Launch virtual resources instantly on ChromeOS : First 10 teams Get FREE Enterprise Support.

Privacy & Security

Privacy Policy

VLauncher by Codimite PTE LTD · Effective May 1, 2026

Overview

Last Updated Date: Apr 20, 2026

This Privacy Policy describes how Codimite PTE LTD (“Codimite,” “we,” “our,” or “us”) handles information in connection with your organization’s use of VLauncher, a ChromeOS-optimized solution that enables secure and seamless launching of virtualized desktops and applications in enterprise healthcare environments.

VLauncher is designed to operate fully within your organization’s managed infrastructure. This policy follows privacy-by-design principles and reflects our commitment to security, transparency, and regulatory compliance.

Scope and Applicability

This Privacy Policy applies to the entire VLauncher ecosystem, distinguishing clearly between our web-based administrative systems and the on-premise execution software. This includes our cloud-hosted administrative properties—the Customer Portal, Licensing Server, and Website—as well as the strictly on-premise VLauncher Product (comprising the Backend, Admin Studio, Configurator, and Chrome Extension). For the cloud administrative services, Codimite acts as the Data Controller regarding your subscription and billing data. For the on-premise VLauncher Product, your organization remains the exclusive Data Controller of all enterprise data.

Information VLauncher Does Not Collect

The on-premise VLauncher Product enforces an architecturally mandated strict data isolation perimeter. Under no circumstances does Codimite access, store, receive, process, intercept, or transmit the following via our cloud infrastructure:

Protected Health Information (PHI) or Personally Identifiable Information (PII) of end-users.
Authentication payloads, including Active Directory credentials, hashes, or Kerberos tickets.
Virtual desktop session telemetry, application content, keystrokes, or screen data.
Internal enterprise files, behavioral analytics, or network traffic payloads.
As VLauncher maintains zero visibility into the applications running inside the virtualized session, Codimite acts solely as a secure conduit and does not function as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA).

Information VLauncher Handles

VLauncher processes only minimal, non-sensitive device-level metadata required to register ChromeOS devices and support secure virtual desktop launching. This includes:

Account & Billing Data (Customer Portal): We collect names, business email addresses, domain names, and payment/billing information (processed securely via our payment partners) to manage subscriptions, upgrades, and downgrades.

Telemetry & Licensing Data (Runtime & Extension): To enforce subscription tiers (e.g., Freemium limits), we securely transmit and validate Client IDs, Device IDs, and anonymized performance metrics (process start/end times).

Infrastructure & Configuration Data (Configurator/Admin Studio): Note on Security: VLauncher requires connection details for Active Directory (AD), LDAPS Service Accounts, and VDI providers (Citrix/Omnissa). This sensitive configuration data is strictly stored and encrypted locally within your cluster’s ETCD and Patroni infrastructure. We do not transmit, view, or store your AD passwords or VDI administrative credentials on our cloud servers.

How We Use Your Information

We use the information we collect for various purposes, including:

To authenticate your Client ID and provision access to appropriate subscription tiers.
To process automated subscription upgrades, downgrades, and billing notifications.
To deliver necessary database schema migrations and cluster updates.
To provide technical support and diagnose infrastructure deployment failures.
To communicate with you, including for customer service, service updates, and marketing/promotional purposes (with your consent where required by law).
For compliance purposes, including enforcing our Terms of Service, protecting legal rights, or to detect, prevent, and address technical issues or fraud.

Data Handling and Processing Model

VLauncher operates on a strictly bifurcated processing model. All core execution, Active Directory bridging, and virtual desktop launching operations occur locally and exclusively within your firewalled enterprise environment. The VLauncher Product communicates strictly via local ChromeOS policies and your internal virtualization infrastructure (Citrix or Omnissa). The cloud-hosted Licensing Server functions only as a subscription validation endpoint. VLauncher does not route your internal enterprise data through third-party cloud data lakes or external processing engines.

Healthcare Data & Protected Health Information (PHI)

VLauncher is designed as a secure launcher infrastructure that brokers connections to VDI environments (like Epic on Citrix). VLauncher does not collect, process, transmit, or store Protected Health Information (PHI).

