Skip to main content
GlobalCodio - AI Workforce for Global Immigration
Home
Security
Contact
Free Tech AuditSign in
Legal · Platform

Platform Privacy Policy.

Effective June 30, 2026 · Version 1.0. How the GlobalCodio application collects, uses, shares, and protects information — including data processed on behalf of our law-firm customers.

Contents
1. Overview & scope2. Information we collect3. Google user data4. How we use information5. Legal bases for processing6. How we share information7. Data retention8. Deleting your data and closing your account9. Your data-sharing choices10. Security11. Your rights & choices12. California privacy rights13. International data transfers14. Cookies & analytics15. Third-party links & services16. Children's privacy17. Changes to this policy18. Contact & DPO

This document governs the GlobalCodio application.

It applies to your account, immigration case data, documents, and integrations — not to the public marketing website, which has its own Website Privacy Policy. This page reproduces the Platform Privacy Policy in full from its canonical source at app.globalcodio.ai/privacy.

Overview & scope

This Privacy Policy explains how Medicodio Inc., the operator of the GlobalCodio platform ("GlobalCodio", "we", "us", or "our"), handles information within the GlobalCodio application — the authenticated product at app.globalcodio.ai and its associated portals. Medicodio Inc. is a Delaware corporation.

This policy is separate from the privacy policy that governs our public marketing website (www.globalcodio.ai). The marketing-site policy covers visitors, contact forms, and website analytics only. This policy governs accounts, immigration case data, documents, and integrations within the product. Where the two differ, this policy controls for the application.

Our roles: controller and processor

GlobalCodio serves law firms, corporate HR teams, service providers, and applicants. Our privacy role depends on the data:

DataOur roleWhat it means
Account, profile, billing, and usage telemetryControllerWe decide why and how this data is processed.
Client matter / immigration case data, foreign-national PII, uploaded documentsProcessorOur law-firm or business customer is the controller. We process this data only on their documented instructions, under our agreement with them.
Google user data (sign-in profile, Gmail send)Controller (limited)We act as controller for the limited Google data we receive, bound by Google’s Limited Use requirements (see “Google user data”).

If you are an applicant or employee whose data was entered by a law firm or employer, that organization is the controller of your case data. Requests about that data are routed to them (see “Your rights & choices”).

Information we collect

Account & profile information

  • Name, work email, phone number, role, and the firm/organization you belong to.
  • Authentication data — password hashes, multi-factor authentication (MFA) settings, and single sign-on (SSO) identifiers.

Client & immigration case data (processed as a processor)

  • Immigration case details, beneficiary and petitioner information, and foreign-national personal data.
  • Uploaded documents (e.g. passports, identity documents, supporting evidence, forms, and letters).
  • Communications, notes, questionnaires, and case-status history.
Case data is entered by our customers (law firms / employers) and processed on their instructions. We do not decide what case data is collected.

Integration data

  • Google account data when you connect Google sign-in or Gmail send (see “Google user data”).
  • Calendar and meeting data when you connect Google Meet scheduling.

Usage, device & log data

  • Product usage and feature telemetry used to operate, secure, and improve the service.
  • Information collected automatically, such as IP address, browser type, operating system, device identifiers, referring pages, and date/time stamps, gathered via cookies and similar technologies.
  • Diagnostic and error logs (including crash and performance data captured for reliability monitoring).
  • Essential cookies for authentication, session, and security (see “Cookies & analytics”).

Sensitive information

Because GlobalCodio supports immigration case work, the case data our customers submit can include the following categories of sensitive information:

  • Health & medical information — for example, Form I-693 civil-surgeon results and vaccination records attached to a case.
  • Biometric-adjacent data — appointment records and identity photos submitted as supporting evidence.
  • Criminal history — police clearance certificates and background-check results submitted as part of a case.
  • National origin & immigration/citizenship status — the core subject matter of an immigration case.
  • Family relationships — information about spouses, dependents, and other relatives named in a case.
  • Financial & billing information — invoicing and payment details for firm and organization accounts.
  • Coarse IP-based location — inferred from request metadata for security and fraud prevention.

This information is submitted by our law-firm and business customers as case data. We process it as a processor, on their documented instructions — see “Our roles: controller and processor” above.

Aggregated & de-identified data

We may aggregate or de-identify information so that it no longer identifies you. We use aggregated data only for internal purposes — operating, securing, and improving the platform, and understanding product usage trends — and only in a form that is not treated as personal information.

Google user data

This section describes how GlobalCodio uses data obtained through Google APIs, and our compliance with the Google API Services User Data Policy.

