Document Record
Privacy Policy
- Legal identity
- Codicis Moneta, LLC, doing business as Kodelamp
- Primary jurisdiction
- Tennessee, United States
- Version
- 2026-07-21
1. Introduction and Scope
This Privacy Policy explains how Codicis Moneta, LLC, doing business as Kodelamp ("Kodelamp", "we", "us", and "our") handles information in connection with the public website, written project intake, quote requests, client portal, administration portal, billing, payments, hosting and domain workflows, support, files, and related business-system services.
This policy describes the current Kodelamp website, portal, payment, hosting, support, and provider-supported workflows. Some live options depend on configured service providers and written agreements.
2. Who Operates the Website
Kodelamp is the public-facing trade name of Codicis Moneta, LLC. The primary jurisdiction identified for this implementation is Tennessee, United States.
3. Information Provided Directly by Users
Users may provide names, email addresses, company names, industry information, project descriptions, budget ranges, timelines, contact preferences, reference links, support messages, uploaded files, payment workflow choices, hosting or domain request details, and similar information.
Public project and quote forms require consent acknowledgement and are protected by CSRF tokens and rate limiting.
4. Account and Profile Information
The client and administration portals store user names, email addresses, password hashes, roles, organization links, session records, and account-related timestamps.
The application does not migrate legacy WordPress users into the new portal.
5. Project Enquiries and Quote Requests
Start-a-project and quote-request submissions create form submission and lead records with a KDL reference number. Attached files are stored on the local private disk with metadata such as original filename, path, size, and MIME type.
6. Communications and Support Records
Support tickets, ticket messages, internal notes, lead notes, project updates, and notification-log records may be stored so work can be handled in writing and reviewed later.
7. Transaction and Invoice Information
Quotes, quote versions, orders, invoices, invoice items, payments, receipts, refunds, and reconciliation records may include organization references, amounts, currencies, statuses, provider references, event identifiers, and non-sensitive metadata.
8. Hosting and Domain-Order Information
Hosting and domain workflows may store requested domain names, domain action choices, terms, auto-renew preferences, hosting plans, provider status, provider correlation IDs, local order and invoice references, and redacted provider logs.
9. Uploaded Files and Documents
The application supports lead attachments, portal private files, admin-managed files, and bank-transfer proof uploads. File validation checks extension, MIME type, and size. Private client files and bank proof files are stored outside the public web root by default.
10. Bank-Transfer Proof Submissions
For manual bank transfer workflows, users may upload proof files and submit notes. Administrators can approve or reject proofs and record review notes. Approval may update the related payment and invoice status and issue a receipt.
11. Information Collected Automatically
The application and web server may process IP address, user agent, request URL, timestamps, session identifiers, CSRF tokens, authentication state, rate-limit activity, error logs, payment webhook payload metadata, and provider event metadata.
The privacy request form stores IP address and user agent to support abuse prevention, auditability, and request handling.
13. Session and Security Cookies
Session records may include user ID, IP address, user agent, encrypted or encoded session payloads, and last activity timestamps, depending on the configured session storage.
14. Analytics
No dedicated analytics or advertising tracking integration is enabled by default. If analytics are enabled later, this policy and any cookie controls should be updated before use.
15. Live-Chat Data
Live chat is not active by default. Support is handled through public support content and authenticated portal tickets unless a live-chat provider is configured.
16. How Information Is Used
Kodelamp uses information to respond to enquiries, prepare quotes, administer accounts, provide portal access, create and manage orders and invoices, process payment workflows, review bank-transfer proofs, deliver projects, support hosting/domain workflows, manage support tickets, secure the application, troubleshoot errors, maintain audit records, and improve services.
17. Legal and Operational Reasons for Processing
Depending on context and applicable law, processing may be based on contract performance, steps requested before entering a contract, legitimate operational interests, compliance with legal, tax, accounting, security, fraud-prevention, and dispute-resolution obligations, or consent where consent is specifically requested.
This policy does not rely on blanket consent for every activity.
18. How Information Is Disclosed
Information may be disclosed to service providers and processors that help operate hosting, domain, payment, email, infrastructure, security, support, storage, accounting, legal, and related services; to administrators and authorized staff; to counterparties involved in a transaction; or when required for legal, safety, fraud-prevention, enforcement, or business-transfer reasons.
19. Payment Providers
PayPal and WiPay International workflows may be used when configured. In non-live environments, payment workflows may use test behavior. When live payment providers are used, payment details may be collected directly by the provider according to that provider's own policies and checkout flow.
20. Hosting and Domain Providers
ResellersPanel and related provider surfaces may receive information directly when a user interacts with a provider-hosted order form, plan table, hosting control-panel login, password-recovery iframe, or future provider API workflow.
21. Embedded Third-Party Services
The public hosting page may load ResellersPanel comparison table scripts and styles. The hosting order page embeds a provider-hosted checkout iframe. The login page includes a CloudLogin form and provider password-recovery iframe when enabled.
Information entered into third-party embeds or direct provider forms may be collected by that provider rather than by Kodelamp.
22. ResellersPanel Integration
ResellersPanel Remote Forms are currently used for plan comparison, provider-hosted checkout, customer login, and password recovery. Kodelamp can also create local hosting, domain, order, invoice, provider-review, and legal-acceptance records in the portal before provider-backed provisioning. The standalone ResellersPanel Remote Domain Search widget is disabled by default because it previously caused browser instability.
23. PayPal
If PayPal is enabled for live payments, PayPal may process payer identity, transaction, fraud-prevention, device, payment, and account information. Kodelamp should receive only the information needed to record and reconcile the transaction, such as status and provider reference details.
24. WiPay International
If WiPay International is enabled for live payments, WiPay may process payment, account, fraud-prevention, and transaction information under its own terms and privacy practices. The current code does not store full card numbers or card security codes.
25. Bank Transfers
Manual bank transfers are represented as a local payment method. Kodelamp may store proof uploads, submitter notes, administrator review notes, payment statuses, and receipts. Bank account details and final payment instructions should be verified for the applicable invoice or account before payment is sent.
26. Email, Notification, Monitoring, and Infrastructure Providers
Notifications may be queued, logged, or delivered through configured mail and infrastructure providers. Production infrastructure may include mail delivery, hosting, storage, logging, error monitoring, queue, backup, or security providers.
27. International Data Transfers
Kodelamp serves a global market. Information may be processed in the United States and in other locations where service providers, payment providers, hosting providers, or infrastructure providers operate. Cross-border transfer obligations depend on the user's location, provider locations, and applicable law.
28. Data Retention
Retention may depend on contractual, operational, hosting, security, tax, accounting, dispute-resolution, fraud-prevention, backup, audit, and legal requirements.
Service-specific retention schedules should be confirmed in the applicable agreement, policy update, or administrative procedure.
29. Data Security
Visible controls include CSRF protection, server-side validation, throttling on sensitive public forms, session regeneration after login, role middleware, authorization policies, private local file storage, MIME and size validation for uploads, redacted provider/payment logs, webhook idempotency, optional HMAC webhook signature verification, security headers, and no card-number or CVV storage.
No system can be guaranteed absolutely secure.
30. User Choices
Users can choose not to submit optional information, use browser cookie controls, decline remember-me login, request marketing opt-out, and contact Kodelamp about privacy requests using the privacy request workflow.
31. Privacy Rights Depending on Location
Depending on your location and applicable law, you may have rights to request access, correction, deletion, portability, restriction, objection, marketing opt-out, appeal, or information about how personal information is processed.
Not every privacy law applies to every business, visitor, transaction, or data category.
32. Tennessee Privacy Rights Where Applicable
The Tennessee Information Protection Act applies only when statutory thresholds and conditions are met. Where applicable, Tennessee consumers may have rights such as confirming processing, access, correction, deletion, portability, opt-out of certain processing, and appeal.
33. United States State Privacy Rights Where Applicable
Residents of some U.S. states may have privacy rights under state laws when those laws apply. Applicability can depend on residency, business size, revenue, data volume, sale or sharing practices, and other thresholds.
34. European and United Kingdom Privacy Rights Where Applicable
Where GDPR or UK GDPR applies, individuals may have rights to be informed, access, rectification, erasure, restriction, portability, objection, and safeguards related to automated decision-making. Some rights are subject to exceptions and identity verification.
35. Access, Correction, Deletion, Portability, and Appeal Requests Where Applicable
Use the privacy request form to submit access, correction, deletion, portability, marketing opt-out, appeal, or other privacy concerns. Kodelamp will not automatically delete records without verification and review of legal, security, contractual, tax, accounting, provider, and dispute-resolution obligations.
36. Marketing Communication Choices
No dedicated newsletter or marketing automation provider is enabled by default. If marketing email is enabled later, emails should identify the sender, avoid deceptive subject lines, include required contact details, and provide an opt-out path where required.
38. Children's Privacy
Kodelamp services are intended for businesses and adults, not children under 13. If Kodelamp learns that it collected personal information from a child under 13 without appropriate consent where required, it will review and delete or restrict that information as appropriate.
39. Third-Party Websites
Links, provider iframes, payment pages, hosting control panels, and other third-party services are governed by their own terms and privacy policies. Kodelamp is not responsible for their independent practices.
40. Changes to the Policy
Kodelamp may update this Privacy Policy as services, providers, legal requirements, or operational practices change. Material changes should be reviewed before publication and may require renewed notices or acknowledgements where appropriate.
41. Contacting Kodelamp
For privacy matters, use the privacy request form linked on this page. If that form is unavailable, use the public support page or an authenticated portal support ticket if you are a client.
42. Effective Date and Last-Updated Date
Effective date: July 20, 2026. Last updated: July 21, 2026. Version: 2026-07-21.
Submit a Privacy Request
Use the secure form for access, correction, deletion, portability, marketing opt-out, appeal, or another privacy concern.