Arts. 13 and 14 · Regulation (EU) 2016/679

Privacy notice on the processing of personal data.

Full privacy notice provided to users of the website and digital services of Esse 2 S.r.l.s., in accordance with Arts. 13 and 14 of Regulation (EU) 2016/679 (GDPR), D.Lgs. 196/2003 as amended (Italian Privacy Code), and the transparency standards set out in the EU AI Act.

This English version is provided for convenience. In case of any discrepancy, the Italian version prevails. Read the Italian version

Controller
Esse 2 S.r.l.s.
Last updated
September 2026
Reference
LGL-GDPR-2026-V4
Contact
privacy@cosen-lab.com

Section 01

Data controller

The Controller of the personal data collected and processed through this website and its related application services is Esse 2 S.r.l.s.
Esse 2 S.r.l.s.
Registered office
Via Roma n. 34/4, 33075 Cordovado (PN), Italy
Operational headquarters
Viale Treviso, 74, 30026 Portogruaro (VE), Italy
Tax code / VAT number
01786010932
Companies Register / REA
PN-104498
Certified email (PEC)
esse2-srls@pec.it
Dedicated privacy channel
privacy@cosen-lab.com

For any request for clarification, for information on the data architecture, or to exercise the rights granted by applicable personal data protection law, data subjects may contact the Controller directly using the contact details above or by email at privacy@cosen-lab.com.

Section 02

Data collected and processed

While browsing, interacting with the components of the website and using the digital services provided by Esse 2 S.r.l.s., the following categories of data may be collected and processed.
  1. 2.1 · Automatic

    Browsing data and technical metadata

    The IT systems and software procedures used to operate this website automatically acquire, in the course of their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This category includes: IP addresses, HTTP status codes, server request times (UTC timestamps), URI/URL notation of the requested resources, operating system parameters, and the resolution and specifications of the browser used by the user.

  2. 2.2 · Provided by you

    Data voluntarily provided by the data subject

    Personal and contact data provided by the user when sending messages through the contact forms, requesting private demos, or subscribing to newsletters or lab communications, namely: first name, last name, business or personal email address, telephone number, company name of the entity or business represented, and the text content of the messages exchanged.

  3. 2.3 · AI features

    Data handled through artificial intelligence features

    Any prompts, advanced search queries and datasets voluntarily provided by the user to interact with the analytical, predictive or simulation components on the website are processed in full and strict compliance with Regulation (EU) 2024/1689 (Artificial Intelligence Act).

  • No improper training

    Personal data entered in prompts are not used for the unauthorized retraining of foundation models or third-party algorithms.

  • No biometric profiling or scoring

    Esse 2 S.r.l.s. categorically rules out any form of biometric profiling, social scoring or unauthorized remote identification.

  • Transparency and human oversight

    Algorithmic results are generated in real time with appropriate technical safeguards to ensure the reliability and traceability of the output.

Section 03

Purposes of processing and legal bases

Each processing of personal data carried out by Esse 2 S.r.l.s. relies on a specific legal basis under Art. 6 of Regulation (EU) 2016/679.
  1. A. Website use and technical management

    To enable smooth browsing, the proper delivery of application modules and the stability of the web infrastructure.

    Art. 6.1.b GDPRRequired

    Performance of a contract or of pre-contractual measures requested by the data subject.

  2. B. Responding to contact and support requests

    To respond to requests for information, technical clarifications, private demo bookings or business partnership inquiries.

    Art. 6.1.b GDPRRequired

    Performance of pre-contractual measures taken at the request of the data subject.

  3. C. Compliance with legal and tax obligations

    To comply with the civil-law, administrative, accounting and tax obligations established by Italian and EU law.

    Art. 6.1.c GDPRRequired

    Compliance with a legal obligation to which the Controller is subject.

  4. D. Security, resilience and fraud prevention

    To prevent unauthorized access, mitigate cyber/DDoS attacks, and preserve data integrity and service continuity.

    Art. 6.1.f GDPRRequired

    The Controller’s legitimate interest in safeguarding IT security.

  5. E. Informational communications about the lab

    Optional delivery of periodic updates, release notes and research publications from Cosen Lab.

    Art. 6.1.a GDPROptional

    The data subject’s freely given, specific and informed consent, which may be withdrawn at any time.

Providing data for purposes A, B, C and D is essential for browsing the website and for the proper handling of requests. Providing data for purpose E is entirely optional; failure to give consent, or its withdrawal, does not in any way affect access to the website or to the other services.

Section 04

Technical and organizational security measures

Pursuant to Art. 32 of Regulation (EU) 2016/679, Esse 2 S.r.l.s. adopts IT security criteria aligned with best practices and with the ISO/IEC 27001 and NIS2 standards (D.Lgs. 138/2024, Italy’s NIS2 implementing decree), ensuring the confidentiality, integrity and continuous availability of its systems.
  • Advanced encryption

    All online sessions and API calls use TLS 1.3 protocols with secure cipher suites and Perfect Forward Secrecy. Data stored on servers is protected with AES-256 encryption.

  • IAM and MFA management

    Access to production systems strictly follows the Principle of Least Privilege (PoLP) and requires multi-factor authentication (MFA) for all administrative identities.

  • Redundant backups and BCDR

    Periodic, encrypted backup procedures, geographically distributed within the EU, with semi-annual restore tests and strictly controlled RTO/RPO parameters.

  • Continuous monitoring

    Logging and auditing of critical events through a Web Application Firewall (WAF), proactive detection of network anomalies, and structured management of any security incidents.

