Website Privacy Policy
Cosylab d.d. and its subsidiaries are committed to respecting your privacy and protecting your personal data, which is any information that can identify you as an individual person. We will process your personal data only in accordance with this Privacy Policy and applicable data protection laws, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the Slovenian Personal Data Protection Act (ZVOP-2), and rules on cookies and similar technologies under the Electronic Communications Act (ZEKom-2) and the EU ePrivacy framework.
This Website Privacy Policy describes the privacy practices which Cosylab d.d., Gerbičeva ulica 64, 1000 Ljubljana, Slovenia, and (when applicable) its subsidiaries (“Cosylab”) apply when processing personal data about you in connection with your use of this website.
Controller and contact details
Cosylab d.d. (Gerbičeva ulica 64, 1000 Ljubljana, Slovenia) is the data controller for personal data processed under this Privacy Policy, unless we explicitly inform you otherwise (e.g., where a subsidiary acts as controller for a specific interaction).
What’s in this Privacy Policy?
This policy tells you:
- What personal data we might collect about you;
- How we might use that personal data;
- When we might use your personal data to contact you;
- What personal data of yours we might share with others;
- Your rights regarding the personal data we process;
- Whether you are required to provide personal data and possible consequences of not providing it;
- Whether we use automated decision-making (including profiling).
What does this Privacy Policy cover?
This Privacy Policy governs your use of the website https://www.cosylab.com and any other websites and/or URL which may replace it, or which may be added to the list of websites published by us and linked to this Privacy Policy (“website”).
By using the website, you do not automatically “consent” to all processing. We process personal data only where we have a valid legal basis under the GDPR. Where consent is required (e.g., non-essential cookies/trackers), we will ask for it via the cookie banner/tool before placing such technologies, and you can withdraw consent at any time.
What’s not covered in this Privacy Policy?
Our website may contain links to other websites that may be of interest to you. Those websites have their own privacy and cookies policy. Remember that the information you give them will follow their rules and not this Privacy Policy.
What types of personal data does Cosylab collect about a website user?
- Technical Information
We collect the data necessary for you to use the website and for us to maintain and analyse the functioning of the website.
We automatically obtain certain information about your computing device, including:
- IP address;
- Country code;
- Language (specific location where a given language is spoken);
- Time zone;
- Network status (Wi-Fi, etc.), browser plug-in types and versions;
- Technical device information (e.g., device model and name, operating system name and version, screen size, mobile phone carrier, Internet service provider);
- Information we collect via cookies: For more information, please see the “Our Use of Cookies and Related Technologies” section of this Privacy Policy.
3. Website usage information
When you visit our website, we store the name of your internet service provider, the website which you visited us from, the parts of our site you visit, the date and duration of your visit, page response times, download errors, length of visits to certain pages and page interaction information such as scrolling, clicks, and mouse-overs.
For information security and fraud detection, we store the IP address when a large file (e.g., pdf, mp4) is downloaded.
We process this usage data in an anonymized form for statistical purposes and to improve our site. Where data is only “pseudonymized” (not truly anonymized), it remains personal data and we treat it as such.
3. Contact information
On our website you can contact us to ask us questions via the contact form or email.
When you contact us using the contact form, we ask you for your contact information that you voluntarily submit (e.g., name, email address, company name etc.).
When you subscribe to our newsletter, we collect your information that you submit in the sign-up forms (e.g., name, email address, company name, marketing preferences).
We use the above data solely in connection with answering the queries we receive or for another purpose for which you provided it to us (e.g., to notify you about updates to our services, offer customer support or marketing emails). We will not share this data with third parties other than those detailed in this Privacy Policy.
When you receive emails from us (including newsletters) based on your consent, we may use certain analytics tools to capture data. We automatically place single pixel gifs, also known as web beacons, in every email where enabled. These are tiny graphic files that contain unique identifiers that enable us and our users to recognize when their subscribers have opened an email or clicked certain links. These technologies record each subscriber’s email address, IP address, date, and time associated with each open and click for a campaign. We use this data to obtain reports about how an email campaign performed and what actions subscribers took and to allow us to improve our emails. This may also include segmentation.
Legal basis: (i) for sending marketing emails: your consent; (ii) for email tracking/analytics (opens/clicks) where required: your consent (you can opt out at any time, including by disabling images or by unsubscribing).
Except for cases where we are required to do so by law (e.g., notifying you of a data breach), you can unsubscribe from receiving these messages at any time. You may opt out by:
(1) Following the instructions to Unsubscribe that we include in each of our promotional email campaign.
(2) Informing us at dpo@cosylab.com that you no longer wish to receive such communications.
Providing personal data through the contact form or newsletter subscription is voluntary. However, if you do not provide the requested contact details, we may not be able to respond to your inquiry or provide the requested service.
How do we use your information?
