Last updated: May 8, 2026
1. Who We Are
This Website (cosmos-instruments.com) is operated by Apex Online International KFT, a limited liability company incorporated under Hungarian law and registered with the Hungarian Trade Register (“we”, “us”, or the “Publisher”).
For any privacy-related question, you can reach us at contact@cosmos-instruments.com.
2. What Data We Collect
We collect the following categories of personal data:
- Account & order data: email address, first and last name, billing address (country, ZIP code, city, street), order history. Collected when you place an order or create an account.
- Payment data: handled exclusively by our payment processor Stripe. We never see or store your card number, CVC, or expiration date.
- Newsletter data: email address only, when you subscribe to our newsletter.
- Technical data: IP address, browser type and version, pages visited, referrer, timestamps. Collected automatically through cookies and server logs.
- Customer support data: any information you voluntarily provide when emailing us at
contact@cosmos-instruments.com.
3. Why We Collect It (Legal Basis)
We process personal data on the following legal grounds (Article 6 GDPR):
- Contract performance: to fulfill your orders, deliver Products, generate invoices, provide customer support.
- Legal obligation: to comply with Hungarian and EU accounting, tax and consumer protection laws.
- Legitimate interest: to secure the Website, prevent fraud, improve our services, send transactional emails.
- Consent: for marketing newsletter, optional analytics. You can withdraw your consent at any time.
4. How Long We Keep It
- Account data: as long as your account is active, plus 3 years after your last order, then anonymized.
- Order & invoice data: 8 years (Hungarian accounting law).
- Newsletter data: until you unsubscribe.
- Server logs: 12 months maximum.
5. Who We Share It With
We do not sell your personal data. We share it only with the following processors :
- Stripe (payment processing) – based in Ireland (EU), GDPR-compliant. stripe.com/privacy
- Hostinger (Website hosting) – based in Cyprus (EU). hostinger.com/privacy-policy
- Newsletter plugin (TNP) – runs on our own server, no third-party transfer for newsletter delivery.
- Meta (Facebook / Instagram) – for ads measurement and audience targeting via the Meta Pixel and Conversions API. We may share hashed email addresses, IP, browser fingerprint and order events with Meta in order to optimize our advertising campaigns. Data is processed under a Data Processing Addendum compliant with the EU Standard Contractual Clauses. facebook.com/about/privacy
- Google (Google Analytics, Google Ads, Google Tag Manager) – for website analytics and ads measurement. We may share pseudonymized identifiers, page events, and order events with Google. IP anonymization is enabled. Data is processed under Google’s EU Standard Contractual Clauses. policies.google.com/privacy
- Tax authorities and accounting service – for legal/tax compliance only.
You can opt out of advertising tracking at any time by adjusting your cookie preferences (see Section 6) or by using the Your Online Choices opt-out tool. We never share your email or personal data with companies outside the list above for commercial purposes.
6. Cookies & Tracking
The Website uses cookies and similar technologies (pixels, local storage, browser fingerprinting) for the following purposes :
- Strictly necessary cookies: shopping cart, login session, currency selection. These cannot be disabled.
- Functional cookies: language preference, recently viewed products.
- Analytics cookies: Google Analytics with IP anonymization to understand how visitors use the Website. Optional.
- Advertising cookies / pixels: Meta Pixel (Facebook / Instagram) and Google Ads conversion tracking, used to measure the performance of our ads and retarget visitors. Optional.
You can control cookies via your browser settings at any time, or use a cookie consent extension. Blocking strictly necessary cookies may break the checkout flow.
7. Your Rights (GDPR)
Under the EU General Data Protection Regulation (GDPR) and the Hungarian Act CXII of 2011 (Infotv.), you have the right to:
- Access your personal data and obtain a copy
- Rectify inaccurate or incomplete data
- Erase your data (“right to be forgotten”) – except for data we are legally required to keep (e.g. invoices)
- Restrict the processing of your data
- Object to processing based on legitimate interest
- Data portability – receive your data in a machine-readable format
- Withdraw your consent at any time for any consent-based processing
- Lodge a complaint with the Hungarian Data Protection Authority (NAIH) or your local supervisory authority
To exercise any of these rights, email us at contact@cosmos-instruments.com. We will respond within 30 days.
8. International Transfers
Your data is hosted within the European Union (Hungary, Ireland, Cyprus). When we use third-party processors (Stripe, Hostinger), they are GDPR-compliant and data remains within the EU/EEA. We do not transfer personal data outside the EU/EEA without appropriate safeguards.
9. Security
We use industry-standard security measures to protect your personal data: HTTPS encryption on all pages, password hashing, restricted backend access, regular security updates, and PCI-DSS compliant payment processing via Stripe.
10. Children
The Website is not directed at children under 16. We do not knowingly collect personal data from children. If you are a parent and believe your child has provided us with personal data, please contact us so we can delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent revision. Material changes will be communicated via email to registered customers when applicable.
12. Contact
For any privacy-related question or to exercise your rights:
Apex Online International KFT
Email: contact@cosmos-instruments.com
Website: cosmos-instruments.com