Privacy Policy - v 2.0
In force from August 20th, 2026

Privacy Policy - v 2.0
In force from August 20th, 2026

Privacy Policy - v 2.0
In force from August 20th, 2026

1. Who we are

KOTZILLA SAS, a French société par actions simplifiée registered under number 921 682 076 with the Toulouse Registry of Commerce, having its registered office at 3 rue Alaric II, 31000 Toulouse, France (“Kotzilla”, “we”, “us”), is responsible for the processing described in this policy.

Contact for any question or request relating to personal data: contact@kotzilla.io, or by post to the address above.

This policy applies to kotzilla.io, blog.kotzilla.io and doc.kotzilla.io (the “Site”), to the Kotzilla console at console.kotzilla.io (the “Console”), and to the Koin IDE Plugin. It is governed by Regulation (EU) 2016/679 (the “GDPR”) and by the French Data Protection Act of 6 January 1978 as amended.

2. Our two roles, and what this policy covers

Kotzilla processes personal data in two distinct capacities, and it matters which one applies to you.

As controller, for the data of the people who deal with us: users of the Console and of the Koin IDE Plugin, billing and support contacts, prospects, and visitors to the Site. That processing is described in this policy.

As processor, for the technical data collected by the Kotzilla SDK in our customers’ applications. Our customer decides what is collected and why; we act on its instructions. That processing is not described in this policy. It is governed by our Terms and Conditions, by the data page of our documentation, and by the Data Processing Terms annexed to our Terms and Conditions, which apply to every subscription, or by our Data Processing Agreement where one is signed, available on request at contact@kotzilla.io.

The Kotzilla SDK is not designed to collect personal data of the end users of our customers’ applications, and we do not intentionally collect any.

3. What we process as controller, why, and on what basis

Who you are

Categories of
personal data

Data

Categories of
personal data

Purposes

Retention
period

Legal basis and retention

Reason for
retention period

User of the Console or of the Koin IDE Plugin


Name, surname, professional email address, company, job title, account and authentication data, connection logs

Creating and administering the account, giving access to the service, authentication, security, support


Performance of the contract, and our legitimate interest in the security of the service


Retention: Account data: duration of the account, then 3 years from its closure. Connection logs, including IP addresses: 12 months from the date on which they are recorded.

Performance of the contract, and our legitimate interest in the security of the service


Retention: Account data: duration of the account, then 3 years from its closure. Connection logs, including IP addresses: 12 months from the date on which they are recorded.

Customer contact

Name, surname, company, professional contact details, contractual documents

Managing the commercial relationship, contract management

Performance of the contract


Retention: 5 years from the end of the contract.

Performance of the contract


Retention: 5 years from the end of the contract.

Billing contact

Billing and payment data, invoices


Billing and payment data, invoices


Invoicing, payment, accounting, recovery of unpaid amounts

Performance of the contract and compliance with our accounting obligations


Retention: 10 years from the end of the financial year, in accordance with Article L123-22 of the French Commercial Code.

Performance of the contract and compliance with our accounting obligations


Retention: 10 years from the end of the financial year, in accordance with Article L123-22 of the French Commercial Code.

Support requester

Content of the request and any element attached to it

Handling the request

Performance of the contract, or our legitimate interest where you are not yet a customer


Retention: 3 years from the closure of the request.

Any user who accepts our contractual documents

A user identifier, your professional email address, the date and time of acceptance, and the version and text fingerprint of each document accepted. No connection data is kept for this purpose

Proof of the formation of the contract: establishing which documents you accepted, in which version, and when. This purpose is distinct from the administration of your account, and the data is used for no other purpose

Article 6(1)(f) of the GDPR. The legitimate interest pursued is our ability to prove the formation and the content of the contract, and to establish, exercise and defend our rights in the event of a claim.

Retention: 5 years from the closure of the account, in a restricted archive used only in the event of a claim. See Article 8.

Prospect

Name, surname, job title, company, professional email address, public professional profile

Contacting you, arranging a demonstration, sending commercial communications

Our legitimate interest in developing our business, or your consent where required

Retention: 3 years from the last contact from you, or until you object.

Visitor to the Site

Browsing data collected through cookies and similar technologies

Operating the Site, measuring audience, marketing

Our legitimate interest for strictly necessary cookies, your consent for all others

Retention: See Article 7

User of the Koin IDE Plugin, usage analytics

Anonymous or pseudonymised technical usage data of the plugin interface and aggregated indicators of use of Koin in projects, excluding source code, method bodies and business logic

Improving the plugin and prioritising features

Our legitimate interest in improving our products


Retention: 12 months from the last use.

Proof of the formation of the contract is a purpose in its own right. It is separate from the administration of your account and from the management of our commercial relationship, it rests on its own legal basis, Article 6(1)(f) of the GDPR, and it has its own retention period. The interest we pursue is to be able to establish, in the event of a dispute, which contractual documents were accepted, in which version, by whom and on which date, since the burden of proving the formation of the contract lies with us. We have weighed that interest against your rights: the record is limited to what is strictly necessary in order to prove acceptance, it is kept in a restricted archive separate from our active databases, access to it is limited and logged, it is used for no operational or commercial purpose, and it is deleted on expiry of the period stated above. You may object to this processing under the conditions set out in Article 8.

You may object at any time to any processing based on our legitimate interest, and withdraw your consent at any time where the processing is based on consent, under the conditions set out in Article 8.

We take no decision based solely on automated processing which produces legal effects concerning you.
We do not sell your personal data.

4. Recipients

Your data is accessible to the Kotzilla personnel who need it in order to perform their duties, and to the following recipients, each of which acts as our processor under a written contract complying with Article 28 of the GDPR.

