Languages: English · Čeština · Deutsch · Español · Français · Italiano · Nederlands · Polski · Português · Română
This document exists in ten languages. The English version is the reference one.

cosmetiFULL Privacy Policy

Last updated: 10 September 2026 · Applies to: the cosmetiFULL platform and all services provided within it

The English version is the reference version and prevails in case of divergence between the versions. For consumers, the version in the language in which you concluded the contract prevails in your favour where the two differ, and where a term is unclear the interpretation most favourable to you prevails.


1. Who we are, and in what capacity

cosmetiFULL is a platform of digital services for the cosmetics industry, operated by:

Nicodemo & Signa Company Srl

Strada Lucian Blaga nr. 21, ap. 16, 310023 Arad, Romania

VAT number / unique registration code: RO15617609

Trade Register number: J02/809/2003

Email: info@cosmetifull.com

In this policy "we", "us" and "our" mean Nicodemo & Signa Company Srl.

We do not have the same role for all the data on the platform, and the difference matters to you.

We hold the same role for every service of the platform, present and future. Today the platform includes LabelCheck (review of cosmetic labels against EU rules, currently in beta) and ExpertDesk (professional guidance produced by an artificial intelligence system, in testing with a small group of professionals). ExpertDesk has its own privacy policy, reachable inside the application, and that one applies instead of this for the content of its conversations. Other services, including PIFBuilder and FormulaArchive, are under construction and are not yet sold. When they become available, they are covered by this same policy, unless we publish a specific notice for one of them.

2. Privacy contact and Data Protection Officer

We have not designated a Data Protection Officer, because our processing does not fall within the cases listed in Art. 37(1) GDPR: we are not a public authority, our core activities do not consist of large scale regular and systematic monitoring of individuals, and we do not process special categories of data on a large scale.

For any question about this policy or about your data, write to info@cosmetifull.com. That is our single public contact point for privacy matters.

3. Who this policy applies to

This policy applies to everyone whose personal data we process, and in particular to:

Where a rule applies only to consumers, we say so. Article 22 collects the points that concern consumers specifically.

4. Where we are a processor, and not a controller

A large part of what passes through the platform is not our data and is not processed for our purposes. When a manufacturer, a consultant or a safety assessor uploads a label artwork, a formulation or a dossier, that material may name people: a Responsible Person printed on a pack, a technical contact, a safety assessor who signs a document.

For those data:

There are several levels of people involved: the customer organisation, its own staff, the users it invites with read only access, and the external professionals it chooses to share a document with. The organisation decides all of that inside the platform.

If you are named in a document that one of our customers uploaded, the duty to inform you under Art. 13 and Art. 14 GDPR lies with that organisation, not with us, because it is the organisation that holds the relationship with you and decides what to do with your data. If you write to us to exercise a right over those data, we do not decide on the request: we pass it on to the organisation without undue delay and we help the organisation answer you, as Art. 28(3)(e) GDPR requires. Tell us which company the document belongs to and we will route it.

The rest of this policy describes the data for which we are the controller, except where it says otherwise.

5. What data we process

5.1 Account data

Name, email address, company name where applicable, password stored as a hash, role within a company account, language and interface preferences, date of registration.

5.2 Content you submit (we are a processor for this, see Article 4)

The label artwork, texts, formulations and product documentation you submit, the analyses and documents saved in your account, and your messages in the clarification chat.

The images you upload for an analysis are processed to produce the result and are not stored: what remains in your account is the analysis, its summary, the versions and your messages. Documents you attach to a declaration, and files you attach to a feedback message, are stored.

We do not ask for special categories of personal data and you should not upload them.

5.3 Purchase and billing data

This category exists because the platform is sold. We process:

The billing elements are not optional. They are what tax law requires an invoice to contain (Art. 319 of Law no. 227/2015, the Romanian Fiscal Code).

5.4 Payment card data

We do not process payment card data. See Article 6.

