Cognitiva Systems Inc.
INTRODUCTION#
This document lists the sub-processors Cognitiva Systems Inc. ("Cognitiva") uses to process personal data on behalf of our customers.
What is a Sub-processor?
A sub-processor is a third-party service provider that processes personal data on behalf of Cognitiva to help us provide our Services.
Why We Disclose This:
- GDPR Article 28(3)(d) requires data processors to inform customers of sub-processors
- Transparency and trust
- Customer due diligence
CURRENT SUB-PROCESSORS#
1. CLOUD AND WEB HOSTING#
Amazon Web Services (AWS)
Entity: Amazon Web Services, Inc.
Purpose: Cloud hosting, compute, storage and database services
Data Processed: Customer data stored on the platform (campaign data, user accounts, files)
Location: United States and European Union regions
Data Transfer Mechanism: EU Standard Contractual Clauses (SCCs)
Certifications: ISO 27001, SOC 2 Type II, ISO 27017, ISO 27018
Privacy Policy: https://aws.amazon.com/privacy/
Website: https://aws.amazon.com
Google Cloud
Entity: Google LLC
Purpose: Document storage
Data Processed: Uploaded documents and files
Location: United States and European Union regions
Data Transfer Mechanism: EU Standard Contractual Clauses (SCCs)
Certifications: ISO 27001, SOC 2 Type II, ISO 27017, ISO 27018
Privacy Policy: https://cloud.google.com/terms/cloud-privacy-notice
Website: https://cloud.google.com
Vercel
Entity: Vercel Inc.
Purpose: Web hosting for the website and web application
Data Processed: HTTP request data (IP addresses, headers), pages and forms served to visitors
Location: United States
Data Transfer Mechanism: EU Standard Contractual Clauses (SCCs)
Certifications: As published in the provider's own trust documentation
Privacy Policy: https://vercel.com/legal/privacy-policy
Website: https://vercel.com
Supabase
Entity: Supabase Inc.
Purpose: Shareholder-portal database and authentication
Data Processed: Portal user accounts, login credentials (hashed), session data, portal records
Location: United States
Data Transfer Mechanism: EU Standard Contractual Clauses (SCCs)
Certifications: As published in the provider's own trust documentation
Privacy Policy: https://supabase.com/privacy
Website: https://supabase.com
2. COMMUNICATION#
Resend
Entity: Resend
Purpose: Transactional email delivery (account notices, workflow notifications, receipts)
Data Processed: Email addresses, email content (transactional only), delivery logs
Location: United States
Data Transfer Mechanism: EU Standard Contractual Clauses (SCCs)
Data Retention: Email logs retained for 30 days
Certifications: As published in the provider's own trust documentation
Privacy Policy: https://resend.com/legal/privacy-policy
Website: https://resend.com
Anthropic
Entity: Anthropic, PBC
Purpose: AI model for the website chat assistant
Data Processed: Chat messages (not the name or email a visitor enters)
Location: United States
Data Transfer Mechanism: EU Standard Contractual Clauses (SCCs)
Certifications: As published in the provider's own trust documentation
Privacy Policy: https://www.anthropic.com/legal/privacy
Website: https://www.anthropic.com
3. ANALYTICS#
Google Analytics
Entity: Google LLC
Purpose: Website analytics (consent-based; loaded only after the visitor allows analytics cookies)
Data Processed: IP addresses (anonymized), browser information, page views, user interactions
Location: United States
Data Transfer Mechanism: EU-U.S. Data Privacy Framework, EU SCCs
IP Anonymization: Enabled (last octet removed before storage)
Data Retention: 14 months
Privacy Policy: https://policies.google.com/privacy
Opt-Out: https://tools.google.com/dlpage/gaoptout
4. IDENTITY VERIFICATION#
Regulated Identity-Verification Provider
Entity: Name provided to customers on request
Purpose: Identity and liveness checks for creator verification
Data Processed: Government-issued identity documents, selfie and liveness (biometric) data, verification result. The provider holds the documents and biometric data; Cognitiva stores only the verification outcome, a reference and the expiry
Location: Provider-dependent; confirmed to customers on request
Data Transfer Mechanism: EU Standard Contractual Clauses (SCCs)
Certifications: Provided to customers on request
5. PAYMENTS#
Licensed Payment Partners
Entity: Names provided to customers on request
Purpose: Funds held and moved for booked jobs (blocked on booking, released on approval) and creator payouts
Data Processed: Payment and bank details, billing information, transaction records
Location: United States and the local markets in which we operate
Data Transfer Mechanism: The payment partner acts as an independent data controller for payment data (not a sub-processor under GDPR); EU SCCs where it processes on our behalf
Certifications: PCI DSS and SOC 2 reports available from the partner on request
Important Note:
Our licensed payment partners are independent data controllers for payment processing. Cognitiva does not store card or bank details and is not responsible for the partner's own data processing. Refer to the partner's privacy policy, available on request, for details.
