Legal · Cognitiva Systems Inc.

Privacy Policy

Last updated: 3 October 2026

In plain language

[Plain-language summary, drafted by counsel]

The full text below is the binding version.

Cognitiva Systems Inc.
Effective Date: 15 April 2026
Last Updated: 3 October 2026


ABOUT THIS NOTICE

This Privacy Policy explains how Cognitiva Systems Inc. collects, uses and shares personal data. It is a notice: reading or using our services does not mean you consent to anything, and where we rely on consent we ask for it separately.

English Version Controls: In case of conflicts between translations, the English version governs.


KEY PRINCIPLES

✓ Data Protection - Your data is protected with industry-standard security
✓ GDPR/CCPA Compliance - Full compliance with global privacy regulations
✓ Your Rights - Access, correct, delete, or export your data anytime
✓ International Standards - EU-U.S. Data Privacy Framework, Standard Contractual Clauses


PREAMBLE

Cognitiva Systems Inc. ("Cognitiva," "we," "us," or "our") is a Texas corporation. Cognitiva operates two products:

  1. CognitivaOS — the capture layer: the campaign execution platform (SaaS subscription) that captures every brief, approval, and payment as a signed, time-stamped record.
  2. CognitivaINTEL — the intelligence layer: benchmarks, scores, and market intelligence built from the record. Within this layer, Cognitiva creates and may license anonymized, aggregated datasets and offers AI-powered decision services.

This Privacy Policy explains how we collect, use, share, and protect personal data across both products.

Critical Disclosure — how the platform is funded: Raw campaign data belongs to the customer and is never sold. Cognitiva creates and may license anonymized, aggregated datasets that cannot be linked back to any person or company; this funds the platform. Customers can opt out of contributing to these datasets.


SECTION 1: SCOPE AND APPLICATION

1.1 Who This Policy Applies To

This Privacy Policy applies to:

  • Website Visitors: Anyone visiting cognitiva.systems or related domains
  • Platform Users: Agencies, brands, creators using CognitivaOS
  • API Clients: Organizations accessing Intelligence Platform APIs
  • Enterprise Customers: Organizations licensing anonymized datasets
  • Job Applicants: Individuals applying for positions
  • Business Partners: Vendors, contractors, and service providers

1.2 Regulatory Compliance

We comply with:

  • GDPR: EU General Data Protection Regulation (Regulation 2016/679)
  • UK GDPR: UK Data Protection Act 2018
  • FADP: Swiss Federal Act on Data Protection
  • CCPA/CPRA: California Consumer Privacy Act and Rights Act
  • Other Jurisdictions: Applicable data protection laws where we operate

1.3 Data Collection Methods

Personal data is collected through:

✓ Direct provision by you (account creation, forms, API usage)
✓ Automatic collection (cookies, logs, analytics)
✓ Client API exports (with explicit authorization)
✓ Licensed datasets of publicly available professional creator profiles, used to operate the Creator Search index and Reputation research features (see Section 4.5)

✗ We do NOT scrape or harvest personal data without a lawful basis
✗ We do NOT purchase personal data from data brokers to sell it on, or for advertising or third-party profiling
✗ We do NOT access client systems without explicit permission

The licensed creator-profile datasets described above cover publicly available professional profile information only (e.g. platform handle, public follower and engagement metrics, content category, market). This is distinct from data-broker resale of personal data: we license this data to operate a search and diligence tool, not to resell it. Its processing is governed by Section 4.5.


SECTION 2: DATA CONTROLLER

2.1 Controller Identity

Data Controller:
Cognitiva Systems Inc.

Privacy Contact:
Phone: +1 302-217-6601
Email: privacy@cognitiva.systems
Response Time: Within 48 hours for urgent requests

2.2 Controller Responsibilities

As data controller, we:

  • Determine purposes and means of personal data processing
  • Ensure lawful, fair, and transparent processing
  • Implement appropriate technical and organizational measures
  • Respect your data subject rights under applicable law
  • Maintain records of processing activities

SECTION 3: EU REPRESENTATIVE

3.1 GDPR Article 27 Representative

For EU data subjects, Cognitiva has appointed an EU Representative under GDPR Article 27. You may reach the representative at:

Contact: eu-datarights@cognitiva.systems

The representative's full name and registered EU address are provided on request via this address.

