Effective 2026-09-09
This policy explains how Cozmond collects, uses, shares, and protects personal data when you visit our website, use the Cozmond Platform, or communicate with us. The Cozmond Platform (the "Platform") is our product; "Cozmond" is the company behind it. Our customers are organizations, and access to the Platform is by invitation only.
We have written this policy to be read, not skimmed. It is specific about what we do because our customers put sensitive business data into the Platform, and they deserve to know exactly how it is handled. If anything is unclear, or you want to exercise any of your rights, contact us at info@cozmond.com.
The Cozmond Platform is operated by two affiliated companies. Which of them is responsible for your organization's personal data is the one named in its Order Form:
| Company | Registered address |
|---|---|
| OZEREN LLC | 30 N Gould St #44460, Sheridan, WY 82801, United States |
| ONAT ÖZEREN BİLGİ TEKNOLOJİLERİ VE DANIŞMANLIK | Esentepe Mah. Talat Paşa Cad. No:5 Kapı No:1, Şişli, İstanbul, Türkiye |
Where there is no Order Form, for example if you are visiting our website or evaluating the Platform, the responsible company is OZEREN LLC, unless you or your organization are established in Türkiye, in which case it is ONAT ÖZEREN BİLGİ TEKNOLOJİLERİ VE DANIŞMANLIK. In this policy, "Cozmond", "we", and "us" mean the company responsible for you, and "the Platform" means the Cozmond Platform. Both companies can be reached at info@cozmond.com or by post at the addresses above.
We handle personal data in two legally different roles, and the difference decides who you should contact.
If your information sits inside a customer's workspace, for example because you are a contact or customer of theirs, or you took part in a call they recorded, that customer is responsible for it and is the one to ask. We pass any request we receive to them without undue delay and help them answer it.
Our website has no forms, no analytics, and no advertising or social-media trackers. Our hosting provider keeps standard server logs (IP address, browser type, page requested, time) to deliver the site and protect it against abuse. They are short-lived and are never used to identify or profile a visitor.
When you are invited into a workspace, we collect:
We hold business contact details (name, role, work email, phone) and our correspondence with the people we deal with at customers, and at organizations we talk to about Cozmond. We get these from you, from your organization, from a referral, or from a public professional source. You can ask us to stop contacting you at any time.
Data-protection law requires a legal basis for each use of personal data. Ours are below. We do not run advertising, we do not sell personal data, and we use no third-party analytics or tracking.
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing and supporting the Platform, including signing you in, running the features you use, sending service messages such as invitations and password resets, and answering your questions | Your account, your place in the workspace, preferences, workspace activity, your messages to us | Performance of the contract with your organization; where you are not a party to it, our legitimate interest in providing the service your organization asked for; our legal obligations where a notice is required by law |
| Keeping the Platform secure: detecting and blocking abuse, investigating incidents, and keeping workspaces isolated from one another | Security events, server logs, workspace activity | Our legitimate interest in running a secure service, and our obligation to protect personal data |
| Contracting, billing, and accounting with your organization | Business contact details, order and invoice records, correspondence | Performance of the contract; our legal obligations under commercial and tax law |
| Staying in touch with people at organizations that may become customers | Business contact details | Our legitimate interest in growing our business, balanced against your interests; you can object at any time |
| Improving the service, using information that cannot identify anyone | Usage measurements and de-identified, aggregated information | Our legitimate interest in improving the service |
| Establishing, exercising, or defending legal claims, and complying with law | Whatever is relevant to the matter | Legal obligation; our legitimate interest in protecting our rights |
Where we rely on legitimate interests, we have assessed that the processing is necessary and does not override your rights, and you can ask us for a summary of that assessment. Where we rely on consent, such as when you connect your own mailbox, you can withdraw it at any time without affecting processing that already happened.
Customers use the Platform to manage their revenue work. Depending on what they turn on, a workspace can hold:
We process all of it only to provide the service to that customer, on their instructions and under the DPA. What is collected, why, and for how long is the customer's decision, and their admins control who on their team sees what.