5.5 Usage and technical data

Logs needed to run and secure the platform: timestamps, IP address, user agent, request metadata, error logs, per account usage records, security events.

5.6 Communications

Messages you send us through the in app feedback channel and by email, including the files you attach to them, and our replies.

This category also covers the details you give us when you ask us to contact you about the Enterprise plan: your name, your email address, your company name, your telephone number and, if you add one, your message.

6. What happens to your card details

Payment is made on a payment page hosted by Stripe. Your card number, expiry date and security code are collected by Stripe directly on Stripe's own systems. They never pass through our systems, we never see them and we never store them.

For each payment we receive only the outcome (successful, failed, refunded), the transaction identifier and the elements we need in order to issue the invoice.

7. Why we process your data, and on what legal basis

7.1 To provide the platform and perform our contract with you

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

Creating and managing your account and your company account; running the services you request; saving analyses and documents in your account; operating the chat and the translations you ask for; selling and crediting prepaid credits; charging the price; deducting credits as you use the services; handling refunds of unconsumed credits; service messages connected to your purchase, such as the confirmation of the contract.

7.2 To issue invoices, keep our accounts and report to the tax authority

Legal basis: Art. 6(1)(c) GDPR (compliance with a legal obligation), with the obligation identified by name:

This processing continues even if you close your account. See Article 17.

7.3 To determine your VAT treatment and check your VAT number

Legal basis: Art. 6(1)(c) GDPR (compliance with a legal obligation).

The obligation is to determine the place of supply and the VAT treatment of the transaction and to hold evidence of your status as a taxable person and of your country: Articles 44 and 59c of Directive 2006/112/EC and Article 24b of Implementing Regulation (EU) No 282/2011, transposed in Law no. 227/2015 (Romanian Fiscal Code). See Article 15 for how the check works.

7.4 To prevent payment fraud and abuse of prepaid credits

Legal basis: Art. 6(1)(f) GDPR (legitimate interest).

Our legitimate interest, stated explicitly as Art. 13(1)(d) GDPR requires, is to prevent fraudulent payments, the unauthorised use of somebody else's card and the abuse of prepaid credits, in our own protection and in the protection of our customers. This includes the automated control on a purchase described in Article 9. Fraud checks on the payment transaction itself are carried out by Stripe with its own tools and under its own rules, as explained in Article 12.

7.5 To keep the platform secure and working correctly

Legal basis: Art. 6(1)(f) GDPR (legitimate interest).

Our legitimate interest is to keep the service available, secure and working correctly: security logs, abuse prevention, error diagnosis and capacity planning.

7.6 To produce aggregated statistics on the use of the platform

Legal basis: Art. 6(1)(f) GDPR (legitimate interest).

Our legitimate interest is understanding which regulatory issues are most frequent, in order to improve the services and to publish sector level reporting. What we keep for this purpose, and how, is described in Article 19. You can object to this processing under Article 21, and business customers can also ask us to exclude their account from it.

7.7 To classify the feedback you send us

Legal basis: Art. 6(1)(f) GDPR (legitimate interest).

Our legitimate interest is to make sure that a real regulatory correction reported by a user is not lost among the messages. How this works, and the role of our AI provider in it, is described in Article 8.

7.8 To improve our curated regulatory knowledge base from submitted content

Legal basis: Art. 6(1)(a) GDPR (consent).

Where an organisation gives us a separate written consent, we may reuse the content of the labels and dossiers it submitted to improve our curated regulatory knowledge base. Without that consent the content is not reused for this purpose. The consent can be withdrawn at any time by writing to info@cosmetifull.com, with no effect on the processing carried out before the withdrawal (Art. 7(3) GDPR), and withdrawing it has no consequence on the service.

7.9 To answer you

Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR.

Replies to your messages and to your feedback, and operational communications about the service.

When you ask us to contact you about the Enterprise plan, we use those details only to call you or write back to you about that request. The legal basis is Art. 6(1)(b) GDPR, steps taken at your request before entering into a contract, and, when you act on behalf of a company, Art. 6(1)(f) GDPR, our legitimate interest in answering a business enquiry, which you can object to as described in Article 21. We do not use those details for marketing.