EU residents may contact our representative regarding:

  • Exercising GDPR rights
  • Data protection inquiries
  • Complaints to supervisory authorities
  • GDPR compliance questions

Note: This does not replace your right to contact us directly or file complaints with your local Data Protection Authority.


SECTION 4: PROCESSING ROLES AND PURPOSES

4.1 When Cognitiva Acts as Controller

We are the data controller for:

Website & Marketing:

  • Website visitor analytics and optimization
  • Marketing communications and lead generation
  • Demo requests and sales inquiries
  • Newsletter subscriptions

Account Management:

  • User account creation and authentication
  • Subscription billing and payment processing
  • Customer support and service delivery
  • Fraud detection and prevention
  • Identity verification (KYC/AML where required)
  • Creator identity, business-entity and sanctions verification, and tax handling for payouts made through the platform

Product Development:

  • Feature usage analytics
  • A/B testing and optimization
  • Bug tracking and error reporting
  • Security monitoring

4.2 When Clients Act as Controller

For campaign execution data within CognitivaOS:

Client is Controller:
Clients determine purposes and means of processing campaign data (messages, approvals, deliverables, participant information, and contracts the client signs with creators on the platform).

Cognitiva is Processor:
We process this data solely on client instructions to provide the CognitivaOS platform.

Data Processing Agreement:
Enterprise clients receive a separate DPA governing processor obligations.

4.3 Joint Controller Arrangements

For certain data transformation activities:

Joint Determination:
When clients authorize export of campaign data for anonymization and AI training, we jointly determine:

  • Anonymization methodologies
  • Dataset creation purposes
  • AI model training scope

Client Rights:
Clients may opt-out of contributing data to anonymized datasets (contact privacy@cognitiva.systems). This may limit access to certain AI-powered features.

4.4 AI Model Training and Commercial Use

Critical Disclosure:

Anonymized campaign data (per Section 8) is used to train machine learning models that power:

✓ Creator matching algorithms
✓ Payment risk detection systems
✓ Campaign success prediction models
✓ Compliance monitoring tools
✓ Content quality scoring
✓ Timeline risk assessment
✓ Budget optimization

Commercial Deployment:

These models are offered commercially as:

  1. Platform Features: Embedded in CognitivaOS subscriptions (included)
  2. API Services: Intelligence Platform APIs (per-decision pricing)
  3. Licensed Technology: Enterprise licensing agreements

Revenue Model:

AI model development and deployment is a core revenue stream. Subscription fees alone do not fund platform development. Data-derived and AI revenues subsidize competitive subscription pricing.

Client Consent:

By using CognitivaOS and authorizing data export, you consent to AI training on anonymized derivatives. You may withdraw consent (limits features).

4.5 Creator Search & Reputation Monitoring (Public-Profile Processing)

This section applies from the CognitivaOS launch on 1 September 2026, when the Creator Search index and Reputation research features become available.

CognitivaOS Creator Search lets customers find and evaluate creators, and Reputation research supports pre-engagement diligence and monitoring of creators under contract. To provide these features we process personal data of creators who may not be Cognitiva users. This subsection is the primary disclosure for that processing.

Sources of data. We process:

  • Publicly available professional profile data obtained through a licensed third-party data provider (accessed programmatically, including via the Model Context Protocol) and from public sources. This covers information creators have made public in a professional capacity — platform handle, public follower and engagement metrics, content category, language, and market.
  • Verified record data for creators who have joined CognitivaOS (e.g. delivery rate, revision rate, dispute and payment history). This appears only for creators who have a Cognitiva record.

