Privacy Policy for Biosyn
Last Updated: August 2026
Biosyn, a self-hosted email campaign software developed and owned by Coderstm (coderstm.com) ("we," "us," or "our"), is dedicated to protecting your privacy. This Privacy Policy describes how we collect, process, and secure personal information when you visit our website, purchase a software license via our reseller, or communicate with our team.
1. Crucial Clarification: Self-Hosted Data and Infrastructure
Unlike cloud-hosted SaaS platforms, Biosyn is a self-hosted software product. This distinction is critical to your privacy and the privacy of your email subscribers:
- Zero Campaign Data Collection: We do NOT host, store, process, or access your email campaigns, templates, subscriber databases, contact lists, verification history, or delivery tracking logs on our servers.
- Data Residency: All database records, campaign telemetry, subscriber email addresses, opt-in statuses, and Amazon SES / SMTP credentials reside strictly and exclusively on your own servers and customer-controlled hosting infrastructure.
- Complete Privacy Ownership: We have no access to your databases, servers, or application interface. You are in complete control of your data, and we cannot read, share, or delete any of your campaign or contact information.
2. Information We Do Collect (Website and Billing)
While we do not have access to your application data, we do collect limited information required to operate our business and verify your software license:
- Account and Purchase Data: When you purchase a software license via our Merchant of Record, we receive customer details such as your name, company name, email address, physical billing address, transaction history, and generated license keys.
- Billing & Payment Information (Paddle): Payment processing is handled securely and entirely by our integrated, PCI-DSS compliant Merchant of Record, Paddle.com Market Limited. We do not store, process, or transmit full credit card numbers or card security codes on our servers; Paddle collects and processes this data securely. We only receive transaction confirmation tokens, billing status, and basic reference data to verify license purchase completion.
- Communications: When you contact our support team or submit a bug report via email, we collect your name, email address, and any logs, code snippets, or configuration details you voluntarily share to help us verify bugs.
- License Verification: To prevent software piracy and ensure compliance with your license terms, the Software may periodically send basic licensing metadata (such as your license key, application domain, and software version) to our license servers to confirm validity.
- Website Analytics and Cookies: When you browse our public website, we utilize standard cookies and traffic analysis tools (such as Google Analytics) to capture technical logs, including page views, IP address, browser type, and referrer URLs to optimize website performance and user experience.
3. How We Use Your Information
We process your personal information under the following lawful bases and for these key purposes:
- Contractual Delivery: To deliver your software files, generate license keys, verify purchases processed by Paddle, and provide transactional assistance.
- Legitimate Business Interests: To protect our intellectual property from license piracy, analyze and improve website performance, and patch verified core software bugs.
- Legal Compliance: To prevent fraud, maintain financial audit logs, and comply with tax and business regulations.
- Consent: To send you product updates, security advisories, or newsletters (which you can opt-out of at any time using the unsubscribe link).
4. Your Role as Data Controller (GDPR & CCPA Compliance)
Because you are hosting the Software on your own systems and executing campaigns directly:
- You are the Data Controller: Under global data protection regulations (such as GDPR, CCPA, and UK GDPR), you are the sole "Data Controller" and "Data Processor" for your subscribers' contact records. You are fully responsible for how you gather, store, and process their personal information.
- Your Compliance Duties: You must establish your own privacy policy, obtain lawful consent to send marketing emails, configure proper opt-out mechanisms (unsubscribe links), handle subscriber data deletion requests (right to be forgotten), and ensure your servers are secured in compliance with local privacy standards.
- Recipient Inquiries: If an email recipient contacts us requesting data access, correction, or deletion, we will direct them to you. We have no technical capability to alter or delete any data stored inside your self-hosted application database.
5. Information Sharing and Third Parties
We do not sell, rent, or trade your personal information. We share limited business data only with trusted partners necessary to provide our business services:
- Authorized Reseller and Merchant of Record: Paddle.com Market Limited, to manage secure payment processing, subscription management, tax compliance, invoicing, and order handling.
- Website Telemetry: Third-party analytics providers to evaluate website traffic.
- Cloud & Hosting: Trusted hosting and server providers used exclusively to run our company website, license servers, and transactional mailing systems.
6. Data Security and Infrastructure Safeguards
We take the security of your account and licensing data seriously. We implement robust, industry-standard security measures (including SSL/TLS encryption for all website communications and restricted access controls) to prevent unauthorized access or disclosure of your purchase history, credentials, and support logs. However, remember that securing the **self-hosted application** database and infrastructure is entirely your responsibility.
7. Data Retention Policy
- License & Account Records: We retain your billing history (received via Paddle), license keys, and account records for as long as your license is active, and as required by tax and auditing laws (typically 7 years).
- Communication Logs: Email threads and related bug report communications are archived to help us track bugs and reference past queries. You can request deletion of your communication logs at any time.
- Campaign Data: As noted, we never store or process your campaign databases, so there is no campaign data for us to retain or delete.
8. Your Global Rights (GDPR & CCPA)
Depending on your jurisdiction, you have the following rights regarding the personal information we hold about you (namely, your purchase and billing records):
- Access & Correction: The right to view and correct the account profile and licensing details we maintain.
- Erasure (Right to be Forgotten): The right to request that we delete your customer account or communication history, subject to our statutory tax retention obligations.
- Portability: The right to request an export of your customer data in a standard digital format.
To exercise any of these rights, please contact our support team at [email protected].
9. Children's Privacy
Our website, software licenses, and support services are not intended for or directed to individuals under the age of 18. We do not knowingly collect personal data from children.
10. Changes to this Privacy Policy
We reserve the right to modify or update this Privacy Policy at any time. Any changes will be posted directly on this page with an updated "Last Updated" date. We encourage you to review this policy periodically to remain informed about how we safeguard your customer data.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to us at [email protected].