Privacy Policy
Last updated: July 30, 2026.
This policy explains who processes your personal data when you visit kozdos.com or get in touch through this website, for what purpose, and what rights you have. It is drafted in accordance with Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003, as amended by Legislative Decree 101/2018 (Codice in materia di protezione dei dati personali).
1. Data controller
- Artist name: KOZ DOS
- Email: info@kozdos.com
- Website: https://kozdos.com
For any question about this policy or the processing of your data, write to info@kozdos.com.
2. What data we process
2.1. Data you provide
Through the contact form or by writing directly to the email address above:
- Name and surname
- Email address
- Type of enquiry (mural / public art, artwork purchase, commission, exhibition or festival, press and interviews, other)
- The content of your message and any data you choose to include in it
Please do not include special categories of data in your message (health, religious or political beliefs, ethnic origin, sexual orientation), nor third-party data without their knowledge.
2.2. Data collected automatically
When you browse the site, the server and, where applicable, measurement tools record technical data: IP address, browser type and version, operating system, language, pages visited, date and time of access, and referring page. This data is used to ensure the operation and security of the site and, if you have given your consent, to compile usage statistics.
3. Purposes and legal bases
- Responding to your enquiries and communicating with you. Legal basis: your consent (Art. 6(1)(a) GDPR) and steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR).
- Handling quotes, commissions, artwork sales and shipping. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Meeting tax, accounting and administrative obligations. Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).
- Ensuring the operation, security and maintenance of the website, and preventing fraudulent or abusive use. Legal basis: the controller’s legitimate interest (Art. 6(1)(f) GDPR).
- Compiling anonymous or aggregated statistics on site usage. Legal basis: your consent given through the cookie banner (Art. 6(1)(a) GDPR).
- Sending you news about new works, murals and exhibitions. Legal basis: your express and separate consent (Art. 6(1)(a) GDPR), which you may withdraw at any time.
No automated decision-making or profiling with legal effects on individuals takes place.
4. Whether providing data is mandatory
The fields marked as required in the form are necessary in order to handle your request. If you do not provide them, we will not be able to reply. All other fields are optional and leaving them blank has no consequences.
5. How long we keep your data
- Enquiries that do not lead to a contractual relationship: 12 months from the last contact, after which they are deleted.
- Commissions, sales and collaborations: for the duration of the relationship and thereafter for the limitation periods applicable to any liabilities arising from the contract.
- Accounting and tax records: ten years, in accordance with Article 2220 of the Italian Civil Code and Italian tax legislation.
- Data processed on the basis of consent: until you withdraw it.
6. Who else has access to your data
We do not sell or share your data with third parties for advertising purposes. It is accessed only by the providers supplying services necessary to run the website and the business, all of them bound by a data processing agreement under Article 28 GDPR:
- Web hosting: IONOS
- Email: soporte@ionos.es
- Contact form: DIVI Form
- Web analytics: Google Analytics / Google Search Console
- Newsletter platform: Mailer Lite
Data may also be disclosed to our tax and accounting advisers, to banks, and to the tax authorities where there is a legal obligation or where it is necessary for the performance of the contract.
7. International transfers
Some of the providers listed above may be established outside the European Economic Area or may process data from there. In those cases, the transfer is based on an adequacy decision of the European Commission — such as the EU-US Data Privacy Framework for certified US providers — or on the Standard Contractual Clauses approved by the Commission, together with any supplementary measures required. You may request information about the safeguards in place by writing to info@kozdos.com.
8. Third-party content and links
This website embeds a feed of Instagram posts and includes links to Instagram, Facebook and YouTube profiles. When this content loads or you follow these links, the relevant providers — Meta Platforms Ireland Ltd. and Google Ireland Ltd. — may collect data about your browsing in accordance with their own privacy policies, over which we have no control. We recommend you review them.
9. Your rights
You may exercise the following rights at any time:
- Access: find out what data we hold about you and obtain a copy.
- Rectification: correct inaccurate data or complete incomplete data.
- Erasure: ask for your data to be deleted when it is no longer necessary.
- Restriction: ask for processing to be suspended in certain circumstances.
- Portability: receive your data in a structured, commonly used format, or have it transmitted to another controller.
- Objection: object to processing based on legitimate interest.
- Withdrawal of consent: at any time, without affecting the lawfulness of processing carried out beforehand.
To exercise them, write to info@kozdos.com stating which right you wish to exercise. We may ask you to verify your identity. We will reply within one month, extendable by a further two months in particularly complex cases.
If you believe your data is not being processed in accordance with the law, you may lodge a complaint with the supervisory authority:
Garante per la protezione dei dati personali
Piazza Venezia, 11 — 00187 Rome, Italy
Phone: (+39) 06 696771
Email: protocollo@gpdp.it — PEC: protocollo@pec.gpdp.it
Website: www.garanteprivacy.it
You may also contact the data protection authority of your country of habitual residence or place of work.
10. Data security
We apply appropriate technical and organisational measures to protect data against destruction, loss, alteration or unauthorised access: encrypted connection via SSL certificate, regular software updates, access controls and backups. No system is entirely foolproof, but we work to maintain a level of security appropriate to the risk.
11. Minors
This website is not directed at children under fourteen, the age set in Italy for valid consent in relation to information society services (Art. 2-quinquies of Legislative Decree 196/2003). If we find that we have received data from a child below that age without the authorisation of a parent or guardian, we will delete it.
12. Cookies
This website uses first-party and third-party cookies. You can find the details and manage your preferences in the Cookie Policy.
13. Changes to this policy
This policy may be updated to reflect changes in legislation or new services on the website. The version in force will always be the one published on this page, showing the date it was last updated. We recommend reviewing it periodically.