Lawful basis (GDPR). We rely on legitimate interest — Article 6(1)(f) — namely operating a professional search and business-diligence tool for our customers. We have carried out and documented a Legitimate Interest Assessment (see Section 9.2), balancing that interest against the rights and reasonable expectations of the creators indexed. We do not process special category data for these features (see Section 6).

Article 14 notice to creators who are not users. Because this data is not collected directly from the creator, we provide the transparency required by GDPR Article 14 through a public notice and a rights portal, and — where required and proportionate — direct notification. The notice explains that the creator appears in the index, the source and categories of data, the legitimate-interest basis, and how to exercise their rights.

Your rights (including if you are not a Cognitiva user). Any creator may access, correct, object to, or request erasure of their profile in the index, and may object to Reputation monitoring, via the rights portal or by contacting privacy@cognitiva.systems. A valid objection under Article 21, or an erasure request, results in removal from the index and from active Reputation monitoring unless we have an overriding lawful ground to retain it.

Reputation monitoring — profiling disclosure. Reputation research compiles a structured review of a creator from public sources, and monitoring scans public signals for creators under active contract. This may constitute profiling. It does not involve solely automated decisions producing legal or similarly significant effects on the creator; findings are surfaced to the customer as informational signals with their sources, for a human to act on. Every check and alert is recorded as a time-stamped event.

No resale. We do not sell this data or these profiles. Licensed data is used to operate the Creator Search and Reputation features; anonymized, aggregated dataset licensing is addressed separately in Section 11.7.


SECTION 5: CATEGORIES OF PERSONAL DATA

5.1 Business & Account Data

What We Collect:

  • Full name
  • Business email address
  • Company/organization name
  • Job title and role
  • Business phone number (optional)
  • Communications with support/sales
  • Technical identifiers (IP address, device ID, browser fingerprint)

Why We Collect:

  • Account creation and authentication
  • Service delivery and support
  • Billing and invoicing
  • Fraud prevention
  • Legal compliance

Legal Basis: Contract performance, legitimate interest

5.2 Identity & Payment Data

What We Collect:

  • Government-issued ID (where required for verification)
  • Tax identification numbers (where legally required)
  • Stripe onboarding data (collected by Stripe, not stored by us)
  • Payment transaction records (amounts, dates, status)
  • Bank account details (tokenized by Stripe)

Why We Collect:

  • Payment processing
  • Tax compliance
  • Anti-money laundering (AML)
  • Know Your Customer (KYC) requirements
  • Fraud prevention

Legal Basis: Contract performance, legal obligation

Important: Actual payment credentials are processed by Stripe, our payment processor. We receive only tokenized references, never raw payment card data.

5.3 Campaign Execution Data

Critical Section - Read Carefully

What Is Campaign Execution Data:

When clients use CognitivaOS, they create campaigns containing:

  • Campaign briefs and requirements
  • Creator communications and messages
  • Approval workflows and decisions
  • Deliverable submissions
  • Payment records
  • Participant metadata

How We Collect It:

✓ Data is generated WITHIN CognitivaOS during normal platform use
✓ Clients may authorize API export for enhanced features
✓ Export is OPTIONAL and explicitly consented to

✗ We do NOT scrape external platforms
✗ We do NOT access client data without authorization
✗ We do NOT collect data from sources outside our platform

What We Do With It:

Raw Data (As Processor):

  • Stored encrypted in client workspace
  • Accessible only to authorized client users
  • Processed solely per client instructions
  • Subject to client's data retention policies

Anonymized Data (As Controller):

When clients authorize export:

  1. Transformation: Raw data undergoes anonymization (Section 8)
  2. Dataset Creation: Anonymized data forms structured datasets
  3. Model Training: Datasets train AI models (Section 4.4)
  4. Commercial Use: Anonymized datasets may be licensed (Section 11.7)

Key Safeguards:

✓ Direct identifiers removed
✓ Contextual information minimized
✓ Re-identification risk assessed
✓ Unique markers suppressed

Client Ownership:

  • Clients own ALL raw campaign data
  • We own anonymized derivatives we create
  • Clients may request dataset exclusion

5.4 Technical & Usage Data

Automatically Collected:

  • IP addresses and geolocation (city-level)
  • Browser type, version, and language
  • Operating system and device type
  • Referring URLs and clickstream data
  • Pages visited and time spent
  • Feature usage patterns
  • API request logs
  • Error reports and crash data

Why We Collect:

  • Platform performance optimization
  • Security monitoring and threat detection
  • Feature usage analytics
  • Bug identification and fixing
  • Capacity planning

Legal Basis: Legitimate interest, contract performance

Retention: Logs retained for 90 days; aggregated analytics retained indefinitely

5.5 Website Chat Assistant

The chat assistant on our website is an AI system, and it says so when you open it.

What We Collect:

  • The name and email address you enter to start a chat
  • Your messages and the assistant's replies (the transcript)

How It's Processed:

  • Your messages are sent to Anthropic, PBC, which runs the AI model that writes the replies (see our sub-processor list)
  • The transcript is emailed to our team at contact@cognitiva.systems, and to you if you ask for a copy

Why: To answer your questions and follow up on them.

Legal Basis: Legitimate interest in responding to enquiries; your request, where you ask for the transcript.

Retention: Transcripts are kept in our team mailbox for as long as needed to follow up on the enquiry.


SECTION 6: SPECIAL CATEGORY DATA

6.1 Intentional Non-Collection

We do NOT intentionally collect special category data under GDPR Article 9:

✗ Health or medical information
✗ Biometric data for unique identification
✗ Religious or philosophical beliefs
✗ Trade union membership
✗ Genetic data
✗ Data concerning sex life or sexual orientation
✗ Racial or ethnic origin
✗ Political opinions
✗ Criminal convictions or offenses

6.2 Inadvertent Detection

If special category data is detected in campaign content:

Automated Response:

  • Processing is immediately halted
  • Content is flagged for review
  • Special category elements are filtered/redacted
  • Remaining content proceeds with extra safeguards

Manual Review:

  • Trained personnel assess context
  • Data minimization applied
  • Excessive special category data triggers deletion
  • Client is notified if content violates terms

6.3 Children's Data

Age Restriction: CognitivaOS requires users be 18+ (or age of majority in jurisdiction).

No Intentional Collection:
We do NOT knowingly collect data from individuals under 18.

Discovery Protocol:
If we learn a user is underage:

  1. Account is suspended immediately
  2. Data is deleted within 30 days
  3. Parent/guardian is notified if contact info available

Campaign Content:
If campaign content involves minors (e.g., educational campaigns):

  • Extra safeguards apply
  • Parental consent must be obtained by client
  • Special category treatment for sensitive contexts

SECTION 7: INSOLVENCY PROCEEDINGS

7.1 Legal Authority Processing

In insolvency, bankruptcy, or liquidation proceedings:

Lawful Basis:
We may process company communications under court authority or administrator direction.

Permitted Uses:

  • Asset valuation for creditors
  • Fraud investigation
  • Claims substantiation
  • Regulatory compliance

Limitations:

  • Only with proper legal authority
  • Limited to insolvency purpose
  • Subject to court oversight
  • Anonymization applies where feasible

No Legal Advice:
This policy does not constitute legal advice about insolvency proceedings. Consult qualified insolvency counsel.


SECTION 8: ANONYMIZATION PROCEDURES

Critical Section for Understanding Data Monetization

8.1 Anonymization Standard

We apply anonymization per:

  • GDPR Recital 26 (irreversible de-identification)
  • Article 29 Working Party Opinion 05/2014
  • ISO/IEC 20889:2018 (Privacy enhancing techniques)
  • NIST Privacy Framework

Anonymization Goal:
Data cannot be re-identified using reasonably available means, considering:

  • Technical feasibility
  • Cost of re-identification
  • Time required
  • Available technology

8.2 Anonymization Techniques

Direct Identifier Removal:

