Privacy Policy
Last updated: May 26, 2026
At COBIZ ("we", "our") we respect your privacy. This policy explains how we collect, use, and protect your data when you visit cobiz.ai or interact with our services.
1. Data controller
COBIZ is operated by C&O Business Consulting LLC, with operational presence and teams in Florida (USA), Spain, Colombia, and Argentina.
- Contact: info@cobiz.ai
- USA: +1 754 308-6454
- Spain: +34 623 95 72 81
2. Data we collect
2.1 Data you give us
When you fill a form (resource download, contact, newsletter), we collect: full name, email, company (optional), phone (optional), role and company size (optional), message content.
2.2 Data we collect automatically
- IP address and approximate location
- Device, browser, and OS
- Pages visited and time on page
- Referrer URL
- UTM campaign parameters
3. How we use data
- Deliver requested service: send the downloaded resource, answer your message.
- Marketing communication: send related content WITH your explicit consent. Unsubscribe anytime.
- Improve the site: aggregate behavior analysis.
- Legal compliance: when required by applicable law.
4. Legal basis (GDPR)
For EU users we process data under: consent, contract execution, legitimate interest (to improve site and prevent fraud).
5. Sharing with third parties
We do NOT sell your data. We share with operational providers: Vercel (hosting), Sanity (CMS), ConvertKit (marketing emails), Resend (transactional emails), Google Analytics 4 (anonymized analytics), Stripe (payment processing for Analyst).
6. Cookies
We use strictly necessary cookies (no consent needed) and analytics cookies (with anonymized IP, require your consent). We do NOT use advertising tracking cookies.
7. Retention
- Newsletter subscribers: until unsubscribe
- Contact leads: 24 months from last contact
- Analytics: 14 months (GA4 default)
- Active clients: relationship duration + 5 years (tax obligation)
8. Your rights
Access, rectification, deletion, portability, opposition, restriction. Email info@cobiz.ai — we respond within 30 days.
9. Security
TLS encryption, role-based access, regular audits, encrypted backups. No system is 100% secure — write us if you spot anything suspicious.
10. International transfers
Some providers process data in USA, using approved transfer mechanisms (Standard Contractual Clauses under GDPR).
11. Minors
Site not directed at minors under 16. If you believe your child sent us info, email us to delete.
12. Changes
We'll notify registered users by email and update the date here. Continued use implies acceptance.
13. Complaints
- Spain: AEPD (aepd.es)
- USA: Federal Trade Commission
14. Contact
For privacy questions: info@cobiz.ai