c0menıus

Privacy Policy

Last Updated: August 25, 2026

1. Introduction and Scope

Welcome to c0menius (referred to as "COMENIUS", "we", "us", or "our"), a spatial interface for human knowledge operated by SOGLAB LIMITED. We are committed to protecting and respecting the privacy of our B2B institutional partners (curators, educators, and administrators using our STUDIO platform) and individual museum visitors experiencing our interactive spatial content through our frictionless MARKETPLACE WebXR viewer.

This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website (https://c0menius.app), use our no-code STUDIO platform, or access our WebXR digital curation experiences at participating cultural institutions.

This policy is designed to comply with the General Data Protection Regulation (GDPR) (EU) 2016/679, the United Kingdom General Data Protection Regulation (UK GDPR), and the UK Data Protection Act 2018 (DPA 2018).

2. Important Role Definitions: Controller vs. Processor

Under EU and UK data protection laws, the distinction between a Data Controller and a Data Processor is crucial:

  • COMENIUS as a Data Controller: We act as a Data Controller for the personal data of our B2B institutional clients’ staff (such as curators and administrators) who create accounts, purchase licenses, or interact with our sales and customer support teams. We also control anonymous, aggregated telemetry data collected across our platforms for optimization.

  • COMENIUS as a Data Processor: When a participating museum or cultural institution uses our STUDIO to curate custom narratives, manage visitor routes, and collect specific visitor feedback, the institution acts as the Data Controller. In these scenarios, COMENIUS acts as a Data Processor, processing visitor-related data strictly in accordance with the institution’s written instructions and a pre-agreed Data Processing Addendum (DPA).

3. Special Technical Disclosure: Augmented Reality (AR) & Camera Data

Because COMENIUS is built upon WebXR technology (utilizing hardware-agnostic stacks such as 8thWall, Three.js, and Google’s Spatial UI) to transform physical museum artifacts into interactive spatial interfaces, our experiences require access to your mobile device's camera.

Our Zero-Image-Transmission Pledge:

  1. Local, On-Device Processing Only: When a visitor scans a COMENIUS QR code to launch an AR experience, browser-level permission to access the device's camera is requested. The video frames from your camera are processed strictly on your local device in real-time for Simultaneous Localization and Mapping (SLAM) and visual anchor alignment.

  2. No Visual Data Transmitted: COMENIUS never transmits, streams, records, or stores raw camera feeds, photos, video frames, or spatial geometry of your surroundings to our cloud servers or any third-party networks.

  3. Instant Discarding: Camera data is used solely to calculate your device's physical orientation relative to the museum artifact and is instantly discarded in-browser. Closing the browser tab terminates all camera access immediately.

4. The Personal Data We Collect

The types of personal data we collect depend on how you interact with the COMENIUS ecosystem.

A. For B2B Institutional Users (Curators, Educators, Administrators)

To operate and manage your STUDIO workspace, we collect:

  • Account Credentials: Full name, institutional email address, job title, and password.

  • Organizational Information: Name of the museum or heritage site, department, physical address, and billing details.

  • Payment & Transaction Data: Billing contact, billing address, VAT/tax registration number, purchase history of licenses (e.g., Closed-Alpha project fee, Growth Card annual subscriptions). Note: We do not directly store credit card numbers; transactions are processed securely through compliant third-party payment gateways.

  • Curation Asset Metadata: Text files, audio narrations, 3D voxel parameters, and metadata uploaded to your Assets Manager ("Knowledge Vault").

  • Technical Usage Log: IP addresses, login timestamps, browser type, and actions taken within the no-code editor.

B. For End-User Visitors (Museum Explorers)

We prioritize a privacy-by-design experience. We collect:

  • Anonymous Device Telemetry: Device brand and model, operating system, web browser type (e.g., Safari, Chrome), screen resolution, and language settings. This is necessary to ensure the WebXR engine delivers optimal performance and correct visual scale.

  • Aggregated Engagement Metrics: Interactive trigger counts (e.g., which AR hotspots are tapped), time spent near specific artifacts (focused dwell-time tracking), route completion rates, and audio playback status.

  • Explicit Voluntary Information: If a visitor voluntarily interacts with integrated e-commerce features (such as buying a souvenir or booking an event), or opts to receive a digital reward or sign up for an institution's newsletter, we may collect email addresses or contact details. This is done only with explicit, opt-in consent.

5. Our Legal Bases for Processing Data

Under Article 6 of the GDPR / UK GDPR, we process personal data under the following legal frameworks:

  1. Performance of a Contract: To provide B2B services, manage licenses, grant access to the STUDIO editor, and handle customer support requests.

  2. Consent: When a visitor explicitly consents to camera permissions in their mobile browser, signs up for a mailing list, or opts into gamified milestone achievements.