  • Names, email addresses, phone numbers removed
  • Account IDs replaced with random tokens
  • IP addresses hashed or removed
  • User-specific metadata stripped

Contextual Minimization:

  • Temporal precision reduced (exact timestamps → day/week)
  • Geographic precision reduced (exact location → region)
  • Rare events suppressed
  • Outliers normalized

Structural Transformation:

  • Message sequences shuffled
  • Syntax preserved, specific phrasing generalized
  • Proper nouns replaced with category labels
  • Unique stylistic markers removed

Metadata Stripping:

  • File metadata removed
  • Creation timestamps generalized
  • Author attribution removed
  • Version history deleted

Re-Identification Risk Controls:

  • Automated uniqueness detection
  • Statistical disclosure control
  • K-anonymity and L-diversity assessment
  • Manual review for high-risk content

8.3 What Anonymization Is NOT

Anonymized data is NOT:

✗ Encrypted data (encryption is reversible)
✗ Pseudonymized data (pseudonyms can be reversed)
✗ Aggregated data (aggregation alone doesn't prevent re-identification)
✗ "De-identified" without verification (we verify irreversibility)

Anonymized data IS:

✓ Irreversibly transformed
✓ No reasonable re-identification path
✓ Outside GDPR scope (Recital 26)
✓ Freely usable for research, AI training, commercial licensing

8.4 Limitations and Risks

No Absolute Guarantee:
While we apply rigorous anonymization, we cannot guarantee absolute elimination of re-identification risk. Future techniques or data combinations might enable re-identification.

Ongoing Assessment:
We continuously monitor:

  • Academic literature on re-identification attacks
  • New privacy-enhancing technologies
  • Regulatory guidance updates
  • Actual re-identification attempts (none to date)

Client Disclosure:
Clients authorizing data export acknowledge anonymization limitations and accept residual risk.


SECTION 9: LEGAL BASES FOR PROCESSING

9.1 GDPR Legal Bases

Contract Performance (GDPR Article 6(1)(b)):

  • Account creation and management
  • Service delivery (CognitivaOS platform)
  • Payment processing
  • Customer support

Legitimate Interest (GDPR Article 6(1)(f)):

  • Fraud detection and security
  • Product improvement and analytics
  • Marketing to existing customers
  • Network and system security

Legal Obligation (GDPR Article 6(1)(c)):

  • Tax compliance
  • AML/KYC requirements
  • Regulatory reporting
  • Court orders and legal process

Consent (GDPR Article 6(1)(a)):

  • Marketing to non-customers
  • Optional data export for anonymization
  • Non-essential cookies
  • Newsletter subscriptions

9.2 Legitimate Interest Balancing

Where we rely on legitimate interest, we balance:

Our Interests:

  • Platform security and fraud prevention
  • Service improvement
  • Efficient operations
  • Direct marketing to customers

Your Rights:

  • Data minimization
  • Transparency
  • Objection rights
  • Reasonable expectations

Assessment:
We conduct and document legitimate interest assessments (LIAs) available upon request.


SECTION 10: DATA PROTECTION IMPACT ASSESSMENT (DPIA)

10.1 High-Risk Processing Assessment

We conduct DPIAs for:

  • Large-scale automated decision-making
  • Special category data processing (if occurs)
  • Systematic monitoring of public areas
  • Data matching or combining datasets
  • Processing data of vulnerable individuals
  • Innovative technologies or processing methods

10.2 Campaign Data Anonymization DPIA

Identified Risks:

  • Re-identification despite anonymization
  • Unexpected data combinations enabling identification
  • Disproportionate impact on data subjects
  • Function creep (expanded use beyond stated purposes)

Mitigation Measures:

  • Multi-layered anonymization (Section 8)
  • Regular re-identification testing
  • Purpose limitation enforcement
  • Ongoing risk monitoring
  • Client opt-out mechanisms

Proportionality Assessment:

  • Benefits: AI development, platform improvement, competitive pricing
  • Risks: Residual re-identification risk (assessed as low)
  • Balance: Benefits outweigh minimal residual risk
  • Necessity: Anonymization necessary for AI training feasibility

10.3 Review and Updates

DPIAs are reviewed:

  • Annually
  • When processing operations change materially
  • When new risks are identified
  • When technology evolves

Supervisory Authority Consultation:
If high residual risk cannot be mitigated, we consult with relevant Data Protection Authority before proceeding.


