Privacy policy
Last updated: 1 October 2026
In short
- MessageWeave is a service of CodeLevel39 (VAT no. IT03778360549), which is the controller of your account data.
- We process your recipients' data (address book, messages, replies) only on your behalf, as a processor: you are the controller of that data.
- We don't sell data, we don't do advertising or profiling, and we use no analytics or tracking tools on the site or in the app.
- We only use strictly necessary cookies and browser storage, which is why there is no cookie banner.
- For any request about your data, write to info@codelevel39.it.
1. Who we are
The data controller is Code Level 39 di Anderlini Michele (“CodeLevel39”), a sole proprietorship, VAT no. IT03778360549, registered at Via Piave 20, 06028 Sigillo (PG), Italy. MessageWeave (the website messageweave.com, the app at app.messageweave.com and the API at api.messageweave.com) is a service of CodeLevel39: there is no separate company called MessageWeave.
For questions about this policy or to exercise your rights, write to info@codelevel39.it. We have not appointed a data protection officer (DPO): we answer directly at that address.
This policy is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and the Italian Privacy Code (Legislative Decree 196/2003). The Italian version is the reference text.
2. CodeLevel39's two roles
There are two kinds of data in the service, and we have a different role for each:
- Data about our customers and their users (people who sign up, invited colleagues, staff of linked agencies, visitors to the website): here CodeLevel39 is the controller, and this policy explains everything we do. See sections 3 to 5.
- Data about message recipients that customers upload or collect with MessageWeave (address book, contact points, consents, message contents, delivery results, replies): here the customer is the controller and CodeLevel39 is a processor under Article 28 GDPR. See section 6.
3. The data we process as controller
When you visit messageweave.com
The website uses no cookies, stores nothing in your browser and contains no analytics tools, social buttons or third-party resources (even the typeface is hosted by us). Like any web server, it technically records the requests it receives (IP address, page requested, date and time, browser type) to work and to defend itself against abuse.
When you create and use an account
- Sign-up and profile data: name, email address, workspace name, password (which we only store in a non-reversible form), preferred language, optional profile picture, role in the workspace.
- Who invited you: if you sign up through an invitation link or referral code, we record which workspace you came from.
- Colleagues and agencies: if an administrator invites you to their workspace, or an agency links you to a client, your name and email were given to us by them.
- Technical and security data: a log of the operations performed (user, operation, IP address, date and time), failed sign-in attempts (username, IP address, browser type, date and time), temporary account locks after too many wrong attempts, session tokens.
- Abuse protection: IP addresses sending abnormal requests (for example automated scans looking for vulnerabilities) are blocked for 24 hours, or for 7 days if they come back within 30 days. The list of blocked IPs is shared among CodeLevel39's services, so an attacker stopped on one is stopped on all.
- Communications with us: what you write to us when you ask for support.
Today the service only has a free plan: we collect no payment data.
4. Why we process it and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account and workspace, providing the service, sending you service emails (address verification, password recovery, invitations, security alerts, a daily activity digest you can turn off) | Performance of the contract (Art. 6(1)(b) GDPR) |
| Protecting the service, users and recipients: operation logs, sign-in attempts, account and IP blocks, spam and abuse prevention | Legitimate interest in security (Art. 6(1)(f) GDPR) |
| Knowing which invitation or referral a new customer comes from | Legitimate interest (Art. 6(1)(f) GDPR) |
| Answering your support requests | Performance of the contract or pre-contractual steps (Art. 6(1)(b) GDPR) |
| Complying with legal obligations and defending our rights | Legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f) GDPR) |
We don't use your data for advertising, we don't sell it, and we make no decisions based solely on automated processing that have legal effects on you (Art. 22 GDPR). If we ever want to send you promotional messages, we will ask you first.
The data requested at sign-up is required: without it we cannot create the account.
5. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | As long as the account is active. When it is closed we delete them, except what we must keep by law or to defend our rights. |
| Sign-ups never confirmed (email not verified and workspace never used) | Deleted after 30 days |
| Operation log (with IP address) | 90 days |
| Failed sign-in attempts | 30 days |
| Session tokens | Expire after 30 days; revoked ones are deleted within 30 days |
| IP address blocks | A block lasts 24 hours (7 days for repeat offenders); a record of the block is kept as security history |
| Support requests | As long as needed to handle them and document the answer |
6. Your recipients' data
When you use MessageWeave you upload or collect data about the people you write to: address book details and contact points, consent status and its history, message contents and attachments, templates, delivery results and events received from channel providers (delivered, opened, clicked, bounced), and replies recipients send on chat channels.
For this data you (the customer) are the controller and CodeLevel39 is a processor (Art. 28 GDPR): we process it only to provide the service and according to your instructions, which are those in the Terms of service (section "Data processed on the customer's behalf") and the settings you choose in the app. We don't use it for our own purposes.
Your responsibilities
- Having a valid legal basis for each recipient and channel: promotional messages by email, SMS, WhatsApp and similar usually require prior consent (in Italy, Art. 130 of the Privacy Code).
- Telling your recipients, in your own privacy notice, that you use MessageWeave (CodeLevel39) as a provider.
- Honouring recipients' objections and requests promptly.
The tools we give you
- Double opt-in: the contact confirms the subscription from a link received by email.
