Effective date: 8 September 2026
This Privacy Policy explains how CosmicFlow (Pty) Ltd, trading as PrinterStats (“cosmicFlow”, “PrinterStats”, “we”, “us” or “our”), collects, uses, stores, shares and protects Personal Information when providing PrinterStats.
Our commitment in plain language: we use Customer Data only to provide, secure, support and lawfully improve PrinterStats. We treat it as confidential. We do not sell, rent, trade, broker or licence Personal Information or Customer Data to data brokers, advertisers or other third parties, and we do not use it for targeted advertising or third-party marketing.
1. Who we are and how to contact us
PrinterStats is operated by cosmicFlow (Pty) Ltd in South Africa.
- Privacy and Information Officer enquiries: christo@printerstats.com
- Location: Menlo Park, Pretoria, South Africa
- Website: https://printerstats.com/
For purposes of South Africa’s Protection of Personal Information Act 4 of 2013 (“POPIA”), cosmicFlow is the Responsible Party for Personal Information for which it determines the purpose and means of Processing. Where we Process information only on a Customer’s documented instructions, we act as that Customer’s Operator. Under other applicable privacy laws, these roles may be called “controller” and “processor”.
2. Scope
This Policy applies to the PrinterStats website, dashboard, mobile or web applications, monitoring agents, StatBox devices, APIs, reports, alerts, support services and related services that link to this Policy (together, the “Service”). It applies to account holders, authorised users, Customer personnel, Customer clients and other people whose Personal Information is Processed through the Service.
“Customer” means the business or other organisation that subscribes to, deploys or controls a PrinterStats account. “Customer Data” means information submitted to, collected through or generated by the Service for a Customer, including printer and fleet information, configuration, reports, support content and any Personal Information contained in those records. “Personal Information” and “Process” have the meanings given by applicable privacy law.
3. Our role and the Customer’s role
For account administration, billing, direct communications, security, website operation and our own legal obligations, cosmicFlow generally acts as the Responsible Party.
For Personal Information that a Customer or its monitoring agents submit about the Customer’s users, clients, contacts, locations or devices, the Customer generally decides why that information is Processed. In that context, the Customer is the Responsible Party and cosmicFlow is its Operator. We Process that information only to provide the Service, on the Customer’s documented instructions, or as required by law.
Customers are responsible for ensuring that they have a lawful basis and authority to provide Customer Data to PrinterStats, for giving any notices and obtaining any permissions required from their users, personnel or clients, and for configuring account access appropriately. Customers must not use PrinterStats for unlawful employee surveillance or submit special or highly sensitive Personal Information unless this is necessary, lawful and expressly agreed with us.
4. Information we collect
Depending on the features used, we may Process the following categories:
- Account and identity information: name, email address, telephone number, profile image, user identifier, company membership, role, account preferences, account creation date, email-verification status and multi-factor authentication status. Authentication credentials are handled through our authentication provider; we do not make passwords available in readable form.
- Company and billing information: company name and identifier, contact details, billing name, billing address, billing email, telephone number, VAT information, invoice information, discounts and monitored-device usage totals. PrinterStats does not currently collect or store payment-card numbers through the application.
- Printer, fleet and device information: agent and device identifiers, printer make and model, serial number, local IP address, host or computer name, configured printer name and location, page and scan counters, colour and mono counters, supply and toner levels, component life, status, alerts, timestamps, heartbeat and version information.
- Technical and diagnostic information: manual IP ranges, SNMP walk data, error records, configuration values, agent notes, diagnostic logs, remote-support or secure-tunnel session metadata, command status, connectivity and ping results, and information required to install, update, troubleshoot and secure monitoring agents or StatBox devices.
- Rollout and notification information: technician identifiers, client and company names, client email addresses, installation or download status, notification preferences, alert recipients, report recipients and email-delivery metadata.
- Support and communications: support-ticket topics, messages, chats, contact details, device or printer references, attachments, feedback and other communications with us.
- Reports and operational records: saved report settings, filters, schedules, report outputs, printer history, toner-yield events, usage statistics and invoice records.
- Security and usage information: IP address, date and time of access, device identifier, device label, browser, platform, language, time zone, screen size, user-agent string, sign-in count, authentication and password-change events, pages or features used, and application diagnostic events.
