1. Purpose of This Policy
1.1. This Privacy Policy explains how MCTO Advisory d.o.o. ("MCTO", "we", "us", or "our") collects, uses, stores, shares, protects, and otherwise processes personal data in connection with Cogeto.
1.2. This Policy applies to personal data processed by MCTO as data controller, including data relating to:
- visitors and users of
www.cogeto.euandmy.cogeto.eu; - persons who register or administer Cogeto Accounts;
- individual Customers;
- representatives, administrators, employees, or other users of Business Customers;
- billing, commercial, support, security, and account-management contacts; and
- persons who communicate with MCTO regarding Cogeto.
1.3. This Policy also explains the separate role MCTO has when personal data is processed inside a Customer's dedicated Cogeto Instance. In that context, where the Customer determines the purposes and means of processing, the Customer is the controller and MCTO acts as processor under the Cogeto Data Processing Agreement.
1.4. This Policy is not intended to convert processing that is necessary for performance of the Cogeto contract, compliance with law, or legitimate interests into consent-based processing. Where consent is the appropriate legal basis, consent is requested separately and may be withdrawn as described below.
2. Who Is the Data Controller?
For personal data processed for Cogeto account administration, platform security, customer relationship management, commercial administration, support, and related purposes, the controller is:
MCTO Advisory d.o.o.
Bregana Pisarovinska 37
10451 Bregana Pisarovinska
Croatia
VAT ID / OIB: HR74348605691
Email: legal@cogeto.eu
MCTO has offices at Radnička cesta 34, 10000 Zagreb, Croatia.
3. Roles Within the Cogeto Service
3.1. Cogeto Account and Platform Data
For data used to register, verify, secure, administer, support, and commercially manage Cogeto Accounts and Customers, MCTO is the controller.
MVT Solutions Group d.o.o., Podolje 11A, 10000 Zagreb, Croatia, VAT ID / OIB HR85300439344 ("MVT"), provides implementation, integration, infrastructure-operation, maintenance, and related technical services to MCTO. To the extent MVT processes personal data for these purposes on MCTO's instructions, MVT acts as MCTO's processor.
3.2. Personal Data Inside a Customer Instance
A dedicated Cogeto Instance is administered by the Customer. MCTO does not determine the Customer's business purposes for data placed in the Instance.
Where a Customer processes personal data inside its Instance and qualifies as a controller under applicable data-protection law:
- Customer: controller;
- MCTO: processor;
- MVT: subprocessor for implementation, integration, infrastructure operation, maintenance, and related technical services;
- OVHcloud: subprocessor for European hosting and block storage;
- Mailgun / Sinch Email: subprocessor for outbound email where the Instance uses the configured email-delivery service.
The detailed processor obligations are set out in the Cogeto Data Processing Agreement.
3.3. No Routine Inspection of Instance Content
MCTO and MVT do not routinely inspect, read, or monitor the contents of Customer databases or the Customer's ordinary activity inside a dedicated Instance.
Exceptional, controlled access may occur where reasonably necessary and legally permitted, including for security incidents, serious technical investigation, suspected unlawful activity, protection of systems or third parties, compliance with a legal obligation or lawful authority request, or where the Customer expressly requests or authorises such access.
4. Categories of Personal Data We Process
Depending on how Cogeto is used, MCTO may process the following categories of personal data.
4.1. Account and Identity Data
- email address;
- internal user or account identifier;
- account role, such as administrator or user;
- email-verification status;
- optional first name and/or surname where provided by the user.
4.2. Customer, Business, and Billing Data
For account administration, billing, tax, invoicing, and commercial purposes, we may process:
- first name and surname;
- billing or registered address;
- country of residence or establishment;
- company or business legal name, where applicable;
- VAT ID/OIB or another applicable tax identifier, where provided or required;
- association between a business organisation and its Account administrator or users; and
- other billing information reasonably necessary to identify the Customer, administer purchases, maintain accounting records, or comply with tax and legal obligations.