Scopes we request and why

Google scopePurposeAccess level
Sign-in — `openid`, `email`, `profile`Authenticate your account and display your identity (name, email, profile photo).Read basic profile/email only.
`.../auth/gmail.send`Send case-status updates and notification emails from your own Gmail mailbox, on your behalf.Send only. We cannot read, search, modify, or delete any message in your mailbox.
`.../auth/calendar.events`, `.../auth/meetings.space.settings`Create and manage Google Meet meetings and calendar events you schedule through GlobalCodio.Create/manage events you initiate in the product.

Limited Use

GlobalCodio’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What we never do with Google user data

  • We never use Google user data to train or improve any AI/ML models — ours or any third party’s.
  • We never use Google user data for advertising or remarketing.
  • We never sell Google user data.
  • We do not transfer Google user data except as needed to provide or improve the user-facing feature you enabled, or to comply with applicable law. A transfer as part of a merger or acquisition is possible, with notice, as described in “How we share.”

Token storage & retention

  • Google access and refresh tokens are encrypted at rest using AES-256-GCM and transmitted only over TLS 1.2+.
  • When you unlink your Google account or close your account, we revoke the tokens with Google immediately and delete them from our systems within 30 days.
  • We do not retain the contents of emails sent through the `gmail.send` integration beyond standard delivery logs (metadata such as recipient, timestamp, and delivery status) needed to operate and audit the service.

Human access

We do not access Gmail-scope data for any routine purpose. A human at GlobalCodio may access this data only in an aggregated or de-identified form, or in one of these specific cases:

  • With your explicit consent.
  • For security purposes or to investigate abuse.
  • To comply with applicable law.

How we use information

  • To provide, operate, secure, and maintain the GlobalCodio platform and its portals.
  • To process immigration cases on the documented instructions of our customer (the controlling firm or organization).
  • To authenticate users, enforce access controls, and protect against fraud and abuse.
  • To provide customer support and respond to your requests.
  • To monitor reliability and diagnose errors (using diagnostic/crash logs).
  • To comply with legal obligations and enforce our agreements.
We do not use client or immigration case data, document contents, or Google user data to train or improve AI/ML models.

Legal bases for processing

Where the GDPR / UK GDPR applies, we process personal data on one or more of the following legal bases:

  • Contract — to provide the service you or your organization have signed up for and to administer your account.
  • Legitimate interests — to operate, secure, and improve the platform, prevent fraud and abuse, and communicate with you, where these interests are not overridden by your rights.
  • Legal obligation — to comply with applicable laws, regulations, and lawful requests.
  • Consent — where we ask for it (for example, before enabling an optional integration); you may withdraw consent at any time.

For immigration case data we process as a processor, the legal basis is determined by the controlling firm or organization, and we act on their documented instructions under our agreement with them.

How we share information

We share information only as described below. We do not sell personal information.

Subprocessors

The vendors below help us run the platform, under contracts that require them to process data only on our instructions:

EntityWhat they processPurposeLocation
Microsoft AzureAccount, case, and document data (hosting & storage)Cloud infrastructure, database, and file storageUnited States
GoogleSign-in profile, and Gmail/Calendar data you connectSign-in, Gmail send, and Google Meet scheduling integrationsUnited States
Google Gemini (paid API tier)Document and case content submitted for AI processingAI-assisted document extraction and case workflowsUnited States
AnthropicProduct usage content submitted for AI processingAI-assisted product featuresUnited States
SentryDiagnostic and crash/error data (no document or case content)Error monitoring and reliabilityUnited States
ResendRecipient, subject, and delivery metadata for outbound emailTransactional email deliveryUnited States
Service ProvidersCase information the firm shares directly with a medical-exam or background-check providerFulfilling firm-directed case steps (e.g. medical exams, background checks)Varies by provider

Third parties are bound to the terms and conditions of this Privacy Policy and are prohibited from using or disclosing your information — including de-identified, anonymized, or pseudonymized information — for any purpose without your active consent.

This commitment does not yet extend to Service Providers — for example, medical-exam or background-check vendors a firm assigns to a case. We limit what a Service Provider can see to the specific documents and data scoped to their assignment. We are working to bring Service Providers under a data-processing agreement directly with GlobalCodio; until then, this policy’s binding commitment applies to every other party in the table above.
  • Legal requirements — when required by law, regulation, legal process, or to protect rights, safety, and security.
  • Business transfers — in connection with a merger, acquisition, or sale of assets. Any acquirer will be bound by data-protection commitments materially equivalent to this policy, and we will provide notice as required by law.

Data retention

DataRetention
Account & profile data365 days after account closure or a deletion request, then permanently deleted.
Client / immigration case data (processor data)365 days by default, subject to any legal hold; returned or deleted per the customer’s instructions on termination of the customer’s agreement.
Logs & diagnostics365 days, then deleted or anonymized.
Google OAuth tokensRevoked and deleted from our systems within 30 days of unlink or account closure (see “Google user data”).
Dormant / inactive accountsNot deleted or anonymized for inactivity alone — an account is retained until you close it or request deletion.
Deletion request SLAUp to 365 days from your request to permanent deletion.
The 365-day figure is enforced in our systems today for case-adjacent records (cases, persons, organizations, and service providers) through an automated purge process. Account-level deletion (the `users` login record) is currently a policy commitment we honor manually; an automated enforcement path is tracked as follow-up engineering work.