- Website and storage technologies: cookies, local-storage identifiers and similar technologies used for authentication, security, preferences, performance and limited analytics as described below.
Printer “location” means the label or site information configured by a Customer. PrinterStats does not intentionally collect precise GPS location unless a clearly identified feature requires it and the user grants permission.
5. Where information comes from
- directly from users when they register, configure the Service, update billing details, create reports, contact support or communicate with us;
- from a Customer or its authorised administrators, technicians and integrations;
- from PrinterStats monitoring agents, StatBox devices and network printers configured by the Customer;
- automatically from browsers, applications, servers and security systems when the Service is accessed; and
- from service providers where necessary to confirm authentication, email delivery, hosting, support or security events.
6. Why we Process information
- provide and administer accounts and the Service;
- discover, monitor and display printer status, counters, supplies, alerts and connectivity;
- calculate operational trends such as toner depletion, yields and usage;
- generate dashboards, exports, scheduled reports and invoices;
- send operational, security, low-toner, printer-alert, agent-offline, rollout and report notifications selected by the Customer;
- authenticate users, provide multi-factor authentication and recovery, detect suspicious sign-ins and prevent abuse;
- provide remote-support functions requested by an authorised user;
- respond to support requests, investigate errors and maintain compatibility;
- maintain, test, secure and improve the reliability and usability of PrinterStats;
- administer subscriptions, billing, accounting and tax records;
- send requested information or limited direct marketing where lawful, with an opt-out; and
- comply with law, enforce agreements, establish or defend legal claims, and protect users, PrinterStats and the public.
7. Lawful grounds
We Process Personal Information only where permitted by applicable law. Depending on the circumstances, our grounds include consent; taking steps at a person’s request or performing a contract; complying with a legal obligation; protecting a legitimate interest of the data subject; and pursuing our or a third party’s legitimate interests where those interests do not unjustifiably override the person’s rights. Our legitimate interests include operating a secure business service, preventing fraud and abuse, supporting Customers, improving reliability and recovering amounts lawfully due.
Where cosmicFlow acts as an Operator, we rely on the Customer’s lawful instructions and the Customer remains responsible for the lawful basis for the Processing. Where consent is required, it may be withdrawn prospectively, but withdrawal does not make earlier lawful Processing unlawful.
Some information is necessary to create or secure an account, provide monitoring, generate requested reports or meet legal obligations. If required information is not provided, the affected feature or Service may not be available. Optional fields may be left blank.
8. Confidentiality, Customer ownership and our no-sale commitment
All Customer Data is treated as protected and confidential information. This includes Personal Information as well as non-personal fleet, device, operational, billing, report and support information.
Customers retain all rights they have in Customer Data. cosmicFlow does not claim ownership of it. The Customer authorises us to Process Customer Data only to provide, secure, support and improve the Service for that Customer, comply with lawful instructions, and meet legal obligations.
Our confidentiality commitment is NDA-style: access is limited to people and service providers who need the information for an authorised purpose and who are subject to confidentiality obligations. We do not disclose Customer Data except as stated in this Policy. These confidentiality duties continue after an account or agreement ends.
The confidentiality commitment does not cover information that the recipient can demonstrate was lawfully public through no breach, already lawfully known without a duty of confidence, lawfully received from another source without restriction, or independently developed without use of the confidential information. If disclosure is legally compelled, we will disclose only what is required and, where legally permitted, give the affected Customer notice.
We never sell data. cosmicFlow will not sell, rent, trade, broker, licence or exchange Personal Information or Customer Data for money or other commercial benefit. We do not provide it to data brokers, use it to build third-party marketing lists, share it for cross-context behavioural advertising, or permit service providers to use it for their own advertising or marketing.
We may use aggregated or de-identified operational statistics to understand and improve PrinterStats, provided they cannot reasonably identify a person, Customer or device. We do not sell those statistics and will not attempt to re-identify them.
PrinterStats is not for sale. cosmicFlow does not intend to, and will not voluntarily, sell or transfer the PrinterStats business. We have deliberately not included a general permission to transfer Customer Data as part of a merger, acquisition or asset sale. Customer Data will never be treated as a saleable or transferable commercial data asset. This does not prevent a disclosure or transfer that is strictly required by law, in which case confidentiality and data-protection obligations continue to apply.
