Privacy Policy

1. Our Commitment to Data Privacy

Protecting the privacy of individuals who provide us with personal information ("Personal Data") is of sincere importance to Kotzilla and to the way we do business. You have shown your trust in us by interacting with our Site and Platform and we value that trust. To this end, we are committed to respecting data privacy legislation, and in particular the (EU) 2016/679 General Data Protection Regulation of the European Parliament and of the Council of 27 April 2016 on the protection of persons with regard to the processing of personal data (the "Applicable Law").

2. General provisions

This Privacy Policy (the "Policy") describes how Kotzilla SAS ("Kotzilla", "we", or "us") collects, uses, stores, shares and protects your information in connection with services offered by Kotzilla as a data controller including, but not limited to, services provided at or using the domain cloud-inject.io (the "Site") and/or the Cloud-Inject platform using the domain dashboard.cloud-inject.io (the "Platform") (collectively, the "Services").

This Privacy Policy applies when you ("you", the "Customer", the "User") access, visit or use any portion of the Services.

For the purposes of this Privacy Policy:

a "Customer" is a person who uses the Platform on the basis of a subscription contract, a "Prospect" is a person who browses the Website out of interest for the Services and/or signs up for the Platform access.

3. Changes to this Privacy Policy‍

We may amend this Privacy Policy from time to time to ensure transparency on all processing operations relating to you and your Personal Data in real-time. We may notify you of any substantial changes to this Privacy Policy, before the effective date of the changes, by sending an email or in another conspicuous manner reasonably designed to notify you.

Therefore, we recommend that you read this Policy regularly.

4. How we process your personal Data

We collect and process information relating to you and your use of the Services. The way we handle it differs as set out below:

Categories of personal dataRetention periodReason for retention period
CustomersIdentification Data (name, surname, company, professional contact details, email address, phone number…). Billing and financial information (payment, refundment…). Any other information you share with us in other contexts such as customer support.Perform the Services requested under the Subscription Contract (creating, setting up and maintaining your Kotzilla account…) Assist you with using the Services through our Customer Support. Contact you in order to invite you to our webinars, keep you updated with our newest features or any other commercial communication. Manage our commercial relationship with you (contracts, invoice…). Manage unpaid debts and litigation; respond to any requests from public authorities.The performance of the Subscription Contract to which you are party. Compliance with our legal obligations. Your consent if so granted to receive our marketing emails or Kotzilla’s legitimate interest in sending marketing emails.
ProspectName, surname, job position, company, email address, social networks linksContact you for a demo and send marketing communicationYour consent if you have expressly consented to Kotzilla contacting you or if you have consented to a third party transmitting your data to its business partners of which Kotzilla is a part. Kotzilla’s legitimate interest, in particular in finding new business partners. Your Consent when you agree to use cookies on the Services.
Browsing the Site and/or the PlatformStrictly necessary cookies. Preference cookies. Statistics cookies. Marketing cookies.To ensure proper functioning of the Services. To store information already entered and personalize and optimize your experience on our Website. To help us understand how the Services are used and anonymously report this information. To track your use of the Services and help us improve your user experienceYour consent if you have expressly consented to Kotzilla contacting you or if you have consented to a third party transmitting your data to its business partners of which Kotzilla is a part. Kotzilla’s legitimate interest, in particular in finding new business partners. Your Consent when you agree to use cookies on the Services.

5. How long will we retain your Personal Data ?

Your Personal Data will be handled in accordance with this Policy as long as it is needed in order to:

perform the Services; provide you with personalized Services; comply with the law and namely prevent fraud, collect any fees owed, resolve disputes, troubleshoot problems, assist with any investigation, and take other actions permitted by law.

Therefore, Kotzilla shall only retain your personal data for the following periods:

When we have no ongoing legitimate business need to process your personal data, we will delete it as soon as it is technically possible.

Categories of personal dataRetention periodReason for retention period
CustomersIdentification data (name, surname, company, email address, …). Any contractual document entered into by you and Kotzilla. Billing and financial information (payment, refunds…)3 years after termination of the contract 5 years after termination of the contract 10 years after termination of the contractTo make statistics and more generally for evidentiary purposes Most claims are subject to a 5 years statute of limitation To collect unpaid debts and more generally evidentiary purposes in accordance with the law.
ProspectProspect information (name, surname, contact details, request for a demo…)3 years after they were firstly collected or upon your request to be deleted, whichever is the soonest.To make statistics regarding your use of our Site, to give you access to a free account and otherwise contact you
Browsing the Site/Platform cookiesCookies13 months after they were firstly installed on your terminalTo allow proposer functioning of the services

6. Do we share your personal data with any third parties?

In connection with the use of the Services, some of your Personal Data may be processed by Third Parties for the purpose of carrying out some of the processing operations listed out above.

Third Party Service Providers

We may disclose your personal data to third-party service providers (the "Subprocessors"). When we do so, we make sure to work only with companies that safeguard and protect your personal data and comply with the Applicable Law in the same way that we do. Therefore, in accordance with Article 28 of the GDPR, access to your Personal Data by our Subprocessors is subject to the signature of a written agreement which allows us to monitor and control the way our Subprocessors handle your personal data.

RecipientsCategories of DataWhy do we use them?
Independent contractorsThe data is strictly necessary for them to perform their dutiesTo perform part of the Services

7. Where do we store your Personal Data ?

The Personal Data we process is stored by our hosting provider on servers located in different place in the world.

In order to perform the Services, we may transfer some of your Personal Data to third party service providers located or using servers located outside the European Union (the "EU") and the European Economic Area (the "EEA"). In such a case, we make sure that:

they are located in a country considered having an adequate level of protection by the European Union in terms of personal data or, if located in the United States: they abide by contractual provisions ensuring an equivalent level of protection of your Personal Data (such as standard contractual clauses established by the European Commission).

8. How do we protect your Personal Data ?

Here at Kotzilla, we care about the security of the Personal Data we process. Therefore, we adopt technical and organizational security measures to guarantee the security of your Personal Data by ensuring a security level adapted to the risks related to the processing and nature of such Personal Data, in particular:

**Authentication Data

Secure Traffic with HTTPS**

All data transferred between the application utilizing the SDK and the cloud platform is secured using the HTTPS protocol. This ensures that all communication between the client and server is encrypted and protected from unauthorized access. The use of HTTPS provides an additional layer of security to safeguard the data during transit.

9. Privacy by Design

The Platform Solution is developed using a "Privacy By Design" approach to ensure the compliance of Personal Data processing. It consists of adapting appropriate organizational and technical measures from the project design stage and by default, to guarantee the protection of privacy and fundamental freedoms.

10. Your rights

Unless stated otherwise by the Applicable Law or any other legal provision or applicable regulations, you may exercise the following rights:

Right to access: the right to be informed and to request access to your Personal Data. Right to data portability: the right to request a copy of your Personal Data in a structured and machine-readable format in order to hand it over to a third party.

Right to rectification: the right to ask us to modify or update inaccurate or incomplete Personal Data.

Right to erasure (right to be forgotten): the right to ask us to permanently delete Personal Data when the data subject considers that we no longer have any reason to do so collect/process.

Right to restriction of processing: the right to ask us to stop temporarily or the processing of all or part of the Personal Data.

Right to object: the right to object at any time, for reasons related to the situation of the data subject, to the processing of Personal Data concerning him/her having as its legal basis the pursuit of a legitimate interest. Unless we demonstrate a legitimate and compelling interest justifying such processing, we will only process plus the Personal Data concerned.

Right to decide the fate of your data after death: the right to impose the fate that you wish to reserve your Personal Data in the event of death.

Right to file a complaint with the supervisory authority or to get compensation from the competent courts.

11. To exercise your right, please send their request directly to us:

by post to Kotzilla SAS, 46Q Rue d’Alger 81600 Gaillac at contact@Kotzilla.io;

In accordance with Applicable Regulations, we will ask you to prove your identity.

12. Contact the competent supervisory authority

We remind you that you have the possibility to file a complaint with the competent supervisory authority. In France, this authority is the Commission National Informatique et Libertés (CNIL), whose website address is: https://www.cnil.fr.

Document VersionDate
1.230/06/2023

Beavy