We may use your information for:
- Enhancing the safety and security of our websites;
- Optimizing the website, understanding and analysing trends in connection with the usage of website and learning about user behaviour on the website (how often you use the website, the events that occur on the website, aggregated usage, performance data etc.) and to customize the website according to your interests;
- To improve our services;
- Providing customer support to you and to respond to your inquiries;
- Sending promotional emails about service updates, events or other information which we think you may find interesting using the email address which you have provided;
- To contact you for market research purposes from time to time (we may contact you by email or phone);
- Internal record keeping about how an email campaign performed.
We do not use your website data to make solely automated decisions that produce legal or similarly significant effects about you. If this changes, we will update this Privacy Policy and provide the information required by the GDPR.
Lawful basis for processing
We process personal data only where we have a valid legal basis under Article 6 GDPR and, where applicable, in accordance with ZEKom-2/ePrivacy rules on cookies and similar technologies.
Depending on the purpose, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b) GDPR): to provide website functionalities you request and to respond to inquiries submitted via contact forms or email.
- Legitimate interests (Art. 6(1)(f) GDPR): to ensure the security, integrity, and proper functioning of our website and systems (e.g., server logs, fraud prevention, protection against misuse) and to establish, exercise, or defend legal claims. We ensure our interests do not override your rights and freedoms.
- Consent (Art. 6(1)(a) GDPR): for non-essential cookies (including Google Analytics and HubSpot), marketing communications, and email tracking where applicable. Non-essential cookies are activated only after your explicit consent via the cookie banner. You may withdraw consent at any time without affecting prior processing.
- Legal obligation (Art. 6(1)(c) GDPR): where processing is required to comply with applicable laws.
If we process data for a new purpose, we will inform you and obtain consent where required.
Third parties with whom we share your personal data
We may disclose your personal data to companies within the Cosylab group that agree to treat it in accordance with this Privacy Policy and to third parties who act for or on our behalf for further processing in accordance with the purposes for which the data were originally collected or may otherwise be lawfully processed, such as technical support (e.g., to the company which hosts and maintains the website).
We share personal data with service providers (“processors”) that help us operate the website and communications, such as website hosting providers and, if enabled, analytics/marketing platforms (e.g., Google and HubSpot). We have data processing agreements in place where required by Article 28 GDPR.
We may also disclose personal data where required by law, or to protect our rights, users, and systems (e.g., in case of misuse or security incidents).
International Data Transfers
Some of our service providers (e.g., e.g., Google LLC, HubSpot, Inc., and LinkedIn Corporation) are located in the United States or may process data outside the EEA.
Where personal data is transferred outside the EEA, we rely on:
- An adequacy decision, including where applicable the EU-U.S. Data Privacy Framework, or
- Standard Contractual Clauses (SCCs) adopted by the European Commission, together with supplementary safeguards where necessary.
You may request further information about the safeguards by contacting dpo@cosylab.com.
Our use of cookies and related technologies
We use cookies and similar technologies (such as pixels, local storage, and tracking scripts) on our website in accordance with the GDPR and the Slovenian Electronic Communications Act (ZEKom-2).
When you first visit our website, you are presented with a cookie consent banner that allows you to:
- Accept all cookies,
- Accept only selected categories, or
- Reject non-essential cookies.
Non-essential cookies are not placed on your device unless you provide prior consent via the cookie banner. Continuing to browse the website does not constitute consent.
We use the following categories of cookies:
- Strictly Necessary Cookies
These cookies are required for the operation and security of the website (e.g., session management, security, load balancing). They do not require consent under ZEKom-2/ePrivacy.
- Statistics / Analytics Cookies
We use Google Analytics (GA4) and HubSpot analytics tools to collect information about how visitors use our website (e.g., pages visited, time spent, navigation patterns, device type). These cookies are used only if you provide consent.
Google Analytics (GA4) may collect information such as device and browser information, pages visited, interactions, and approximate location derived from IP addresses.
IP addresses are processed by Google Analytics in accordance with Google’s GA4 configuration. Google states that IP addresses are not logged or stored in GA4; however, data may be processed on servers outside the EEA.
HubSpot may place cookies to:
- Analyse website traffic,
- Track interactions with marketing content,
- Measure effectiveness of campaigns.
Data collected through analytics cookies may be transmitted to Google LLC and HubSpot, Inc., which may process data outside the EEA (see “International Data Transfers”).
- Marketing /PersonalisationCookies
Where enabled, these cookies allow us to measure campaign performance and personalise content. They are used only if you provide consent.
We use the LinkedIn Insight Tag, a JavaScript-based tracking technology provided by LinkedIn Ireland Unlimited Company. The LinkedIn Insight Tag enables conversion tracking, retargeting, and website analytics related to LinkedIn advertising campaigns. It collects data about visitors who are LinkedIn members, including the URL and referrer URL of the visited page, IP address (anonymized), device and browser characteristics, and timestamp. For LinkedIn members who are logged in at the time of their visit, LinkedIn may also associate this data with their LinkedIn profile. This cookie is activated only if you provide consent via the cookie banner. You can opt out of LinkedIn’s data collection for targeting purposes via your LinkedIn account settings.
