Privacy Policy
Last updated: 2026-09-26
Effective from: 2026-09-25
This version of our Privacy Policy takes effect on 25 September 2026, the day cosmospm.com became a simple static website. It replaces the version that applied to our former website before that date. A copy of the earlier version is available on request.
This Privacy Policy explains how CosmosPM Ltd (referred to as “we”, “us”, or “our” in this policy) collects, uses, and protects personal data when you visit our website (cosmospm.com), email us, ask for early access to LogicReader, take part in a pilot, buy from us, or otherwise deal with us.
LogicReader has its own privacy policy. If you register for or use the LogicReader service at logicreader.io, the LogicReader Privacy Policy applies to that use. It explains how we handle your LogicReader account, the schedules you upload and the LogicReader features you use, and it lists the service providers that support LogicReader. Where the two policies differ about the LogicReader service, the LogicReader Privacy Policy applies.
1. Who we are
CosmosPM Ltd is a private limited company registered in England and Wales.
| Detail | Value |
|---|---|
| Registered company number | 16886156 |
| Registered office | C/O The Accountancy Partnership, Suite 5, 5th Floor, City Reach, 5 Greenwich View Place, London E14 9NN, United Kingdom |
| Information Commissioner’s Office (ICO) data protection registration | ZC143102 |
| General contact | contact@cosmospm.com |
| Data protection contact | privacy@cosmospm.com |
We are the data controller for the personal data we collect about you on this website and in our products. The exception is schedule content that you or your organisation upload to LogicReader, including during a pilot: for that content we act as a data processor (see section 7 and the LogicReader Privacy Policy).
2. The personal data we collect
We collect different categories of personal data depending on how you interact with us. The categories are:
a) Information you give us directly
- Emails you send us: your name, your email address and anything you include in your message. Our website has no forms; you contact us by email.
- Early-access requests: if you ask for early access to LogicReader using the early-access form on logicreader.io, we collect your email address and, if you choose to give them, your name, company, role and a message. With each request we also record the date and time, the web page you came from, your IP address and your browser’s identification details. We use the IP address and browser details only to detect spam. Your request is stored on the server that runs LogicReader (see Hostinger in section 5); we do not pass it to any other service.
- Pilot and customer contacts: if your organisation takes part in a pilot or buys from us, we hold the names and work contact details of the people we deal with.
- Project schedule data that you upload during a paid pilot — files such as XER, MPP, Asta XML, or CSV exports from your scheduling tool. These files may incidentally contain names of individuals (project team members, resources). See section 7 for how we handle this.
- Data from our former website: until September 2026 this website ran on WordPress, with member accounts and a Suggest a Feature form. The new website has neither. If you created a member account or sent us a feature suggestion through the former website, we deleted that data (your username, email address, any optional profile fields you completed, and the text of your suggestion) on 26 September 2026, together with the former website’s security and form logs. See section 8.
b) Information collected automatically when you visit our website
- Web server logs: like almost every website, our web server records each request it receives. The record contains your IP address, the date and time, the web address requested, whether the request succeeded, how much data was sent and how long it took, the page that referred you (if your browser sends it), and your browser’s identification details (such as browser type and version, and operating system). We use these logs only to keep the website secure and working, and we delete them after 90 days.
- No cookies and no analytics: our website sets no cookies, stores nothing in your browser, and uses no analytics, advertising or tracking tools (see section 6).
- Analytics data from our former website: until 25 September 2026, our former website used Google Analytics, but only if you accepted analytics cookies. We deleted our Google Analytics property on 25 September 2026, and Google then removes the data permanently (see section 8). Our new website does not use Google Analytics.
c) Information from third parties
- Paddle: when we start to sell through Paddle (see section 5), Paddle will share with us the details of your order that we need to provide what you bought and to support you.
- Your organisation: if your organisation arranges a pilot or a purchase with us, it may give us your name and work contact details.
d) Do you have to give us personal data?
You do not have to give us any personal data to read our website. Our web server logs, described above, are created automatically when you visit. Everything else is your choice. If you decide not to email us or not to use the early-access form, we simply cannot reply to you or invite you. If your organisation signs a pilot or purchase agreement with us, or you buy through Paddle, some personal data (such as a contact name and email address) is needed to perform that contract; without it, we cannot supply the product or service. No law requires you to give us personal data.
