CCOSIGNET

Legal

Privacy Policy

This policy explains what personal data Cosignet processes, why, on what legal basis, who we share it with, and the rights you have. We keep it plain and honest.

Last updated: 18 June 2026.

Who we are

Cosignet (“we”, “us”) provides a hosted service that pauses high-risk actions and requires an explicit, payload-bound passkey approval. For any privacy matter, contact privacy@cosignet.com.

For account, security, billing, support, and service-administration data, Cosignet acts as controller. For approval payloads, approver metadata, and workflow data submitted by a customer for its own processes, Cosignet generally acts as processor under the customer's instructions, subject to the applicable Data Processing Agreement. The customer remains responsible for deciding what payload data is submitted to Cosignet and for ensuring it has a lawful basis to do so.

What we collect

Why we use it & legal bases

Sub-processors

We use a small set of providers to run the service:

Some providers may process data outside your country; where required we rely on appropriate safeguards (e.g. Standard Contractual Clauses).

Retention

During early access, confirmations (action, payload, hash, status, and the raw assertion once approved) are kept until you request removal. Avoid placing personal, secret, or sensitive data in payloads and pass references or IDs where possible. Ephemeral records (login/registration challenges, magic links, and short-lived sessions) expire automatically. Configurable automatic retention, aligned with the audit-history windows in our pricing (for example 7 days, 90 days, or 1 year by plan), is planned for paid and enterprise accounts; until it ships, confirmations persist until deletion is requested.

Public reveal is permanent. Once an approval is published to the public transparency log, its revealed action, payload, and account-designated email hash are part of an append-only, externally-anchored record and cannot be retracted, even if the underlying confirmation is later deleted. Only opt in when public, permanent disclosure is intended.

Your rights

Subject to applicable law (including the GDPR), you may request access, rectification, erasure, restriction, portability, or object to processing. To exercise any of these, or to ask about deletion, export, or data residency, contact privacy@cosignet.com. You also have the right to lodge a complaint with your local data-protection authority.

Cookies & security

We use only strictly-necessary cookies and run no tracking — details on the Cookie Policy. For how we secure data and bind approvals, see Security.

We may update this policy; material changes will be reflected by the “last updated” date above.