Last updated: 14 September 2026

1. Who is responsible for your personal data

ReloTide is powered and operated by Codenix Labs OÜ, registry code 17357290, Tallinn, Estonia. For the processing described in this policy, Codenix Labs OÜ is the data controller unless another notice states otherwise.

Privacy and data-protection enquiries can be sent to ask@codenixlabs.ee.

2. Scope of this policy

This policy applies to the public ReloTide website, editorial content, search and discovery features, correction requests, contact communications, and assistance enquiries that we receive directly.

The current public Phase 1 website does not provide user accounts or a general-purpose immigration-document upload facility. If ReloTide later introduces accounts, case management, secure document storage, payments, newsletters, or other features that materially change how personal data is processed, this policy will be updated and additional notices may be provided where appropriate.

3. Personal data we may process

Website and technical data

When the site is requested, hosting, security, and delivery systems may process technical information such as IP address, request time, requested URL, browser or user-agent information, network and device information, and security or diagnostic events. This data is used to deliver the site, protect it from abuse, investigate faults, and maintain security and reliability.

Contact and assistance data

If you contact us, we may process your name, email address, country or jurisdiction information, the contents of your message, and any other information you choose to provide. If you ask for professional assistance, we may also process the information reasonably necessary to understand and respond to the enquiry.

Editorial corrections and feedback

If you report a suspected error, suggest a correction, or provide source material, we may process your contact details, the relevant page or source, and your correspondence so that we can investigate and respond.

4. Sensitive immigration information

Immigration matters can involve passports, identity documents, financial records, criminal-history information, health information, family information, and other sensitive data. The public website is not intended as an open channel for submitting those materials.

Please do not send highly sensitive immigration documents by ordinary email unless we have specifically instructed you to use an approved secure channel. If sensitive material is sent to us unexpectedly, we may delete it, restrict access to it, or ask you to resubmit only the information that is necessary through a more appropriate channel.

5. Why we process personal data and our legal bases

Depending on the context, we may process personal data under one or more of the following GDPR legal bases:

  • Legitimate interests: operating and securing the website, preventing abuse, maintaining records of correspondence, improving editorial quality, and responding to general enquiries, provided those interests are not overridden by your rights and freedoms.
  • Steps before entering into a contract or performance of a contract: where you ask us to assess or respond to a request for a service.
  • Consent: where we specifically ask for consent for an optional activity and consent is the appropriate legal basis. You may withdraw consent at any time without affecting processing that was lawful before withdrawal.
  • Legal obligation: where processing is necessary to comply with applicable law, regulatory requirements, court orders, accounting obligations, or lawful requests from authorities.

6. Cookies and tracking

ReloTide does not currently use advertising cookies or behavioural advertising trackers in the public Phase 1 experience. Infrastructure providers may use strictly necessary technical mechanisms to deliver, secure, or protect the service.

If we introduce analytics, advertising, or other non-essential cookies or similar technologies that require consent, we will provide the required notice and choice mechanism before using them and will update this policy as appropriate.

7. Who may receive personal data

We disclose personal data only where there is a legitimate operational or legal reason. Depending on the service used, recipients may include:

  • website hosting, cloud infrastructure, security, and technical service providers;
  • email and communications providers used to receive and respond to messages;
  • contractors or professional advisers who need access for a defined purpose and are subject to appropriate confidentiality or data-protection obligations;
  • licensed or otherwise qualified professionals where you request assistance and a disclosure is appropriate for handling that request; and
  • courts, regulators, law-enforcement bodies, or public authorities where disclosure is required or permitted by law.

ReloTide does not sell personal data.

8. International data transfers

Some technology providers may process data outside Estonia or the European Economic Area. Where the GDPR requires safeguards for an international transfer, we use or rely on an appropriate transfer mechanism, such as an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful safeguard applicable to the transfer.

9. How long we keep personal data

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, taking account of legal, security, accounting, dispute-resolution, and evidentiary needs.

  • General contact, correction, and assistance-enquiry correspondence is normally retained for up to 24 months after the last meaningful interaction, unless a shorter period is appropriate or a longer period is required for a contract, legal obligation, complaint, or legal claim.
  • Technical and security logs are retained for the period reasonably necessary for service delivery, security, abuse prevention, and troubleshooting, subject to the configuration and retention practices of the relevant infrastructure provider.
  • Records that must be retained by law may be kept for the applicable statutory period.

When personal data is no longer needed, it is deleted, anonymised, or otherwise put beyond routine use, subject to lawful backup and record-retention requirements.

10. Your data-protection rights

Where the GDPR applies, you may have the right to request access to your personal data, correction of inaccurate data, erasure, restriction of processing, and data portability where the legal conditions are met. You may also object to processing based on legitimate interests and withdraw consent where processing is based on consent.

You can exercise these rights by contacting ask@codenixlabs.ee. We may need to verify your identity before acting on a request. GDPR requests are handled without undue delay and, in principle, within one month, subject to the extensions and exceptions permitted by law.

11. Automated decision-making

The current ReloTide public service does not make decisions based solely on automated processing that produce legal effects or similarly significant effects for you. Any eligibility checker, comparison, ranking, or informational tool is a research aid and is not an immigration decision or a substitute for an official authority or qualified professional.

12. Security

We use organisational and technical measures appropriate to the nature of the service and the data processed. No internet service can promise absolute security, so users should avoid sending unnecessary sensitive information and should follow any secure-submission instructions provided for future case-management features.

13. Third-party websites

ReloTide links to government authorities and other external websites. Those services operate under their own privacy notices and practices. This policy does not govern independent third-party websites.

14. Complaints

If you have a privacy concern, we encourage you to contact us first so that we can investigate it. You also have the right to lodge a complaint with a competent supervisory authority. In Estonia, the supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

15. Changes to this policy

We may update this policy when the service, legal requirements, or our processing activities change. The latest version will be published on this page with an updated date. Material changes may also be highlighted through the website where appropriate.

16. Contact

Codenix Labs OÜ
Registry code 17357290
Tallinn, Estonia
Email: ask@codenixlabs.ee