Customers and their team members can connect third-party services. Every connection is authorized deliberately, by an admin for the workspace or by the individual for a personal connection such as their own mailbox, and can be disconnected at any time. Connections use each provider's official authorization flow, ask for the narrowest permissions the feature needs, and are read-only wherever the provider allows it. Stored credentials are encrypted. Disconnecting stops future syncing; data already in the workspace stays until the customer deletes it. Each provider's own terms govern its side.
Cozmond Platform's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We use information received from Google APIs only to provide the features the connecting user set up: charting the spreadsheets and channel statistics they select, and putting their business correspondence on the right account timelines. We do not use it for advertising; we do not sell it; we do not transfer it to anyone else except as needed to provide those features, for security, or to comply with applicable law; we do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models; and no person at Cozmond reads it except with the workspace's permission for support, for security, or to comply with law. Workspace members with access to an account see the correspondence on it, because that is the feature the connecting user set up.
Spreadsheet and video connections read only what the connecting person selects. Gmail connections use the read-only Gmail permission and are covered in "Email connectors (Gmail and Outlook)" below. Each connection receives only its own permissions: a spreadsheet connection can never read mail, and a mailbox connection can never read files.
Outlook mailboxes connect with a read-only mail permission and follow the same rules as Gmail. Workbook, CRM, and billing connections read only the records or files an admin selects; a billing connection sees payment totals, never card numbers. Where a source holds free-form pages, reading their body text is a separate choice the admin makes and can undo. A customer can also import accounts once from a spreadsheet file, which is processed and not kept. Call recording services are covered in "Call recordings and transcripts" below. To show company logos, we ask a public icon service for the icon of an account's web domain, sending the domain only and no personal data.
A team member can connect their own work mailbox so that their correspondence with the companies in the workspace appears on those companies' timelines. Because this touches a mailbox, here is exactly what it does and does not do.
The Platform does not record calls. Transcripts reach a workspace in one of two ways: from a call recording service the customer connects, or pasted in by a team member.
The Platform's AI features (workspace agents, account intelligence, call analysis, report writing, drafting, and similar) run on large language models from Anthropic, called through Cozmond's own account. When a feature runs, the relevant workspace data is sent securely to the model provider, retained only briefly for the provider's safety checks and then deleted, and is never used to train models. We do not use customer-supplied AI accounts, so a customer's data is never mixed with a third party's account.
The Platform learns inside each customer's workspace so that it works better for that customer, for example the terminology its team uses and which of its suggestions the team accepted. This learned data belongs to that workspace: it is visible and deletable in the workspace's settings, it is never shared with or used for another customer, and it is deleted with the workspace. A customer can also ask us to purge learned entries that relate to a specific person, for example to honor a request from that person.
Across customers, we use only information that has been de-identified and aggregated so that it cannot identify a customer, a person, or any customer's customer. We never use one customer's content for another customer, and we never include anything received from a connected mailbox or from Google or Microsoft services. The limits we hold ourselves to, and the customer's right to opt out, are set out in our Terms of Service.
We run the Platform on a small number of specialist providers. Each processes data only on our instructions, under a written data-processing agreement, may not use it for its own purposes, and is reviewed before we use it.
| Type of provider | What it does for us | Processing location |
|---|---|---|
| Managed cloud database, authentication, and file storage | Stores each workspace's data, files, and encrypted backups, and runs sign-in. Workspaces are hosted in the European Union today; a United States region is planned. | European Union |
| Application hosting and content delivery | Runs the Platform and delivers it to your browser. | United States |
| AI model provider | Runs the models behind the AI features, and is named in "AI processing" above. | United States |
| Transactional email delivery | Sends invitations, email confirmations, and password resets. | United States |
| Public icon lookup service | Returns a company logo for a web domain. Receives the domain only, never personal data. | United States |
We name each provider individually, with its role and location, in the Data Processing Agreement every customer signs, and we give at least 30 days' notice before we add or replace one. If you would like the current list of named providers, ask us at info@cozmond.com and we will send it. Services a customer chooses to connect are not our service providers; the customer authorizes those directly. We also disclose personal data where the law requires it, telling the affected customer unless we are prevented from doing so. We share it with nobody else, and we never sell it.
