Compliance Framework

Legal & Compliance

Chronological compliance timeline outlining our security audits, data handling procedures, and your rights as a client.

01
Initial Assessment

Pre-Engagement Security Review

Before any project commences, CosmicLogicStudio conducts a preliminary security assessment of the client's existing infrastructure to identify immediate vulnerabilities and compliance gaps.

02
Data Collection

Information Gathering & Processing

We collect only the minimum necessary data required to deliver our services. This includes contact information, system configuration details, and project specifications. All data is processed under legitimate interest or explicit consent basis as defined by GDPR Article 6.

03
Implementation

Secure Service Delivery

All services are delivered through encrypted channels. Access to client systems is granted via secure, time-limited credentials. CosmicLogicStudio maintains ISO 27001-aligned security practices throughout the engagement lifecycle.

04
Verification

Post-Implementation Audit

Upon project completion, CosmicLogicStudio performs a comprehensive security audit to verify all deliverables meet agreed-upon security standards and compliance requirements. A detailed report is provided to the client.

05
Retention

Data Handling & Retention

Client data is retained only for the duration necessary to fulfill the contractual obligation. Upon project completion or contract termination, all personal data is securely deleted within 30 days unless legal retention requirements apply.

Privacy Policy

1. Data Controller
CosmicLogicStudio, headquartered at Rua Garrett 24, 1200-273 Lisboa, Portugal, is the data controller responsible for processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR").

2. Data We Collect
We collect the following categories of personal data: full name, email address, phone number, company information, and project-specific technical requirements. We do not collect special category data (Article 9 GDPR).

3. Purpose of Processing
Your data is processed for the following purposes: (a) to deliver requested technology services; (b) to communicate regarding project status and deliverables; (c) to maintain accurate billing records; (d) to comply with legal obligations under Portuguese and EU law.

4. Legal Basis
We process your data based on: (a) performance of a contract (Article 6(1)(b) GDPR); (b) legitimate interest in improving our services (Article 6(1)(f) GDPR); (c) compliance with legal obligations (Article 6(1)(c) GDPR).

5. Data Security
CosmicLogicStudio implements appropriate technical and organizational measures including AES-256 encryption, TLS 1.3 for data in transit, role-based access controls, and regular security audits aligned with ISO 27001 standards.

6. Your Rights
Under GDPR, you have the right to: access your data (Article 15), rectification (Article 16), erasure (Article 17), restrict processing (Article 18), data portability (Article 20), and object to processing (Article 21). To exercise these rights, contact us at [email protected].

7. Data Transfers
If data is transferred outside the EEA, we ensure appropriate safeguards are in place through Standard Contractual Clauses (SCCs) or adequacy decisions as required by Article 46 GDPR.

Terms of Service

1. Acceptance of Terms
By engaging CosmicLogicStudio for technology services, you agree to these Terms of Service. These terms govern the relationship between CosmicLogicStudio (Rua Garrett 24, 1200-273 Lisboa, Portugal) and the client.

2. Scope of Services
CosmicLogicStudio provides technology services including but not limited to: legacy system modernization, DevOps pipeline implementation, IT management, cloud migration, security auditing, and container orchestration. The specific scope is defined in the individual project proposal.

3. Payment Terms
All payments are due according to the milestones defined in the project proposal. Invoices are payable within 14 days of issuance. Late payments incur a statutory interest rate as per Portuguese Civil Code Article 1022.

4. Intellectual Property
Upon full payment, all deliverables and intellectual property created specifically for the client are transferred to the client. CosmicLogicStudio retains ownership of pre-existing frameworks, tools, and methodologies used in service delivery.

5. Confidentiality
Both parties agree to maintain strict confidentiality regarding proprietary information shared during the engagement. This obligation survives termination of the agreement for a period of 24 months.

6. Limitation of Liability
CosmicLogicStudio's total liability shall not exceed the total fees paid under the specific project agreement. We shall not be liable for indirect, incidental, or consequential damages.

7. Termination
Either party may terminate the agreement with 30 days written notice. Upon termination, the client is responsible for payment of all services rendered up to the termination date.

Cookie Policy

1. What Are Cookies
Cookies are small text files stored on your device when you visit our website. They help us provide you with a better experience and allow certain features to function.

2. Essential Cookies
CosmicLogicStudio uses strictly necessary cookies to ensure the website functions correctly. These cookies do not require consent as they are essential for the service requested by you (Article 5(3) ePrivacy Directive).

3. Cookie We Use
We use a single cookie: cookiesAccepted — This cookie stores your cookie consent preference using localStorage and expires after 365 days. It contains no personal data.

4. No Tracking
CosmicLogicStudio does not use analytics cookies, advertising cookies, or any third-party tracking technologies. We do not share cookie data with any third parties.

5. Managing Cookies
You can manage your cookie preferences at any time by clearing your browser's localStorage. Disabling essential cookies may affect the functionality of our website.

Refund & Reimbursement Policy

1. Eligibility
Refund requests must be submitted in writing to [email protected] within 14 days of the invoice date. Refunds are evaluated on a case-by-case basis according to the project milestones completed.

2. Milestone-Based Refunds
If a project is terminated before completion, the client is entitled to a refund for any milestone payments made for work not yet delivered. Delivered and accepted milestones are non-refundable.

3. Service Defects
If delivered services do not meet the specifications outlined in the project proposal, CosmicLogicStudio will, at its discretion: (a) remedy the defect at no additional cost; (b) provide a partial refund proportional to the defective deliverable; or (c) offer additional services to compensate.

4. Processing Time
Approved refunds will be processed within 14 business days using the original payment method. The client will receive email confirmation once the refund has been initiated.

5. Non-Refundable Items
The following are non-refundable: (a) completed and accepted project milestones; (b) third-party software licenses procured on behalf of the client; (c) consulting hours that have been delivered and documented.

6. Dispute Resolution
Any disputes arising from refund requests will be resolved in accordance with Portuguese law, subject to the jurisdiction of the courts of Lisboa, Portugal.