DATA PROCESSING

COSMO data-processing commitments.

A product-facing summary of the standard commitments COSMO expects to use when processing personal data on behalf of a workspace customer.

Last updated 25 August 2026

Scope and roles

Where a customer determines the purposes and means of personal-data processing and instructs COSMO to process that data to provide the service, the customer acts as controller and COSMO acts as processor. This page is a summary and is not a substitute for an executed DPA where one is required.

Processing details

Subject matterProviding COSMO workspace, integration, export, support and related SaaS functionality.Service delivery
DurationFor the customer relationship plus limited retention necessary for deletion, security, billing or legal obligations.Contract term
Data subjectsCustomer personnel, collaborators, workspace users and individuals whose data the customer chooses to process through connected services.Customer-defined
Data categoriesAccount identifiers, workspace configuration, usage metadata, connected-service identifiers and customer content needed for requested workflows.Limited to purpose

Customer instructions

COSMO will process customer personal data only to provide and secure the service, comply with documented customer instructions, or meet a legal requirement. If COSMO believes an instruction conflicts with applicable data-protection law, it may pause the affected processing while the issue is clarified.

Confidentiality and security

COSMO applies technical and organizational controls appropriate to the current product, including authenticated access, workspace isolation, server-side credential handling, encrypted integration credentials, revocable device sessions and controlled production changes. The current security model is described on the Security page.

Subprocessors

COSMO may use subprocessors for hosting, database/authentication, payment processing and transactional communication. Customer-connected platforms such as Klaviyo are destinations selected by the customer rather than subprocessors used independently by COSMO. The current provider overview is maintained in the Trust Center.

Assistance and incidents

Taking into account the nature of the processing and information available to it, COSMO will reasonably assist customers with data-subject requests, security obligations and required privacy assessments. COSMO will notify affected customers of a confirmed personal-data breach without undue delay after becoming aware of it, subject to applicable law and available facts.

Deletion and return

At the end of service, COSMO will delete or return customer personal data as reasonably applicable, except where retention is required by law or necessary for narrowly limited security, billing, backup or dispute-resolution purposes. Backup deletion may follow the provider’s normal lifecycle rather than occurring instantly.

International transfers and audits

Where restricted international transfers occur, COSMO will use an appropriate lawful transfer mechanism before the relevant production use. Enterprise customers may request reasonable security and data-processing information for procurement. Formal audit rights, transfer clauses and jurisdiction-specific terms should be documented in the executed DPA or order form.

Discuss an Enterprise DPA →