Except for the purpose in Article 7.8, we do not use consent as a legal basis. In particular we do not use it for invoicing, accounting or fraud prevention, because that processing cannot stop on request: it is imposed on us by law or needed to protect the service.

8. AI processing and AI transparency

The analyses, drafts and answers produced by the platform are generated by an artificial intelligence system. When you use the chat or any assisted function, you are interacting with an artificial intelligence system and not with a human operator. We state this in the interface as well, in line with the transparency obligation of Article 50 of Regulation (EU) 2024/1689, which applies from 2 August 2026.

The content you submit is processed through the API of our AI provider (Anthropic) in order to produce your results. Under the commercial terms that govern our use of that API, the content submitted is not used to train the provider's models.

We also use the same provider to classify the feedback you send us, so that a real regulatory correction is not lost among the messages. The message, a short excerpt of the analysis it refers to and the classification are kept, the proposal that comes out of it is always reviewed by a person before anything changes, and the same contractual exclusion of training applies.

Our AI provider retains the content transmitted and the results for no longer than 30 days from receipt or generation, except for the longer period the provider applies to cases where its usage policy has been breached, for abuse monitoring, and for no other purpose. We do not authorise any further use.

Results are informational and can contain errors. They assist professional review, they do not replace the judgement of a qualified professional and they do not certify compliance. Responsibility for the compliance of a cosmetic product remains with the economic operator and with the Responsible Person under Regulation (EC) No 1223/2009.

9. Automated checks on purchases and accounts

We do not profile you.

An automated control on the purchase exists and it is limited to one thing: a purchase whose data are abnormal, for example an unusually large quantity of credits or an account we cannot match, is put on hold automatically and reviewed by a person before the credits are added. The decision to suspend an account or to refuse a purchase is always taken by a person, never by the system. You can ask us to review the outcome by writing to info@cosmetifull.com.

The payment itself can also be automatically declined or blocked by Stripe's fraud systems, according to Stripe's own criteria. That assessment is made by Stripe, not by us. If a payment of yours is refused you can write to us and you can also contact Stripe directly.

10. What happens if you do not provide your data

Some data are required by law, others by the contract:

11. Who receives your data

We keep the provider chain short. The recipients fall into three different groups, and the difference matters, because they do not have the same duties towards you.

11.1 Group A: processors acting on our instructions (Art. 28 GDPR)

RecipientWhat it does for usWhat it receives
Cloudflare, Inc. (United States, globally distributed infrastructure)Hosting, database, file storage, perimeter securityAll service data as stored on its platform: account data, submitted content, analyses, technical and security logs
AnthropicAI processing of the content you submit, to produce your results, and classification of the feedback you send usThe content transmitted for processing and the feedback messages sent for classification, including a short excerpt of the analysis a feedback refers to. No credentials, no payment data, no security logs
Amazon SES (Amazon Web Services, Europe region, Frankfurt)Sending the service emails: invitations, access notifications, password reset, confirmation of the contract, operational noticesRecipient email address, name, organisation, subject and content of the transactional message
Proton AG (Switzerland, servers in Switzerland, Germany or Norway)Hosting our company email mailbox, including info@cosmetifull.comThe emails you send us, including the files you attach to them, and our replies; the details you give us when you ask us to contact you about the Enterprise plan: your name, your email address, your company name, your telephone number and, if you add one, your message
SmartBill (Intelligent IT SRL, Romania)Issuing our invoicesCompany name or name, billing address, VAT number, invoice data
AirtableOur internal customer relationship recordsContact and account data, and the commercial history of our relationship with you

We do not use a processor without a data processing agreement consistent with Art. 28 GDPR. Each of the recipients above processes data only on our documented instructions and cannot use them for its own purposes.