Section 05

Recipients and disclosure of data

The personal data collected are not disseminated, monetized or transferred to third parties for advertising purposes. Data may be disclosed only to parties belonging to the following categories.
  1. Data processors (Art. 28 GDPR)

    Cloud hosting providers located in the European Union, email and telecommunications providers, IT consultants responsible for infrastructure maintenance, and tax and legal advisory firms engaged for legal obligations.

  2. Authorized personnel

    Internal employees and collaborators of Esse 2 S.r.l.s., specifically instructed, authorized and bound by strict contractual confidentiality obligations.

  3. Public and judicial authorities

    Supervisory bodies and law enforcement agencies, solely in the cases provided for by mandatory rules or by lawful orders of the competent national or European authorities.

The up-to-date list of external Data Processors is kept at the Controller’s registered office and is promptly made available upon written request sent to privacy@cosen-lab.com.

Section 06

Transfers of data outside the EU / EEA

Personal data are stored and processed primarily within the European Economic Area (EEA).
Rule

Within the EEA

Storage and processing take place primarily within the European Economic Area.

Exception · Chapter V GDPR (Arts. 44 et seq.)

Should a transfer of data to non-EEA countries become necessary due to contingent operational needs, network infrastructure resilience or the use of specialized technology providers, such transfer will take place in full compliance with the safeguards established by Chapter V of the GDPR:

  • Art. 45To third countries for which the European Commission has issued a formal Adequacy Decision, or to entities certified under the EU-U.S. Data Privacy Framework;
  • Art. 46In the absence of adequacy decisions, through the adoption of the Standard Contractual Clauses (SCCs) adopted by the European Commission by Decision (EU) 2021/914, supplemented by appropriate additional encryption and technical security measures.

Section 07

Retention periods (data retention)

In accordance with the principles of proportionality and data minimization (Art. 5.1.e GDPR), Esse 2 S.r.l.s. retains personal data only for as long as strictly necessary to achieve the purposes for which they were collected.
  1. Browsing data and technical system logs

    Up to 180 days

  2. Contact data and pre-contractual / demo requests

    Max. 24 months from closure of the request

  3. Administrative, accounting and contractual data

    10 years (pursuant to Art. 2220 of the Italian Civil Code)

  4. Data for newsletters and lab communications

    Until consent is withdrawn (opt-out)

Not to scale. The dashed bar indicates a period tied to the withdrawal of consent.

Upon expiry of the respective retention period, data are securely and irreversibly deleted or permanently anonymized through certified IT procedures.

Section 08

Data subject rights (Arts. 15-22 GDPR)

In accordance with Articles 15 to 22 of Regulation (EU) 2016/679, users have the right to exercise the following rights against Esse 2 S.r.l.s. at any time.
  • Art. 15

    Right of access

    To obtain confirmation as to whether or not personal data concerning you are being processed, and to receive a clear copy of them.

  • Art. 16

    Right to rectification

    To obtain the prompt correction of inaccurate data or the completion of incomplete data.

  • Art. 17

    Right to erasure (right to be forgotten)

    To request the permanent deletion of data when no longer necessary for the original purposes, or upon withdrawal of consent.

  • Art. 18

    Right to restriction

    To request the temporary suspension of processing where data are contested or a complaint has been lodged.

  • Art. 20

    Right to data portability

    To receive your data in a structured, commonly used and machine-readable format (e.g. JSON or CSV).

  • Art. 21

    Right to object

    To object at any time to processing based on the Controller’s legitimate interest.

Data subjects may exercise their rights at any time, entirely free of charge and without formal requirements, by sending a written communication to the dedicated addresses: privacy@cosen-lab.com or PEC (certified email) esse2-srls@pec.it.

Prepare your request

Free of charge, no formal requirements.

Choose the right and the channel: your email program opens with the text already filled in.

Right
Channel

To: privacy@cosen-lab.com

Subject: Exercise of the right of access (Art. 15 GDPR)

Dear Esse 2 S.r.l.s., I hereby wish to exercise my right of access to my personal data, pursuant to Art. 15 of Regulation (EU) 2016/679. Full name: Email address used in my communications with you: Any details that may help identify the data: I look forward to your reply within the statutory time limits. Kind regards

Open in your email program

This page neither sends nor stores anything: the message is sent only from your own email program.

Esse 2 S.r.l.s. will handle the request without undue delay and in any event within a maximum of 30 days of receipt of the communication (extendable by 60 days for particularly complex requests).

Section 09

Complaints to the supervisory authority

Without prejudice to any other administrative or judicial remedy, data subjects who consider that the processing of their personal data infringes Regulation (EU) 2016/679 have the right to lodge a complaint with the competent national supervisory authority.
Garante per la protezione dei dati personali (Italian Data Protection Authority)
Official address
Piazza Venezia n. 11, 00187 Roma (RM), Italy
Switchboard
(+39) 06.696771
Official website
www.garanteprivacy.it
Official PEC (certified email)
protocollo@pec.gpdp.it

Data subjects residing or established in another Member State of the European Union may also lodge a complaint with the supervisory authority of the country in which they habitually reside, work, or in which the alleged infringement took place.

Section 10

Updates and changes

Current version

September 2026

Ref. LGL-GDPR-2026-V4

This privacy notice on the processing of personal data was last updated in September 2026.

Esse 2 S.r.l.s. reserves the right to make changes, additions or updates to this document at any time, in line with developments in applicable law (including the consolidation of the EU AI Act’s delegated acts) or as a result of technical and architectural implementations by the lab.

Any material changes will be communicated to registered users or made clearly visible through a dedicated banner before they actually take effect.