This public commitment supplements applicable law and our written agreements. A Customer that requires a bilateral, project-specific non-disclosure agreement or data-processing agreement may request one from christo@printerstats.com. If a signed agreement provides stronger confidentiality or data-protection terms, those stronger terms apply to that Customer.
9. When information may be disclosed
We disclose information only as reasonably necessary for the following limited purposes:
- Authorised Customer users and recipients: according to the Customer’s roles, settings, integrations, support requests, report recipients and notification preferences.
- Operators and service providers: vetted providers that host, transmit, secure, support or maintain the Service. They may Process information only for contracted services and subject to appropriate confidentiality and data-protection obligations.
- Professional advisers: lawyers, accountants, auditors and insurers who need the information to provide professional services and are bound by duties of confidence.
- Law and safety: where disclosure is required by a valid law, court order or regulator; necessary to protect rights, safety or property; or necessary to investigate fraud, abuse or a security incident. We assess requests and disclose only what is legally necessary.
Core providers currently include Google Cloud and Firebase for application hosting, authentication, database, storage and cloud functions, and Twilio SendGrid for transactional and notification email. The legacy application may use Firebase or Google Analytics for limited product-usage events. Provider details may change where reasonably necessary to operate the Service, but any replacement must be subject to appropriate contractual and security protections.
- Firebase privacy and security information
- Google Cloud Data Processing Addendum
- Twilio Data Protection Addendum
10. International Processing and transfers
PrinterStats is operated from South Africa and uses cloud and email providers that may Process information in the United States and other countries where they or their approved sub-operators maintain facilities. This means information may be Processed outside the country where it was collected.
Where POPIA applies, we transfer Personal Information outside South Africa only in accordance with section 72 of POPIA, such as where the recipient is subject to a law, binding corporate rules or a binding agreement providing an adequate level of protection, where the transfer is necessary under a permitted legal ground, or where the data subject has consented. Where the EU or UK GDPR applies, we use an applicable adequacy mechanism, approved contractual safeguards or another lawful transfer mechanism.
11. Retention and deletion
We keep information only for as long as reasonably necessary for the purpose for which it was collected, to provide the Service, comply with law, resolve disputes and enforce agreements. Our current standard schedules include:
- printer history, technical error records and remote-session records are generally scheduled for deletion after approximately three months;
- closed support tickets and related chats are generally scheduled for deletion after approximately six months;
- agents placed in trash and their associated printer records are generally scheduled for deletion after seven days;
- inactive printers are generally scheduled for deletion after approximately three months and inactive agents after approximately four months;
- short-lived email-deduplication records are generally scheduled for deletion after seven days;
- active account, company, current fleet and configuration records are kept while needed to provide the Service and are deleted or de-identified within a reasonable period after a valid deletion request or the end of the relationship, subject to the exceptions below; and
- invoices, billing and tax records are generally retained for at least five years from the relevant return or transaction period, or longer where an audit, dispute or law requires it.
Deletion schedules may be delayed where records are subject to a legal hold, investigation, unresolved dispute, security requirement or statutory retention duty. Data deleted from active systems may remain for a limited period in encrypted backups or a provider’s deletion cycle before being overwritten or securely deleted. We may retain properly de-identified information that can no longer reasonably identify a person, Customer or device.
12. Security
We take appropriate and reasonable technical and organisational measures designed to protect the integrity and confidentiality of Personal Information and Customer Data against loss, damage, unauthorised destruction, unlawful access and unlawful Processing. Depending on the risk and feature, these measures include authentication, optional authenticator-app multi-factor authentication, access controls, security-event logging and alerts, encrypted network transport, provider encryption at rest, backups, retention controls, incident response, and confidentiality obligations for personnel and service providers.
Customers must protect their credentials, use multi-factor authentication where available, maintain accurate authorised-user lists, configure permissions carefully, secure their own networks and devices, and notify us promptly of suspected misuse. No internet or storage system can be guaranteed to be completely secure. This statement does not reduce any duty imposed on us by applicable law.
13. Security incidents
If we reasonably believe that Personal Information has been accessed or acquired by an unauthorised person, we will investigate, take reasonable containment and remediation steps, and notify the affected Responsible Party, the Information Regulator and/or affected data subjects where and as required by applicable law. Notice may be delayed where a competent authority or legitimate investigation requires it.