Deleting your data and closing your account

You can close your account or request deletion of your account data at any time. This is currently an email-driven process — we do not yet offer a self-serve “Delete my account” control in the product.

  1. Email info@globalcodio.ai from your registered account email and state that you want to close your account or delete your data.
  2. We verify the request and confirm receipt.
  3. We process the request within 365 days, per the retention table above.
Closing your account deletes the data we control directly — your account and profile. Client and immigration case data is different: it belongs to the law firm or organization that submitted it, and we act only as their processor. A request to delete case data is routed to that organization; we cannot delete it unilaterally on your instruction alone.

You can also request an export of the account data we control by emailing the same address.

Your data-sharing choices

If you are an applicant or beneficiary whose case is managed through GlobalCodio, you can choose how much of your case history is visible to people the controlling firm gives access to.

For example, this controls what a corporate HR contact or a co-applicant can see about your case.

This choice is set in-product and can be changed at any time.

LevelWhat it shares
Full historyYour complete case history and status updates.
Current status onlyYour case’s current status, without historical detail.
DeclinedNo case information is shared beyond what the firm itself already has direct access to as case controller.
A single case file can carry information about more than one person — for example, a spouse or dependent named on a family-based petition. Because of this, one person’s sharing choice can affect what information reaches a third party about people who never used GlobalCodio themselves and did not make that choice.

This setting controls sharing with people the firm designates as having limited access. It does not limit the controlling firm’s own access to the case data it submitted — the firm is the controller of that data.

Security

  • Encryption in transit (TLS 1.2+) and at rest; OAuth tokens encrypted with AES-256-GCM.
  • Role-based access control (RBAC), multi-tenant isolation, and least-privilege access.
  • Multi-factor authentication (MFA) support and audit logging of sensitive actions.
  • Continuous monitoring and a documented incident-response process.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a personal-data breach likely to present a risk to affected individuals, we will notify the relevant data-protection authorities without undue delay. Where feasible under the GDPR, we will do so within 72 hours, and will notify affected individuals where required.

If we notify you of a breach

A breach notice we send you will describe what happened, what categories of information were involved, and the steps we are taking in response. We will send it to the email address on file for your account, or route it through the controlling firm or organization where we act as processor for the affected data.

  • Change your account password and enable multi-factor authentication if you have not already.
  • Review your recent account activity for anything you do not recognize.
  • If the notice concerns case data, contact the law firm or organization that controls your case — they can advise on any case-specific steps.
  • Contact us at info@globalcodio.ai with any questions about the notice.

We are actively working toward recognized security certifications, including SOC 2 and ISO 27001. We do not currently claim to hold these certifications and will update this policy as any are formally achieved.

Your rights & choices

Depending on where you live, you may have rights over your personal data. Under the GDPR / UK GDPR, these include:

  • The right to be informed about how we store, use, and share your data.
  • The right to access your data.
  • The right to rectify (correct) your data.
  • The right to erase your data.
  • The right to restrict or object to our processing of your data.
  • The right to data portability — to receive your data in a commonly used, machine-readable format.
  • The right not to be subject to solely automated decision-making that produces legal or similarly significant effects.

We do not charge for responding to a request and aim to respond within 30 days. We may decline or charge for requests that are manifestly unfounded or excessive, and will explain why if we do. You also have the right to lodge a complaint with your local data-protection supervisory authority.

How to exercise your rights

  • For data we control (account, profile, billing), contact us at info@globalcodio.ai.
  • For immigration case data, the controlling firm or organization is responsible. We will route your request to them, or assist them in responding, as a processor.
  • You can unlink your Google account at any time from your in-app integration settings, which revokes our access and our stored tokens.
  • You can request export or deletion of your account data; account deletion purges or returns controller data within 365 days (see “Deleting your data and closing your account”).

California privacy rights

If you are a California resident, the CCPA / CPRA gives you rights over your personal information:

  • The right to know what we collect, use, and disclose.
  • The right to request access to and deletion of your personal information.
  • The right to correct inaccurate information.
  • The right not to be discriminated against for exercising these rights.

Notice at collection

The table below is our Notice at Collection: the categories of personal information we collect, why, and how long we keep them. See “Information we collect” and “Data retention” above for the full detail behind each row.

