Privacy Policy

Last updated: 2026-08-05.

Who we are

Cozens Software Solutions Limited (company number 09856828) is registered in England and Wales, with its registered office at Cawley Priory, South Pallant, Chichester, West Sussex, PO19 1SY. The company operates cososo.co.uk and is the data controller for personal data collected through this website and its associated reporting channels. In this policy, “COSOSO” or “we” refers to Cozens Software Solutions Limited.

For data-protection enquiries or to exercise any right described below, please contact us using the website contact form with “privacy request” in the subject line.

What SolidSyslog does not collect

SolidSyslog is source-available software you run inside your own systems. It transmits log data between endpoints you control, contains no telemetry, and sends no data to COSOSO. We do not receive, see, or store the logs it transports.

When you deploy SolidSyslog, you remain the data controller for the log content, including any personal data your logs may contain. This policy covers only the personal data COSOSO collects through the cososo.co.uk website and the reporting channels we operate.

What we collect, and why

Each processing activity is described below, together with the categories of data involved, the purpose for which we use it, our lawful basis under the UK GDPR, and how long we retain it.

Contact form and commercial enquiries

When you submit the contact form on the home page, including via the SolidSyslog commercial-licence route at /?service=solidsyslog#contact, we collect the name, email address, enquiry type, subject and message you provide.

  • Purpose: to respond to your enquiry and, where relevant, to enter into a commercial relationship with you.
  • Lawful basis: taking steps at your request prior to entering into a contract (UK GDPR Article 6(1)(b)) for commercial enquiries; our legitimate interests in responding to general contact (Article 6(1)(f)) for other enquiries.
  • Retention: correspondence is retained for 24 months from your last message. Where an enquiry leads to an ongoing customer relationship, correspondence is retained for the duration of the relationship plus six years, in line with UK statutory record-keeping requirements.
  • Where it goes: submissions are emailed to the COSOSO inbox, hosted on Google Workspace (Gmail).

Vulnerability reports

You may report a security vulnerability in a COSOSO product either through the form at cososo.co.uk/security/report or via GitHub’s private vulnerability reporting on the relevant repository. In either case, we collect:

  • Your name or handle (optional; reports may be submitted pseudonymously).
  • An email address (required, so that we can acknowledge the report and coordinate a response).
  • Your consent, if given, to public credit in any resulting advisory.
  • Report content: affected product and version, vulnerability class, suggested severity, description, and reproduction steps.

We use this data to acknowledge the report within 72 hours, coordinate a fix and disclosure, and, where you have consented, credit you in the resulting public advisory. Consent to credit is opt-in on the report form; where you have not opted in, we will not include your name or handle in any advisory we publish. You may withdraw consent at any time before an advisory is published.

  • Purposes: triage and remediation of the reported issue; communication with you during coordination; publication of a credited advisory where consent has been given.
  • Lawful basis: our legitimate interests in maintaining product security (UK GDPR Article 6(1)(f)) for triage and coordination; your consent (Article 6(1)(a)) for public credit.
  • Access: reports are visible to COSOSO maintainers only. We do not disclose reporter identity outside COSOSO except where you have consented to public credit in a published advisory.
  • Retention: reports are retained for the working life of the affected product, so that we can trace the history of vulnerabilities and their fixes. Once an advisory has been published on GitHub Security Advisories, that public record persists there indefinitely; GitHub, not COSOSO, controls how long a published advisory remains public.
  • Erasure: we will erase your reporter data from our records on request. Where an advisory is already public and credits you, we will ask GitHub to remove your name from the advisory; the outcome is governed by their processes. The advisory itself cannot be withdrawn once published.

Blog comments

When you leave a comment on an article, WordPress records the name, email address and website URL you provide, together with your IP address and browser user-agent string. The IP address and user-agent are used to help detect spam.

  • Lawful basis: our legitimate interests in moderating discussion on articles we publish (UK GDPR Article 6(1)(f)).
  • Retention: comment records are retained for as long as the article they attach to remains published. You may request removal of a specific comment at any time.
  • An anonymised hash of your email address may be sent to the Gravatar service to check for a profile picture.

Server logs and security plugins

Our hosting provider (names.co.uk) records standard web server logs. For each request these contain your IP address, the timestamp, the URL requested, the HTTP response code, your browser’s user-agent string, and the referring page. They do not contain data submitted through forms on the site: form submissions travel in the request body, which is not logged.

Security plugins on the site (Kadence Security Basic) also log authentication attempts and requests judged suspicious. These records carry the same categories of data plus, for authentication attempts, the username tried.

  • Purpose: operating the site, diagnosing errors, and protecting against attacks.
  • Lawful basis: our legitimate interests in a secure and reliable site (UK GDPR Article 6(1)(f)).
  • Retention: web server logs are retained by our hosting provider under their standard policy, typically 30 to 90 days. Security-plugin event logs are limited to a rolling window controlled by the plugin.

Website analytics

We use Plausible Analytics to understand how the website and our product documentation are used, across both cososo.co.uk and docs.cososo.co.uk. Plausible is a privacy-focused, cookieless analytics service hosted in the European Union.