14. Cookies, local storage and analytics
The Service uses cookies, browser local storage and similar technologies for essential functions such as authentication, session continuity, security, remembering preferences and maintaining a pseudonymous security-device identifier. The website and legacy application may also use limited analytics to understand feature usage, performance and errors.
We do not use these technologies to sell information or build third-party advertising profiles. Where applicable law requires consent for non-essential analytics, we will request it before enabling those technologies. Browser controls can block or clear cookies and local storage, but doing so may prevent authentication, security and preference features from working correctly. Because there is no universally accepted technical standard for “Do Not Track”, the Service may not respond to that signal; however, our no-sale commitment applies regardless.
15. Direct marketing
We may send service-related messages that are necessary for an account or requested feature. We send promotional email only where permitted by law, such as with consent or to an existing Customer where the communication concerns similar PrinterStats services and an opt-out is provided. A person may unsubscribe using the link in a message or by emailing us. Opting out of marketing does not stop essential security, billing, support or operational messages.
16. Automated monitoring, predictions and optional AI features
PrinterStats uses automated calculations to identify printer conditions, generate alerts and estimate matters such as toner depletion and toner yield. These outputs support fleet operations and are not used to make decisions about a person that produce legal or similarly significant effects.
We do not use Customer Data to train or fine-tune general-purpose artificial-intelligence models, and we do not sell Customer Data for AI training. No fleet or account data is automatically sent to a third-party AI service. If an optional AI chat feature is made available and a user intentionally uses it, the text that the user enters and the resulting conversation context may be sent to the disclosed AI API provider solely to generate a response. Users should not enter unnecessary Personal Information, passwords or confidential Customer Data into such a feature.
Where the OpenAI API is used, PrinterStats does not opt Customer content into model training. OpenAI states that API inputs and outputs are not used for training by default, but limited logs may be retained under its then-current API data controls. See OpenAI API data controls.
17. Your privacy rights
Subject to applicable law, a data subject may ask us to:
- confirm whether we hold Personal Information about them and provide access to it;
- correct or update inaccurate, irrelevant, excessive, outdated, incomplete, misleading or unlawfully obtained information;
- delete or destroy information that we are no longer authorised or required to retain;
- object to certain Processing on reasonable grounds;
- withdraw consent for future Processing where consent is the basis;
- object at any time to direct marketing;
- receive information in a portable format where applicable law provides that right;
- request restriction of Processing where applicable; and
- complain to a competent data-protection authority.
Send requests to christo@printerstats.com. Please describe the information and request clearly. We may need to verify identity and authority before acting. We will respond within the period required by applicable law and may refuse or limit a request only where the law permits, including to protect another person’s rights, preserve security or comply with a legal duty.
If cosmicFlow holds the information only as an Operator for a Customer, the request should normally be directed to that Customer. We will assist the Customer as required by our agreement and applicable law.
South African data subjects may lodge a POPIA complaint with the Information Regulator (South Africa) or email POPIAComplaints@inforegulator.org.za. We encourage you to contact us first so that we can try to resolve the concern promptly.
18. Children
PrinterStats is a business service and is not directed to children under 18. We do not knowingly create accounts for or collect Personal Information directly from children. If you believe a child has provided information to us, contact us so that we can investigate and take appropriate action.
19. Third-party websites and Customer integrations
The Service may link to printer web interfaces, Customer systems or third-party websites and integrations that we do not control. Their privacy and security practices are governed by their own terms. Customers are responsible for integrations they choose to enable and for ensuring that recipients of exports or reports are authorised.
20. Changes to this Policy
We may update this Policy to reflect changes in the Service, law or our practices. We will post the updated version and change the effective date. If a change materially affects how we use Personal Information, we will provide additional notice where reasonably possible or legally required. We will not materially weaken the confidentiality and no-sale commitments for information already collected without an appropriate lawful basis and any notice or consent required by law.
21. Questions and complaints
Questions, privacy requests, complaints and requests for a Customer-specific NDA or data-processing agreement may be sent to:
cosmicFlow (Pty) Ltd, trading as PrinterStats
Privacy and Information Officer enquiries
Menlo Park, Pretoria, South Africa
Email: christo@printerstats.com
