Privacy Policy
Last updated: December 8, 2025
1. Controller
The controller responsible for data processing on this website is:
cosmoventures OÜ
Uus-Sadama tn 21-207
10120 Tallinn, Estonia
Email: info@cosmoventures.eu
2. Data Protection Officer
According to Art. 37 GDPR, the appointment of a data protection officer is not mandatory for our company, as we do not carry out core activities involving extensive, regular and systematic monitoring of individuals and do not process special categories of personal data on a large scale.
For data protection questions, please contact us directly at: info@cosmoventures.eu
3. Collection and Storage of Personal Data
a) Server log files when visiting the website
When you visit our website, information is automatically transmitted by your browser and stored in server log files:
- IP address (anonymized)
- Date and time of the request
- Browser type and version
- Operating system used
- Referrer URL (previously visited page)
- Hostname of the accessing computer
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in ensuring system security and functionality)
Balancing of interests: Our legitimate interest lies in ensuring stable and secure operation of our website. Temporary storage of anonymized IP addresses and technical access data is necessary for detecting and defending against attacks as well as for error diagnosis. Your interests are protected through IP address anonymization and the short storage period of 30 days.
Retention period: Log files are automatically deleted after 30 days.
Recipients: Base44 Platform (hosting provider), Supabase Inc. (see Section 11)
4. Use of the Questionnaire
When using our emigration questionnaire, we store your answers to provide you with personalized country recommendations.
Processed data: Your answers regarding age, budget, language skills, climate preferences, professional situation, and emigration priorities
Legal basis: Art. 6 (1) lit. b GDPR (contract fulfillment or pre-contractual measures) and Art. 6 (1) lit. f GDPR (legitimate interest in providing personalized recommendations)
Balancing of interests: Our legitimate interest is to provide you with suitable country recommendations based on your information and make them available for later review. This enables you to have a well-founded decision-making basis for your emigration plans. Your interests are protected as the processing is transparent, you can delete the data at any time, and no sensitive categories of personal data are processed.
Retention period: Your questionnaire data is stored as long as you have a user account. In case of inactivity (no login for 24 months), we will contact you by email and inform you of an upcoming deletion. Without response within 30 days, your account and all associated data will be deleted. You can delete your account and all data yourself at any time via your dashboard or by emailing us.
Profiling: Yes. We use an AI-powered algorithm (OpenAI GPT) to determine suitable countries based on your answers. The logic takes into account your stated preferences and priorities to calculate a matching score for each country. No automated decision-making within the meaning of Art. 22 GDPR takes place – the recommendations serve only for your information and support.
Right to object: You have the right under Art. 21 (1) GDPR to object at any time to the processing of your data for profiling purposes. Contact us at info@cosmoventures.eu for this purpose.
Recipients: OpenAI (see Section 12)
Data Protection Impact Assessment (DPIA): We have conducted an impact assessment according to Art. 35 GDPR. The AI-powered profiling was classified as low-risk because (1) no sensitive data categories are processed, (2) data is transmitted to OpenAI in pseudonymized form, (3) no automated decision-making with legal effect occurs, (4) recommendations are purely informational, and (5) users can object at any time. A copy of the DPIA documentation can be requested at info@cosmoventures.eu.
5. Cookies
Our website uses cookies. Cookies are small text files that are stored locally in your browser's cache.
a) Technically necessary cookies
These cookies are required for the operation of the website and cannot be deactivated. They store, for example, your cookie settings.
b) Analysis cookies (only with consent)
With your explicit consent, we use Google Analytics for statistical analysis of website usage. These cookies are only set after your consent in the cookie banner.
Legal basis for technically necessary cookies: Art. 6 (1) lit. f GDPR (legitimate interest)
Legal basis for analysis cookies: Art. 6 (1) lit. a GDPR (consent)
Retention period: Technically necessary cookies: up to 12 months. Analysis cookies: see Google Analytics section.
Withdrawal of your consent:
You can withdraw your consent to analysis cookies at any time by clicking on the cookie settings icon (bottom right on every page) or by deleting the cookies in your browser. The withdrawal is effective for the future – data already collected remains unaffected by the lawfulness of the previous processing.
6. Google Analytics
This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
Legal basis: Your consent according to Art. 6 (1) lit. a GDPR, which you can provide via our cookie banner.
Data processing: Google Analytics uses cookies and collects information about your use of this website (e.g., pages visited, duration of stay, device used). We have activated IP anonymization, so your IP address is shortened by Google within the EU/EEA.