We do not intentionally collect special-category personal data (data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation). If you submit such data to us inadvertently (for example, in an email or in the message field of the early-access form), we will delete it.
3. How we use your personal data — and our lawful basis
UK GDPR requires us to identify a lawful basis for each purpose for which we use your personal data. The bases we rely on are:
| Purpose | Personal data used | Lawful basis |
|---|---|---|
| Replying to enquiries you send us by email | Your name, email address and whatever you include in the message | Legitimate interest in responding to people who contact us |
| Keeping a list of people who asked for early access to LogicReader, and inviting them | Email address; name, company, role and message if you gave them | Consent — you opt in by submitting the early-access form, and you can withdraw at any time |
| Sending you product news and marketing emails | Email address, name, prior engagement | Consent — withdraw at any time via the unsubscribe link |
| Running pilot projects on schedules your organisation uploads | Schedule data files | We act as your organisation’s processor, under the pilot agreement and Data Processing Agreement; your organisation decides the lawful basis (see section 7) |
| Working with organisations that take part in pilots or buy from us | Names and work contact details of the people we deal with | Legitimate interest in managing our business relationships |
| Selling our products through Paddle, and providing and supporting what you bought | Name, email address and the order details that Paddle shares with us | Contract, where you buy for yourself; legitimate interest in providing what was bought, where you buy for your organisation |
| Keeping our website and our early-access form secure and working, and detecting spam | Web server logs (IP address, request details, browser details); the IP address and browser details recorded with early-access requests | Legitimate interest in protecting our services |
| Complying with legal obligations (tax records, ICO requests) | Whatever the obligation requires | Legal obligation |
You have the right to object to processing carried out under “legitimate interest” — see section 9.
4. Marketing communications
We will only send you marketing emails if you have given us specific consent to do so. At present you can give it in two ways: by joining our early-access list, after which we email you about early access and product previews; or by ticking the marketing box when you register for LogicReader. You can withdraw consent at any time by clicking the unsubscribe link in any marketing email or by emailing privacy@cosmospm.com. If you have a LogicReader account, you can also use Email preferences in your account menu.
Marketing emails to LogicReader users are sent through our email delivery provider, Brevo, which is listed in the LogicReader Privacy Policy.
We do not sell your personal data to third parties for their own marketing purposes. We do not share your data with advertising networks.
5. Who we share your personal data with
We use a small number of carefully selected providers to run our website, our email and our business. Hostinger and Microsoft process personal data on our behalf, as our processors, and each of them is bound by a Data Processing Agreement (DPA). Google was also our processor, under a DPA, for Google Analytics on our former website. Paddle (for purchases) handles personal data under its own privacy notice, not on our behalf. The providers are:
| Provider | Service | Location of processing | Personal data shared |
|---|---|---|---|
| Hostinger UK Limited (London, United Kingdom) | Hosting of this website and of the LogicReader service (including the early-access list and pilot data); hosting of our former website until we close it down | United Kingdom (this website and the LogicReader service). Our former website is held on Hostinger shared hosting until we close it down. | Web server logs; early-access requests; pilot schedule data; LogicReader service data (see the LogicReader Privacy Policy) |
| Microsoft Corporation (with Microsoft Ireland Operations Limited as the EU contracting entity) | Microsoft 365: our business email (including the addresses in this policy), documents and office tools | United Kingdom (data at rest). For our account, the United Kingdom is both the current and the committed data location (geography) for our email (Exchange Online), OneDrive, SharePoint, Teams and Microsoft 365 Copilot, under Microsoft’s data residency commitments | Your emails to us and our replies; contact details; business documents, such as pilot and customer records |
| Google LLC (with Google Ireland Limited as the EU contracting entity) | Google Analytics on our former website, until 25 September 2026 (as our processor). We deleted the Analytics property on 25 September 2026, and Google then removes the data permanently. | United States and other countries where Google operates | Pseudonymous usage data from our former website, collected only with your consent. Our current website sends no data to Google. |
| Paddle.com Market Limited (United Kingdom) and its group companies | Merchant of record (reseller) for purchases, when we start to sell (under Paddle’s own privacy notice) | United Kingdom, and Paddle group companies in Ireland, the United States and Canada | Paddle collects your name, email address, billing details and payment details directly when you buy. It shares with us the order details we need to provide what you bought and to support you. Your card details go to Paddle only; we never see or store them. |
When you buy from us through Paddle, Paddle is the merchant of record: it is the reseller that sells the product to you, takes your payment, and handles VAT and sales tax. Paddle processes your order and payment data as a controller under its own privacy notice. We do not sell through Paddle yet; this applies from the date we start.
