Cogrova logo

Legal

GDPR compliance

This page summarizes how Cogrova approaches the EU General Data Protection Regulation (GDPR) for customers and end users of cogrova.com.

Draft / placeholder. Not legal advice. Have counsel confirm roles (controller vs processor), DPAs, and transfer mechanisms for your entity.

Roles

For account and billing data of workspace owners, Cogrova typically acts as a controller. For customer content uploaded into a workspace, we generally act as a processor on documented instructions from the customer (controller).

Lawful bases

Depending on the processing, bases may include contract performance, legitimate interests (security, product improvement where appropriate), and consent (for example certain marketing cookies).

Rights of data subjects

Where GDPR applies, individuals may have rights to access, rectification, erasure, restriction, portability, and objection. Requests can be started via Contact; workspace admins should also handle end-user requests for data they control.

Processors & transfers

We use subprocessors (hosting, email, payments, analytics where enabled). International transfers rely on appropriate safeguards such as Standard Contractual Clauses where required.

Security & retention

We apply technical and organizational measures appropriate to a multi-tenant SaaS product. Retention follows account lifecycle, legal obligations, and backup windows — detail these in your DPA and Privacy Policy.