Recipient

Categories of
personal data

Purpose

Categories of
personal data

Location

Retention
period

Transfer Mechanism

Reason for
retention period

Google Cloud Platform

Google Cloud Platform

Main infrastructure hosting

United States / European Union

United States / European Union

Data Privacy Framework, standard contractual clauses in the alternative

Amazon Web Services

Amazon Web Services

Hosting of the iOS components

United States

United States

Data Privacy Framework, standard contractual clauses in the alternative

Data Privacy Framework, standard contractual clauses in the alternative

Okta, Inc. (Auth0)

Authentication of access to the Console and to the plugins

United States

United States

Data Privacy Framework, standard contractual clauses in the alternative

Data Privacy Framework, standard contractual clauses in the alternative

HubSpot, Inc.

Customer relationship management, sending emails to platform users

Germany, European Union

No transfer outside the European Union

Stripe

Processing of card payments

United States

Data Privacy Framework, standard contractual clauses in the alternative

Pennylane

Invoicing and accounting

Ireland / France

No transfer outside the European Union

Independent contractors of Kotzilla

Performance of part of the services

European Union

No transfer outside the European Union

We may also disclose your data where we are required to do so by law, by a court or by a public authority, and in connection with a merger, a reorganisation or a transfer of all or part of our business, in which case we inform you.

5. Where your data is stored, and transfers outside the European Union

Data processed in the course of supplying our platform is hosted in the United States by default. Where the applicable Order Form so provides, it is hosted in the European Union.

Some of our recipients are established in the United States, as set out in Article 4. Each transfer is covered by an adequacy decision of the European Commission, including the EU-US Data Privacy Framework where the recipient is certified under it, or, failing that, by the standard contractual clauses adopted by the European Commission by Decision 2021/914/EU. A copy of the safeguards in place is available on request at contact@kotzilla.io.

  1. Security

We implement technical and organisational measures appropriate to the risk, and in particular:

•          encryption of communications in transit using HTTPS with TLS 1.2 as a minimum, and encryption of data at rest;

•          role-based access control, and multi-factor authentication for access to production environments;

•          access to data limited to the personnel who need it in order to perform the service;

•          logging of accesses and of operations carried out on the data;

•          backups, restoration procedures and continuous monitoring of the infrastructure;

•          segregation of development, test and production environments, with no use of production data in non-production environments;

•          a documented incident response procedure;

•          periodic security reviews, vulnerability management, and written data protection commitments from our personnel and independent contractors.

Our platform is designed on a privacy by design basis: the technical data collected by the SDK is technical metadata, and the SDK does not collect source code, screen contents, input field data or network payloads.

7. Cookies and similar technologies

We use cookies and similar technologies on the Site and on the Console. Strictly necessary cookies are set without your consent, as they are required for the service to function. All other cookies, in particular audience measurement and marketing cookies, are set only after you have consented through the banner presented on your first visit.

You may withdraw or change your choice at any time through your browser settings. Cookies are retained for a maximum of thirteen (13) months from the date on which they are set, and the consent you give is retained for a maximum of six (6) months.

Category

Categories of
personal data

Purpose

Retention
period

Retention

Reason for
retention period

Strictly necessary

Operation of the Site and of the Console, session, security

maximum of six (6) months

Audience measurement

Understanding how the Site is used

maximum of six (6) months

Marketing

Measuring the effectiveness of our campaigns

maximum of six (6) months

8. Your rights

Under the conditions set out by the GDPR, you have the right to access your data, to have it rectified, to have it erased, to restrict its processing, to data portability, to object to processing based on our legitimate interest, and to withdraw your consent at any time where the processing is based on consent. You also have the right to give directions as to what becomes of your data after your death.

To exercise these rights, write to contact@kotzilla.io or to KOTZILLA SAS, 3 rue Alaric II, 31000 Toulouse, France. We reply within one month of receiving your request, a period which may be extended by two months where the request is complex, in which case we inform you. We may ask you for evidence of your identity where there is reasonable doubt as to who you are.

Where you ask us to erase your data, we delete your account and its content. We keep the record of your acceptance of our contractual documents, described in Article 3, in a restricted archive. Article 17(3)(e) of the GDPR allows us to do so, since that record is necessary in order to establish and defend our respective rights. It is limited to what is necessary in order to prove that acceptance, it holds no connection data, it is kept separately from our active databases with limited and logged access, it is not used for any other purpose, no commercial communication is sent on its basis, and it is deleted on expiry of the period stated in Article 3. We keep your data for the same reason where it is necessary in order to comply with a legal obligation, in particular our accounting obligations.

Where we act as processor on behalf of one of our customers, we forward your request to that customer, which is responsible for answering it, and we inform you that we have done so.

9. Complaints

If you consider that your rights have not been respected, you may:

  • contact us by by post to Kotzilla SAS, 3 rue Alaric II - ATHome - 31000 Toulouse, France, or at contact@Kotzilla.io; In accordance with Applicable Regulations, we will ask you to prove your identity.

  • lodge a complaint with the French data protection authority, the Commission Nationale de l’Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr, or with the supervisory authority of your country of residence.

10. Changes to this policy

We may amend this policy in order to reflect changes to our processing activities or to the applicable law. Where a change is substantial, we inform you before it takes effect, by email or by a notice on the Site. Each version is numbered and dated.

Document Version

Date

2.0

20/08/2026

1.6

01/01/2026

1.5

01/06/2025

1.4

12/12/2024

1.3

30/11/2024

1.2

30/06/2023

The developer observability platform for Android & Kotlin Multiplatform apps. From detection to accurate remediation.

Powered by Koin

The developer observability platform for Android & Kotlin Multiplatform apps. From detection to accurate remediation.

Powered by Koin

The developer observability platform for Android & Kotlin Multiplatform apps. From detection to accurate remediation.

Powered by Koin