Section 01
Data controller
- Registered office
- Via Roma n. 34/4, 33075 Cordovado (PN), Italy
- Operational headquarters
- Viale Treviso, 74, 30026 Portogruaro (VE), Italy
- Tax code / VAT number
- 01786010932
- Companies Register / REA
- PN-104498
- Certified email (PEC)
- esse2-srls@pec.it
- Dedicated privacy channel
- privacy@cosen-lab.com
For any request for clarification, for information on the data architecture, or to exercise the rights granted by applicable personal data protection law, data subjects may contact the Controller directly using the contact details above or by email at privacy@cosen-lab.com.
Section 02
Data collected and processed
- 2.1 · Automatic
Browsing data and technical metadata
The IT systems and software procedures used to operate this website automatically acquire, in the course of their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This category includes: IP addresses, HTTP status codes, server request times (UTC timestamps), URI/URL notation of the requested resources, operating system parameters, and the resolution and specifications of the browser used by the user.
- 2.2 · Provided by you
Data voluntarily provided by the data subject
Personal and contact data provided by the user when sending messages through the contact forms, requesting private demos, or subscribing to newsletters or lab communications, namely: first name, last name, business or personal email address, telephone number, company name of the entity or business represented, and the text content of the messages exchanged.
- 2.3 · AI features
Data handled through artificial intelligence features
Any prompts, advanced search queries and datasets voluntarily provided by the user to interact with the analytical, predictive or simulation components on the website are processed in full and strict compliance with Regulation (EU) 2024/1689 (Artificial Intelligence Act).
No improper training
Personal data entered in prompts are not used for the unauthorized retraining of foundation models or third-party algorithms.
No biometric profiling or scoring
Esse 2 S.r.l.s. categorically rules out any form of biometric profiling, social scoring or unauthorized remote identification.
Transparency and human oversight
Algorithmic results are generated in real time with appropriate technical safeguards to ensure the reliability and traceability of the output.
Section 03
Purposes of processing and legal bases
A. Website use and technical management
To enable smooth browsing, the proper delivery of application modules and the stability of the web infrastructure.
Art. 6.1.b GDPRRequiredPerformance of a contract or of pre-contractual measures requested by the data subject.
B. Responding to contact and support requests
To respond to requests for information, technical clarifications, private demo bookings or business partnership inquiries.
Art. 6.1.b GDPRRequiredPerformance of pre-contractual measures taken at the request of the data subject.
C. Compliance with legal and tax obligations
To comply with the civil-law, administrative, accounting and tax obligations established by Italian and EU law.
Art. 6.1.c GDPRRequiredCompliance with a legal obligation to which the Controller is subject.
D. Security, resilience and fraud prevention
To prevent unauthorized access, mitigate cyber/DDoS attacks, and preserve data integrity and service continuity.
Art. 6.1.f GDPRRequiredThe Controller’s legitimate interest in safeguarding IT security.
E. Informational communications about the lab
Optional delivery of periodic updates, release notes and research publications from Cosen Lab.
Art. 6.1.a GDPROptionalThe data subject’s freely given, specific and informed consent, which may be withdrawn at any time.
Providing data for purposes A, B, C and D is essential for browsing the website and for the proper handling of requests. Providing data for purpose E is entirely optional; failure to give consent, or its withdrawal, does not in any way affect access to the website or to the other services.
Section 04
Technical and organizational security measures
Advanced encryption
All online sessions and API calls use TLS 1.3 protocols with secure cipher suites and Perfect Forward Secrecy. Data stored on servers is protected with AES-256 encryption.
IAM and MFA management
Access to production systems strictly follows the Principle of Least Privilege (PoLP) and requires multi-factor authentication (MFA) for all administrative identities.
Redundant backups and BCDR
Periodic, encrypted backup procedures, geographically distributed within the EU, with semi-annual restore tests and strictly controlled RTO/RPO parameters.
Continuous monitoring
Logging and auditing of critical events through a Web Application Firewall (WAF), proactive detection of network anomalies, and structured management of any security incidents.
Section 05
Recipients and disclosure of data
Data processors (Art. 28 GDPR)
Cloud hosting providers located in the European Union, email and telecommunications providers, IT consultants responsible for infrastructure maintenance, and tax and legal advisory firms engaged for legal obligations.