- Unsubscribe: every email sent includes an unsubscribe link and the standard one-click unsubscribe header; on chat channels a reply such as "STOP" records the objection.
- Consent history: every change of consent (who, when, how, why) is recorded as proof.
- Suppression list: MessageWeave sends nothing more to a contact point that has objected, even after the contact has been deleted.
- Export and deletion: you can export a person's data (to answer an access or portability request) and delete them.
Open and click tracking
For email senders, open and click counting is on by default and can be turned off for each sender. It uses an invisible image and links that go through api.messageweave.com; for each message we only store the number of opens and clicks and the date, not the recipient's IP address. If you use it, it is up to you to inform recipients and, where required, collect their consent.
Default retention
| Data | Retention |
|---|---|
| Messages sent (recipient and content) | 180 days from creation, once the sending is concluded |
| Attachments | 30 days, then the files are deleted |
| Delivery attempts | 90 days |
| Events received from channel providers | 90 days |
| Replies received from recipients | 180 days |
| Status notifications sent to your systems (callbacks and webhooks) | 30 days after completion |
| Address book | Until you delete the contact. 30 days after deletion the personal data is anonymised; only contact points that had objected are kept (as a suppression list), together with the consent history (channel, contact point, date and method), as proof of the objection. |
When your account is closed, your recipients' data is deleted, with the exceptions just described. Before that you can export your address book.
Are you a recipient? If you received a message sent with MessageWeave, the controller of your data is the organisation that sent it: contact them to exercise your rights. You can always unsubscribe from the link in the message. If you write to us, we will forward your request to the customer concerned.
7. Where the data is and who helps us
To provide the service we rely on these providers, which process data on our behalf under contracts binding them to confidentiality and security:
- Hetzner Online GmbH (Germany): servers running the website, app, API and database, in data centres in the European Union.
- Microsoft (Azure Blob Storage service): storage of message attachments and of images uploaded to email templates. Template images are published at a web address, because they must be visible in emails.
- Zoho (ZeptoMail service): delivery of the platform's service emails (address verification, password recovery, invitations, alerts).
Channel providers chosen by you. Messages to your recipients are sent through the providers you configure with your own accounts and credentials: for example Twilio and SendGrid, Meta (WhatsApp Cloud API), Telegram, Aruba, Google Firebase Cloud Messaging, Slack, Microsoft Teams, Discord, or your mailbox's mail server. You choose them, under your own contract: MessageWeave passes messages to them on your instruction and receives results and replies from them. Their terms and privacy notices apply, and some may process data outside the European Union.
We disclose data to authorities only when the law requires it. We don't sell or hand over data to third parties for their own purposes.
Transfers outside the EU. If one of our providers processes data outside the European Economic Area, it does so under the safeguards of Articles 44–49 GDPR, such as an adequacy decision of the European Commission (for the United States, the Data Privacy Framework) or standard contractual clauses. You can ask us for more information at info@codelevel39.it.
8. Security
We protect data with technical and organisational measures appropriate to the risk: connections always encrypted (HTTPS), passwords stored in a non-reversible form, short-lived sessions, role-based access and strict separation between workspaces, account locking after repeated wrong sign-in attempts, limits against abusive use, signatures on communications exchanged with external systems, and automatic deletion of data when the periods above expire.
Found a security issue? Report it to the address in our security.txt (help@codelevel39.it). If a personal data breach occurs, we will notify the Italian Data Protection Authority and, where required, the people affected; for recipients' data we will notify the customer (the controller) without undue delay.
9. Cookies and browser storage
Website messageweave.com
No cookies and no data stored in the browser.
App (app.messageweave.com)
The app only uses strictly necessary tools that it needs to work:
- One session cookie,
mw_rt, set byapi.messageweave.com: it keeps you signed in by renewing your access. It cannot be read by the page's scripts, travels only over encrypted connections, is never sent to third-party sites, lasts at most 30 days and is deleted when you sign out. - The browser's local storage (localStorage) keeps: the details of the open session (name, role and permissions, not the password), the language and theme you chose, the last username used to sign in, list filters, a temporary copy of some interface data and, if you are accepting an agency invitation, the invitation code.
We use no profiling, advertising or statistics cookies, neither ours nor third parties'. Strictly necessary tools do not require consent (Art. 122 of the Italian Privacy Code and the Italian Data Protection Authority's cookie guidelines of 10 June 2021): that is why we show no banner. You can clear cookies and local storage in your browser settings; without the session cookie you will have to sign in again.
10. Your rights
For the data we control, you can ask us at any time:
- to access your data and get a copy (Art. 15 GDPR);
- to correct or complete it (Art. 16);
- to erase it (Art. 17);
- to restrict its processing (Art. 18);
- to receive it in a structured, commonly used format to move it elsewhere (portability, Art. 20);
- to object to processing based on our legitimate interest (Art. 21).
Write to info@codelevel39.it. It is free and we reply within one month (for complex requests this can be extended by two more months, and we will tell you). We may ask you to confirm your identity, for example by writing from your account's email address.
If you believe the processing breaches the GDPR, you can lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the supervisory authority of the EU country where you live or work.
11. Changes to this policy
We may update this policy, for example when the service or our providers change. The current version is always on this page, with the date of the last update; if the changes are significant we will also tell you by email.