Retention period: Google stores the collected data for 14 months. After this period expires, the data is automatically deleted.
Data transfer to third countries: Google may transfer data to the USA. According to current law, the USA is considered an unsafe third country. The transfer is based on EU Standard Contractual Clauses (SCC) concluded with Google. These clauses oblige Google to ensure an adequate level of data protection.
Summary of SCC: The Standard Contractual Clauses are contractual guarantees approved by the EU Commission that ensure personal data is protected when transferred outside the EEA. They oblige the data recipient (Google) to comply with European data protection standards. The complete SCC can be viewed at https://business.safety.google/adsprocessorterms. Google has implemented additional guarantees, including technical security measures (TLS encryption, access control) and ISO 27001 certification.
Recipients: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (as data processor)
Data Processing Agreement: A Data Processing Agreement (DPA) according to Art. 28 GDPR has been concluded with Google.
Objection/Opt-out: You can prevent collection by Google Analytics by:
- Selecting "Decline" in the cookie banner
- Installing the Google Analytics opt-out browser add-on: https://tools.google.com/dlpage/gaoptout
- Deleting cookies in your browser and selecting "Decline" on your next visit
For more information, see Google's Privacy Policy.
7. Newsletter
You can subscribe to a newsletter on our website to receive information about news and tips on emigration.
Processed data: Email address, time of registration and confirmation
Legal basis: Art. 6 (1) lit. a GDPR (consent). We use the double opt-in procedure, i.e., you receive a confirmation email before the newsletter delivery begins.
Retention period: Your email address is stored until you unsubscribe from the newsletter.
Withdrawal: You can withdraw your consent at any time by clicking on the unsubscribe link in each newsletter email or by sending us an email at info@cosmoventures.eu.
Recipients: Newsletters are sent via our own infrastructure (Base44 Platform, Supabase). For sending, we use the Core.SendEmail integration, which runs through our hosting provider (see Section 11).
8. Experience Reports and Comments
You can share experience reports about your emigration experiences on our website and leave comments on our guides.
Processed data: Name, country, title and content of the report/comment, possibly other voluntary information
Legal basis: Art. 6 (1) lit. a GDPR (consent to publication)
Retention period: Your posts are published permanently until you contact us for deletion.
Retention period: Published posts are stored permanently. In case of author inactivity (no login for 36 months), we will contact you by email and ask if the posts should remain published. Without response within 60 days, posts will be anonymized (your name will be replaced by "Former User"). You can request complete deletion of your posts at any time.
Note: All posts are reviewed and approved by us before publication.
9. Technical and Organizational Measures (TOM)
We have implemented technical and organizational security measures to protect your personal data from loss, manipulation, or unauthorized access:
- TLS encryption: All data transmission between your browser and our servers is encrypted via HTTPS/TLS.
- Access control: Access to personal data is restricted to authorized employees who need this data to fulfill their tasks.
- Secure storage: Passwords are stored hashed. Databases are protected by authentication.
- Regular updates: Our systems and software are regularly updated to close security vulnerabilities.
- Backup strategy: Regular backups protect against data loss.
These measures are continuously reviewed and adapted to the state of the art.
10. Disclosure of Data to Third Parties
We only disclose your personal data to third parties if:
- You have expressly consented according to Art. 6 (1) lit. a GDPR,
- The disclosure is necessary according to Art. 6 (1) lit. f GDPR for asserting, exercising, or defending legal claims,
- There is a legal obligation according to Art. 6 (1) lit. c GDPR.
The following service providers process data on our behalf (data processors according to Art. 28 GDPR):
Base44 Platform / Supabase Inc.
Purpose: Hosting and database services
Location: USA (data transfer based on SCC)
DPA: Yes
Google Ireland Limited (Google Analytics)
Purpose: Web analytics (see Section 6)
Location: Ireland / USA (data transfer based on SCC)
DPA: Yes
OpenAI Inc.
Purpose: AI-powered country recommendations (see Section 12)
Location: USA (data transfer based on SCC)
DPA: Yes
11. Hosting
Our website is hosted on servers of Base44 Platform (based on Supabase Inc.).
Provider: Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992
Scope: The hosting provider processes all data collected via our website as part of data processing (server logs, user data, questionnaire answers, etc.).
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in reliable website operation)
Balancing of interests: Our legitimate interest lies in the technical provision and secure operation of our website. Hosting providers are essential for professional website operation. Your interests are protected by contractual guarantees (DPA, SCC) and technical security measures.