Zero-Knowledge of Patient Data: Our software strictly handles telemetry regarding the performance of the launcher application itself. It has no visibility into the applications running inside the VDI session.
Business Associate Agreements (BAA): Because VLauncher does not access or store PHI, a Business Associate Agreement is generally not required for standard operation. However, if your specific deployment architecture or custom support requirements involve potential exposure of PHI to our personnel, a BAA must be executed prior to implementation.

How We Share Your Information

VLauncher is designed as a secure launcher infrastructure that brokers connections to VDI environments (like Epic on Citrix). VLauncher does not collect, process, transmit, or store Protected Health Information (PHI).

Service Providers: With trusted third-party subprocessors strictly necessary to operate our SaaS environment (e.g., Stripe for payment processing, cloud hosting providers). All subprocessors are bound by strict data processing agreements.
Legal Obligations: Where we are legally required to do so to comply with applicable law, governmental requests, court orders, or legal process.
Vital Interests and Legal Rights: Where we believe it is necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, threats to the safety of any person, or as evidence in litigation.
Business Transfers: In connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition. You will be notified via email and/or a prominent notice on our Services of any change in ownership.

GDPR Notice for EEA, UK, and Swiss Residents

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have specific rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, or erase your personal data, restrict or object to processing, and lodge a complaint with your local data protection authority.

Codimite processes your personal data only when necessary for the performance of a contract (providing the VLauncher service), compliance with legal obligations, and legitimate business interests. We have established Data Processing Agreements (DPAs) with our subprocessors and use EU Standard Contractual Clauses (SCCs) to ensure lawful data transfers outside the EEA. No data is stored by default beyond what is strictly necessary to maintain your subscription, and you may request deletion of your account at any time.

Security, Audit Trails & Data Retention

VLauncher is developed and maintained following industry security standards, including secure coding practices, access control principles, SAST scanning, dependency checks, and code signing. We use commercially reasonable administrative, technical, and physical security measures (e.g., TLS in transit, AES-256 at rest) to protect your personal information.

Local Audit Trails & Log Management: To support your internal compliance, the VLauncher Admin Studio maintains comprehensive admin activity logs. These logs utilize automated log rotation to ensure continuous availability. These audit logs remain strictly within your local environment; we do not transmit, collect, or store these logs on our cloud servers.

Data Retention: We retain cloud-based billing and portal data as long as your account is active, or as required by financial compliance laws. Once uninstalled, all locally stored VLauncher data, including audit logs and ETCD configurations, are purged from your environment.

User Rights and Data Subject Requests

Codimite enforces robust Data Subject Access Request (DSAR) protocols in compliance with the GDPR, UK GDPR, Swiss FADP, and applicable US State jurisdictions (e.g., CCPA/CPRA). DSAR routing is strictly determined by the data subject’s relationship to the product:

End-Users (Employees, Clinicians, Contractors): Given that the on-premise VLauncher Product processes no personal end-user data on our servers, end-users must route all access, correction, or deletion requests directly through their employing organization’s IT or Privacy departments.
Customer Portal Administrators: Administrative users retain the right to access, rectify, restrict processing of, or request the erasure of their administrative personal data. Such requests may be submitted directly to Codimite’s compliance team.
Opt-out of Marketing: You may opt-out of receiving promotional communications from us by following the unsubscribe link provided in any email we send, or by contacting us directly.

Third-Party Services

To deliver enterprise services, Codimite utilizes vetted sub-processors (e.g., SOC 2 Type II compliant payment gateways like Stripe) to securely process financial transactions. Codimite does not store full Primary Account Numbers (PAN). The on-premise VLauncher Product interfaces with your proprietary deployments of Citrix or Omnissa; Codimite disclaims liability for the privacy practices, vulnerabilities, or operational continuity of these independent third-party architectures.

Policy Review and Updates

This Privacy Policy is subject to annual review by our security and legal teams. We reserve the right to deploy updates reflecting architectural enhancements, threat landscape shifts, or evolving regulatory mandates. For material changes affecting data processing scopes within the Customer Portal, Codimite will provide a minimum of thirty (30) days’ conspicuous prior notice via portal alerts or direct administrative email communication.

Contact Information

If you have any questions or concerns about this Privacy Policy, please contact us. Codimite will acknowledge and respond to privacy-related inquiries within 30 days, in accordance with applicable data protection regulations.

Email:

vlauncher-support@codimite.com

Address: 10 Anson Road, #22-02 International Plaza Singapore 079903