This policy explains what personal data we collect, the lawful basis for processing it, how we use and protect it, and the rights you have over your information. We do not sell your personal data to anyone.
Introduction
CosmOTT ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy describes how we collect, use, store, protect, and share personal information when you visit our website at cosmott.com or use our IPTV streaming service (collectively, the "Service").
This policy applies to all subscribers, visitors, and reseller partners. By subscribing to or using the CosmOTT Service, you acknowledge that you have read this Privacy Policy and understand how your data is handled.
We process personal data in accordance with applicable data protection legislation, including the General Data Protection Regulation (GDPR) where applicable, and the California Consumer Privacy Act (CCPA) for California residents.
Data We Collect
We collect two categories of data: information you provide to us directly, and information collected automatically when you use the Service.
| Data Type | What We Collect | Why |
|---|---|---|
| Account Data | Name, email address, WhatsApp/phone number, country | Account creation & service delivery |
| Payment Data | Billing details (processed by payment processor β we do not store card numbers) | Processing transactions |
| Device Identifiers | MAC address (for MAG Box activation only) | Device authentication |
| Usage Data | Channels watched, viewing duration, stream quality, connection timestamps | Service optimisation & fraud prevention |
| Technical Data | IP address, device type, OS, browser/app version, approximate location (country/city) | Security, diagnostics & geolocation compliance |
| Support Communications | Messages, emails, and chat conversations with our support team | Customer service & dispute resolution |
How We Use Your Data
We process your personal data for the following purposes, each with a lawful basis under applicable law:
- Service delivery: Creating and managing your account, activating your subscription, and providing access to the IPTV service. (Contractual necessity)
- Customer support: Responding to queries, troubleshooting issues, and resolving disputes. (Contractual necessity / Legitimate interest)
- Payment processing: Processing transactions and sending payment confirmations or renewal reminders. (Contractual necessity)
- Service improvement: Analysing usage patterns to improve performance, features, and content offerings. (Legitimate interest)
- Security & fraud prevention: Detecting and preventing credential sharing, account abuse, and fraudulent activity. (Legitimate interest)
- Legal compliance: Complying with applicable laws, court orders, or regulatory requirements. (Legal obligation)
- Marketing communications: Sending service updates or promotional offers where you have opted in. You can withdraw consent at any time. (Consent)
CosmOTT does not sell, rent, or trade your personal information to third parties for their own marketing purposes. Your data is used solely to operate and improve the CosmOTT service.
Cookies & Tracking
Our website uses cookies and similar tracking technologies. Cookies are small text files placed on your device that help us improve your experience and analyse usage.
You can manage or disable cookies through your browser settings at any time. Disabling essential cookies may impair website functionality.
Data Retention
We retain your personal data only as long as necessary to fulfil the purposes described in this policy or as required by law. Our specific retention periods are:
After the applicable retention period, your data is securely and permanently deleted or irreversibly anonymised.
Security Measures
We implement industry-standard technical and organisational security measures to protect your personal information against unauthorised access, loss, destruction, or alteration:
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher.
- Password hashing: Account passwords are stored as one-way cryptographic hashes β we cannot retrieve your plain-text password.
- Access controls: Personal data access is restricted to authorised personnel with a legitimate business need, subject to confidentiality obligations.
- Regular assessments: We conduct periodic security reviews, vulnerability assessments, and penetration testing.
- Incident response: We maintain a data breach response plan and will notify affected subscribers and relevant authorities within legally required timeframes.
Despite these measures, no internet transmission is completely secure. We commit to promptly addressing any data security incidents that occur.
Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data. To exercise any right, contact us at support@cosmott.com β we will respond within 30 days.
International Data Transfers
CosmOTT serves customers globally. Your personal data may be processed in countries other than where you reside, including countries that may not have the same level of data protection laws as your home country.
Where we transfer data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by relevant data protection authorities, adequacy decisions, or other legally recognised transfer mechanisms.
Children's Privacy
CosmOTT is not directed to, and does not knowingly collect personal information from, persons under the age of 18. Our Service requires subscribers to be at least 18 years old as set out in our Terms of Service.
If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately at support@cosmott.com. We will promptly investigate and take appropriate action, including deletion of the relevant data.
Policy Updates
We may update this Privacy Policy periodically to reflect changes in our data practices, technology, legal requirements, or for operational reasons. When material changes are made, we will update the "Last updated" date and, where practicable, notify active subscribers by email.
We encourage you to review this policy periodically. Continued use of the Service after any changes constitutes your acceptance of the updated policy.
Contact & Data Protection
For any questions, concerns, data subject requests, or complaints regarding this Privacy Policy or the processing of your personal information, please contact our Data Protection team: