Cozmond
PrivacyTermsSign in

Effective 2026-09-09

Privacy Policy

This policy explains how Cozmond collects, uses, shares, and protects personal data when you visit our website, use the Cozmond Platform, or communicate with us. The Cozmond Platform (the "Platform") is our product; "Cozmond" is the company behind it. Our customers are organizations, and access to the Platform is by invitation only.

We have written this policy to be read, not skimmed. It is specific about what we do because our customers put sensitive business data into the Platform, and they deserve to know exactly how it is handled. If anything is unclear, or you want to exercise any of your rights, contact us at info@cozmond.com.

Contents

  1. 1Who we are
  2. 2The two roles we act in
  3. 3Data we collect as a controller
  4. 4Why we use your data and our legal bases
  5. 5Customer Data we process for our customers
  6. 6Connected services
  7. 7Email connectors (Gmail and Outlook)
  8. 8Call recordings and transcripts
  9. 9AI processing
  10. 10Learning and derived data
  11. 11Who can see data inside a workspace
  12. 12Cookies and local storage
  13. 13Service providers we use
  14. 14International data transfers
  15. 15How long we keep data
  16. 16How we protect data
  17. 17Your rights
  18. 18Automated decision-making
  19. 19If something goes wrong
  20. 20Children
  21. 21Links to other services
  22. 22Changes to this policy
  23. 23Contact

Also

Terms of Service

1Who we are

The Cozmond Platform is operated by two affiliated companies. Which of them is responsible for your organization's personal data is the one named in its Order Form:

CompanyRegistered address
OZEREN LLC30 N Gould St #44460, Sheridan, WY 82801, United States
ONAT ÖZEREN BİLGİ TEKNOLOJİLERİ VE DANIŞMANLIKEsentepe Mah. Talat Paşa Cad. No:5 Kapı No:1, Şişli, İstanbul, Türkiye

Where there is no Order Form, for example if you are visiting our website or evaluating the Platform, the responsible company is OZEREN LLC, unless you or your organization are established in Türkiye, in which case it is ONAT ÖZEREN BİLGİ TEKNOLOJİLERİ VE DANIŞMANLIK. In this policy, "Cozmond", "we", and "us" mean the company responsible for you, and "the Platform" means the Cozmond Platform. Both companies can be reached at info@cozmond.com or by post at the addresses above.

2The two roles we act in

We handle personal data in two legally different roles, and the difference decides who you should contact.

  • We are the data controller for the accounts of the people who use the Platform, for visitors to our website, and for the people we deal with at customer and prospective-customer organizations. This policy is your privacy notice for that data.
  • We are a data processor for the business data our customers put into their workspace: their accounts, contacts, deals, notes, files, correspondence, and call transcripts (together "Customer Data"). The customer decides what goes in, why, and for how long. We act on their instructions under a signed Data Processing Agreement (DPA).

If your information sits inside a customer's workspace, for example because you are a contact or customer of theirs, or you took part in a call they recorded, that customer is responsible for it and is the one to ask. We pass any request we receive to them without undue delay and help them answer it.

3Data we collect as a controller

Website visitors

Our website has no forms, no analytics, and no advertising or social-media trackers. Our hosting provider keeps standard server logs (IP address, browser type, page requested, time) to deliver the site and protect it against abuse. They are short-lived and are never used to identify or profile a visitor.

People who use the Platform

When you are invited into a workspace, we collect:

  • Your account: name, work email address, and a profile picture if you upload one. Passwords are handled by our authentication provider and stored only as secure hashes; we never see them.
  • Your place in the workspace: which workspace, your role, who invited you, and which accounts you are assigned to.
  • Security events such as sign-ins, password resets, and invitation acceptance, with timestamps.
  • Your interface preferences, and the email address of any service you connect, so the Platform can tell your organization's own domains from those of its accounts.
  • What you do in the workspace, as part of that workspace's records, and any messages you send us.

People at customer and prospective-customer organizations

We hold business contact details (name, role, work email, phone) and our correspondence with the people we deal with at customers, and at organizations we talk to about Cozmond. We get these from you, from your organization, from a referral, or from a public professional source. You can ask us to stop contacting you at any time.

