Legal information
Privacy Policy
Information about how personal data is processed on cognivoxlabs.com
1. Controller
The controller responsible for the processing of personal data in connection with this website is:
Cognivox Labs
Proprietor: Jasenthu Kankanamge Shehan Akalanka Samarasena
Schweppermannstraße 27
90408 Nuremberg
Germany
Phone: +49 1522 1449074
Email: info@cognivoxlabs.de
2. General information about processing
We process personal data only where necessary to provide this website, communicate with prospective and existing clients, respond to enquiries, or take steps in connection with a potential or existing contractual relationship.
Unless a more specific legal basis is stated below, processing is primarily based on Article 6(1)(b) GDPR where it is necessary for pre-contractual measures or the performance of a contract, or Article 6(1)(f) GDPR where processing is necessary for our legitimate interests.
Our legitimate interests include operating a secure and reliable website, responding to business enquiries, and maintaining efficient business communications.
3. Website hosting and technical access data
This website is hosted on infrastructure provided by:
Hetzner Online GmbH
Industriestraße 25
91710 Gunzenhausen
Germany
When you access the website, technically necessary connection and request data may be processed. This may include:
- IP address
- date and time of access
- requested page or resource
- amount of data transferred
- browser type and version
- operating system
- referrer information
- technical request and error information
This processing is necessary to deliver the website, maintain system stability and security, identify technical problems, and protect the service against misuse.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and technically reliable operation of the website.
The application is deployed using a Cognivox Labs-managed Coolify installation running on the Hetzner infrastructure. Coolify is not integrated into the public website as a separate external analytics service.
Technical log data is retained only for as long as required for secure operation, troubleshooting and protection against abuse, subject to any applicable statutory retention requirements.
4. Contact form
You can use our website contact form to send us project and business enquiries.
Depending on the information you provide, the following data may be processed:
- name
- email address
- company
- information about the project you intend to build
- description of the problem you are trying to solve
- budget range
- timeline
- information about existing systems or tools
- any other information you voluntarily provide
Required fields are identified in the form.
We process this information to respond to your enquiry, communicate with you and, where applicable, prepare a contractual relationship.
Where the enquiry relates to entering into or performing a contract, the legal basis is Article 6(1)(b) GDPR.
Other business enquiries are processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest is responding to incoming business communications.
Submitting the public contact form does not by itself create a record in a dedicated Cognivox Labs website database. The message is, however, transmitted using Resend and subsequently processed in our business email systems.
After submission, an acknowledgement containing a copy of your enquiry may also be sent to the email address you supplied.
5. Email delivery through Resend
We use Resend to technically deliver messages submitted through the contact form.
The service is provided by:
Plus Five Five, Inc.
United States
Service: Resend
When you submit the contact form, data processed through Resend may include:
- your name
- email address
- company
- enquiry content
- sender and recipient information
- technical email delivery and status information
Resend processes this information on our behalf for the purpose of transmitting the relevant emails.
According to Resend, customer data, including message content and delivery logs, is processed or stored in the United States. Resend provides a Data Processing Addendum and describes Standard Contractual Clauses and other applicable transfer mechanisms for international transfers.
Depending on the nature of your enquiry, processing is based on Article 6(1)(b) GDPR or Article 6(1)(f) GDPR.
We retain business correspondence only for as long as required to handle the enquiry, maintain the relevant business relationship, or comply with statutory retention obligations.
Further information:
https://resend.com/security/gdpr
6. Business email and Microsoft 365
Our business email accounts are provided using Microsoft 365.
For the European market, the relevant Microsoft entity includes:
Microsoft Ireland Operations Limited
One Microsoft Place
South County Business Park
Leopardstown
Dublin 18
Ireland
If you contact us by email, or if a contact-form message reaches our business mailbox, the message and associated communication data are processed through our Microsoft 365 environment.
This can include:
- name
- email address
- company
- message content
- attachments
- date and time
- technical communication and delivery information
The applicable legal basis depends on the purpose of the communication. Pre-contractual and contractual enquiries are processed under Article 6(1)(b) GDPR. Other business communications are processed under Article 6(1)(f) GDPR.
Microsoft provides contractual privacy and security terms for its online services through the Microsoft Products and Services Data Protection Addendum. Data location and any international transfers depend on the relevant Microsoft service, tenant configuration and applicable Microsoft contractual terms.
Further information:
https://www.microsoft.com/en-us/privacy/privacystatement
7. Telephone enquiries
If you contact us by telephone, we process the information you provide to the extent necessary to handle your enquiry.
Depending on the purpose of the call, processing is based on Article 6(1)(b) GDPR or Article 6(1)(f) GDPR.
8. Scheduling through Calendly
Our website contains a link to our scheduling page on Calendly.
Provider:
Calendly LLC
United States
Calendly is not embedded as a widget on the Cognivox Labs website. Merely loading cognivoxlabs.com therefore does not establish a connection to Calendly as a result of this link.
A connection to Calendly is made when you choose to open the scheduling link and leave our website. Calendly's own privacy information then also applies.
When you schedule a meeting, information processed may include:
- name
- email address
- meeting time
- time zone
- meeting information
- other information you choose to provide
Calendly may transmit the booking information required to organize the meeting to us.
Where a booking relates to steps before entering into a contract or the performance of a contract, processing is based on Article 6(1)(b) GDPR. Otherwise, it is based on Article 6(1)(f) GDPR and our legitimate interest in efficient meeting scheduling and business communication.
Calendly provides a Data Processing Addendum addressing international data transfers.
Further information:
https://calendly.com/legal/privacy-notice
9. External links
The website contains links to third-party websites and services.
A standard external link generally establishes a connection to the destination provider only when you choose to open the link.
The respective third-party provider is responsible for processing that takes place on its own website.
10. Fonts, images and website assets
Fonts used on this website are delivered through the website itself.
In particular, fonts integrated through Next.js are locally served to visitors at runtime. Loading a Cognivox Labs page therefore does not establish a direct browser connection to Google Fonts as a result of these fonts.
Images, logos and core visual assets are also served locally through the website unless otherwise stated in this Privacy Policy.
11. Cookies, local storage and tracking
The public Cognivox Labs website currently does not use analytics, advertising or marketing cookies.
Based on the current implementation, we do not use visitor-tracking systems.
The public website therefore does not currently operate a general consent-management platform for marketing or analytics technologies.
If we introduce technologies in the future that require prior consent, we will update both the technical implementation and this Privacy Policy accordingly.
12. Recipients and processors
Personal data is disclosed only where necessary for the purposes described in this Privacy Policy or where disclosure is required by law.
Recipients may include:
- hosting and infrastructure providers
- email and communications providers
- scheduling providers
- technical service providers acting on our behalf
Where a service provider processes personal data on our behalf, processing is arranged in accordance with Article 28 GDPR where that provision applies to the relevant relationship.
13. International data transfers
Some service providers used by Cognivox Labs are established outside the European Economic Area or may process data outside the European Economic Area.
This currently applies in particular to Resend and may, depending on the relevant use and configuration, also apply to international providers such as Calendly or certain Microsoft services.
Where personal data is transferred to a third country, the transfer is made in accordance with the applicable requirements of Chapter V GDPR. Depending on the circumstances, safeguards may include an adequacy decision of the European Commission, Standard Contractual Clauses, or another legally permitted transfer mechanism.
Further details are available in the privacy and contractual documentation of the relevant provider.
14. Retention
We retain personal data only for as long as necessary for the relevant processing purpose.
Information contained in enquiries and business communications is generally retained for as long as needed to handle the enquiry, establish or maintain a business relationship, and protect legitimate business interests.
Where commercial, tax or other statutory retention obligations apply, relevant records may be retained for the required statutory period.
Once the purpose of processing no longer applies and applicable statutory retention periods have expired, the relevant data is deleted unless another legal basis permits continued retention.
15. Your rights
Subject to the applicable statutory requirements, you have the right to:
- access your personal data under Article 15 GDPR,
- request correction of inaccurate data under Article 16 GDPR,
- request erasure under Article 17 GDPR,
- request restriction of processing under Article 18 GDPR,
- receive applicable data in a portable format under Article 20 GDPR,
- object under Article 21 GDPR to processing based on Article 6(1)(e) or (f) GDPR on grounds relating to your particular situation.
Where processing is based on consent, you may withdraw that consent at any time with future effect in accordance with Article 7(3) GDPR.
To exercise your rights, contact:
16. Right to complain to a supervisory authority
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority.
For private-sector organisations based in Bavaria, the relevant authority includes:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
Phone: +49 981 180093-0
17. Data security
We use appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access and other unlawful processing.
The website is transmitted using HTTPS/TLS encryption.
18. Automated decision-making
The website functionality currently offered to the public does not use solely automated decision-making within the meaning of Article 22 GDPR in relation to website visitors.
19. Changes to this Privacy Policy
We may update this Privacy Policy when the website, service providers or applicable legal requirements change.
The current version will remain available on this page.