Third Party Index

Snapshot 20337

Document
Privacy policy
URL
https://kotavlabs.com/en/privacy
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
28420 bytes
SHA-256 (raw)
b6037d725657333860fcde1875846bcb782ccd31cf98a7d9a80014e8d9f56a3a
SHA-256 (normalized text)
d2aaa8f055d91ae1e9eef534856d758d0b7c01004b47931d64a44c7a78c4eb80

Normalized text

Scripts and page chrome removed; this is what change detection compares.

// legal · privacy notice
Privacy Notice
Effective 2026-08-09 · governed by Portuguese law and EU Regulation 2016/679 (GDPR) · language: EN
1. Who we are
Kotav International — business and assets, Lda. ("Kotav", "we") is the controller of personal data processed through kotavlabs.com and the Kotav Labs platform. We are a private limited company organised under the laws of Portugal, with registered office in Lisbon.
Contact: [email protected] · DPO enquiries: [email protected].
2. What we collect and why
We collect only what is necessary to provide and improve the service:
Account data (name, work email, organisation, role) — to create and manage your account. Lawful basis: contract (Art. 6(1)(b) GDPR).
Service usage (logins, pages viewed, features used, IP address, browser metadata) — to operate the platform, audit access, and detect abuse. Lawful basis: legitimate interest (Art. 6(1)(f)).
Engagement data (scan results, findings, evidence, audit logs) — to deliver the contracted service. Customer is the controller of this data; Kotav is the processor.
Billing data (company name, billing address, VAT ID, payment method via Stripe) — to invoice and account. Lawful basis: legal obligation (Art. 6(1)(c)) + contract.
Communications (emails, support tickets, demo recordings — only with consent) — to respond and improve service. Lawful basis: contract or consent.
We do not sell personal data. We do not use personal data for advertising profiling.
3. Subprocessors
We disclose our subprocessors in the Data Processing Addendum. As of 2026-08-09:
Hetzner Online GmbH (Germany) — infrastructure hosting, EU region only.
Anthropic PBC (USA / EU regions) — LLM inference for the Argus agent. Enterprise terms with zero-retention setting.
Stripe Payments Europe Ltd (Ireland) — payment processing.
Postmark / Resend — transactional email.
Google Workspace — internal email and collaboration.
We will give Customer 30 days' prior written notice of any new subprocessor via the DPA mechanism.
4. International transfers
Infrastructure for the platform sits in Germany (Hetzner DE). Some subprocessors are US-headquartered (Anthropic, Stripe). Where transfers leave the EEA, they are covered by the European Commission's Standard Contractual Clauses (Module 1 or 2 as applicable, 2021 version) and supplementary measures including encryption in transit (TLS 1.2+) and at rest.
5. Retention
Account and service-usage data: retained while the account is active and for 24 months after account closure for audit and legal-defence purposes, then deleted or anonymised. Billing records: retained for 10 years as required by Portuguese tax law (RGIT / Código Comercial).
Engagement data (scan results, findings, audit logs): retained per the contracted retention term in the Customer's Master Services Agreement, default 7 years for audit defensibility. Customer may request export or deletion at any time.
6. Your rights
Under the GDPR you have the right to:
Access your personal data (Art. 15)
Rectify inaccurate data (Art. 16)
Erasure ("right to be forgotten") (Art. 17), subject to legal-retention requirements
Restrict processing (Art. 18)
Data portability (Art. 20)
Object to processing based on legitimate interest (Art. 21)
Lodge a complaint with the Portuguese supervisory authority (CNPD) or your local authority
To exercise these rights, email [email protected]. We respond within 30 days (Art. 12(3)). Identity verification may be required.
7. Cookies
We use strictly necessary cookies for session management and CSRF protection. We do not use advertising or third-party tracking cookies. Analytics is server-side, aggregated, and does not place cookies on your device. Campaign parameters may be kept in browser session storage until that tab is closed; we do not store IP addresses or user-agent strings in marketing analytics events.
8. Security
Standard controls: TLS 1.2+ in transit, encrypted database storage, role-based access controls, JWT short-lived sessions, audit logging of administrative actions, regular vulnerability scanning of our own infrastructure (we dogfood Argus on ourselves), incident-response runbook with 72-hour notification commitment.
Report a security concern: [email protected].
9. Changes to this notice
We will notify users by email of material changes to this notice and post a revised version with at least 30 days' notice before the change takes effect. The "Effective" date at the top of this page reflects the most recent revision.
10. Translations
This notice is maintained in English as the legally controlling text. Working translations into Portuguese and Russian are available on request from [email protected] and are provided as courtesy summaries only — the English version prevails in the event of any conflict.