SECTION 11: DATA SHARING AND DISCLOSURE

11.1 Internal Personnel

Who Has Access:

  • Engineering teams (platform operations)
  • Support teams (customer service)
  • Security teams (threat monitoring)
  • Legal/compliance teams (regulatory obligations)

Access Controls:

  • Role-based access control (RBAC)
  • Least privilege principle
  • Audit logging of all access
  • Regular access reviews

11.2 Service Providers

Categories:

  • Cloud infrastructure (AWS, GCP)
  • Payment processing (Stripe)
  • Analytics services (anonymized data only)
  • Customer support tools
  • Security monitoring

Safeguards:

  • Data Processing Agreements (DPAs)
  • Contractual data protection obligations
  • Regular vendor assessments
  • Subprocessor lists maintained

11.3 Stripe Payment Processing

What Stripe Receives:

  • Payment card details (entered directly to Stripe)
  • Billing information
  • Transaction details
  • Identity verification data

Stripe's Role:
Stripe is an independent data controller for payment data.

Stripe's Privacy Policy:
https://stripe.com/privacy

Our Responsibility:
We are NOT liable for:

  • Stripe's data security
  • Stripe's compliance decisions
  • Payment holds or verification requirements
  • Stripe's fraud detection actions

11.4 Legal and Regulatory

Required Disclosures:

  • Court orders and subpoenas
  • Law enforcement requests (with legal basis)
  • Regulatory authorities
  • Tax authorities
  • Insolvency administrators (with court authority)

Disclosure Protocol:

  • Legal basis verification
  • Scope minimization
  • User notification (unless legally prohibited)
  • Transparency report publication (annual)

11.5 Business Transfers

Mergers, Acquisitions, Asset Sales:

If Cognitiva is acquired or merges:

  • Your data may transfer to the acquiring entity
  • This Privacy Policy remains in effect
  • You will be notified before transfer
  • You may delete your account before transfer

Bankruptcy/Insolvency:

If Cognitiva enters insolvency:

  • Data may transfer to administrator or buyer
  • Anonymized datasets may be sold as assets
  • Raw customer data subject to court approval
  • You will be notified per legal requirements

11.6 Advisors and Auditors

Limited Access:

  • Legal counsel (attorney-client privilege)
  • Financial auditors (confidentiality agreements)
  • Security auditors (NDA-protected)
  • Board of directors (fiduciary duties)

Purpose: Corporate governance, compliance, financial reporting

11.7 Data-Derived Products (Revenue Model)

CRITICAL COMMERCIAL DISCLOSURE

Revenue Stream Transparency

Cognitiva generates revenue from THREE sources:

1. Platform fees (see /pricing):

  • Seat, per-clearance and transaction fees for CognitivaOS
  • Feature access and support

2. Data Product Licensing (Enterprise pricing):

  • Anonymized datasets licensed to third parties
  • Per Section 8 anonymization procedures
  • This is a CORE REVENUE STREAM

3. AI Intelligence Services (Per-decision pricing):

  • API access to ML models
  • Trained on anonymized campaign data
  • Commercial AI-as-a-Service offering

Who We License Anonymized Data To

Permitted Licensees:

  • Academic and research institutions
  • Market intelligence providers
  • AI/ML platform companies
  • Enterprise organizations for internal use
  • Technology companies building products

Prohibited Licensees:

  • Direct competitors to our clients
  • Data brokers for re-sale
  • Surveillance or law enforcement (without legal order)
  • Entities in sanctioned jurisdictions
  • Any party attempting re-identification

