These notices describe current operation. Details of provider contracts, processing locations and certain deletion periods still need to be completed; the affected sections identify them explicitly.
Controller
FARE Development GmbH · Bauvereinstr. 31 · 32049 Herford · Germany, represented by Nick Fahr. Privacy enquiries: contact@cozymals.com. This notice covers cozymals.com, including Soft Life, Cards, sign-in and publicly shared cards.
Page access and hosting
The application and database run in the Azure region West Europe. Accessing the website technically involves processing data such as your IP address, time, requested path, browser details and connection information. The application and database are hosted on Microsoft Azure. Processing supports delivery, troubleshooting and abuse prevention (GDPR Article 6(1)(f)); our interest is a safe, functioning service. The current application contains no advertising or analytics trackers and serves its own images and font files.
Account and security
We process email address, protected sign-in data, internal identifier, language, creation and last sign-in times, and session and security data. Passwords are not stored in plain text. Processing supports the account (GDPR Article 6(1)(b)) and access security (Article 6(1)(f)). Sign-in and reset links contain time-limited tokens. Abuse counters use hashes derived from IP addresses or email addresses.
Soft Life and Cards
Reminders, plans, settings, card drafts, design selections and pack unlocks are stored in your account to provide your chosen functions across devices (GDPR Article 6(1)(b)). Optional planner text is entered by you. Avoid unnecessary sensitive information about yourself or others. Account-based functions cannot be provided without the necessary account details.
Cards can also be used without an account. Guest drafts and finished guest cards are stored on the server and associated with a random browser identifier. A sharing link permits viewing, but not editing or claiming ownership as the creator.
Sharing links and opening status
Anyone with a random sharing link can access its card without signing in. The public card API does not expose the account email address. The link includes the chosen language and may be forwarded. Opening the envelope records the first opening time for its creator; a preview by the signed-in owner does not count. No recipient identity is inferred. The basis is our legitimate interest in providing this status (GDPR Article 6(1)(f)). Revocation prevents new requests but does not automatically delete the draft or stored version.
Recipients with an account can save an uneditable copy in their private collection. This copy remains available even if the sharing link is later revoked. Finished cards and envelopes cannot be edited after final confirmation.
Cookies and browser storage
We use our own cookies so you can stay signed in, choose your language and return to your guest cards. We do not use advertising or analytics trackers.
Sign-in and security: Sign-in lasts up to 30 days. Specially protected access and individual security checks have shorter lifetimes of up to 8 hours and 2 minutes respectively.
Language: Your chosen language is remembered for up to one year.
Guest cards: When you start the guest editor, your browser is recognised for up to one year. This lets you access your own guest cards and later transfer them into your account. The cards themselves are kept only for the periods stated below.
You can delete this data in your browser settings. You may then need to sign in again, and access to your own guest cards may be lost. A previously saved language choice may remain in your browser until you clear the website data.
Where storage or access is strictly necessary to provide a function you expressly request, section 25(2)(2) TDDDG applies. Storage beyond that scope would require prior consent under section 25(1) TDDDG. Processing personal data additionally relies on the GDPR grounds stated in the relevant sections.
Contact and email
We process the sender address, message and necessary handling data for enquiries. Contract-related enquiries rely on GDPR Article 6(1)(b); other enquiries rely on our interest in answering them (Article 6(1)(f)). Requested sign-in and reset emails include an access link. We use OVH Email Pro to send email. Greeting cards are currently shared only through links you pass on yourself.
Recipients and processing locations
The application and database run in the Azure region West Europe. We use Microsoft Azure for the application and database, and OVH Email Pro to send account, verification, invitation and password-reset emails. Hosting providers process data necessary for operation, storage and security. The email provider processes recipient addresses, message contents including requested access links, and delivery data. Responsible operations and support staff access data only within their duties. Legal obligations may require disclosure to authorities.
Still to complete: The specific Microsoft and OVH contracting entities, confirmed processing-agreement status, other processing locations (particularly email and support) and any applicable safeguards for third-country transfers have not yet been fully documented. A European hosting region alone does not exclude access from third countries.
Retention
Account content is generally retained until deletion or account closure, unless legal obligations or legitimate claims require longer retention. Archiving is not deletion. Erasure requests can be sent to contact@cozymals.com.
Your sign-in expires after at most 30 days. Email sign-in links are valid for 15 minutes; verification and password-reset links for 30 minutes. These access methods can no longer be used after expiry. Associated security records are not always deleted immediately.
Still to complete: Binding deletion periods for operational logs, backups, enquiries and obsolete security records, and the detailed account-erasure procedure, still need to be defined and checked against actual operation.
Guest drafts expire 7 days after the last edit; finished guest cards expire 30 days after completion. Access is blocked at expiry and the entries are removed from the active database during the next hourly cleanup or server startup. If the creator claims a card into their account before expiry, or a recipient saves it to their collection, this guest expiry no longer applies. Saved cards follow the retention rules for account content. These periods do not describe the separate retention of backups.
Your rights
Subject to legal requirements, you may request access, rectification, erasure, restriction and data portability. Where processing relies on legitimate interests, you may object on grounds relating to your particular situation. Consent may be withdrawn for the future. Contact: contact@cozymals.com. You may also complain to a supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia. There is no automated decision-making with legal or similarly significant effects.