1. Who we are
KOTZILLA SAS, a French société par actions simplifiée registered under number 921 682 076 with the Toulouse Registry of Commerce, having its registered office at 3 rue Alaric II, 31000 Toulouse, France (“Kotzilla”, “we”, “us”), is responsible for the processing described in this policy.
Contact for any question or request relating to personal data: contact@kotzilla.io, or by post to the address above.
This policy applies to kotzilla.io, blog.kotzilla.io and doc.kotzilla.io (the “Site”), to the Kotzilla console at console.kotzilla.io (the “Console”), and to the Koin IDE Plugin. It is governed by Regulation (EU) 2016/679 (the “GDPR”) and by the French Data Protection Act of 6 January 1978 as amended.
2. Our two roles, and what this policy covers
Kotzilla processes personal data in two distinct capacities, and it matters which one applies to you.
As controller, for the data of the people who deal with us: users of the Console and of the Koin IDE Plugin, billing and support contacts, prospects, and visitors to the Site. That processing is described in this policy.
As processor, for the technical data collected by the Kotzilla SDK in our customers’ applications. Our customer decides what is collected and why; we act on its instructions. That processing is not described in this policy. It is governed by our Terms and Conditions, by the data page of our documentation, and by the Data Processing Terms annexed to our Terms and Conditions, which apply to every subscription, or by our Data Processing Agreement where one is signed, available on request at contact@kotzilla.io.
The Kotzilla SDK is not designed to collect personal data of the end users of our customers’ applications, and we do not intentionally collect any.
3. What we process as controller, why, and on what basis
User of the Console or of the Koin IDE Plugin
Name, surname, professional email address, company, job title, account and authentication data, connection logs
Creating and administering the account, giving access to the service, authentication, security, support
Customer contact
Name, surname, company, professional contact details, contractual documents
Managing the commercial relationship, contract management
Billing contact
Invoicing, payment, accounting, recovery of unpaid amounts
Support requester
Content of the request and any element attached to it
Handling the request
Performance of the contract, or our legitimate interest where you are not yet a customer
Retention: 3 years from the closure of the request.
Any user who accepts our contractual documents
A user identifier, your professional email address, the date and time of acceptance, and the version and text fingerprint of each document accepted. No connection data is kept for this purpose
Proof of the formation of the contract: establishing which documents you accepted, in which version, and when. This purpose is distinct from the administration of your account, and the data is used for no other purpose
Article 6(1)(f) of the GDPR. The legitimate interest pursued is our ability to prove the formation and the content of the contract, and to establish, exercise and defend our rights in the event of a claim.
Retention: 5 years from the closure of the account, in a restricted archive used only in the event of a claim. See Article 8.
Prospect
Name, surname, job title, company, professional email address, public professional profile
Contacting you, arranging a demonstration, sending commercial communications
Our legitimate interest in developing our business, or your consent where required
Retention: 3 years from the last contact from you, or until you object.
Visitor to the Site
Browsing data collected through cookies and similar technologies
Operating the Site, measuring audience, marketing
Our legitimate interest for strictly necessary cookies, your consent for all others
Retention: See Article 7
User of the Koin IDE Plugin, usage analytics
Anonymous or pseudonymised technical usage data of the plugin interface and aggregated indicators of use of Koin in projects, excluding source code, method bodies and business logic
Improving the plugin and prioritising features
Our legitimate interest in improving our products
Retention: 12 months from the last use.
Proof of the formation of the contract is a purpose in its own right. It is separate from the administration of your account and from the management of our commercial relationship, it rests on its own legal basis, Article 6(1)(f) of the GDPR, and it has its own retention period. The interest we pursue is to be able to establish, in the event of a dispute, which contractual documents were accepted, in which version, by whom and on which date, since the burden of proving the formation of the contract lies with us. We have weighed that interest against your rights: the record is limited to what is strictly necessary in order to prove acceptance, it is kept in a restricted archive separate from our active databases, access to it is limited and logged, it is used for no operational or commercial purpose, and it is deleted on expiry of the period stated above. You may object to this processing under the conditions set out in Article 8.
You may object at any time to any processing based on our legitimate interest, and withdraw your consent at any time where the processing is based on consent, under the conditions set out in Article 8.
We take no decision based solely on automated processing which produces legal effects concerning you.
We do not sell your personal data.
4. Recipients
Your data is accessible to the Kotzilla personnel who need it in order to perform their duties, and to the following recipients, each of which acts as our processor under a written contract complying with Article 28 of the GDPR.
Main infrastructure hosting
Data Privacy Framework, standard contractual clauses in the alternative
Hosting of the iOS components
Okta, Inc. (Auth0)
Authentication of access to the Console and to the plugins
HubSpot, Inc.
