Privacy Policy
Last updated: May 2026
Scope
This privacy policy applies to the cozycrossings.com website and all associated domains (cozy-crossings.com, cozycrossings.de, cozy-crossings.de), which redirect to cozycrossings.com. The Cozy Crossings mobile app has its own separate privacy policy, which is provided in the app and on the App Store.
Controller
The controller responsible for data processing on this website within the meaning of Art. 4(7) GDPR is:
Leon Dudlik
Regentenstr. 15
51063 Köln
Germany
Email: hello@cozycrossings.com
Further details are available in the Legal Notice.
Data Protection Officer
We have not designated a Data Protection Officer, as we are not legally required to do so under Art. 37 GDPR or § 38 BDSG. For any data protection inquiries, please contact us at hello@cozycrossings.com.
Data we collect directly
This website does not use cookies, localStorage, sessionStorage, analytics tools, or tracking scripts. No information is stored on your device by this website. The only personal data we collect directly is your email address, if you choose to sign up for the newsletter described below.
Because this website does not use cookies or comparable storage technologies on your device, no consent within the meaning of § 25 TDDDG (formerly TTDSG) is required.
Email correspondence
If you contact us by email (e.g. at hello@cozycrossings.com), we will process the personal data you provide (in particular your email address, name where given, and the content of your message) for the sole purpose of handling your inquiry and any follow-up communication. The legal basis is Art. 6(1)(b) GDPR where your message relates to the performance of a contract or pre-contractual measures, otherwise our legitimate interest in responding to inquiries (Art. 6(1)(f) GDPR). Your message is stored in our email mailbox and deleted once the inquiry is fully handled and no statutory retention obligations require longer storage.
Newsletter — Brevo
If you sign up for the newsletter, we collect your email address for the purpose of sending you updates about Cozy Crossings, including launch announcements and beta access notifications. Providing your email address is voluntary; without it we are simply unable to send you the newsletter, but you incur no other disadvantage.
We use a double opt-in procedure: after submitting the form you will receive a confirmation email, and your address is only added to the mailing list once you click the confirmation link.
When you submit the form, your email address is first transmitted to our own application server (see "API server" below), which then forwards it to Brevo. Newsletter delivery itself is handled by Brevo SAS, 55 rue d'Amsterdam, 75008 Paris, France. Brevo acts as a data processor on our behalf under a data processing agreement in accordance with Art. 28 GDPR. For details on how Brevo processes your data, please refer to Brevo's privacy policy.
Brevo also notifies our application server of subscription-related events (e.g. when a confirmed sign-up is added to the mailing list) so that we can keep the subscription state in sync. These notifications contain only your email address and the type of event.
To document your consent in accordance with Art. 7(1) GDPR, Brevo additionally stores the IP address and timestamp of both your sign-up and your confirmation click. The legal basis for this documentation is our legitimate interest in being able to demonstrate valid consent (Art. 6(1)(f) GDPR in conjunction with Art. 7 GDPR).
Brevo may engage sub-processors in accordance with its data processing agreement; where any such sub-processor is located outside the EU/EEA, transfers are safeguarded by EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). Details are available in Brevo's sub-processor list.
The legal basis for processing is your consent (Art. 6(1)(a) GDPR). You can withdraw your consent and unsubscribe at any time by clicking the unsubscribe link in any newsletter email or by contacting us at hello@cozycrossings.com. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
Your email address is retained for as long as you remain subscribed. After you unsubscribe, your address is removed from the active mailing list. Brevo may continue to store your address in line with its own retention practices (in particular to honor your opt-out and prevent us from contacting you again without your renewed consent); please refer to Brevo's privacy policy for details. The legal basis for this continued storage on our side is our legitimate interest in honoring your opt-out and being able to demonstrate compliance (Art. 6(1)(f) GDPR). You can request full deletion of your data at any time by contacting us at hello@cozycrossings.com.
API server — Hetzner
Form submissions (currently the newsletter sign-up) are processed by our own application server hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server receives your email address and forwards it to Brevo as described above.
For the technical operation and security of the API (in particular to detect and prevent abuse such as spam or brute-force attempts), the server temporarily processes your IP address in memory for rate-limiting purposes. IP addresses are not written to persistent logs by our application and are discarded automatically after the 15-minute rate-limit window expires. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the integrity and availability of the service).
Hetzner is based in Germany; no transfer of data to countries outside the European Union is expected. We have concluded a data processing agreement (Auftragsverarbeitungsvertrag) with Hetzner in accordance with Art. 28 GDPR. For details, please refer to Hetzner's privacy policy.
The form also contains a hidden field used solely for spam detection. Submissions in which this field is filled are discarded and not forwarded to Brevo.
Hosting — IONOS
This website is hosted by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. When you visit this site, IONOS automatically records server log data, which may include:
your IP address, browser type and version, operating system, referring URL, pages visited, and date and time of access.
This processing is necessary for the technical operation and security of the website. The legal basis is Art. 6(1)(f) GDPR (legitimate interest). IONOS is based in Germany; no transfer of this data to countries outside the European Union is expected. Log data is typically retained for 7 days. We have concluded a data processing agreement (Auftragsverarbeitungsvertrag) with IONOS in accordance with Art. 28 GDPR. For full details, please refer to IONOS's privacy policy on their website.
External links
This site contains a link to Instagram, operated by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. When you click this link you leave this website entirely and Meta's own privacy policy and data practices apply. We have no influence over the data collected by third-party websites and are not responsible for their content. You can review Meta's privacy policy at privacycenter.instagram.com/policy.
Security
This website is secured by TLS encryption (HTTPS) to protect the confidentiality and integrity of data transmitted between your device and our servers.
Automated decision-making
We do not carry out any automated decision-making or profiling as defined in Art. 22 GDPR.
Children
This website is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can address it.
Your rights under GDPR
You have the following rights regarding your personal data:
Access (Art. 15): You may request confirmation of whether and which personal data concerning you is being processed.
Rectification (Art. 16): You may request correction of inaccurate data.
Erasure (Art. 17): You may request deletion of your data under certain conditions.
Restriction (Art. 18): You may request that processing be restricted in certain circumstances.
Data portability (Art. 20): Where processing is based on consent or a contract and carried out by automated means, you may request a machine-readable copy of your data.
Objection (Art. 21): You may object to processing based on legitimate interest at any time.
As the controller, we are your point of contact for all GDPR rights requests, even where the data is processed by our hosting provider on our behalf. To exercise your rights, please contact us at hello@cozycrossings.com (or via the details in the Legal Notice) and we will coordinate with IONOS as necessary.
Right to object to direct marketing (Art. 21(2) GDPR)
You have the right to object at any time, without giving reasons, to the processing of your personal data for direct marketing purposes (including newsletter mailings). If you object, we will no longer process your data for these purposes. The easiest way to object is to click the unsubscribe link in any newsletter email or to write to hello@cozycrossings.com.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority at any time, in particular in the EU member state of your habitual residence, place of work, or the place of an alleged infringement (Art. 77 GDPR). The supervisory authority competent for the controller is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestr. 2–4, 40213 Düsseldorf, Germany.
Changes to this Privacy Policy
We may update this privacy policy from time to time, for example to reflect changes in our processing activities or in applicable law. The current version is always available at this URL; the date of the most recent update is shown at the top of this page.