Legal

Privacy Policy

What we collect, why, and what we do with it. This describes our actual practices, not a template.

Last updated:

Who we are

Cosmiqube is a remote-first software engineering company. For questions about this policy or about data we hold, email contact@cosmiqube.com.

What we collect

Information you give us. When you submit the contact form we receive your name, email address, and optionally your company name, the topic you selected, and your message. That is the entire set of fields on the form.

Information collected automatically. Our hosting provider, Cloudflare, records standard request data including IP address, user agent and timestamps for security and abuse prevention. We record your IP address with contact form submissions and use it to rate-limit the endpoint.

We do not currently run analytics, advertising trackers or third-party marketing scripts on this site. If that changes, this policy will be updated before the change goes live.

Why we use it

To reply to your enquiry, and to protect the contact form from spam and automated abuse. We do not sell personal data, and we do not share it with third parties for their own marketing.

Who processes it

  • Cloudflare — hosting, content delivery, bot protection and rate limiting.
  • Resend — delivers contact form submissions to our inbox as email.
  • Google (Gmail) — our email is hosted with Google, so messages you send us are stored there.

How long we keep it

Enquiry emails are kept for as long as the conversation is commercially relevant, and reviewed periodically. Rate-limiting records expire automatically within one hour. You can ask us to delete your enquiry at any time and we will do so.

Your rights

Depending on where you live, you may have the right to access, correct, delete or restrict the processing of your personal data, and to object to it. To exercise any of these, email contact@cosmiqube.com. We will respond within 30 days.

Regional frameworks

We are a small team, not a law firm, so we will not claim blanket compliance with every regulation in every country. Here is how we approach the main ones relevant to who we work with:

  • GDPR (EU/UK). We design our data practices — minimal collection, named processors, a clear deletion path — to support GDPR principles. If you need a Data Processing Agreement for a commercial engagement, email us and we will put one in place.
  • DPDP Act (India). We apply the same principles above to support India's Digital Personal Data Protection framework where it applies to us.
  • U.S. state privacy laws (e.g. CCPA). The same rights described above — access, correction, deletion — are available to you regardless of which state's law would otherwise apply.
  • Elsewhere. If you are contacting us from another jurisdiction with its own data protection law, the rights and contact process above apply the same way — email us and we will handle the request under whichever framework governs it.

Security

The site is served over HTTPS only. The contact form is protected by CSRF tokens, server side validation and rate limiting, and API credentials are held as encrypted secrets that never reach your browser. No system is perfectly secure, but we do not treat that as an excuse to skip the basics.

Cookies

We set one strictly necessary cookie to protect forms against cross-site request forgery. See our cookie policy for the detail.

Changes

If we change this policy we will update the date at the top of this page. Material changes will be described here rather than made silently.