Legal
GDPR compliance
This page summarizes how Cogrova approaches the EU General Data Protection Regulation (GDPR) for customers and end users of cogrova.com.
Draft / placeholder. Not legal advice. Have counsel confirm roles (controller vs processor), DPAs, and transfer mechanisms for your entity.
Roles
For account and billing data of workspace owners, Cogrova typically acts as a controller. For customer content uploaded into a workspace, we generally act as a processor on documented instructions from the customer (controller).
Lawful bases
Depending on the processing, bases may include contract performance, legitimate interests (security, product improvement where appropriate), and consent (for example certain marketing cookies).
Rights of data subjects
Where GDPR applies, individuals may have rights to access, rectification, erasure, restriction, portability, and objection. Requests can be started via Contact; workspace admins should also handle end-user requests for data they control.
Processors & transfers
We use subprocessors (hosting, email, payments, analytics where enabled). International transfers rely on appropriate safeguards such as Standard Contractual Clauses where required.
Security & retention
We apply technical and organizational measures appropriate to a multi-tenant SaaS product. Retention follows account lifecycle, legal obligations, and backup windows — detail these in your DPA and Privacy Policy.