4.3. Security, Audit, and Technical Data
- login and account-security events;
- timestamps;
- internal user IDs;
- role or permission changes;
- provisioning and instance-management events;
- security alerts and incident-related records;
- technical request and error information where necessary for operation or security;
- IP-address information in truncated form.
Cogeto truncates IP addresses when audit information is written. IPv4 addresses are truncated to /24 and IPv6 addresses to /48. The full IP address is not intentionally retained in the Cogeto audit record.
4.4. Audit Ledger Information
Cogeto maintains an append-only, hash-chained audit log for security, integrity, accountability, and traceability. Audit rows use internal user identifiers rather than names or email addresses.
4.5. Credit and Commercial Data
- Cogeto Credit balance and ledger entries;
- purchased and promotional Credit events;
- usage deductions;
- transaction identifiers received from Paddle;
- transaction amount, currency, status, and related reconciliation information;
- information necessary to associate a payment transaction with a Cogeto Account;
- chargeback, refund, or payment-reversal status where relevant.
MCTO does not receive or store full payment-card numbers, card security codes, or equivalent payment credentials used at Paddle checkout.
4.6. Communications and Support Data
- email and support communications;
- legal or privacy requests;
- complaints;
- information voluntarily supplied when requesting assistance;
- records necessary to document the handling and resolution of a request.
4.7. Customer-Instance Email Data
Where a Customer Instance sends email through the configured Mailgun service, the email service may process sender, recipient, message, routing, delivery, suppression, and event information necessary to transmit and operate the email function.
Platform/provisioning email and Customer-Instance email use logically separate configurations. Instance email data is associated with the relevant Instance and is not intentionally pooled into another Customer's Instance data.
5. Data We Do Not Intentionally Collect at Platform Level
5.1. MCTO does not require payment-card credentials to be entered into Cogeto. Payment credentials are handled by Paddle and its payment partners.
5.2. MCTO does not maintain a general activity history describing what a Customer does inside the Customer's dedicated application database.
5.3. Cogeto does not intentionally store full IP addresses in its append-only audit rows.
5.4. If a Customer chooses to process additional personal data inside its own Instance, that data is Customer Data and is governed by the controller-processor arrangement described in the Data Processing Agreement.
6. Why We Process Personal Data and Our Legal Bases
| Purpose | Typical data | Legal basis under GDPR |
|---|---|---|
| Create, verify, and administer an Account | Email, internal ID, role, optional name | Performance of a contract or steps requested before entering a contract — Art. 6(1)(b) |
| Provide and technically administer Cogeto | Account data, provisioning records, Credit and usage records | Performance of a contract — Art. 6(1)(b) |
| Administer Customer billing, tax, and business information | Name, surname, billing or registered address, country, company legal name, VAT ID/OIB or other tax identifier where applicable | Performance of a contract or steps requested before entering a contract — Art. 6(1)(b); compliance with accounting, tax, invoicing, and other legal obligations — Art. 6(1)(c) |
| Maintain the Credit ledger and reconcile Paddle transactions | Credit entries, transaction identifiers and status | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f) |
| Security, fraud prevention, abuse prevention, audit integrity, and incident investigation | Internal IDs, timestamps, truncated IP data, security events | Legitimate interests in securing Cogeto and protecting customers and MCTO — Art. 6(1)(f); legal obligation where applicable — Art. 6(1)(c) |
| Send essential technical, security, balance, legal, or service communications | Email and Account information | Contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f); legal obligation where applicable — Art. 6(1)(c) |
| Respond to support, complaints, privacy requests, and legal correspondence | Contact and communication data | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f) |
| Accounting, tax, fraud, dispute, and compliance records | Business identity, transaction and commercial records | Legal obligation — Art. 6(1)(c); legitimate interests in establishing, exercising, or defending legal claims — Art. 6(1)(f) |
| Optional direct marketing from MCTO, where offered | Email and optional name | Consent — Art. 6(1)(a), unless another lawful basis is expressly permitted by applicable law |
6.1. Where processing is based on legitimate interests, MCTO considers the necessity of the processing, its impact on individuals, and reasonable expectations arising from the use and security of a cloud service.
6.2. Where processing is necessary to provide the contractual Service, refusal to provide required data may mean that MCTO cannot create or maintain the relevant Account or provide the requested functionality.
6.3. Where processing is required by law, MCTO may be unable to delete or stop processing the relevant information until the legal obligation ends.
7. Consent and Optional Processing
7.1. Use of Cogeto is not generally based on consent. Account administration, security, provision of the Service, essential communications, Credit management, and legal compliance are processed on other lawful bases described in Section 6.
7.2. Where MCTO asks for consent, such as for optional marketing, consent is:
- voluntary;
- specific to the stated purpose;
- not a condition of receiving the core Service unless the processing is genuinely necessary for that Service; and
- withdrawable at any time for future processing.
7.3. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal and does not require MCTO to stop processing the same data where another lawful basis independently applies.
Optional Marketing Consent Wording
Where MCTO offers optional marketing communications, the following or substantially equivalent wording may be used in the interface:
Optional marketing consent: I consent to MCTO Advisory d.o.o. using my email address and, if provided, my name to send me information about Cogeto products, features, offers, and related MCTO services. I understand that this consent is optional and that I may withdraw it at any time, including by using the unsubscribe option in a marketing message or contacting legal@cogeto.eu.
8. Paddle and Payment Processing
8.1. Purchases of Cogeto Purchased Credits are handled through Paddle as Merchant of Record.
8.2. Paddle acts as the seller for the payment transaction and handles payment collection, payment methods, applicable taxes and VAT, invoicing, payment fraud controls, refunds, and chargebacks under Paddle's own terms and legal obligations.
8.3. Paddle processes payment and buyer information as an independent controller where it determines the purposes and means of processing required for its Merchant-of-Record, tax, payment, fraud-prevention, and legal functions.
8.4. When Paddle Checkout or Paddle price-preview functionality is used, Paddle may receive technical information directly from the user's browser or device, including the user's full IP address, in order to determine approximate location, applicable taxes, localized pricing or payment requirements, prevent fraud, and comply with legal obligations. MCTO does not intentionally retain the full IP address in Cogeto audit records; IP addresses recorded by Cogeto for audit purposes are truncated as described in Section 4.3.
8.5. MCTO does not receive full payment-card credentials. MCTO receives transaction metadata necessary to credit the correct Cogeto Account, reconcile the transaction, administer the Service, handle support, and meet accounting and legal requirements.
8.6. The Paddle contracting entity depends on the buyer's location and Paddle's current structure. Paddle's current buyer terms identify Paddle.com Market Limited, 30 Old Bailey, London, EC4M 7AU, United Kingdom, as the relevant entity for most buyers outside the United States and Canada, with other Paddle group entities applying in certain locations.
9. Processors, Subprocessors, and Other Recipients
MCTO limits disclosures to what is reasonably necessary for the relevant purpose and applicable legal obligations.
9.1. MVT Solutions Group d.o.o.
MVT Solutions Group d.o.o.
Podolje 11A
10000 Zagreb
Croatia
VAT ID / OIB: HR85300439344
Role: implementation, integration, technical operation, maintenance, infrastructure administration, and related technical services.
MVT acts as processor for MCTO in relation to platform-level personal data and as subprocessor where MCTO processes Customer-Instance personal data on behalf of a Customer.
9.2. OVHcloud
OVH SAS
2 rue Kellermann
59100 Roubaix
France
Role: European cloud hosting, compute infrastructure, network services, and block storage.
Cogeto Customer Instances and their attached storage are hosted in European OVHcloud infrastructure selected by MCTO.
9.3. Mailgun / Sinch Email
Mailgun / Sinch Email
Processing region used by Cogeto: European Union
Role: outbound transactional and application email for the Cogeto Platform and, through separate configuration, Customer Instances.
The exact Sinch Email contracting entity is the entity identified in MCTO's applicable Mailgun/Sinch Service Order. Mailgun's current terms operate under the Sinch Email group structure, which includes Mailgun entities. Cogeto configures the EU region for message-data processing.
9.4. Paddle
Role: Merchant of Record and payment transaction provider for Purchased Credits.
Paddle is generally an independent controller for payment, buyer, fraud, tax, invoicing, and chargeback processing rather than a Cogeto Customer-Instance subprocessor.
9.5. Authorities and Professional Advisers
MCTO may disclose personal data to courts, law-enforcement bodies, regulators, tax authorities, supervisory authorities, legal counsel, auditors, insurers, or other recipients where disclosure is required by law or reasonably necessary to establish, exercise, or defend legal rights.
10. International Data Transfers
10.1. MCTO's core Cogeto hosting is operated in Europe through OVHcloud.
10.2. Cogeto configures Mailgun's EU region for message-data processing. Mailgun/Sinch is an international group and may process certain account, support, security, or service information through group entities or subprocessors in accordance with its data-processing terms.
10.3. Paddle is an international Merchant of Record and may process data through the Paddle entity and infrastructure applicable to the transaction.
10.4. Where personal data is transferred outside the European Economic Area and the destination is not covered by an applicable adequacy decision, MCTO or the relevant recipient will use an appropriate transfer mechanism where required, such as European Commission Standard Contractual Clauses, together with supplementary measures where appropriate.
11. Data Retention
MCTO retains identifiable personal data only for as long as reasonably necessary for the purpose for which it was collected and as required by applicable law.
11.1. Active Account Data
Account identity and administration data is generally retained while the Account is active and is deleted or anonymised after Account closure when no longer necessary, subject to statutory retention, security, fraud, dispute, accounting, or legal requirements.
11.2. Business and Transaction Records
Company details, transaction records, Paddle reconciliation data, and other records required for accounting, tax, audit, fraud prevention, or legal claims may be retained for the period required or permitted by applicable law and no longer than reasonably necessary for those purposes.
11.3. Security and Audit Records
Cogeto's audit log is append-only and hash-chained. It records internal user IDs rather than names or email addresses and stores truncated IP information rather than full IP addresses.
Audit entries may be retained for an extended or indefinite period for integrity and security purposes only where they are no longer reasonably linkable to an identifiable person. When an Account is deleted, the link that would ordinarily associate the internal audit identifier with the deleted user is removed where technically applicable.
If an audit record remains reasonably linkable to an identifiable person, it remains personal data and is retained only for a lawful and necessary retention period.
11.4. Support and Legal Records
Support communications, complaints, privacy requests, and legal correspondence are retained for as long as reasonably necessary to resolve the matter and for any applicable legal limitation or mandatory record-retention period.
11.5. Customer-Instance Deletion and Backups
When a Customer Instance is deleted, its active containers, database, storage volume, and active Customer Data are deleted as part of the Instance-deletion process.
Restricted technical backup copies may remain for up to 30 additional days solely for internal technical, resilience, security, or disaster-recovery purposes. These copies are not available to the Customer for restoration, retrieval, export, or archive access and are deleted or overwritten through the technical retention process, unless a longer retention period is legally required.
11.6. Legal Holds and Authority Requests
Where MCTO is legally required to preserve information, or preservation is necessary for an active legal claim, investigation, or binding authority request, deletion may be postponed only for the necessary scope and period.
12. Security Measures
MCTO applies technical and organisational measures appropriate to the nature of the Cogeto Service and the risks of processing. These measures include, as applicable:
- dedicated single-tenant Customer Instance architecture;
- separate application containers, database, and storage volume per Instance;
- TLS certificates and encrypted network transport;
- controlled administrative access to infrastructure;
- self-hosted identity management for the Cogeto Platform;
- account verification and role-based permissions;
- restricted technical access on a need-to-know basis;
- append-only, hash-chained audit logging;
- IP-address truncation at the time relevant audit information is written;
- security monitoring and incident-response procedures;
- software, infrastructure, and dependency patching and maintenance;
- separation between Platform email configuration and individual Customer-Instance email configuration;
- confidentiality obligations for persons authorised to perform technical operations; and
- backup and deletion controls appropriate to the Service architecture.