4Why we use your data and our legal bases

Data-protection law requires a legal basis for each use of personal data. Ours are below. We do not run advertising, we do not sell personal data, and we use no third-party analytics or tracking.

PurposeData usedLegal basis
Providing and supporting the Platform, including signing you in, running the features you use, sending service messages such as invitations and password resets, and answering your questionsYour account, your place in the workspace, preferences, workspace activity, your messages to usPerformance of the contract with your organization; where you are not a party to it, our legitimate interest in providing the service your organization asked for; our legal obligations where a notice is required by law
Keeping the Platform secure: detecting and blocking abuse, investigating incidents, and keeping workspaces isolated from one anotherSecurity events, server logs, workspace activityOur legitimate interest in running a secure service, and our obligation to protect personal data
Contracting, billing, and accounting with your organizationBusiness contact details, order and invoice records, correspondencePerformance of the contract; our legal obligations under commercial and tax law
Staying in touch with people at organizations that may become customersBusiness contact detailsOur legitimate interest in growing our business, balanced against your interests; you can object at any time
Improving the service, using information that cannot identify anyoneUsage measurements and de-identified, aggregated informationOur legitimate interest in improving the service
Establishing, exercising, or defending legal claims, and complying with lawWhatever is relevant to the matterLegal obligation; our legitimate interest in protecting our rights

Where we rely on legitimate interests, we have assessed that the processing is necessary and does not override your rights, and you can ask us for a summary of that assessment. Where we rely on consent, such as when you connect your own mailbox, you can withdraw it at any time without affecting processing that already happened.

5Customer Data we process for our customers

Customers use the Platform to manage their revenue work. Depending on what they turn on, a workspace can hold:

  • CRM records: companies, the people at them (name, role, work email, phone), deals, values, notes, and history.
  • Files their team uploads.
  • Correspondence with their accounts, and sales call transcripts with the analyses produced from them.
  • Data from the services the customer connects, such as its CRM, spreadsheets, or billing tool.
  • Conversations with the Platform's assistants, and what the workspace has learned from its own history.

We process all of it only to provide the service to that customer, on their instructions and under the DPA. What is collected, why, and for how long is the customer's decision, and their admins control who on their team sees what.

6Connected services

Customers and their team members can connect third-party services. Every connection is authorized deliberately, by an admin for the workspace or by the individual for a personal connection such as their own mailbox, and can be disconnected at any time. Connections use each provider's official authorization flow, ask for the narrowest permissions the feature needs, and are read-only wherever the provider allows it. Stored credentials are encrypted. Disconnecting stops future syncing; data already in the workspace stays until the customer deletes it. Each provider's own terms govern its side.

Google services

Cozmond Platform's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We use information received from Google APIs only to provide the features the connecting user set up: charting the spreadsheets and channel statistics they select, and putting their business correspondence on the right account timelines. We do not use it for advertising; we do not sell it; we do not transfer it to anyone else except as needed to provide those features, for security, or to comply with applicable law; we do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models; and no person at Cozmond reads it except with the workspace's permission for support, for security, or to comply with law. Workspace members with access to an account see the correspondence on it, because that is the feature the connecting user set up.

Spreadsheet and video connections read only what the connecting person selects. Gmail connections use the read-only Gmail permission and are covered in "Email connectors (Gmail and Outlook)" below. Each connection receives only its own permissions: a spreadsheet connection can never read mail, and a mailbox connection can never read files.

Everything else

Outlook mailboxes connect with a read-only mail permission and follow the same rules as Gmail. Workbook, CRM, and billing connections read only the records or files an admin selects; a billing connection sees payment totals, never card numbers. Where a source holds free-form pages, reading their body text is a separate choice the admin makes and can undo. A customer can also import accounts once from a spreadsheet file, which is processed and not kept. Call recording services are covered in "Call recordings and transcripts" below. To show company logos, we ask a public icon service for the icon of an account's web domain, sending the domain only and no personal data.

7Email connectors (Gmail and Outlook)

A team member can connect their own work mailbox so that their correspondence with the companies in the workspace appears on those companies' timelines. Because this touches a mailbox, here is exactly what it does and does not do.

  • Personal and read-only. The connection is made by the individual, belongs to them, and uses each provider's read-only permission (gmail.readonly for Gmail, Mail.Read for Outlook). We cannot send, delete, move, or change mail, and we never request a permission that would allow it.
  • We keep only correspondence with your accounts. A message is kept only when the person on the other side of it belongs to a company that exists as an account in the workspace. Personal mail, mail between colleagues, newsletters, and automated notifications are discarded as they are read and are never stored. On first connection we look back up to six months.
  • What is stored: for a kept message, the sender and recipient names and addresses, the date, the subject, the message text, its direction, and its thread. Email attachments are not imported.
  • Who sees it: the workspace members with access to that account, and that workspace's own AI features. Nowhere else.
  • Deleting, and leaving the team. Deleting a message here removes our copy everywhere, and we keep a minimal record, containing no message content, so that it is not brought back in; that record is kept for as long as the workspace exists. When a member leaves the workspace, the connections they own end with their access, while messages already on an account stay as the customer's business record.
  • Never elsewhere. Mailbox information is never used for advertising, never sold, never used to build anything shared across customers, and never used to develop, improve, or train generalized artificial-intelligence or machine-learning models.

8Call recordings and transcripts

The Platform does not record calls. Transcripts reach a workspace in one of two ways: from a call recording service the customer connects, or pasted in by a team member.

  • Only meetings with people outside the customer's own organization are brought in and attributed to one of its accounts. Meetings that are purely internal are not analyzed. Where a meeting cannot be attributed clearly, an admin decides what happens to it.
  • What is stored: the transcript and the analysis produced from it, on that account's timeline, visible to the members who have access to that account.
  • Removing a meeting in the Platform does not delete anything from the customer's recording service, which remains the system of record. We keep a minimal record, with the personal details removed, so that the meeting is not brought back in; it expires within about nine months.
  • The customer is responsible for recording calls lawfully, including any consents and notices required where the participants are located. Our agreement with each customer requires this, and someone who took part in a recorded call should direct questions to the customer.

9AI processing

The Platform's AI features (workspace agents, account intelligence, call analysis, report writing, drafting, and similar) run on large language models from Anthropic, called through Cozmond's own account. When a feature runs, the relevant workspace data is sent securely to the model provider, retained only briefly for the provider's safety checks and then deleted, and is never used to train models. We do not use customer-supplied AI accounts, so a customer's data is never mixed with a third party's account.

  • Each workspace has an AI data policy agreed with the customer. It can minimize personal identifiers before anything reaches the model, or switch live AI processing off altogether.
  • AI access to workspace data is logged, so there is a record of what was used and when. The log holds identifiers, not the content sent, and is kept for the life of the workspace as the customer's audit record.
  • AI features never change a workspace's records on their own. A person confirms the change first.
  • Files attached to a chat: we take the text out of documents and do not keep the file, and we re-encode images, which removes embedded metadata such as location. Both are deleted with the conversation.
  • Usage limits protect each workspace against runaway use.
  • AI output supports the people using the Platform. We do not use AI to make automated decisions that produce legal or similarly significant effects about anyone.

10Learning and derived data

The Platform learns inside each customer's workspace so that it works better for that customer, for example the terminology its team uses and which of its suggestions the team accepted. This learned data belongs to that workspace: it is visible and deletable in the workspace's settings, it is never shared with or used for another customer, and it is deleted with the workspace. A customer can also ask us to purge learned entries that relate to a specific person, for example to honor a request from that person.

Across customers, we use only information that has been de-identified and aggregated so that it cannot identify a customer, a person, or any customer's customer. We never use one customer's content for another customer, and we never include anything received from a connected mailbox or from Google or Microsoft services. The limits we hold ourselves to, and the customer's right to opt out, are set out in our Terms of Service.

11Who can see data inside a workspace

  • The customer's admins control access. Roles (owner, admin, member, viewer) determine what each person can do, per-account access rules determine which accounts a person can see, and dashboards, reports, and datasets can be restricted to named people.
  • Conversations with the Platform's agents about an account are shared with the members who can access that account, so the team sees the same history. Admins can remove conversations.
  • Cozmond staff (operators) can access a customer's workspace to set it up, configure it, support it, and investigate security issues, because the Platform is a managed service. This access is limited to those purposes, is covered by confidentiality obligations and the DPA, and is never used to read a workspace's content for any other reason.
  • Our application logs are designed to contain no personal data, so support and debugging do not depend on reading your content.

