GDPR
Last updated: October 11, 2026
1. Overview
Cosmoner is a service of DataBlock AB, a Swedish company based in Stockholm. "We", "our", and "us" on this page mean DataBlock AB. We are subject to the EU General Data Protection Regulation (GDPR), and this page explains how we meet it: which role we play for which data, where that data is kept, who else handles it, and how you exercise your rights.
It complements our Privacy Policy and Cookie Policy, which describe what we collect and why.
2. Our Role
Which obligations apply to us depends on whose data it is.
- Controller. For the data we need to run your account — your name, email address, login details, billing information, support messages, and how you use our website and control panel — we decide why and how it is processed, and we are the data controller.
- Processor. For the content you put on the platform — the files, databases, emails, container images, and application data in your projects — you decide what is stored and why. You (or your own customer) are the controller, and we process that data only on your instructions, to provide the services you have ordered.
If you host personal data about other people on Cosmoner, you remain responsible for having a legal basis for it and for answering requests from those individuals. We will help you do that.
3. Legal Bases
Where we are the controller, we rely on the following legal bases under Article 6 of the GDPR:
| Purpose | Legal basis |
|---|---|
| Creating and running your account, providing the services you order, billing | Performance of a contract |
| Keeping accounting records and invoices | Legal obligation |
| Securing the platform, preventing fraud and abuse, diagnosing errors | Legitimate interests |
| Service announcements and security alerts | Legitimate interests |
| Analytics and marketing cookies | Consent |
You can withdraw consent at any time through the Cookie Settings link in the site footer. Withdrawing it does not affect processing that happened before.
4. Where Your Data Is Stored
Cosmoner runs on our own hardware in Stockholm, Sweden. Applications, web hosting, and the PostgreSQL and Valkey databases we host ourselves live there, as does our own account database.
Some products run on a supplier's infrastructure instead. For those, your data is stored in the region you select when you create the resource. Web hosting backups are stored in Stockholm.
5. Subprocessors
We use the following companies to deliver our services. Each one handles only the data needed for its task.
| Subprocessor | What it does for us | Where |
|---|---|---|
| Amazon Web Services | Object storage, backups, managed databases, container registries, and email delivery | Stockholm, Sweden, or the region you select. Email delivery is processed in the United States. |
| DigitalOcean | Virtual servers and managed databases, when you order them | The region you select |
| Redis | Managed Redis databases, when you order them | The region you select |
| Stripe | Payment processing and invoicing | EU and United States |
| Cloudflare | DNS and network protection for our website and API | Global |
| Sentry | Error monitoring | Germany |
| name.com | Domain registration | United States |
| Sign in with Google. Analytics and advertising measurement, only with your consent. | EU and United States | |
| GitHub | Sign in with GitHub and repository connections for deployments | United States |
Google acts as a controller in its own right for parts of the analytics and advertising processing. None of it happens unless you consent to those cookies.
Registering a domain requires us to pass the registrant's contact details to the registrar and the registry for that domain ending.
We will update this page before a new subprocessor starts handling personal data.
6. International Transfers
Some of the subprocessors above are based in, or process data in, the United States. Where personal data leaves the EU/EEA, the transfer relies on the EU–US Data Privacy Framework for providers certified under it, and on the European Commission's Standard Contractual Clauses otherwise.
7. Data Processing Agreement
If you process personal data on Cosmoner as a controller, the GDPR requires a data processing agreement (DPA) between us. Email [email protected] and we will put one in place with you.
8. Security
We protect personal data with technical and organizational measures, including:
- Encryption in transit (TLS) for the website, control panel, and API
- Passwords stored hashed, and service credentials hashed or encrypted, never in plaintext
- Two-factor authentication and passkeys for your account
- Each organization's resources kept separate from every other organization's
- Access to production systems limited to the staff who need it
9. Retention
- Account data is kept for as long as your account is open.
- Your content is deleted when you delete the resource that holds it. After you close your account, it remains available for export for 30 days and is then removed.
- Invoices and accounting records are kept for seven years, as Swedish accounting law requires.
- Backups outlive the data they copy. Web hosting sites are backed up nightly and each backup is kept for 7, 30, or 90 days, depending on the retention you choose. Backups of the databases we host are kept for the retention period set on the database. When you delete a site, its backups are removed once that period has passed.
10. Your Rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Rectify data that is inaccurate or incomplete
- Erase your data when we no longer have a reason to keep it
- Restrict processing in certain situations
- Data portability — receive your data in a commonly used, machine-readable format
- Object to processing based on our legitimate interests
- Withdraw consent where processing is based on it
To exercise any of these, email [email protected]. We answer within one month. We may ask you to confirm your identity first, so that nobody else can request your data.
If your request concerns data that one of our customers stores on Cosmoner, that customer is the controller. We will pass your request on to them.
11. Personal Data Breaches
If a breach affects personal data we are the controller for, we notify the Swedish Authority for Privacy Protection within 72 hours where the GDPR requires it, and the people affected when the risk to them is high.
If a breach affects data we process on your behalf, we notify you without undue delay, with the information you need to meet your own obligations.
12. Complaints
If you believe we have handled your personal data unlawfully, please contact us first so we can put it right. You also have the right to lodge a complaint with a supervisory authority. In Sweden that is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se. You may instead turn to the authority in the EU/EEA country where you live or work.
13. Contact Us
If you have questions about data protection at Cosmoner, please contact us at:
- Email: [email protected]
- Address: DataBlock AB, Stockholm, Sweden