CHANGE MANAGEMENT#
Notification of Changes#
30-Day Advance Notice:
We will notify customers at least 30 days in advance before:
- Adding a new sub-processor
- Changing an existing sub-processor's purpose or data processing scope
- Replacing a sub-processor with a different entity
Notification Method:
- Email to account administrator
- In-app notification
- Update to this page (check "Last Updated" date)
Customer Objection Rights#
You have the right to object to new sub-processors or changes.
How to Object:
- Email: dpa@cognitiva.systems
- Subject: "Sub-Processor Objection - [Company Name]"
- Within: 15 days of notification
- Include: Specific objection reasons (data protection grounds)
If We Cannot Accommodate Objection:
- Good faith discussion to resolve concerns
- If unresolved, you may terminate Services Agreement with 30 days notice
- Pro-rated refund of prepaid fees
If No Objection:
Failure to object within 15 days constitutes acceptance.
DATA PROTECTION SAFEGUARDS#
Contractual Protections#
All sub-processors are contractually obligated to:
✓ Process data only on Cognitiva's instructions
✓ Maintain confidentiality
✓ Implement appropriate technical and organizational security measures
✓ Assist with data subject rights requests
✓ Notify Cognitiva of personal data breaches
✓ Delete or return data upon termination
✓ Submit to audits and inspections
International Data Transfers#
For sub-processors located outside the European Economic Area:
✓ EU Standard Contractual Clauses (SCCs): Executed with all non-EU sub-processors
✓ UK International Data Transfer Addendum (IDTA): For UK personal data
✓ Transfer Impact Assessments (TIAs): Conducted per Schrems II requirements
✓ Supplementary Measures: Encryption in transit (TLS 1.3) and at rest (AES-256)
Security Measures#
All sub-processors must implement:
✓ Encryption in transit and at rest
✓ Access controls and authentication
✓ Regular security assessments
✓ Incident response procedures
✓ Employee training on data protection
✓ Industry-standard certifications (ISO 27001, SOC 2, etc.)
SUB-PROCESSOR CATEGORIES#
Processing Activities#
| Sub-Processor | Hosting | Analytics | Communication | Payment | Identity |
|---|---|---|---|---|---|
| AWS | ✅ | ||||
| Google Cloud | ✅ | ||||
| Vercel | ✅ | ||||
| Supabase | ✅ | ||||
| Resend | ✅ | ||||
| Google Analytics | ✅ | ||||
| Anthropic | ✅ | ||||
| Identity-verification provider | ✅ | ||||
| Licensed payment partners | ✅ |
DATA LOCATIONS#
Where Your Data May Be Processed#
United States:
- AWS (US regions)
- Google Cloud (US regions)
- Vercel
- Supabase
- Resend
- Google Analytics
- Anthropic
- Licensed payment partners (US and local markets)
European Union:
- AWS (EU regions)
- Google Cloud (EU regions)
Provider-Dependent:
- Regulated identity-verification provider (location confirmed to customers on request)
Customer Control:
Enterprise customers can specify data residency preferences (US-only, EU-only, or multi-region).