Authorized personnel
Internal employees and collaborators of Esse 2 S.r.l.s., specifically instructed, authorized and bound by strict contractual confidentiality obligations.
Public and judicial authorities
Supervisory bodies and law enforcement agencies, solely in the cases provided for by mandatory rules or by lawful orders of the competent national or European authorities.
The up-to-date list of external Data Processors is kept at the Controller’s registered office and is promptly made available upon written request sent to privacy@cosen-lab.com.
Section 06
Transfers of data outside the EU / EEA
Within the EEA
Storage and processing take place primarily within the European Economic Area.
Should a transfer of data to non-EEA countries become necessary due to contingent operational needs, network infrastructure resilience or the use of specialized technology providers, such transfer will take place in full compliance with the safeguards established by Chapter V of the GDPR:
- Art. 45To third countries for which the European Commission has issued a formal Adequacy Decision, or to entities certified under the EU-U.S. Data Privacy Framework;
- Art. 46In the absence of adequacy decisions, through the adoption of the Standard Contractual Clauses (SCCs) adopted by the European Commission by Decision (EU) 2021/914, supplemented by appropriate additional encryption and technical security measures.
Section 07
Retention periods (data retention)
Browsing data and technical system logs
Up to 180 days
Contact data and pre-contractual / demo requests
Max. 24 months from closure of the request
Administrative, accounting and contractual data
10 years (pursuant to Art. 2220 of the Italian Civil Code)
Data for newsletters and lab communications
Until consent is withdrawn (opt-out)
Not to scale. The dashed bar indicates a period tied to the withdrawal of consent.
Upon expiry of the respective retention period, data are securely and irreversibly deleted or permanently anonymized through certified IT procedures.
Section 08
Data subject rights (Arts. 15-22 GDPR)
- Art. 15
Right of access
To obtain confirmation as to whether or not personal data concerning you are being processed, and to receive a clear copy of them.
- Art. 16
Right to rectification
To obtain the prompt correction of inaccurate data or the completion of incomplete data.
- Art. 17
Right to erasure (right to be forgotten)
To request the permanent deletion of data when no longer necessary for the original purposes, or upon withdrawal of consent.
- Art. 18
Right to restriction
To request the temporary suspension of processing where data are contested or a complaint has been lodged.
- Art. 20
Right to data portability
To receive your data in a structured, commonly used and machine-readable format (e.g. JSON or CSV).
- Art. 21
Right to object
To object at any time to processing based on the Controller’s legitimate interest.
Data subjects may exercise their rights at any time, entirely free of charge and without formal requirements, by sending a written communication to the dedicated addresses: privacy@cosen-lab.com or PEC (certified email) esse2-srls@pec.it.
Prepare your request
Free of charge, no formal requirements.
Choose the right and the channel: your email program opens with the text already filled in.
To: privacy@cosen-lab.com
Subject: Exercise of the right of access (Art. 15 GDPR)
Dear Esse 2 S.r.l.s., I hereby wish to exercise my right of access to my personal data, pursuant to Art. 15 of Regulation (EU) 2016/679. Full name: Email address used in my communications with you: Any details that may help identify the data: I look forward to your reply within the statutory time limits. Kind regards
This page neither sends nor stores anything: the message is sent only from your own email program.
Esse 2 S.r.l.s. will handle the request without undue delay and in any event within a maximum of 30 days of receipt of the communication (extendable by 60 days for particularly complex requests).
Section 09
Complaints to the supervisory authority
- Official address
- Piazza Venezia n. 11, 00187 Roma (RM), Italy
- Switchboard
- (+39) 06.696771
- Official website
- www.garanteprivacy.it
- Official PEC (certified email)
- protocollo@pec.gpdp.it
Data subjects residing or established in another Member State of the European Union may also lodge a complaint with the supervisory authority of the country in which they habitually reside, work, or in which the alleged infringement took place.
Section 10
Updates and changes
September 2026
Ref. LGL-GDPR-2026-V4
This privacy notice on the processing of personal data was last updated in September 2026.
Esse 2 S.r.l.s. reserves the right to make changes, additions or updates to this document at any time, in line with developments in applicable law (including the consolidation of the EU AI Act’s delegated acts) or as a result of technical and architectural implementations by the lab.
Any material changes will be communicated to registered users or made clearly visible through a dedicated banner before they actually take effect.