CCPA categoryExamples we collectPurposeRetention
IdentifiersName, email, phone numberAccount creation & authentication365 days post-closure
Customer recordsBilling and payment detailsInvoicing your firm/organization365 days post-closure
Protected classificationsNational origin, immigration status (case data only)Immigration case processing, as a processorPer the retention table
Commercial informationProduct usage and feature telemetryOperating and improving the platform365 days
Internet/network activityIP address, device, and log dataSecurity, reliability, troubleshooting365 days
Professional/employment infoRole, firm/organization affiliationAccess control and account administrationWhile account is active
Sensitive personal informationHealth, criminal history, precise case details (case data only)Immigration case processing, as a processorPer the retention table

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

Exercising your rights

To exercise your California rights, contact us at info@globalcodio.ai, or by mail at 2603 Camino Ramon #200, San Ramon, CA 94583, USA. You may also designate an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your authorization, and may still require you to directly verify your own identity. We will verify your request and respond within the timeframe required by law (generally 45 days).

International data transfers

GlobalCodio operates in the United States and India, and may process information in both. Where we transfer personal data across borders, we rely on appropriate safeguards, including the EU/UK Standard Contractual Clauses (SCCs) where applicable.

Cookies & analytics

The application uses only essential cookies required to operate — for authentication, session management, and security. These are exempt from consent because the service cannot function without them. We use both session cookies (which expire when you close your browser) and short-lived persistent cookies needed to keep you signed in.

We use Sentry, an error-monitoring tool, to capture diagnostic and crash data so we can keep the service reliable. The application does not use advertising, marketing, or behavioral-tracking cookies, and does not load non-essential analytics.

Because there is no non-essential tracking, we do not display a cookie-consent banner in the application. If we introduce non-essential analytics in the future, we will add consent controls (default-denied, opt-in) before doing so.

Do Not Track

Because the application does not perform cross-site tracking, it does not respond differently to browser "Do Not Track" signals. If that changes, we will describe our response here.

Third-party links & services

The application may link to or integrate with third-party services (for example, Google sign-in, Gmail send, and Google Meet). This policy does not cover the practices of those third parties, and we are not responsible for their privacy practices. Your use of a linked third-party service is governed by that party’s own terms and privacy policy.

Children's privacy

GlobalCodio is a business platform and is not directed to children. The GDPR sets the age of consent at up to 16, and the U.S. Children’s Online Privacy Protection Act (COPPA) sets its own protections for children under 13. We do not knowingly create accounts for or collect personal information directly from children. If you believe a child has provided us personal information through an account, contact us at info@globalcodio.ai and we will take appropriate steps.

Immigration cases may include information about minor beneficiaries (for example, dependents) provided by our customers as part of a case. Such data is processed as case data on the customer’s instructions (we act as a processor), not collected from the minor directly.

Changes to this policy

We may update this policy from time to time. Every update revises the effective date and version number shown above, so you can always tell whether you are looking at the current version.

For a material change, we will email you a plain-language summary of what changed and ask you to acknowledge it before you continue using the application. Non-material changes (clarifications, formatting) take effect on posting, without a separate notice.

Contact & DPO

For privacy questions or to exercise your rights, contact us at info@globalcodio.ai. We aim to respond within 30 days.

Medicodio Inc. (operator of GlobalCodio) Delaware (registered office): 16192 Coastal Hwy, Lewes, DE 19958, USA · California: 2603 Camino Ramon #200, San Ramon, CA 94583, USA · India (operations): B-Block, 8th Floor, Brigade Tech Park, 134/1, Whitefield, Bangalore – 560 066, India

Published by Medicodio Inc., operator of the GlobalCodio platform. This page is served from www.globalcodio.ai and reproduces the document maintained at app.globalcodio.ai/privacy, which is the controlling version if the two ever differ.

GlobalCodio - AI Workforce for Global Immigration

AI Workforce for Global Immigration. Deployed and Managed.

www.globalcodio.aiinfo@globalcodio.ai

GlobalCodio is a product of Medicodio Inc., a Delaware corporation.

Products
  • CodioCMS
  • CodioForms
  • Codio AI Agents
  • CodioNetwork
Services
  • CodioOps
  • HRMS Integration
  • RFP Response Service
  • Customer Support
  • Migration & Onboarding
  • IT Support Services
  • Managed Operations
Solutions
  • For Immigration Law Firms
  • For Corporate Teams
  • Security & Compliance
Company
  • About
  • Letter from the Founder
  • Blog
  • Events
  • Contact Us
  • Book Free Tech Audit
Legal
  • Platform Privacy Policy
  • Platform Terms of Service
  • Website Privacy Policy
  • Website Terms of Use
Connect
  • info@globalcodio.ai
  • LinkedIn
© 2026 GlobalCodio, a product of Medicodio Inc. All rights reserved.·Privacy Policy·Terms of Use·Platform Privacy Policy·Platform Terms··California, USA · Bangalore, India
Win Cases. We’ll Handle All the Technology.
GlobalCodio.ai