FREQUENTLY ASKED QUESTIONS#
Q1: Can I request that my data only be processed in the EU?#
A: Yes. Enterprise customers can request EU-only data residency. This limits sub-processors to AWS (EU regions) and Google Cloud (EU regions). Some features may have limited availability.
Contact: sales@cognitiva.systems for EU data residency options
Q2: What happens if a sub-processor has a data breach?#
A: Sub-processors are contractually required to notify us within 24-48 hours. We then:
- Assess impact on customer data
- Notify affected customers without undue delay, so that a controller can meet its 72-hour duty to the supervisory authority under GDPR Article 33
- Cooperate with investigation and remediation
- Evaluate continued relationship with sub-processor
Q3: Can I audit sub-processors?#
A: Customers can audit Cognitiva's compliance (including sub-processor management). Direct sub-processor audits typically require:
- Reasonable advance notice
- Confidentiality agreements
- Coordination with Cognitiva
- Or: Review of sub-processor's SOC 2 / ISO 27001 reports (substitute for on-site audit)
Contact: dpa@cognitiva.systems to arrange audit
Q4: Does Cognitiva use any sub-processors in China, Russia, or other high-risk countries?#
A: No. We do not use sub-processors located in or subject to laws of countries deemed high-risk for data protection. All sub-processors are in US, EU, or equivalent jurisdictions with strong data protection frameworks.
Q5: What if I object to a sub-processor on GDPR Article 28 grounds?#
A: You have the right to object. We will:
- Discuss your concerns in good faith
- Seek alternative sub-processor if feasible
- If we cannot accommodate, you may terminate agreement with 30 days notice and receive pro-rated refund
This is a legal right under GDPR Article 28(2).
Q6: Are sub-processors in the US subject to CLOUD Act or FISA 702?#
A: Yes, US-based sub-processors may be subject to US government access requests under:
- CLOUD Act (cross-border lawful access)
- FISA Section 702 (foreign intelligence surveillance)
Our Safeguards:
- Encryption prevents government access to plaintext data
- Transfer Impact Assessments conducted
- Contractual commitments to challenge overbroad requests
- Transparency reporting of government requests (annual)
Read More: Privacy Policy Section 12.3 (Schrems II Compliance)
CONTACT INFORMATION#
For Sub-Processor Questions:#
Email: dpa@cognitiva.systems
Subject: "Sub-Processor Inquiry - [Company Name]"
Response Time: 5 business days
To Object to Sub-Processor:#
Email: dpa@cognitiva.systems
Subject: "Sub-Processor Objection - [Company Name]"
Deadline: Within 15 days of notification
For Data Processing Agreement:#
Email: dpa@cognitiva.systems
Request: Full Data Processing Agreement (DPA) template
LEGAL REFERENCES#
This sub-processor list is maintained pursuant to:
- GDPR Article 28(3)(d): Processor must inform controller of sub-processors
- GDPR Article 28(2): Prior written authorization required for sub-processors
- GDPR Article 28(4): Processor remains liable for sub-processor performance
DOCUMENT HISTORY#
| Version | Date | Changes |
|---|---|---|
| 1.0 | 15 April 2026 | Initial publication |
| 2.0 | 8 October 2026 | Vendor list aligned with the live stack |
Next Review: April 2027
TRANSPARENCY COMMITMENT#
We are committed to transparency about our data processing practices. This sub-processor list is updated promptly when changes occur.
Subscribe to Updates:
Email dpa@cognitiva.systems with subject "Subscribe to Sub-Processor Updates" to receive automatic notifications.
END OF SUB-PROCESSOR LIST
Published: 8 October 2026 (version 2.0)
Maintained by: Legal & Compliance Team
Contact: dpa@cognitiva.systems