What Anonymized Datasets Include

Included:

  • Anonymized message content (linguistic patterns preserved)
  • Workflow structures (anonymized participant roles)
  • Outcome data (success/failure indicators)
  • Temporal patterns (time-series data)
  • Categorical variables (industry, campaign type)

Excluded:

  • Direct identifiers (names, emails, IDs)
  • Unique identifying information
  • Special category data
  • Children's data
  • Confidential business information beyond linguistic patterns

Dataset Use Restrictions

Licensees are contractually prohibited from:

✗ Attempting to re-identify data subjects
✗ Combining datasets to reverse anonymization
✗ Selling or sublicensing data
✗ Using data for discriminatory purposes
✗ Using data for surveillance
✗ Using data beyond licensed scope

Enforcement:
License violations result in immediate termination and legal action.

Client Rights Regarding Data Licensing

Opt-Out Option:

Clients may request exclusion from data product contributions:

  • Email: privacy@cognitiva.systems
  • Subject: "Data Product Opt-Out Request"
  • Processing time: 30 days
  • Effect: Future data excluded; past anonymized data already distributed cannot be recalled

Opt-Out Consequences:

Exclusion may limit access to:

  • AI-powered creator matching
  • Predictive analytics features
  • Benchmark comparisons
  • Advanced insights

Basic platform functionality remains available.

No Opt-Out Fee:
Opt-out is free. Subscription price remains unchanged.

Revenue Necessity Disclosure

Why Data Revenue Matters:

Platform fees do NOT fully fund:

  • Platform development costs
  • Infrastructure expenses
  • AI research and development
  • Competitive feature development

Data product revenue subsidizes subscription pricing, keeping CognitivaOS affordable for small agencies while funding innovation.

Alternative Business Model:

Without data revenue, subscription prices would need to be 3-5x higher to achieve financial sustainability. Data licensing enables us to serve smaller agencies that couldn't afford premium-only pricing.

Transparency Commitment

Public Reporting:

We publish annually:

  • Number of dataset licenses sold
  • General categories of licensees (without names)
  • Approximate data volume licensed
  • Anonymization effectiveness metrics

Next Report: 15 April 2026

CCPA "Sale" Disclosure

California Residents:

Under CCPA/CPRA, licensing anonymized data may constitute a "sale" even if data is anonymized.

Your CCPA Rights:

  • Right to know what data is "sold"
  • Right to opt-out of "sales"
  • Right to non-discrimination for opting out

Opt-Out Link:
Do Not Sell or Share My Personal Information

Processing Time: 15 business days

Note: Opt-out applies to future data only. We cannot recall anonymized data already distributed.


SECTION 12: INTERNATIONAL DATA TRANSFERS

12.1 Transfer Necessity

Cognitiva operates globally. Data may be transferred to:

  • United States (primary processing location)
  • European Economic Area (EU representative, some clients)
  • Other jurisdictions where clients or service providers operate

12.2 Transfer Safeguards

For EEA to U.S. Transfers:

  • EU-U.S. Data Privacy Framework (if certified)
  • Standard Contractual Clauses (SCCs): EU Commission-approved
  • Adequacy Decisions: Where available
  • Binding Corporate Rules: For intra-group transfers

SCC Modules Used:

  • Controller-to-Controller (for data product licensing)
  • Controller-to-Processor (for CognitivaOS client data)

Supplementary Measures:

  • Encryption in transit and at rest
  • Pseudonymization where feasible
  • Access controls and logging
  • Transfer impact assessments (TIAs)
  • Legal review of destination country laws

12.3 Schrems II Compliance

Following CJEU Schrems II decision:

Risk Assessment:
We assess U.S. surveillance law impact on each data transfer.

Additional Safeguards:

  • Encryption prevents government access to plaintext
  • Minimal personal data in anonymized datasets
  • Contractual commitments to resist overbroad demands
  • Transparency reporting of government requests

Client Notification:
If we receive government access demands affecting EEA data, we notify affected clients unless legally prohibited.