Customer relationship management, sending emails to platform users
Germany, European Union
No transfer outside the European Union
Stripe
Processing of card payments
United States
Data Privacy Framework, standard contractual clauses in the alternative
Pennylane
Invoicing and accounting
Ireland / France
No transfer outside the European Union
Independent contractors of Kotzilla
Performance of part of the services
European Union
No transfer outside the European Union
We may also disclose your data where we are required to do so by law, by a court or by a public authority, and in connection with a merger, a reorganisation or a transfer of all or part of our business, in which case we inform you.
5. Where your data is stored, and transfers outside the European Union
Data processed in the course of supplying our platform is hosted in the United States by default. Where the applicable Order Form so provides, it is hosted in the European Union.
Some of our recipients are established in the United States, as set out in Article 4. Each transfer is covered by an adequacy decision of the European Commission, including the EU-US Data Privacy Framework where the recipient is certified under it, or, failing that, by the standard contractual clauses adopted by the European Commission by Decision 2021/914/EU. A copy of the safeguards in place is available on request at contact@kotzilla.io.
Security
We implement technical and organisational measures appropriate to the risk, and in particular:
• encryption of communications in transit using HTTPS with TLS 1.2 as a minimum, and encryption of data at rest;
• role-based access control, and multi-factor authentication for access to production environments;
• access to data limited to the personnel who need it in order to perform the service;
• logging of accesses and of operations carried out on the data;
• backups, restoration procedures and continuous monitoring of the infrastructure;
• segregation of development, test and production environments, with no use of production data in non-production environments;
• a documented incident response procedure;
• periodic security reviews, vulnerability management, and written data protection commitments from our personnel and independent contractors.
Our platform is designed on a privacy by design basis: the technical data collected by the SDK is technical metadata, and the SDK does not collect source code, screen contents, input field data or network payloads.
7. Cookies and similar technologies
We use cookies and similar technologies on the Site and on the Console. Strictly necessary cookies are set without your consent, as they are required for the service to function. All other cookies, in particular audience measurement and marketing cookies, are set only after you have consented through the banner presented on your first visit.
You may withdraw or change your choice at any time through your browser settings. Cookies are retained for a maximum of thirteen (13) months from the date on which they are set, and the consent you give is retained for a maximum of six (6) months.
Strictly necessary
Operation of the Site and of the Console, session, security
maximum of six (6) months
Audience measurement
Understanding how the Site is used
maximum of six (6) months
Marketing
Measuring the effectiveness of our campaigns
maximum of six (6) months
8. Your rights
Under the conditions set out by the GDPR, you have the right to access your data, to have it rectified, to have it erased, to restrict its processing, to data portability, to object to processing based on our legitimate interest, and to withdraw your consent at any time where the processing is based on consent. You also have the right to give directions as to what becomes of your data after your death.
To exercise these rights, write to contact@kotzilla.io or to KOTZILLA SAS, 3 rue Alaric II, 31000 Toulouse, France. We reply within one month of receiving your request, a period which may be extended by two months where the request is complex, in which case we inform you. We may ask you for evidence of your identity where there is reasonable doubt as to who you are.
Where you ask us to erase your data, we delete your account and its content. We keep the record of your acceptance of our contractual documents, described in Article 3, in a restricted archive. Article 17(3)(e) of the GDPR allows us to do so, since that record is necessary in order to establish and defend our respective rights. It is limited to what is necessary in order to prove that acceptance, it holds no connection data, it is kept separately from our active databases with limited and logged access, it is not used for any other purpose, no commercial communication is sent on its basis, and it is deleted on expiry of the period stated in Article 3. We keep your data for the same reason where it is necessary in order to comply with a legal obligation, in particular our accounting obligations.
Where we act as processor on behalf of one of our customers, we forward your request to that customer, which is responsible for answering it, and we inform you that we have done so.
9. Complaints
If you consider that your rights have not been respected, you may:
contact us by by post to Kotzilla SAS, 3 rue Alaric II - ATHome - 31000 Toulouse, France, or at contact@Kotzilla.io; In accordance with Applicable Regulations, we will ask you to prove your identity.
lodge a complaint with the French data protection authority, the Commission Nationale de l’Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr, or with the supervisory authority of your country of residence.
10. Changes to this policy
We may amend this policy in order to reflect changes to our processing activities or to the applicable law. Where a change is substantial, we inform you before it takes effect, by email or by a notice on the Site. Each version is numbered and dated.
Document Version
Date
2.0
20/08/2026
1.6
01/01/2026
1.5
01/06/2025
1.4
12/12/2024
1.3
30/11/2024
1.2
30/06/2023
