> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cosmo.humanizing.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Protection & GDPR

> Understand GDPR roles, customer content, and data processing across Cosmo's Voicebot, Chatbot, and Kiosk Avatar

Use this section to prepare a compliant Cosmo deployment. It explains which legal document applies, which information each channel can process, and what your organization must complete before going live.

<Note>
  This documentation is an operational starting point, not legal advice. Your organization must assess its purposes, legal bases, retention periods, notices, and any sector-specific requirements.
</Note>

## Which document applies?

| Processing context                                                                                | GDPR role                                                        | Relevant document                                                                           |
| ------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------- | ------------------------------------------------------------------------------------------- |
| Cosmo account, administrator, billing, and support data                                           | Humanizing is the controller                                     | [Cosmo Web App Privacy Notice](https://cosmo.humanizing.com/web-app-privacy)                |
| Prompts, knowledge sources, integrations, and end-user interactions handled for your organization | Your organization is the controller; Humanizing is the processor | Your organization's privacy notice and the separately concluded [AVV](/data-protection/avv) |
| Contract terms and customer responsibilities                                                      | Defined in the Cosmo B2B Terms                                   | [Cosmo B2B Terms](https://cosmo.humanizing.com/terms)                                       |

The Web App Privacy Notice covers the business users who create, administer, pay for, or request support for a Cosmo account. It does not replace the privacy notice that you provide to people who interact with your agent.

## Data processing by channel

Use this table as a review checklist. Confirm each category against your live configuration and current AVV before you publish your notice.

| Channel                   | Categories to verify for your configuration                                                                                      |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------- |
| **Voicebot**              | Voice input, transcripts, generated replies and speech, call time and duration, and any enabled recording or routing data.       |
| **Chatbot**               | Chat messages, generated replies, timestamps, and information that an end user enters in the conversation.                       |
| **Kiosk Avatar**          | Information submitted through enabled touch, voice, language, visit, contact-search, call, or notification features.             |
| **Shared technical data** | Session identifiers, agent and language settings, and technical information recorded to provide and protect the enabled service. |

Your prompts, knowledge sources, uploaded documents, integration data, conversations, calls, and transcripts are customer content. Humanizing processes this content for your organization under the AVV.

## Before you go live

<Steps>
  <Step title="Conclude the AVV">
    Conclude the AVV before Cosmo processes customer content or end-user personal data for your organization. [Request the current AVV](/data-protection/avv).
  </Step>

  <Step title="Document your processing">
    Define the purpose, legal basis, data categories, recipients, retention period, and deletion process for your actual configuration.
  </Step>

  <Step title="Inform end users">
    Clearly state that the person is interacting with an AI system. Make your privacy notice available at each relevant interface. Start with the [privacy notice template](/data-protection/privacy-notice-template).
  </Step>

  <Step title="Check Voicebot requirements">
    Assess the rules that apply to telephone services, call recording, consent, caller identification, and emergency communications. Do not describe a call as recorded unless recording is enabled and your organization has established a lawful process.
  </Step>

  <Step title="Verify the live experience">
    Test the final notice, links, opening message, enabled channels, and retention settings in the deployed experience.
  </Step>
</Steps>

## Public legal documents

<CardGroup cols={2}>
  <Card title="Web App Privacy Notice" icon="user-shield" href="https://cosmo.humanizing.com/web-app-privacy">
    How Humanizing processes Cosmo account, administration, billing, and support data.
  </Card>

  <Card title="B2B Terms" icon="file-contract" href="https://cosmo.humanizing.com/terms">
    Contract terms, customer duties, and the separate AVV requirement.
  </Card>
</CardGroup>
