Privacy Notice
Effective 2026-08-09 · governed by Portuguese law and EU Regulation 2016/679 (GDPR) · language: FR(translation summary; the English version is the legally controlling text — email global@kotav.org for a certified copy)
1. Who we are
Kotav International — business and assets, Lda. ("Kotav", "we") is the controller of personal data processed through kotavlabs.com and the Kotav Labs platform. We are a private limited company organised under the laws of Portugal, with registered office in Lisbon.
Contact: global@kotav.org · DPO enquiries: global@kotav.org.
2. What we collect and why
We collect only what is necessary to provide and improve the service:
- Account data (name, work email, organisation, role) — to create and manage your account. Lawful basis: contract (Art. 6(1)(b) GDPR).
- Service usage (logins, pages viewed, features used, IP address, browser metadata) — to operate the platform, audit access, and detect abuse. Lawful basis: legitimate interest (Art. 6(1)(f)).
- Engagement data (scan results, findings, evidence, audit logs) — to deliver the contracted service. Customer is the controller of this data; Kotav is the processor.
- Billing data (company name, billing address, VAT ID, payment method via Stripe) — to invoice and account. Lawful basis: legal obligation (Art. 6(1)(c)) + contract.
- Communications (emails, support tickets, demo recordings — only with consent) — to respond and improve service. Lawful basis: contract or consent.
We do not sell personal data. We do not use personal data for advertising profiling.
3. Subprocessors
We disclose our subprocessors in the Data Processing Addendum. As of 2026-08-09:
- Hetzner Online GmbH (Germany) — infrastructure hosting, EU region only.
- Anthropic PBC (USA / EU regions) — LLM inference for the Argus agent. Enterprise terms with zero-retention setting.
- Stripe Payments Europe Ltd (Ireland) — payment processing.
- Postmark / Resend — transactional email.
- Google Workspace — internal email and collaboration.
We will give Customer 30 days' prior written notice of any new subprocessor via the DPA mechanism.
4. International transfers
Infrastructure for the platform sits in Germany (Hetzner DE). Some subprocessors are US-headquartered (Anthropic, Stripe). Where transfers leave the EEA, they are covered by the European Commission's Standard Contractual Clauses (Module 1 or 2 as applicable, 2021 version) and supplementary measures including encryption in transit (TLS 1.2+) and at rest.
5. Retention
Account and service-usage data: retained while the account is active and for 24 months after account closure for audit and legal-defence purposes, then deleted or anonymised. Billing records: retained for 10 years as required by Portuguese tax law (RGIT / Código Comercial).
Engagement data (scan results, findings, audit logs): retained per the contracted retention term in the Customer's Master Services Agreement, default 7 years for audit defensibility. Customer may request export or deletion at any time.
6. Your rights
Under the GDPR you have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erasure ("right to be forgotten") (Art. 17), subject to legal-retention requirements
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Lodge a complaint with the Portuguese supervisory authority (CNPD) or your local authority
To exercise these rights, email global@kotav.org. We respond within 30 days (Art. 12(3)). Identity verification may be required.
7. Cookies
We use strictly necessary cookies for session management and CSRF protection. We do not use advertising or third-party tracking cookies. Analytics is server-side, aggregated, and does not place cookies on your device. Campaign parameters may be kept in browser session storage until that tab is closed; we do not store IP addresses or user-agent strings in marketing analytics events.
8. Security
Standard controls: TLS 1.2+ in transit, encrypted database storage, role-based access controls, JWT short-lived sessions, audit logging of administrative actions, regular vulnerability scanning of our own infrastructure (we dogfood Argus on ourselves), incident-response runbook with 72-hour notification commitment.
Report a security concern: global@kotav.org.
9. Changes to this notice
We will notify users by email of material changes to this notice and post a revised version with at least 30 days' notice before the change takes effect. The "Effective" date at the top of this page reflects the most recent revision.
10. Translations
This notice is maintained in English as the legally controlling text. Working translations into Portuguese and Russian are available on request from global@kotav.org and are provided as courtesy summaries only — the English version prevails in the event of any conflict.