LogicReader — including pilots, which run on LogicReader — also uses its own providers: among them Anthropic for the optional AI features, Brevo for account and marketing emails, and PostHog for usage statistics. The LogicReader Privacy Policy lists them and explains what each one receives.
Section 11 explains how we protect personal data that leaves the UK.
We may also disclose personal data to:
- Law enforcement, regulators, or courts where we are legally obliged to do so.
- Professional advisers such as our solicitors, accountants, or insurers, where necessary and bound by confidentiality.
- A successor entity in the event of a sale, merger, or restructuring of CosmosPM Ltd, in which case the recipient will be bound by this Privacy Policy or one substantially equivalent.
We will never sell your personal data to data brokers.
6. Cookies and similar technologies
Our website does not use cookies. It does not store anything in your browser (no local storage or similar technologies), and it runs no analytics, advertising or tracking tools. For this reason there is no cookie banner, and there is nothing for you to accept or change.
LogicReader, at logicreader.io, is a separate service with its own Cookie Policy. It uses only a strictly necessary cookie, to keep you signed in, and your browser’s local storage, to remember your preferences.
7. Schedule data uploaded during pilots
If your organisation enters a pilot agreement with us, you may upload project schedule files. These files may contain personal data — typically names of project team members, resource owners, or originators.
For this data:
- Your organisation is the data controller; CosmosPM Ltd is the data processor.
- A separate Data Processing Agreement (DPA) governs the processing.
- We will only use the data for the purposes set out in the pilot agreement.
- We will not share the data with anyone other than our sub-processors: the providers that support LogicReader, listed in the LogicReader Privacy Policy, or those agreed in the DPA.
- If the optional AI features are used on pilot schedules, the relevant schedule content is sent to Anthropic. We do not strip or redact names before sending: activity names and other schedule labels go to Anthropic as they are. Anthropic keeps API inputs and outputs for 30 days.
- We will delete the data within 90 days of pilot end, unless instructed otherwise in writing.
- Encryption in transit (TLS 1.2 or higher) applies.
We are happy to sign your organisation’s preferred DPA. We can also provide our standard one on request.
If you use the free self-serve LogicReader service rather than a pilot, the LogicReader Privacy Policy explains how we handle the schedules you upload.
8. How long we keep your personal data
We keep your personal data only for as long as necessary for the purposes for which it was collected. Specific retention periods are:
| Data category | Retention |
|---|---|
| Emails you send us, and our replies | Up to 6 years (in line with HMRC record-keeping rules) |
| Early-access list | 24 months from your last contact with us, then deleted. You can ask us to delete your data sooner. |
| Pilot and customer contact details | While we work with your organisation, then 24 months after our last contact. Where the details form part of contract or tax records, up to 6 years. |
| Pilot customer schedule data | Length of the pilot plus 90 days, then deleted |
| Web server logs (this website) | 90 days, then deleted automatically. Copies may remain in our server backups until those backups are replaced. |
| Data from our former website (member accounts, feature suggestions, and the former website’s own security and form logs) | Deleted on 26 September 2026. Copies may remain in our hosting provider’s automatic backups until those backups are replaced. |
| Google Analytics data from our former website | We deleted our Google Analytics property on 25 September 2026. Google then removes the data permanently. |
| AI feature inputs and outputs (Anthropic), including in pilots | 30 days, kept by Anthropic under its published data retention policy |
| Purchase records, and other financial and tax records | 6 years from the end of the relevant accounting period (HMRC requirement) |
| LogicReader account data, including your marketing email choices | See the LogicReader Privacy Policy |
When the retention period expires, we delete or fully anonymise the data.
