Cosmo Logic IT Solutions Logo
Corporate Governance & Compliance Protocol

Enterprise Privacy Policy & Data Governance

Effective Date: January 1, 2026 • Version 2.4 • Applicable to all corporate engagements, candidate recruitment, and digital interactions with Cosmo Logic IT Solutions Private Limited.

1. Corporate Identity & Scope

This Privacy Policy is promulgated by Cosmo Logic IT Solutions Private Limited, having its registered technology facilities at Techno Innovation Tower, 4th Floor, Electronic City Phase 1, Bengaluru, Karnataka 560100, India (“Cosmo Logic”, “we”, “our”, or “us”).

This document sets forth our comprehensive data protection governance framework governing enterprise client engagements, architectural discovery sessions, engineering candidate recruitment, and portal visitors. We operate under stringent engineering principles and observe applicable data protection frameworks including India's Digital Personal Data Protection Act (DPDPA 2023), GDPR (EU), and ISO/IEC 27001 data governance standards.

2. Categories of Information We Process

We process information categorized strictly according to the scope of professional interaction:

  • Enterprise Business Contact Data: Full name, corporate email, executive telephone number, company identity, and project scope summary provided during architectural consultation requests.
  • Technical Telemetry & System Logs: Anonymized server logs, browser user-agents, IP subnets, and performance metrics collected solely to maintain infrastructure uptime and prevent malicious denial-of-service attempts.
  • Recruitment & Candidate Information: Curriculum vitae, professional certifications, repository links (e.g. GitHub), and employment history submitted to our talent desk.
  • Client Operational Data: Artifacts, architectural diagrams, and schema specifications shared under executed Non-Disclosure Agreements (NDAs).

3. Purpose and Legal Basis of Processing

Data processing activities are conducted strictly pursuant to legitimate business interests and explicit contractual consent:

  • Formulating architectural feasibility reviews and commercial proposals.
  • Fulfilling bilateral Master Service Agreements (MSAs) and Statements of Work (SOWs).
  • Evaluating candidates for engineering, cloud architecture, and research openings.
  • Ensuring zero-trust authentication and access logging across our corporate networks.

4. NDA & Client Confidentiality Guarantee

We treat all technical briefs, source code reviews, and enterprise architectural topologies as strictly confidential trade secrets. Prior to receiving proprietary infrastructure topologies, Cosmo Logic routinely executes mutual or client-provided NDAs.

Under no circumstances do we sell, rent, monetize, or utilize client proprietary information for training public machine learning models or third-party commercial applications.

5. Zero-Trust Security Protocols

Our engineering infrastructure operates on strict Zero-Trust paradigms aligned with ISO/IEC 27001:2013 and SOC 2 Type II control frameworks:

  • Data in Transit: Enforced TLS 1.3 with Perfect Forward Secrecy across all endpoints.
  • Data at Rest: AES-256 GCM encryption utilizing HSM-backed customer-managed encryption keys.
  • Least-Privilege Access: Role-based access control (RBAC) with mandatory multi-factor hardware keys.

6. Cross-Border Data Transfers & Cloud Hosting

Cosmo Logic utilizes sovereign cloud infrastructure hosted in ISO 27001-certified Tier-4 data center facilities located in India (AWS Asia-Pacific Mumbai / GCP Delhi), with client data strictly pinned to mutually agreed jurisdiction boundaries pursuant to international data transfer clauses.

7. Data Retention & Cryptographic Disposal

Client technical data and project briefs are retained only for the duration of the exploratory evaluation or active master service agreement. Following termination, data is subjected to certified cryptographic erasure and purge routines within 30 business days.

8. Statutory Data Subject Rights

Pursuant to the Digital Personal Data Protection Act (DPDPA) and GDPR, enterprise stakeholders and candidates possess:

  • Right to access summaries of personal or business contact data processed.
  • Right to request immediate correction or updating of inaccurate records.
  • Right to withdrawal of consent and complete data erasure.
  • Right to nominate a representative in the event of incapacity.

9. Contact & Grievance Redressal

To exercise your statutory data rights or lodge a governance inquiry, contact our Data Protection Officer:

Grievance Officer: Data Protection & Legal Compliance Directorate

Corporate Entity: Cosmo Logic IT Solutions Private Limited

Electronic Mail: [email protected]

Address: Techno Innovation Tower, Electronic City Phase 1, Bengaluru 560100, India