Privacy Policy
How we collect, use, and protect your personal information
Introduction
cosmolcolor Ltd ("we", "our", or "us") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website cosmolcolor.world or use our services.
As a company registered in Scotland (Registration Number: 74968532), we comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as well as applicable EU data protection laws for our European clients.
Data Controller Information
The data controller responsible for your personal information is:
- Company: cosmolcolor Ltd
- Address: 253 Park Road, Edinburgh, EH5B 7JA, Scotland, United Kingdom
- Registration Number: 74968532
- VAT Number: GB743625195
- Email: privacy@cosmolcolor.world
- Phone: +44 1311957737
Data Collection
We collect several types of information from and about users of our website and services. The data we collect includes:
Personal Information You Provide
When you interact with our services, we may collect personal information that you voluntarily provide, including:
- Contact information (name, email address, phone number, company name)
- Professional information (job title, company details, industry)
- Communication preferences and marketing consent
- Information provided in contact forms, consultation requests, or correspondence
- Account information if you create an account with our platforms
Automatically Collected Information
When you visit our website, we automatically collect certain information about your device and usage patterns:
- Device information (IP address, browser type, operating system)
- Usage data (pages visited, time spent, referral sources)
- Location information (general geographic location based on IP address)
- Technical information for website functionality and security
How We Use Your Information
We use the personal information we collect for various legitimate business purposes. How we use your information depends on the specific services you use and how you interact with us. We use of your data includes:
Service Provision
- Providing and maintaining our strategic alignment management services
- Processing consultation requests and service enquiries
- Delivering customer support and technical assistance
- Managing client relationships and project implementations
Communication
- Responding to your enquiries and providing requested information
- Sending service updates, newsletters, and marketing communications (with consent)
- Notifying you about changes to our services or policies
- Conducting customer satisfaction surveys and feedback collection
Business Operations
- Improving our website, services, and customer experience
- Conducting business analysis and market research
- Ensuring security and preventing fraud or misuse
- Complying with legal obligations and regulatory requirements
Cookies and Tracking Technologies
We may use cookies and tracking technologies for analytics, advertising, and remarketing purposes, including Google Ads. These technologies help us measure campaign effectiveness, deliver relevant advertisements, and improve our services. You can manage your cookie preferences at any time through our cookie consent banner.
Our use of cookies includes:
- Necessary cookies: Essential for website functionality and security
- Analytics cookies: Google Analytics to understand website usage and performance
- Functional cookies: To remember your preferences and settings
- Marketing cookies: Google Ads and remarketing to show relevant advertisements
For detailed information about our cookie usage, please see our Cookie Policy.
Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
- Consent: Where you have given clear consent for specific processing activities
- Contract: Processing necessary for performing our services or entering into a contract
- Legitimate interests: For business operations, security, and service improvement
- Legal obligation: To comply with applicable laws and regulations
Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
- Service providers: Trusted third parties who assist in operating our website and services
- Legal requirements: When required by law, court order, or regulatory authority
- Business transfers: In connection with mergers, acquisitions, or asset sales
- Protection of rights: To protect our rights, property, or safety, or that of others
All third-party service providers are bound by confidentiality agreements and data protection requirements.
International Data Transfers
As we serve clients across the European Union, your personal data may be transferred to and processed in countries outside your home jurisdiction. When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions recognising equivalent data protection standards
- Other appropriate safeguards as required by applicable law
Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Our data retention periods include:
- Contact enquiries: 3 years from last contact
- Client data: Duration of service relationship plus 7 years for legal requirements
- Marketing data: Until consent is withdrawn or 3 years from last engagement
- Website analytics: 26 months (Google Analytics default retention)
After the retention period expires, we securely delete or anonymise your personal information.
Your Rights
Under GDPR and UK data protection laws, you have several rights regarding your personal information:
- Right of access: Request copies of your personal data
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data
- Right to restrict processing: Request limitation of how we use your data
- Right to data portability: Request transfer of your data to another service
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Withdraw consent for specific processing activities
To exercise any of these rights, please contact us at privacy@cosmolcolor.world or +44 1311957737. We will respond to your request within one month.
Data Security
We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. Our security measures include:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and employee training
- Secure data centres and hosting infrastructure
- Incident response and breach notification procedures
However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.
Children's Privacy
Our services are not directed to children under the age of 16, and we do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete such information promptly.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable laws. We will notify you of any material changes by posting the updated policy on our website and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.
Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: privacy@cosmolcolor.world
- Phone: +44 1311957737
- Post: cosmolcolor Ltd, 253 Park Road, Edinburgh, EH5B 7JA, Scotland, United Kingdom
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not handled your personal data appropriately.
Supervisory Authority
If you have concerns about how we handle your personal data, you can contact the UK Information Commissioner's Office:
- Website: ico.org.uk
- Phone: 0303 123 1113
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF