Scope and roles
Where a customer determines the purposes and means of personal-data processing and instructs COSMO to process that data to provide the service, the customer acts as controller and COSMO acts as processor. This page is a summary and is not a substitute for an executed DPA where one is required.
Processing details
Customer instructions
COSMO will process customer personal data only to provide and secure the service, comply with documented customer instructions, or meet a legal requirement. If COSMO believes an instruction conflicts with applicable data-protection law, it may pause the affected processing while the issue is clarified.
Confidentiality and security
COSMO applies technical and organizational controls appropriate to the current product, including authenticated access, workspace isolation, server-side credential handling, encrypted integration credentials, revocable device sessions and controlled production changes. The current security model is described on the Security page.
Subprocessors
COSMO may use subprocessors for hosting, database/authentication, payment processing and transactional communication. Customer-connected platforms such as Klaviyo are destinations selected by the customer rather than subprocessors used independently by COSMO. The current provider overview is maintained in the Trust Center.
Assistance and incidents
Taking into account the nature of the processing and information available to it, COSMO will reasonably assist customers with data-subject requests, security obligations and required privacy assessments. COSMO will notify affected customers of a confirmed personal-data breach without undue delay after becoming aware of it, subject to applicable law and available facts.
Deletion and return
At the end of service, COSMO will delete or return customer personal data as reasonably applicable, except where retention is required by law or necessary for narrowly limited security, billing, backup or dispute-resolution purposes. Backup deletion may follow the provider’s normal lifecycle rather than occurring instantly.
International transfers and audits
Where restricted international transfers occur, COSMO will use an appropriate lawful transfer mechanism before the relevant production use. Enterprise customers may request reasonable security and data-processing information for procurement. Formal audit rights, transfer clauses and jurisdiction-specific terms should be documented in the executed DPA or order form.