Data transfer: Data may be transferred to the USA. The transfer is based on EU Standard Contractual Clauses (SCC). A copy of the SCC can be viewed at Supabase at https://supabase.com/privacy or requested from us. Additionally, Supabase has implemented technical and organizational measures that ensure an adequate level of protection (e.g., encryption, access control).
Data Processing Agreement: A Data Processing Agreement according to Art. 28 GDPR has been concluded with Supabase.
12. Use of AI Services (OpenAI)
To create personalized country recommendations, we use the API from OpenAI (GPT-4).
Provider: OpenAI Inc., 3180 18th Street, San Francisco, CA 94110, USA
Processed data: Your pseudonymized questionnaire answers are transmitted to OpenAI to generate country recommendations. No personally identifiable data (name, email) is transmitted.
Legal basis: Art. 6 (1) lit. b GDPR (contract fulfillment) and Art. 6 (1) lit. f GDPR (legitimate interest in providing intelligent recommendations)
Balancing of interests: Our legitimate interest lies in providing high-quality, personalized recommendations through the use of modern AI technology. This enables more precise and useful results than conventional algorithms. Your interests are protected through pseudonymization of data, short storage periods at OpenAI (30 days), and contractual guarantees.
Data transfer: Data is transferred to the USA. The transfer is based on EU Standard Contractual Clauses (SCC). The SCC used by OpenAI can be viewed at https://openai.com/enterprise-privacy. OpenAI has implemented additional technical and organizational measures (e.g., SOC 2 Type II certification, encryption in transit and at rest).
Data deletion: According to OpenAI policies, API requests are automatically deleted after 30 days and are not used for training models.
Data Processing Agreement: A Data Processing Agreement according to Art. 28 GDPR has been concluded with OpenAI.
13. Your Rights
You have the following rights under GDPR with respect to us regarding your personal data:
Right to access (Art. 15 GDPR)
You can request information about your stored personal data.
Right to rectification (Art. 16 GDPR)
You can request the correction of incorrect data.
Right to erasure (Art. 17 GDPR)
You can request the deletion of your data, provided there are no legal retention obligations.
Right to restriction of processing (Art. 18 GDPR)
You can request the restriction of processing of your data.
Right to data portability (Art. 20 GDPR)
You can request that we provide you with your data in a structured, commonly used and machine-readable format.
Right to object (Art. 21 GDPR)
You can object at any time to the processing of your data if it is based on a legitimate interest (Art. 6 (1) lit. f GDPR).
Withdrawal of consent (Art. 7 (3) GDPR)
If processing is based on consent, you can withdraw it at any time with effect for the future. The lawfulness of the processing carried out until the withdrawal remains unaffected.
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR):
You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data.
Competent supervisory authority for Estonia:
Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Tatari 39, 10134 Tallinn, Estonia
Email: info@aki.ee
Website: www.aki.ee
You can also contact your local data protection authority in your country of residence. A list of all EU data protection authorities can be found at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
14. Deletion Concept
We have implemented a structured deletion concept to ensure that personal data is not stored longer than necessary:
- Server log files: Automatic deletion after 30 days
- Google Analytics: Automatic deletion after 14 months
- Newsletter subscribers: Deletion upon unsubscribing or upon request
- User accounts: In case of inactivity (no login for 24 months), an email notification is sent. After another 30 days without response, the account and all associated data (questionnaire answers, favorites, checklists) are deleted.
- Experience reports/comments: Permanent publication. In case of author inactivity (no login for 36 months), an email notification is sent. After another 60 days without response, posts are anonymized. Complete deletion possible at any time upon request.
- OpenAI API requests: Automatic deletion after 30 days (according to OpenAI policies)
You can request deletion of your data at any time by contacting us at info@cosmoventures.eu. We will comply with your request immediately, unless there are legal retention obligations.
15. Updates and Changes to the Privacy Policy
This privacy policy is dated December 8, 2025. Due to the further development of our website or due to changed legal or regulatory requirements, it may become necessary to change this privacy policy.
We review this privacy policy at least once a year for currency and completeness. In case of material changes, we will inform you via our website or by email (if you have a user account).
The current privacy policy can be accessed and printed on this page at any time.
Version History:
- December 8, 2025: Initial version with comprehensive information on data processing, retention periods, balancing of interests, deletion concept, and detailed information on third-party service providers
16. Contact
For questions about data protection or to exercise your rights, please contact us at:
cosmoventures OÜ
Uus-Sadama tn 21-207
10120 Tallinn, Estonia
Phone: +49 15679 745389
Email: info@cosmoventures.eu