9. Your rights under UK GDPR
You have the following rights in relation to your personal data:
| Right | What it means |
|---|---|
| Right of access | Get a copy of the personal data we hold about you |
| Right to rectification | Have inaccurate data corrected |
| Right to erasure | Have your data deleted (“right to be forgotten”) |
| Right to restriction | Pause or limit how we process your data |
| Right to portability | Receive your data in a structured, machine-readable format |
| Right to object | Object to processing that relies on our legitimate interest |
| Right to withdraw consent | Withdraw consent at any time, where consent is the lawful basis |
| Right not to be subject to automated decisions | Not to be left to a decision made only by a computer, with no person involved, when that decision has a legal or similarly significant effect on you — for example, an application refused automatically |
We do not make any decision about you by solely automated means that has a legal or similarly significant effect on you.
To exercise any of these rights, email us at privacy@cosmospm.com. We will respond within one calendar month, and may extend by a further two months for complex requests, in which case we’ll tell you why.
We may need to verify your identity before disclosing personal data. This is to protect your data from being released to someone impersonating you.
If you are unhappy with how we have handled your request, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
Helpline: 0303 123 1113
https://ico.org.uk/make-a-complaint/
We would, of course, prefer the chance to resolve your concern first — please email us before going to the ICO if you can.
10. Security
We protect your personal data with appropriate technical and organisational measures, including:
- Encryption in transit (TLS 1.2 or higher). Our website redirects every plain HTTP visit to its secure HTTPS address.
- A simple website: cosmospm.com is a static website with no login, no database and no forms, so the only visitor data it holds is its web server logs.
- Access controls (least-privilege principle; only authorised people can access personal data).
- Restricted, authenticated access to the servers that run our website and LogicReader.
- Regular backups of our servers.
- Security patching of our software stack on a regular cadence.
No system is perfectly secure. In the event of a personal data breach that creates a risk to your rights and freedoms, we will notify the ICO within 72 hours and will inform you directly if the risk is high.
11. International transfers
Most of the personal data this policy covers is stored in the United Kingdom: our website and LogicReader run on servers in the United Kingdom, and our Microsoft 365 email and documents are stored in the United Kingdom. Some personal data does leave the UK:
- when LogicReader’s optional AI features are used, including in a pilot, the relevant schedule content goes to Anthropic in the United States (see section 7 and the LogicReader Privacy Policy);
- our providers, or their group companies and support teams, may access data from outside the UK where this is needed to provide their service; and
- Google Analytics data from our former website was processed by Google, including in the United States; we deleted the Analytics property on 25 September 2026 (see section 8).
UK GDPR allows such transfers only when adequate safeguards are in place. We rely on:
- UK adequacy regulations, where the UK recognises the destination country as protecting personal data adequately (for example, countries in the European Economic Area).
- The UK International Data Transfer Addendum to the EU Standard Contractual Clauses, in our agreements with the relevant providers.
- The UK Extension to the EU-US Data Privacy Framework, where the US provider is certified under it.
- Technical measures such as TLS encryption.
- Data minimisation — only the data that is strictly necessary leaves the UK.
In short: our contracts with these providers require them to protect your data to UK standards, even when they process it abroad.
Paddle (for purchases) is responsible for its own transfer safeguards, as described in its privacy notice. The LogicReader Privacy Policy describes the transfers made by LogicReader’s own providers.
For full details of any specific transfer, contact privacy@cosmospm.com.
12. Children’s data
Our products and website are designed for business users aged 18 and over. We do not knowingly collect personal data from children. If you believe we have inadvertently collected personal data from a child, please contact us at privacy@cosmospm.com and we will delete it promptly.
13. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of the policy reflects the most recent change. If we make a material change that affects how we use your personal data, we will notify you directly (where we have your email) before the change takes effect.
A full version history of this policy is available on request.
14. Contact
For any questions about this Privacy Policy, your personal data, or to exercise any of your rights:
Email:
privacy@cosmospm.com
Postal: CosmosPM Ltd, C/O The Accountancy
Partnership, Suite 5, 5th Floor, City Reach, 5 Greenwich View
Place, London E14 9NN, United Kingdom
This policy is governed by the laws of England and Wales. Any disputes will be resolved in the courts of England and Wales.