  3. Legitimate Interests: To analyze anonymous, aggregated visitor behavior (such as tracking if a curated path increases dwell time by the targeted 44%) to improve platform performance, secure our services, and provide non-identifiable ROI reporting back to participating museums.

  4. Legal Obligation: To comply with corporate, tax, and accounting regulations in the UK and European Union.

6. Anonymous Visitor Analytics and "Cookies"

COMENIUS utilizes cookies and local browser storage (Local Storage) to maintain a seamless visitor experience.

  • Frictionless Experience Caching: We use browser Local Storage to temporarily save your progress along a "Curated Journey" so that if your browser tab refreshes or cellular signal drops briefly within the museum, you do not lose your spot or audio-guide playback position.

  • No Cross-Site Tracking: We do not use tracking cookies or behavioral targeting cookies that follow you across the internet. All telemetry is localized to the COMENIUS domain (c0menius.app) and is strictly used to evaluate on-site heritage learning interactions.

For detailed information, please review our separate Cookie Policy.

7. Data Sharing and Third-Party Processors

We do not sell, rent, or lease your personal data. To provide our integrated spatial experience, we share necessary data with trusted, GDPR-compliant service providers who act as our Data Processors under strict confidentiality agreements:

  • Cloud Infrastructure: Secured hosting services (e.g., Amazon Web Services or Google Cloud Platform) situated within UK/EEA data centers.

  • AI Synthesis Services: When curators utilize our STUDIO to generate text-to-speech audio guidance, text inputs are sent securely to the Google Cloud Text-to-Audio API for processing. No voice files or visitor telemetry are linked to this transactional text rendering.

  • Verification Services: For high-security institutional configurations or digital credential issuance, we may integrate with verified identity checking tools (such as Veriff).

  • Analytics Engines: Internal, private telemetry trackers that aggregate interaction data with zero tracking of Personally Identifiable Information (PII).

8. Data Security & Storage (The "Knowledge Vault")

We implement industry-standard administrative, physical, and electronic security measures to safeguard all active and archived digital assets:

  • Encryption in Transit & at Rest: All data exchanged between your devices and our STUDIO editor or MARKETPLACE is encrypted using Transport Layer Security (TLS) and stored using AES-256 encryption standards.

  • The Vault Segmentation: Curatorial digital assets (such as 3D models and high-fidelity tracker images) are kept in private, logically separated repositories with strict access controls.

  • Retention Periods:

    • B2B Account Data: Retained for the duration of the active subscription plus a grace period of up to 12 months for seasonal/rotating exhibitions, unless erasure is explicitly requested.

    • Visitor Telemetry: Aggregated and fully anonymized within 30 days of collection. Raw access logs are deleted on a rolling 90-day cycle.

9. International Data Transfers

COMENIUS operates by SOGLAB LIMITED is a UK-founded enterprise targeting cultural institutions across the UK and the European Economic Area (EEA).

  • To the extent that personal data is transferred outside the UK or the EEA (for example, to US-based server clusters), we ensure that appropriate safeguards are in place.

  • This includes utilizing Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Addendum (IDTA), or ensuring processors operate under equivalent adequacy decisions.

10. Your Rights Under GDPR & UK DPA 2018

If you are a resident of the United Kingdom or the European Union, you possess comprehensive statutory rights regarding your personal data:

  • Right of Access: You can request a copy of the personal data we hold about you.

  • Right to Rectification: You can request that we correct inaccurate or incomplete data.

  • Right to Erasure ("Right to be Forgotten"): You can request that we delete your personal data under certain conditions.

  • Right to Restrict Processing: You have the right to request a temporary freeze on how we process your data.

  • Right to Data Portability: You can request that we transmit your data to another organization in a machine-readable format.

  • Right to Object: You can object to our processing of your data based on legitimate interests.

  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, please contact our Data Protection Officer at: privacy@c0menius.app. We will respond to verified requests within 30 days in compliance with statutory requirements.

11. Contact Information & Supervisory Authority

If you have questions, concerns, or complaints about this Privacy Policy or our data handling practices, please contact us at:

c0menius App
SOGLAB LIMITED
(Registered in England and Wales)
Email: hello@c0menius.app
Company number: 12816260
Address: 338a Regents Park Road, Finchley Central, London, England, N3 2LN

Right to Lodge a Complaint:

If you feel we have not addressed your concerns satisfactorily, you have the right to file a complaint with a data protection supervisory authority:

  • In the UK: The Information Commissioner's Office (ICO) (https://ico.org.uk).

  • In the EU: Your local national Data Protection Authority (DPA) within your member state.

Background Image
Background Image
Background Image
Background Image