Customer workspace databases and files are stored in the European Union. Some of our providers process data in the United States, as the table above shows, which means that AI processing, transactional email, and application hosting involve transfers out of the country where you or your organization are located.
We keep personal data only for as long as the purpose requires, then delete or de-identify it. The main periods are:
| Data | Retention |
|---|---|
| Your account, including your profile, preferences, and security events | Kept while you have access to at least one workspace. Deleted on request, and in any case within 30 days after the last workspace you belong to ends, except records we must keep by law. |
| Customer Data | The customer's decision, for the life of their workspace. What a customer archives is kept as its history until it deletes it. |
| Items a user deletes | Restorable for 7 days, then permanently removed, including any files attached to them. |
| What a workspace has learned | For the life of the workspace. Individual entries can be deleted in settings or purged on request. |
| Closed workspaces | Held for 7 days in case the customer asks us to restore, then permanently removed. After an agreement ends, the customer gets a 30-day export window first. |
| Backups | Encrypted backups roll off within 30 days, so deleted data leaves them inside that period. |
| Operational and server logs | Days, and designed to contain no personal data. |
| Contracts, invoices, and correspondence | As long as commercial and tax law requires, typically up to 10 years after the relationship ends. |
| Business-development contacts | Until you ask us to stop, or after two years without any engagement. |
Data sent to the AI model provider is covered in "AI processing" above.
No system is perfectly secure. We do not claim any certification we do not hold, and we will tell you plainly if something goes wrong. Customers and prospective customers can ask us at info@cozmond.com for our security overview, which describes these measures in full. If you believe you have found a vulnerability, please write to the same address.
You have rights over your personal data. Which of them apply depends on where you live, but in practice we honor all of the following for everyone whose data we hold as a controller:
This policy is also the disclosure required by Article 10 of Law No. 6698 (KVKK). Article 11 gives you closely matching rights: to learn whether your data is processed and to ask about it, to learn the purpose and whether it is used accordingly, to know the recipients in Türkiye or abroad, to ask for correction, deletion, or destruction and for those to be notified to anyone who received the data, to object to a result produced solely by automated analysis, and to claim compensation for damage caused by unlawful processing.
We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of. Where a state law gives you rights of access, correction, deletion, or portability, we honor them as described here, we will not treat you differently for asking, and you can appeal a refusal by replying to our answer.
Email info@cozmond.com, or write to the addresses in "Who we are". We will confirm receipt, may ask you to verify your identity, and will answer within one month, or within 30 days under KVKK, telling you if a complex request needs longer. There is no fee unless a request is manifestly unfounded or excessive. You may also complain to a supervisory authority: in Türkiye, the Personal Data Protection Authority; in the European Union, the authority in your country; in the United Kingdom, the Information Commissioner's Office.
If your data sits inside a customer's workspace, we are a processor for it: we will pass your request to that customer without undue delay and support their answer, because only they can decide it. A workspace member who wants a record about themselves corrected or removed can usually ask their own admin.
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you. AI features in the Platform produce analysis and suggestions for the people using it, and a person decides what to do with them. Where the Platform scores or prioritizes accounts or deals, that is decision support for the customer's team and is not applied to individuals.
If a personal data breach occurs, we will act on it immediately, contain it, and notify the affected customers and the competent authorities as applicable law requires, and the affected individuals where the law requires it or the risk to them warrants it. Our customer agreements commit us to notifying an affected customer without undue delay, and in any case within 48 hours of confirming a breach affecting their workspace, with the information they need for their own obligations.
The Platform is a business tool for professional teams. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
The Platform and our website may link to third-party services, including the providers you can connect. Their privacy practices are their own, and this policy does not cover them. Please read their policies before connecting or using them.
We may update this policy as the service and the law evolve. Every version carries its effective date at the top of this page, and previous versions are available on request. Material changes, including any new purpose for which we would use personal data, are announced to workspace admins by email or in the product before they take effect, and where the law requires it we will ask for consent.
Questions, requests, complaints, and security reports: info@cozmond.com. Postal addresses for both companies are in "Who we are". If you contact us about data inside a customer's workspace, please tell us which organization it is so that we can refer your request to the right controller quickly.