Privacy & security
Where your data livesis your decision.
Before we build anything, we write down which data your system handles, where it lives, which services see it and who has access. You read it, you approve it. Then we build.
And this website? Its own list is further down.
Every service.With your approval.
Every service that sees data from your system is on one list: what it is for, what it sees and where it sits. For hosting you choose: providers from Germany and Europe, for example Hetzner or netcup, data protection first. Or your own environment.
If a service is added later, it appears here first. Then you decide.
Which services your system needs is settled before we build. Provider names are trademarks of their owners. Self-hosting alone does not satisfy privacy requirements.
We are onthe list too.
Access belongs to you. Every person gets an account of their own and only the rights their job needs. That applies to us as well: whoever looks after your system at cognatio labs is on the list by name.
When someone leaves your company or our work ends, the account is blocked. The list shows the current state.
Roles and rights are defined together with you.
The same list.For ourselves.
It is how cognatiolabs.de handles data today. Client projects do not run through this website; your own list applies to them.
If any of this changes, this list and the privacy policy change first.
Security questionsbelong before the proposal.
Send us your requirements, your policies or simply your open questions. The technology is our part: location, services, access, operations. Your part is what only you can decide: who in your company may see what, how long data is kept, and how your data protection officer assesses it.
In writing, before we build
- Service listEvery service with its purpose, location and your approval.
- Access listEvery person with their job and rights.
- DPAWe conclude the data processing agreement on request.
Another question?
Can our data stay on our own servers?
Yes. On request we run your system in your own environment. What needs to be in place on your side is clarified before the proposal.
Do you use services from the United States?
Only if you approve it. Some jobs are best done by an external service, payments for example. It is on the service list first, with its purpose and location. If there is a European alternative, it is listed next to it.
Do you work with our data protection officer or our IT?
Yes. The lists are written for that: you can read them without being a developer. We answer questions about them directly.
What happens if something fails or data is lost?
That is part of operations: backups, restore rehearsals and what happens in an incident are set out in the operations plan. The Operations & support page shows what that looks like.
How do we get out again?
Code, data and access belong to you. A handover to your team or another provider is possible at any time. That is also covered on Operations & support.
We are a software provider, not a law firm. What applies to your company legally is for your data protection officer or your lawyers to assess.