You can withdraw or modify your cookie preferences at any time using the cookie management tool available on our website.
Disabling strictly necessary cookies may affect website functionality.
For detailed information about specific cookies (name, provider, purpose, retention period), please consult the cookie management tool.
Cookies used on our website
We may use session or persistent cookies.
We use session cookies to remember your credentials for when you log into our Client Area. You can learn more about session cookies and what they are used for at http://www.allaboutcookies.org/cookies/session-cookies-used-for.html
Persistent cookies remain on your device even after you close your browser and may be used the next time you visit our website.
We also use traffic log cookies to identify which pages are being used. This helps us analyse data about webpage traffic and improve our website in order to tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system.
For additional information on the cookies used on this website see the cookie management tool.
Third-Party Services and Tracking Partners
We currently use the following third-party services on our website:
- Google Analytics (GA4) – website usage analytics
- Provider: Google LLC
- Privacy policy: https://policies.google.com/privacy
- HubSpot – marketing automation, analytics and newsletter management
- Provider: HubSpot, Inc.
- Privacy policy: https://legal.hubspot.com/privacy-policy
- LinkedIn Insight Tag – conversion tracking, retargeting, and website analytics
- Provider: LinkedIn Ireland Unlimited Company (for users in the EEA/UK); LinkedIn Corporation (United States)
- Privacy policy: https://www.linkedin.com/legal/privacy-policy.
These services place cookies and process data only after you provide consent through our cookie banner (except where strictly necessary).
We use advertising remarketing and behavioural advertising cookies only where explicitly disclosed in this Privacy Policy and the cookie management tool. We currently use the LinkedIn Insight Tag for retargeting and conversion tracking purposes, as described above. No other advertising remarketing or behavioural advertising cookies are enabled unless explicitly stated in the cookie management tool.
https://policies.google.com/privacyhttps://legal.hubspot.com/privacy-policyhttps://tools.google.com/dlpage/gaoptoutManaging your cookie preferences
You can choose to accept or decline cookies in the cookie management tool.
Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of our website.
If you don’t want to receive cookies, you can modify your browser so that it notifies you when cookies are sent to it, or you can refuse cookies altogether. You can also delete cookies that have already been set.
If you wish to restrict or block web browser cookies which are set on your device, then you can do this through your browser settings. The Help function within your browser should tell you how.
Alternatively, you may wish to visit www.aboutcookies.org, which contains comprehensive information on how to do this on a wide variety of desktop browsers.
Retention
We retain personal data as follows:
- Server logs and security logs (including IP addresses): up to 6–12 months, unless required longer for security investigations or legal claims.
- Contact form inquiries: up to 3 years after last communication.
- Newsletter subscription data: until you withdraw consent.
- Cookie consent records: up to 2 years to demonstrate compliance.
- Analytics data: according to the retention settings configured in Google Analytics and HubSpot.
Personal data may be retained longer where required by law or for the establishment, exercise, or defence of legal claims.
Your rights in connection to personal data processing
Under the GDPR and applicable Slovenian data protection law (ZVOP-2), you have the following rights in relation to your personal data:
- Right of access – to obtain confirmation as to whether we process your personal data and to receive a copy of it.
- Right to rectification – to request correction of inaccurate or incomplete personal data.
- Right to erasure (“right to be forgotten”) – to request deletion of your personal data where there is no legal basis for continued processing.
- Right to restriction of processing – to request that we temporarily limit the processing of your data in certain circumstances.
- Right to data portability – to receive your personal data in a structured, commonly used and machine-readable format and to transmit it to another controller where processing is based on consent or contract and carried out by automated means.
- Right to object – to object to processing based on our legitimate interests and at any time to processing for direct marketing purposes.
- Right to withdraw consent – where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Right not to be subject to solely automated decision-making, including profiling, that produces legal or similarly significant effects on you (where applicable).
To exercise your rights, please contact us at dpo@cosylab.com. We may need to verify your identity before responding to your request.
You also have the right to lodge a complaint with the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec) or with your local supervisory authority within the EU/EEA.
You may address in writing to dpo@cosylab.com all requirements relating to the exercise of rights in connection with the personal data processed and stored by Cosylab.
If you believe that your rights or regulations on the protection of personal data have been violated, you can appeal to the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec): https://www.ip-rs.si/.
Contact us
If you have any questions about this Privacy Policy or if you would like to communicate with Cosylab’s Data Protection Officer, please send an e-mail to dpo@cosylab.com.
Changes to our Privacy Policy
Cosylab reserves the right to modify this policy. We will post any changes to the Privacy Policy on this page. Please check this page regularly to keep up to date.
This policy was last updated in April 2026.