Invoicing your firm/organization | 365 days post-closure |
| Protected classifications | National origin, immigration status (case data only) | Immigration case processing, as a processor | Per the retention table |
| Commercial information | Product usage and feature telemetry | Operating and improving the platform | 365 days |
| Internet/network activity | IP address, device, and log data | Security, reliability, troubleshooting | 365 days |
| Professional/employment info | Role, firm/organization affiliation | Access control and account administration | While account is active |
| Sensitive personal information | Health, criminal history, precise case details (case data only) | Immigration case processing, as a processor | Per the retention table |
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
Exercising your rights
To exercise your California rights, contact us at info@globalcodio.ai, or by mail at 2603 Camino Ramon #200, San Ramon, CA 94583, USA. You may also designate an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your authorization, and may still require you to directly verify your own identity. We will verify your request and respond within the timeframe required by law (generally 45 days).
International data transfers
GlobalCodio operates in the United States and India, and may process information in both. Where we transfer personal data across borders, we rely on appropriate safeguards, including the EU/UK Standard Contractual Clauses (SCCs) where applicable.
Third-party links & services
The application may link to or integrate with third-party services (for example, Google sign-in, Gmail send, and Google Meet). This policy does not cover the practices of those third parties, and we are not responsible for their privacy practices. Your use of a linked third-party service is governed by that party’s own terms and privacy policy.
Children's privacy
GlobalCodio is a business platform and is not directed to children. The GDPR sets the age of consent at up to 16, and the U.S. Children’s Online Privacy Protection Act (COPPA) sets its own protections for children under 13. We do not knowingly create accounts for or collect personal information directly from children. If you believe a child has provided us personal information through an account, contact us at info@globalcodio.ai and we will take appropriate steps.
Immigration cases may include information about minor beneficiaries (for example, dependents) provided by our customers as part of a case. Such data is processed as case data on the customer’s instructions (we act as a processor), not collected from the minor directly.
Changes to this policy
We may update this policy from time to time. Every update revises the effective date and version number shown above, so you can always tell whether you are looking at the current version.
For a material change, we will email you a plain-language summary of what changed and ask you to acknowledge it before you continue using the application. Non-material changes (clarifications, formatting) take effect on posting, without a separate notice.
Contact & DPO
For privacy questions or to exercise your rights, contact us at info@globalcodio.ai. We aim to respond within 30 days.
Medicodio Inc. (operator of GlobalCodio) Delaware (registered office): 16192 Coastal Hwy, Lewes, DE 19958, USA · California: 2603 Camino Ramon #200, San Ramon, CA 94583, USA · India (operations): B-Block, 8th Floor, Brigade Tech Park, 134/1, Whitefield, Bangalore – 560 066, India
Published by Medicodio Inc., operator of the GlobalCodio platform. This page is served from www.globalcodio.ai and reproduces the document maintained at app.globalcodio.ai/privacy, which is the controlling version if the two ever differ.