12Cookies and local storage

We use only what the Platform needs to work, plus the choices you make about how it looks. There are no advertising cookies and no third-party analytics, and nothing follows you to other websites. That is why there is no cookie banner: consent is required for non-essential cookies, and we set none.

NamePurposeLifetime
Authentication cookies (names begin with sb-)Keep you securely signed in.Session, or longer if you chose to stay signed in
cz-rememberRemembers whether you chose to stay signed in on this browser.Up to one year
theme, accent, deals_columnsRemember your appearance and table layout choices so pages render correctly.Up to one year
Browser local storageHolds the same preferences in your browser only.Until you clear it

Because we do not track anyone across sites, signals such as Do Not Track or Global Privacy Control have nothing to change: we already behave as if they were set.

13Service providers we use

We run the Platform on a small number of specialist providers. Each processes data only on our instructions, under a written data-processing agreement, may not use it for its own purposes, and is reviewed before we use it.

Type of providerWhat it does for usProcessing location
Managed cloud database, authentication, and file storageStores each workspace's data, files, and encrypted backups, and runs sign-in. Workspaces are hosted in the European Union today; a United States region is planned.European Union
Application hosting and content deliveryRuns the Platform and delivers it to your browser.United States
AI model providerRuns the models behind the AI features, and is named in "AI processing" above.United States
Transactional email deliverySends invitations, email confirmations, and password resets.United States
Public icon lookup serviceReturns a company logo for a web domain. Receives the domain only, never personal data.United States

We name each provider individually, with its role and location, in the Data Processing Agreement every customer signs, and we give at least 30 days' notice before we add or replace one. If you would like the current list of named providers, ask us at info@cozmond.com and we will send it. Services a customer chooses to connect are not our service providers; the customer authorizes those directly. We also disclose personal data where the law requires it, telling the affected customer unless we are prevented from doing so. We share it with nobody else, and we never sell it.

14International data transfers

Customer workspace databases and files are stored in the European Union. Some of our providers process data in the United States, as the table above shows, which means that AI processing, transactional email, and application hosting involve transfers out of the country where you or your organization are located.

  • For personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement where applicable) with each provider, and, where a provider is certified, on the EU-US Data Privacy Framework and its UK and Swiss extensions. We assess each transfer and apply supplementary measures where needed.
  • For customers contracting with our Turkish company, cross-border transfers are made in line with the transfer rules of the Turkish Personal Data Protection Law (KVKK), using the standard contracts and other mechanisms recognized by the Personal Data Protection Board, and are notified to the Board where the law requires.
  • You can ask us for more information about the safeguards for a specific transfer.

15How long we keep data

We keep personal data only for as long as the purpose requires, then delete or de-identify it. The main periods are:

DataRetention
Your account, including your profile, preferences, and security eventsKept while you have access to at least one workspace. Deleted on request, and in any case within 30 days after the last workspace you belong to ends, except records we must keep by law.
Customer DataThe customer's decision, for the life of their workspace. What a customer archives is kept as its history until it deletes it.
Items a user deletesRestorable for 7 days, then permanently removed, including any files attached to them.
What a workspace has learnedFor the life of the workspace. Individual entries can be deleted in settings or purged on request.
Closed workspacesHeld for 7 days in case the customer asks us to restore, then permanently removed. After an agreement ends, the customer gets a 30-day export window first.
BackupsEncrypted backups roll off within 30 days, so deleted data leaves them inside that period.
Operational and server logsDays, and designed to contain no personal data.
Contracts, invoices, and correspondenceAs long as commercial and tax law requires, typically up to 10 years after the relationship ends.
Business-development contactsUntil you ask us to stop, or after two years without any engagement.

Data sent to the AI model provider is covered in "AI processing" above.