Plausible does not use cookies, does not store any identifier on your device, and does not track you across websites or over time. It collects no personal data and does not create a persistent profile of you. For each page view it records the page URL, the referring source, and coarse information derived from your request — country, and browser, operating system and device type. Your IP address and user-agent are used only momentarily, in memory, to generate a daily-rotating one-way hash that lets Plausible count a visitor once per day; the hash cannot be reversed and is discarded when it rotates. Neither your IP address nor your user-agent is stored.

Alongside page views, Plausible counts three kinds of interaction: clicks on links leading away from our sites, file downloads, and the fact that a form was submitted. For form submissions it records only that a submission occurred, as a count — it does not capture the contents of any field. What you type into the contact form is handled solely as described under Contact form and commercial enquiries above.

Because nothing is stored on or read from your device, this measurement does not require consent under the Privacy and Electronic Communications Regulations, and the site therefore shows no cookie banner for it.

  • Purpose: to see which pages and documentation are read, and where visitors arrive from, so that we can improve them.
  • Lawful basis: our legitimate interests in understanding and improving our website (UK GDPR Article 6(1)(f)). We consider this proportionate because the measurement is aggregate, uses no cookies, and identifies no individual.
  • Retention: Plausible retains only aggregate statistics, which we keep for the life of our account. No individual-level record is created, so there is nothing to retain about you personally.

Our product documentation at docs.cososo.co.uk is hosted by GitHub Pages rather than names.co.uk. GitHub records standard web server logs for requests to it, of the same categories and for the same purposes described under Server logs and security plugins above.

Backups

Our hosting provider (names.co.uk) takes platform-level backups of the site as part of their service. COSOSO also takes an independent rolling backup using WPvivid, stored on Google Drive.

  • Purpose: disaster recovery.
  • Lawful basis: our legitimate interests in keeping the site recoverable (UK GDPR Article 6(1)(f)).
  • Retention: names.co.uk retain their platform backups under their published policy. The WPvivid copy rolls over every seven days.

Cookies and reCAPTCHA

The site uses a small number of cookies:

  • Comment cookies: if you leave a comment and select “save my details”, WordPress stores your name, email and website in a cookie so that you do not have to re-enter them on future visits. These cookies last one year and may be cleared from your browser at any time.
  • Login cookies: relevant only if you have a login on the site (currently limited to COSOSO staff). These allow the WordPress admin area to remember an authenticated session.
  • Cache and session cookies: the hosting layer may set short-lived cookies to serve pages efficiently. These contain no personal data.

Our website analytics set no cookies at all, which is why the site shows no cookie banner.

The contact form is protected by Google reCAPTCHA v3, which runs invisibly on pages where the form appears. It analyses browser and device signals to score the likelihood that a submission originates from a bot. Google receives this data. Its use is governed by Google’s privacy policy and terms.

Who processes personal data on our behalf

The following third parties receive some of the data described above, acting as our data processors or as independent controllers as noted:

  • names.co.uk — web host. Processes anything stored on or transmitted through the website, including platform-level backups. Their privacy policy.
  • Google (Workspace / Gmail) — receives contact-form and security-report emails routed to the COSOSO inbox.
  • Google (reCAPTCHA) — receives browser signals from visitors on pages carrying the contact form.
  • Google (Drive) — stores website backups.
  • Plausible Analytics — receives page-view data from visitors to cososo.co.uk and docs.cososo.co.uk. Hosted in the European Union. Their data policy.
  • GitHub — hosts the SolidSyslog repository, private vulnerability reports, published Security Advisories, and the documentation site at docs.cososo.co.uk. Data submitted directly to GitHub (issues, discussions, private vulnerability reports) is processed under GitHub’s own privacy statement.

International transfers

Google and GitHub are United States-based providers. Where personal data is transferred outside the United Kingdom to reach them, the transfer is made under safeguards published by each provider, typically the UK international data transfer addendum in combination with EU Standard Contractual Clauses, together with the providers’ technical and organisational measures. Copies of the relevant safeguards are available from each provider directly.

Plausible Analytics hosts its data within the European Economic Area, which the United Kingdom recognises as providing an adequate level of data protection. No additional transfer safeguard is required.

Your rights

Under the UK GDPR you have the right to:

  • request a copy of the personal data we hold about you;
  • request that inaccurate data is corrected;
  • request that data we hold about you is deleted, subject to the limitations described in the vulnerability reports section and any legal obligation to retain it;
  • request that we restrict how we use your data;
  • object to processing that we carry out on the basis of our legitimate interests;
  • withdraw any consent you have previously given, including consent to credit in a published advisory.

To exercise any of these rights, please contact us using the contact form with “privacy request” in the subject line.

Complaints

If you are not satisfied with how we have handled your personal data or a data-rights request, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk).

Changes to this policy

We may update this policy from time to time. When we do, we will update the “last updated” date at the top of the page. Where a change affects the handling of personal data we already hold, we will contact affected people directly where practical.