11.2 Telegram: an internal channel, stated as it is

We use a Telegram channel, strictly internal to our own team, to be alerted immediately when a feedback message arrives. That notification carries your name, your email address, your company name and the text of the message you sent us, including a short excerpt of the analysis a feedback refers to. It never carries the content of the documents you upload. We also use this channel to be alerted when a request to be contacted about the Enterprise plan arrives: that alert carries only a fixed text and none of your data.

Telegram does not make a data processing agreement available for bots. We say this plainly rather than claim a safeguard we do not have, and it is the reason why we limit this channel to internal alerts and keep the content of your documents out of it. Telegram is established outside the European Economic Area.

11.3 Group B: recipients that decide for themselves how to process the data

These recipients decide for themselves how to process the data they receive. They act as independent controllers, each under its own privacy policy and its own legal duties:

RecipientWhat it doesWhat it receives
ANAF, the Romanian tax authority, through the RO e-Factura system (Article 14)Receives the invoice under a legal obligationThe invoice and any credit note, with the billing data they contain
The European Commission (VIES) (Article 15)Answers our query validating an EU VAT numberOnly the VAT number queried, together with our own VAT number
Our bankSettlement of payments and refundsAmount, transaction reference, our own account data
Our external accountant or auditorKeeps our accounts, under their own professional dutiesThe accounting documents, including invoices
Our legal advisersOnly in the event of a disputeOnly the data necessary to that specific dispute

11.4 Stripe: a mixed role

Stripe is treated separately because its role is mixed. See Article 12.

12. Why Stripe has a mixed role

Stripe plays a mixed role, and we prefer to say so plainly rather than simplify it:

Stripe receives your name, your email address, your company name, your billing address, your VAT number where applicable, and the amount and identifier of the transaction. For the controller part, sending your data to Stripe is a disclosure between two separate controllers. We are not joint controllers with Stripe.

13. Why SmartBill is a processor

SmartBill is the opposite case, and the reason is worth stating.

SmartBill is the software we use to issue our invoice. It receives your company name, address and VAT number because we pass them to it, it processes them according to our instructions, and it has no professional duty of its own regarding the content of the invoice. It is therefore a processor under Art. 28 GDPR, bound by a data processing agreement.

Our external accountant or auditor, who receives the same documents, is instead an independent controller, because that role is regulated by law and the accountant decides on their own what they need and for how long.

14. ANAF and e-Factura

For customers whose operation has its place of supply in Romania, the invoice is transmitted to the Romanian tax authority through the RO e-Factura national system.

ANAF is not our supplier and does not act on our behalf. It is an authority that receives the data under a legal obligation and processes them as a separate controller. This transmission does not require your consent and cannot be switched off. The same applies to a credit note issued after a refund.

15. VAT number check (VIES)

Before we apply or do not apply the reverse charge, we check the VAT number you give us in VIES, the European Commission system, for VAT numbers issued in the European Union. VIES is a system of an EU institution and the query does not involve a transfer outside the European Economic Area.

In reply we receive whether the number is valid, or that the system could not answer, which is recorded as a separate outcome, and, where the system provides it, the name and address associated with that number. We keep evidence of the check, including its date and its outcome, as the supporting document for the VAT treatment we applied to your purchase.

For a sole trader the VAT number is personal data, which is why we declare this check even though it looks like company information.

16. Transfers outside the European Economic Area

Some of our providers are established outside the European Economic Area, or belong to groups that are. For each of them we state the country and the safeguard actually applied:

ProviderCountry of the providerWhere the data are processedSafeguard applied
Cloudflare, Inc.United StatesGlobally distributed infrastructureCloudflare Data Processing Addendum, including the Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c) GDPR)
AnthropicAnthropic Ireland, Limited, IrelandUnited StatesAnthropic Data Processing Addendum, including the Standard Contractual Clauses (Art. 46(2)(c) GDPR), together with the contractual commitment that submitted content is not used to train models
Amazon SESAmazon Web Services EMEA SARL, LuxembourgEurope region, FrankfurtProcessing inside the EEA. The AWS GDPR Data Processing Addendum, which incorporates the Standard Contractual Clauses, covers any access from outside the EEA, for example for technical support
Proton AGSwitzerlandSwitzerland, Germany or NorwayAdequacy decision of the European Commission for Switzerland, Decision 2000/518/EC (Art. 45 GDPR). Proton's data processing agreement, which forms part of its terms of service, commits Proton to transfer data, to the extent possible, only to Switzerland, the European Union or countries covered by an adequacy decision, and otherwise to rely on standard contractual clauses or another transfer mechanism provided for by data protection law
SmartBillRomaniaRomaniaNo transfer outside the EEA
AirtableUnited StatesUnited StatesData processing agreement including the Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Stripe, processor partStripe Payments Europe Limited, Ireland, for European customersIreland, with intra group transfers to the United StatesStripe's data processing terms, including the Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Stripe, independent controller partSame entity, part of a group established in the United StatesDecided by StripeAny onward transfer is decided by Stripe under its own responsibility and under its own privacy policy. We do not claim a safeguard over a transfer we do not control
Telegram (internal alerts only, Article 11.2)Outside the European Economic AreaOutside the European Economic AreaNo data processing agreement is available from this provider. We keep the content of your documents out of this channel for that reason

You can ask us for a copy of the safeguards we hold by writing to info@cosmetifull.com.

17. How long we keep your data

Different data have different retention periods. We do not use a single generic formula.

DataHow long we keep them
Account dataFor the life of the account, then deleted, as a rule immediately on your request
Analyses and the documents saved in your accountKept available for download for 30 days after closure, then deleted within the following 60 days, or earlier at your request
Files attached to feedback and documents attached to a declarationUntil you delete them, or until the account is deleted
Security and usage logs12 months from the date of the event, then deleted
Transactional email delivery metadata and bounce logs12 months from the date of the message, then deleted. The record of the confirmations that document a contract is kept instead for the same period as the accounting records, because it is the evidence that the contractual document was delivered
Customer relationship records, and requests to be contacted about the Enterprise planFor the duration of the relationship and for 24 months after the last contact
Per analysis statistical metadata, without content (Article 19)Kept without a time limit, in pseudonymised form, and detached from your account when the account is deleted
Feedback and support messagesFor the life of the account, then deleted
Credit ledger and usage statementsThe same period as the accounting records they support
Invoices, billing data, accounting records and the evidence of the VAT checkFive years, counted from 1 July of the year following the financial year in which the document was drawn up
Copies in our backupsUp to 30 days after the deletion, after which the copy itself is overwritten

17.1 The accounting period explained

Romanian law (Art. 23 and Art. 25 of Accounting Law no. 82/1991, as amended by Law no. 36/2023 in force since 15 January 2023) requires mandatory accounting records and the supporting documents behind them, invoices included, to be kept for five years counted from 1 July of the year following the financial year in which they were drawn up. In practice, for an invoice issued in 2026 the period runs from 1 July 2027 and ends on 30 June 2032.

That period matches the tax limitation period: under Art. 110 of Law no. 207/2015 (Fiscal Procedure Code) the right of the tax authority to establish tax claims expires after five years, running from 1 July of the year following the one the tax obligation relates to. The number is taken from the law, it is not an estimate of ours.

17.2 Closing your account does not delete your invoices

This is the point customers are most often surprised by, so we say it in advance. Closing your account deletes your account, your analyses and the content you submitted, on the timetable in the table above. It does not delete the invoice and the billing data behind it, which we must keep until the legal period above has expired. A request for erasure cannot shorten that period (Art. 17(3)(b) GDPR).

A deletion removes the data from the live systems on the timetable above. Backup copies that still contain them are rotated within 30 days, after which the copy itself no longer exists.

18. Security

Traffic runs over HTTPS and data are encrypted in transit. Passwords are never stored in clear: they are stored as a PBKDF2-SHA256 derivation with a per user salt and 100.000 iterations. Each account sees only its own analyses, and company accounts share only among their approved members. Administrative access is restricted to the persons who need it. Card details never reach our systems, as explained in Article 6.

