01
Who is responsible
CODARIS is operated by Serhat Soruklu. The operator is responsible for deciding how and why personal information is used for this service. Write to [email protected] about privacy, data requests or a data-protection complaint. General account help is available at [email protected].
The operator’s legal status and the contact details appropriate for formal privacy requests are being confirmed for this release. The published email addresses must be monitored and able to receive those requests before this notice is relied on as final controller information.
02
Information we use
When account registration is available, the account service receives the information below directly from you. The public account service is not currently deployed; this describes the implemented account workflow for when it is enabled.
| Information | Source and use |
|---|---|
| Account and application | Your name, email address, country, selected role, joining statement and randomly generated membership ID. These are entered during registration; the statement is stored with the account and cannot be edited in account settings. |
| Profile details | Optional LinkedIn, GitHub and website URLs, and an optional profile image. URLs are stored as claims; CODARIS does not verify profile ownership. The browser sends a 100 × 100 pixel image representation rather than the selected original file. |
| Authentication | Your password is processed to create an Argon2id password hash. The database stores that hash, not the password. Session and one-time action tokens are random; the database stores token hashes for sessions and action links. |
| Membership credential | CODARIS creates a randomly assigned public membership number and a separate opaque verification identifier. Neither is your private sign-in membership ID. Your credential status and issue date are maintained with the account. New members see the public-field disclosure at registration; existing members must enable public verification themselves. |
| Learning progress | When you mark a topic as read while signed in, the topic and time are associated with your account so progress can be restored. |
| Account messages | Your email address receives verification, password recovery, email-change and password-change messages. The service records message recipient, type, timestamps and delivery attempts in its mail queue. |
| Contact form | If you use the contact form, we receive your name, email address, selected topic and message. The message is encrypted in the application’s PostgreSQL outbox while awaiting delivery. The form does not accept attachments. |
| Request and security data | The service uses request source information, endpoint names and, for some limits, the submitted email address or login identifier to limit repeated registration, sign-in and recovery attempts. Standard web-server logs can also record technical request details. The production log configuration and its retention are not yet confirmed. |
Please do not include sensitive personal information in the joining statement or profile links. Do not send us passwords, one-time links or other credentials by email.
03
Why we use information
- To handle an application and provide an account: create an account, identify it, save profile settings and learning progress, and provide membership features you request.
- To verify and protect account access: confirm access to the email address, authenticate sign-ins, support password recovery and respond to email or password changes.
- To protect and operate the service: rate-limit requests, investigate faults and prevent misuse.
- To show community totals: calculate the number of email-verified accounts and the number of distinct self-reported countries. The totals do not identify individual members.
- To answer contact messages: route your message to the fixed CODARIS support inbox and send a receipt to the email address you supplied.
Lawful bases
For registration, account administration, membership access, verification messages and saved progress, we use information because it is needed to take steps you request before membership and, once membership is active, to provide the account service under our terms. To respond to a message you send, we use your information to take steps at your request or, where appropriate, for our legitimate interest in handling enquiries. For request limits, fault investigation and service security, we rely on our legitimate interests in operating and protecting CODARIS. We also rely on our legitimate interests in publishing non-identifying community totals. We use these interests only where they are not overridden by your rights and interests. If we need information to meet a legal obligation, we will use it for that obligation.
04
Email verification and membership
Email verification confirms that you can use the supplied mailbox. It does not establish your identity, country, role or control of a LinkedIn, GitHub or other external profile.
In the implemented workflow, confirming the email address activates membership automatically. There is no staff application-review or approval feature. Changing the account email clears its verified state until the new address is confirmed. Password reset and email verification links are single-use; their expiry periods are listed below.
05
What other people can see
CODARIS does not provide a browsable public member directory. When public verification is enabled for your credential, anyone who has its unique verification link or scans its QR code can see your display name, role, public membership number, current membership status and issue date. New members explicitly accept this disclosure during registration; existing members must enable public verification in their dashboard. You can disable it at any time.
The credential is for verification only. Its opaque link identifier is not an account login, password or authorization token. It does not expose your email, country, joining statement, profile image, profile links, internal account identifiers or learning progress. If public verification is disabled, unavailable, or your membership is not active, the page returns a generic unavailable message.
Your name, email, role, joining statement, profile image, profile links and learning progress otherwise remain available only to you in your signed-in account; they are not included in public community totals.
The public community endpoint returns aggregate counts for verified accounts and distinct country values supplied by members. Country is self-reported; the totals do not verify where anyone lives. Information you choose to publish on an external website is governed by that website’s own rules.
06
Cookies and browser storage
The signed-in account service uses a first-party cookie named codaris_session. It carries an opaque session token, is marked HttpOnly and SameSite=Strict, and expires after 12 hours. Production is configured to mark it Secure. It is used to keep you signed in and is not an advertising cookie.
The site code contains no analytics or advertising scripts and does not use localStorage or sessionStorage for account data. The public site also links to external websites; opening one takes you under that site’s privacy and cookie practices.
07
Providers and international transfers
The account service is designed to use PostgreSQL for account data and an SMTP email provider for transactional account messages. The contact form routes submissions to the fixed inbox [email protected] and sends an acknowledgement to the address you supplied, using the configured CODARIS sender address. The release configuration names Google Workspace SMTP, but live production use of that service and mailbox, access to the inbox, and the hosting/database provider have not been verified. The message will also be present in the receiving email provider’s systems and inbox after delivery; their own retention and access controls apply.
We do not yet have verified information about the live providers’ locations, subprocessors or international transfer arrangements. We will identify relevant providers and explain applicable safeguards before relying on processing that transfers your information outside the UK.
08
How long information is kept
| Record | Period in the implementation |
|---|---|
| Account, profile, joining statement and learning progress | While the account remains in the database. There is no self-service deletion feature. How account data is deleted, retained for legal reasons or removed from backups has not been operationally confirmed. |
| Signed-in sessions | Expire after 12 hours. The mail worker removes expired session records when it runs. |
| Email verification links | Expire after 24 hours and can be used once. Expired action-token records are removed when the mail worker runs. |
| Password reset links | Expire after 30 minutes and can be used once. Expired action-token records are removed when the mail worker runs. |
| Account mail records | Removed 30 days after creation by the mail worker. The queue clears the encrypted one-time token after successful delivery. |
| Contact form messages | The message is encrypted in the outbox until both the admin notification and sender receipt are accepted for delivery, then the outbox record is deleted. If delivery keeps failing, the record is deleted after 30 days. The worker retries each message up to eight times. Copies in email systems and mailboxes follow those providers’ retention practices. |
| Request-limit records | Removed when their limit window is more than one day old, by the mail worker. |
| Web and system logs, backups | Retention and deletion behavior are not specified by the repository and must be confirmed by the operator. |
These periods describe the code. The production mail worker, deletion process, log rotation and backup retention must be installed and checked before they can be treated as live operational guarantees.
09
Your choices and rights
You can change your name, country, role, profile links and image in account settings. The original joining statement cannot currently be changed there. You can ask us to correct it or to close your account by emailing [email protected]; the account interface does not provide a deletion control.
Depending on the circumstances and legal basis, UK data-protection law may give you rights to access your information, have inaccurate information corrected, have information erased, restrict or object to some processing, and receive certain information in a portable form. You may also withdraw consent where processing is based on consent; the account processing described here is not based on consent. Some rights are conditional and exceptions can apply. We may ask for information needed to confirm your identity before responding.
You can object to processing based on our legitimate interests. Contact us using the privacy address above and explain what you object to.
10
Security, age, automation and complaints
The implementation uses password hashing, opaque session tokens, parameterized database queries, request limits and restricted session cookies. These measures reduce specific risks; no online service can promise absolute security. Production controls and operations must be checked separately from the source code.
The registration flow does not ask for age or enforce an age threshold. CODARIS’s age-eligibility position has not been set. The account code contains no AI processing or automated decisions about membership; verification activates membership automatically when you confirm mailbox access.
Raise a concern or complain
Email [email protected] and say that you are making a data-protection complaint. We will acknowledge it within 30 days, investigate it and explain the outcome. You can also complain to the UK Information Commissioner’s Office (ICO) using its data-protection complaints service.
11
Changes and contact
We will update this notice when our data use or service changes. If a change is material, we will bring it to your attention before using your information for a new purpose.
Read the Membership terms or visit Contact CODARIS.
CODARIS / PRIVACY NOTICE / 26 SEP 2026