Legal
Privacy Policy
This policy explains how Kosmia Labs processes personal data when you use this website, in line with the EU General Data Protection Regulation (GDPR).
01 — Data controller
The controller responsible for data processing on this website within the meaning of Art. 4(7) GDPR is:
Kosmia Labs
[LEGAL ENTITY NAME]
[STREET ADDRESS]
[POSTAL CODE, CITY, COUNTRY]
[CONTACT EMAIL]
[COMMERCIAL REGISTER / VAT ID, IF APPLICABLE]
A data protection officer has not been appointed unless indicated here: [DPO DETAILS, IF REQUIRED].
02 — Data we collect
When you visit this website, our hosting provider automatically records technical information in server log files. This typically includes the requested page, the date and time of the request, the referring URL, the browser type and version, the operating system, and an abbreviated or full IP address.
Beyond this, we only process data that you actively provide, for example when you submit the contact form or write to us by email.
03 — Legal bases
Processing of technical log data is based on our legitimate interest in operating a secure and functional website (Art. 6(1)(f) GDPR). Processing of enquiries is based on pre-contractual or contractual measures (Art. 6(1)(b) GDPR) or on your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future.
04 — Website analytics
[ANALYTICS STATUS TBD.] If an analytics service is used, this section must state the provider, the data processed, whether measurement is cookieless, the legal basis, the retention period, and how to object. No analytics provider is configured on this website at the time of writing.
06 — Contact forms and enquiries
If you contact us through the form or by email, the details you provide, including your name, email address, organisation and message, are stored for the purpose of handling your enquiry and any follow-up questions. We do not use this data for unrelated purposes and do not pass it on without your consent.
07 — Hosting and third-party services
This website is operated on infrastructure provided by [HOSTING PROVIDER TBD], with whom a data processing agreement under Art. 28 GDPR is in place. Additional processors, such as form delivery, email or font providers, must be listed here with their purpose and location: [PROCESSOR LIST TBD].
08 — International data transfers
Where a processor is located outside the European Economic Area, transfers take place on the basis of an adequacy decision or EU standard contractual clauses under Art. 46 GDPR. [TRANSFER DETAILS TBD.]
09 — Data retention
Personal data is retained only as long as necessary for the purpose it was collected for, or as long as statutory retention obligations require. Server log data is deleted after [RETENTION PERIOD TBD]. Enquiry correspondence is deleted once the matter is concluded and no legal obligations prevent deletion.
10 — Your rights under the GDPR
You have the right to request information about the personal data we hold about you (Art. 15), to have inaccurate data corrected (Art. 16), to request erasure (Art. 17), to request restriction of processing (Art. 18), to data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21).
You also have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence, place of work, or the place of the alleged infringement. The competent authority for us is [SUPERVISORY AUTHORITY TBD].
11 — Security
This website uses TLS encryption for all connections. We apply appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access, and review them as our systems change.
12 — Changes to this policy
We update this policy when our services or the legal requirements change. The version published on this page always applies, together with the effective date shown above.
13 — Contact
For any question about this policy or to exercise your rights, use the contact form or write to [CONTACT EMAIL TBD].
Contact Kosmia Labs →