19. Statistical metadata and aggregated statistics

For each analysis we keep a record of statistical metadata, never of content: the type and severity of the issues found, the markets, the languages and the score. That record is linked to a one way code derived from your email address, not to your name, and it stays pseudonymised: it is not anonymous data, so we treat it as personal data and you keep your rights over it.

We use those records only in aggregate, to see which types of labelling issue are most frequent and where, in order to improve the services and, in the future, for sector level reporting. An aggregate is only used or released where it covers at least 20 analyses and at least 5 distinct accounts. The aggregates never include the content of your documents, product names, your identity or anything that could identify your company.

They are derived from metadata only. They are not derived from the substance of the documents you submit, from product names or from formulations. Business customers can ask us at info@cosmetifull.com to exclude their account from this processing, at no cost and without any effect on the service.

20. Your rights

You have the right to:

To exercise these rights, write to info@cosmetifull.com. We reply within the time limits set by the GDPR, as a rule within one month. Our lead supervisory authority is the Romanian ANSPDCP (Bd. G-ral Gheorghe Magheru nr. 28-30, sector 1, Bucharest, dataprotection.ro). You can also address the supervisory authority of the country where you live or work.

If your request concerns data contained in a document uploaded by one of our customers, Article 4 explains what we do with it.

21. Your right to object

This right is set out separately, because it deserves your attention.

Where we process your data on the basis of our legitimate interest (Articles 7.4, 7.5, 7.6, 7.7 and 7.9), you have the right to object at any time, on grounds relating to your particular situation. Write to info@cosmetifull.com, tell us which processing you object to and why. We stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless we need the data to establish, exercise or defend legal claims.

Two honest clarifications:

22. If you are a consumer

This article applies only to individuals who buy for purposes outside their trade, business or profession. It adds to, and where they conflict it prevails over, the rest of this policy.

23. Cookies and local storage

The platform uses only strictly necessary technical storage on your device: the session token that keeps you signed in, your email address and company name so the interface can show them without a further request, a record that you have seen the legal notices, and preferences such as language, theme and how your archive is displayed.

Only one of those items is a cookie, and we set it ourselves:

CookieWho sets itWhat it is forHow long it lasts
`__Host-lobby_sess`uskeeps you signed in after you enter your password. It is the only cookie you receive when you use the platform.30 days, renewed while you use it

Our infrastructure provider sets none today, and we did not assume it: we measured it. On 23 August 2026 we opened the four public surfaces with a real browser (the LabelCheck application, its presentation page, ExpertDesk and the website) and counted the cookies present: zero, on all four. If one day we switch on a Cloudflare feature that sets one (bot detection, for instance), this table will say so before it happens.

In the browser's local storage, which is not a cookie and does not travel with requests, we keep the token that keeps you signed in to the application, your email address, your company name, your language and your theme. It disappears if you clear the site's data.

We use no advertising cookies, no third party analytics and no tracking. Strictly necessary technical cookies are exempt from consent under Art. 4(5) of Law no. 506/2004, which is why the site shows no cookie banner. This conclusion holds only for as long as the table above contains nothing beyond what is strictly necessary.

The payment page is hosted by Stripe on Stripe's own domain. Any storage or reading of information on your device that happens on that page is done by Stripe under its own privacy policy, and is outside our pages.

24. Changes to this policy

If we change this policy we update the date at the top, and for substantial changes we notify you inside the platform. When a change concerns a new purpose or a new recipient, we inform you before that processing starts, not afterwards.

This policy, in the version in force at the time, applies to every purchase made on the platform.


Nicodemo & Signa Company Srl · Strada Lucian Blaga nr. 21, ap. 16, 310023 Arad, Romania · CUI RO15617609 · Reg. J02/809/2003 · info@cosmetifull.com

Terms of service

← cosmetiFULL