No online service can guarantee absolute security. Customers are responsible for securing their own in-Instance users, credentials, configurations, and lawful data-processing practices.
13. Automated Decision-Making
MCTO does not currently use Cogeto Account personal data to make decisions producing legal effects or similarly significant effects solely by automated processing within the meaning of Article 22 GDPR.
Automated technical actions, such as security controls, quota enforcement, Credit deductions, Grace Period countdowns, or deletion after an unpaid Grace Period, are operational functions of the Service and are governed by the General Terms. Where applicable law gives an individual a right regarding an automated decision, MCTO will respect that right.
14. Your Rights
Subject to the conditions and limitations of applicable law, you may have the right to:
- obtain confirmation whether MCTO processes your personal data;
- access your personal data and receive a copy;
- correct inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive data in a structured, commonly used, machine-readable format where the right to data portability applies;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with a competent supervisory authority; and
- exercise rights relating to certain automated decision-making where applicable.
To exercise a right relating to personal data for which MCTO is controller, contact legal@cogeto.eu.
MCTO may need to verify identity before acting on a request and may request information reasonably necessary to prevent unauthorised disclosure.
Where a request concerns personal data contained inside a Customer Instance for which the Customer is controller, the request should ordinarily be directed to that Customer. MCTO will assist the Customer as required by the Data Processing Agreement and applicable law.
15. Right to Object
Where MCTO relies on legitimate interests under Article 6(1)(f) GDPR, you may object to processing on grounds relating to your particular situation. MCTO will stop the relevant processing unless it demonstrates compelling legitimate grounds overriding your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.
Where personal data is processed for direct marketing, you may object at any time and MCTO will stop using the data for that direct-marketing purpose.
16. Supervisory Authority
You have the right to lodge a complaint with a competent data-protection supervisory authority.
For MCTO in Croatia, the lead national authority is:
Croatian Personal Data Protection Agency
Agencija za zaštitu osobnih podataka (AZOP)
You may also have the right to complain to the supervisory authority in the EU/EEA country of your habitual residence, place of work, or place of the alleged infringement.
17. Children
Cogeto is not directed to children. Consumers must be at least 18 years old or otherwise have full legal capacity to enter into the Cogeto contract under applicable law.
MCTO does not knowingly seek to create consumer Accounts for children. If we become aware that an Account was created contrary to this requirement, we may restrict or close it and handle the related personal data in accordance with applicable law.
This Section does not prevent a Customer from processing lawfully obtained personal data relating to minors inside its own Instance where the Customer has an appropriate legal basis and complies with all applicable obligations as controller.
18. Lawful Requests and Cooperation With Authorities
18.1. MCTO will cooperate with competent courts, law-enforcement authorities, regulators, supervisory bodies, and other legally authorised institutions where required by applicable law.
18.2. MCTO may preserve, access, or disclose information where legally required by a binding request or where necessary and lawful to protect against serious security threats, unlawful activity, or material harm.
18.3. Where legally permitted and appropriate, MCTO will limit any disclosure to the scope reasonably necessary for the relevant request.
19. Changes to This Privacy Policy
19.1. MCTO may update this Policy to reflect legal, regulatory, technical, organisational, supplier, or Service changes.
19.2. Material changes will be communicated through the Cogeto Platform, by email, or another appropriate method where required by law.
19.3. The current version will be made available through the Cogeto website or Platform and will state its effective date.
19.4. If a new processing purpose requires consent, MCTO will request that consent separately rather than treating continued use of the Service as consent where consent is legally required.
20. Contact
For privacy questions, data-subject requests, withdrawal of optional consent, or other personal-data matters, contact:
MCTO Advisory d.o.o.
Bregana Pisarovinska 37
10451 Bregana Pisarovinska
Croatia
VAT ID / OIB: HR74348605691
Email: legal@cogeto.eu
Website: www.cogeto.eu