Trust & security Guarantee & refunds Terms of service Right of withdrawal Privacy & GDPR Data processing (DPA) Legal notice Disclaimers
Last updated: 2026. This notice explains how AppUnblock processes personal data under the EU/UK General Data Protection Regulation (GDPR).
The controller of your personal data is CodifyAI SRL (Romania), Reg. Com. J2025004646003 | CUI 51174729 | EUID ROONRC.J2025004646003, VAT Not registered for VAT (neplatitor de TVA), CUI 51174729, trading as AppUnblock. Registered address: Sat Checea nr. 681, cam. 2, jud. Timiș, 307102, Romania. Privacy contact: [email protected].
| Purpose | Lawful basis |
|---|---|
| Diagnose and fix your rejection, deliver the service | Performance of a contract (Art. 6(1)(b)) |
| Take payment, keep accounting records | Contract + legal obligation (Art. 6(1)(b),(c)) |
| Security, fraud/abuse prevention, service operation | Legitimate interests (Art. 6(1)(f)) |
| Service emails (diagnosis, quote, delivery, support) | Contract (Art. 6(1)(b)) |
| Any marketing email | Consent (Art. 6(1)(a)) — opt-in, withdrawable anytime |
We do not sell your data and never share it with advertisers. - Processors acting on our instructions (Art. 28 GDPR): Hetzner Online GmbH (EU hosting/infrastructure, Germany); our EU-based mail server; Cloudflare, Inc. (CDN, TLS and DDoS protection); and — only to generate an automated fix kit from your rejection text — the CodAI AI gateway (ai.codai.ro) and, through it, the model provider Anthropic, PBC (see "AI processing" below). - Independent recipient acting as its own controller: Stripe, Inc., which processes your payment data to provide card/payment services under its own responsibility and privacy policy (PCI-DSS compliant; EU-U.S. Data Privacy Framework certified) — not as our sub-processor.
Where we process personal data belonging to your end-users contained in files you provide, we act as your processor under the Data Processing Agreement that forms part of our Terms. We are not affiliated with Apple or Google and never share your data with them beyond what you submit through your own developer accounts.
When we generate an automated fix kit, we send the AI only your store-rejection message and our internal playbook — never your source code, and not your end-users' personal data. This is processed through our AI gateway (ai.codai.ro), which routes it to a third-party model provider (Anthropic — Claude) as our sub-processor. It is designed to be private: our team does not read these requests in normal operation; the gateway does not store full message content for standard use — it keeps only a truncated extract of up to 500 characters, encrypted, for at most 7 days for routing and abuse-prevention, then deletes it (technical metadata such as model, token count and latency is kept for at most 30 days). The model provider processes the text under its own API/commercial terms, which by default do not use API traffic to train its models. You control what you submit; please don't paste other people's personal data, secrets or credentials into a rejection message.
We keep core data within the EU: hosting/infrastructure is provided by Hetzner Online GmbH (Germany) and our mail server is operated within the EU. Some recipients are outside the EEA — in particular payment processing by Stripe, Inc. (United States). Stripe is self-certified under the EU-U.S. Data Privacy Framework, and the European Commission's adequacy decision of 10 July 2023 (Implementing Decision (EU) 2023/1795) recognises an adequate level of protection for transfers to organisations certified under that framework — this is the primary safeguard for that transfer. As an additional safeguard, transfers to Stripe are also covered by the EU Standard Contractual Clauses. You can request a copy of the safeguards by emailing [email protected]. We do not transfer your data to any other third country without an adequacy decision or appropriate safeguards under Articles 44–46 GDPR.
For legitimate interests (Art. 6(1)(f)) our specific interests are service security, fraud prevention, and improving our diagnoses; you can object at any time under Art. 21 GDPR. Where we rely on consent, you can withdraw it at any time; withdrawal does not affect processing carried out before you withdrew.
You have the right to: access your data, rectify it, request erasure ("right to be forgotten"), restrict or object to processing, request data portability, and — where processing is based on consent — withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority: the Romanian authority ANSPDCP (B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, [email protected]), or the supervisory authority in your own EU country of residence or work (Art. 77). (ANSPDCP - National Supervisory Authority for Personal Data Processing (www.dataprotection.ro))
To exercise any right, use our data request form or email [email protected]. We respond within one month.
The free triage tool classifies your rejection text to suggest a guideline and service tier. This is not a decision producing legal effects; a human reviews every case. We do not carry out Art. 22 automated decisions.
We use a single strictly-necessary cookie to keep the admin operator signed in. We do not use advertising or third-party tracking cookies, so no cookie-consent banner is required for marketing — only this notice.
Providing your rejection message and contact details is necessary for us to provide the service; without them we cannot diagnose or fix your rejection.
We may update this notice; the "last updated" date shows the current version. Material changes affecting you will be communicated where appropriate.