16How we protect data

  • Each workspace's data is isolated at the database level, and that isolation is verified by automated tests before changes ship.
  • Data is encrypted in transit and at rest, and credentials for connected services get a further layer of encryption, with the keys held server-side only.
  • Uploaded files are private: they are served only through short-lived links issued after an access check, and images are re-encoded on upload, which strips embedded metadata.
  • Access follows least privilege: roles and per-account rules control who sees what, and our own staff's access is limited to running and supporting the service.
  • The workspace's AI data policy is enforced on every call to a model, with no way around it, and AI access is logged. Our application logs are designed to hold no personal data.
  • Backups are encrypted, and restore and incident-response procedures are documented.

No system is perfectly secure. We do not claim any certification we do not hold, and we will tell you plainly if something goes wrong. Customers and prospective customers can ask us at info@cozmond.com for our security overview, which describes these measures in full. If you believe you have found a vulnerability, please write to the same address.

17Your rights

You have rights over your personal data. Which of them apply depends on where you live, but in practice we honor all of the following for everyone whose data we hold as a controller:

  • Access: to know whether we hold your data and to receive a copy, with an explanation of how it is used.
  • Correction: to have inaccurate data fixed and incomplete data completed.
  • Deletion: to have your data erased where there is no longer a lawful reason to keep it.
  • Portability: to receive what you gave us in a machine-readable form, and to have it sent to another provider where that is feasible.
  • Restriction and objection: to have processing limited, and to object to anything we do on the basis of legitimate interests, including our contacting you.
  • Withdrawing consent, where consent is the basis, at any time, without affecting what came before.

Türkiye

This policy is also the disclosure required by Article 10 of Law No. 6698 (KVKK). Article 11 gives you closely matching rights: to learn whether your data is processed and to ask about it, to learn the purpose and whether it is used accordingly, to know the recipients in Türkiye or abroad, to ask for correction, deletion, or destruction and for those to be notified to anyone who received the data, to object to a result produced solely by automated analysis, and to claim compensation for damage caused by unlawful processing.

United States

We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of. Where a state law gives you rights of access, correction, deletion, or portability, we honor them as described here, we will not treat you differently for asking, and you can appeal a refusal by replying to our answer.

How to exercise them

Email info@cozmond.com, or write to the addresses in "Who we are". We will confirm receipt, may ask you to verify your identity, and will answer within one month, or within 30 days under KVKK, telling you if a complex request needs longer. There is no fee unless a request is manifestly unfounded or excessive. You may also complain to a supervisory authority: in Türkiye, the Personal Data Protection Authority; in the European Union, the authority in your country; in the United Kingdom, the Information Commissioner's Office.

If your data sits inside a customer's workspace, we are a processor for it: we will pass your request to that customer without undue delay and support their answer, because only they can decide it. A workspace member who wants a record about themselves corrected or removed can usually ask their own admin.

18Automated decision-making

We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you. AI features in the Platform produce analysis and suggestions for the people using it, and a person decides what to do with them. Where the Platform scores or prioritizes accounts or deals, that is decision support for the customer's team and is not applied to individuals.

19If something goes wrong

If a personal data breach occurs, we will act on it immediately, contain it, and notify the affected customers and the competent authorities as applicable law requires, and the affected individuals where the law requires it or the risk to them warrants it. Our customer agreements commit us to notifying an affected customer without undue delay, and in any case within 48 hours of confirming a breach affecting their workspace, with the information they need for their own obligations.

20Children

The Platform is a business tool for professional teams. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.

21Links to other services

The Platform and our website may link to third-party services, including the providers you can connect. Their privacy practices are their own, and this policy does not cover them. Please read their policies before connecting or using them.

22Changes to this policy

We may update this policy as the service and the law evolve. Every version carries its effective date at the top of this page, and previous versions are available on request. Material changes, including any new purpose for which we would use personal data, are announced to workspace admins by email or in the product before they take effect, and where the law requires it we will ask for consent.

23Contact

Questions, requests, complaints, and security reports: info@cozmond.com. Postal addresses for both companies are in "Who we are". If you contact us about data inside a customer's workspace, please tell us which organization it is so that we can refer your request to the right controller quickly.

Cozmond

A Revenue Brain that actually sells.

Book a callSign inCustom implementationPrivacyTerms

© 2026 Cozmond