12.4 Data Localization Options

Enterprise Clients:

Upon request and subject to feasibility:

  • EU-only data residency
  • Regional data isolation
  • Local processing nodes

Additional Cost:
Data localization may incur additional infrastructure costs.


SECTION 13: DATA RETENTION

13.1 Retention Principles

We retain personal data only as long as necessary for:

  • Fulfilling processing purposes
  • Compliance with legal obligations
  • Establishment, exercise, or defense of legal claims
  • Legitimate business interests

13.2 Retention Periods

Account Data:

  • Active accounts: Duration of account + 90 days post-deletion
  • Inactive accounts: Deleted after 3 years of inactivity
  • Financial records: 7 years (tax compliance)
  • Identity verification: 7 years (AML compliance)

Campaign Execution Data:

  • Raw data in client workspace: Per client retention policy
  • Platform-generated metadata: 2 years post-campaign completion
  • Anonymized datasets: Indefinite (outside GDPR scope)

Technical Logs:

  • Access logs: 90 days
  • Security logs: 1 year
  • Aggregated analytics: Indefinite

Marketing Data:

  • Opted-in subscribers: Until opt-out
  • Non-customer leads: 2 years of inactivity
  • Rejected applications: 90 days

Legal Hold:
Data subject to litigation, investigation, or regulatory action is retained until matter resolution.

13.3 Deletion Procedures

Secure Deletion:

  • Overwriting with random data
  • Cryptographic erasure (destroy encryption keys)
  • Physical destruction of media (when retired)
  • Deletion verification and logging

Anonymized Data:

Once data is anonymized (Section 8), it is outside GDPR scope and may be retained indefinitely without deletion upon request.

Backup Retention:

Backups containing personal data:

  • Retained for 30 days
  • Automatically overwritten
  • Not used for restoration unless catastrophic failure
  • Subject to same security as live data

SECTION 14: YOUR RIGHTS

14.1 GDPR Rights (EEA/UK Residents)

Right of Access (Article 15):

  • Obtain confirmation we process your data
  • Receive a copy of your data
  • Learn processing purposes, categories, recipients
  • Request time: 30 days, free of charge

Right to Rectification (Article 16):

  • Correct inaccurate personal data
  • Complete incomplete data
  • Immediate effect on live data
  • Backups updated on next cycle

Right to Erasure / "Right to be Forgotten" (Article 17):

  • Delete data when no longer necessary
  • Withdraw consent (where consent is legal basis)
  • Object to processing (legitimate interest basis)
  • Exception: Anonymized data cannot be "erased" (already anonymized)

Right to Restriction (Article 18):

  • Limit processing while accuracy is contested
  • Suspend processing pending objection resolution
  • Retain data but not actively process

Right to Data Portability (Article 20):

  • Receive personal data in structured, machine-readable format
  • Transmit data to another controller
  • API export available
  • Limitation: Only data YOU provided, not derived data

Right to Object (Article 21):

  • Object to processing based on legitimate interest
  • Object to direct marketing (absolute right)
  • Object to profiling and automated decision-making
  • We must stop unless compelling legitimate grounds

Right to Not Be Subject to Automated Decisions (Article 22):

  • Not be subject to solely automated decisions with legal/significant effects
  • Right to human review
  • Right to explanation
  • Our Practice: All significant decisions include human review

14.2 CCPA/CPRA Rights (California Residents)

Right to Know:

  • Categories of personal information collected
  • Categories of sources
  • Business purposes for collection
  • Categories of third parties we share with
  • Specific pieces of information we hold about you

Right to Delete:

  • Request deletion of personal information
  • Exceptions: Legal obligations, fraud prevention, internal uses

Right to Correct:

  • Correct inaccurate personal information

Right to Opt-Out of Sale/Sharing:

Right to Limit Use of Sensitive Personal Information:

  • We collect sensitive personal information as defined by the CCPA/CPRA (government ID, tax ID and bank account details) to verify identity, handle tax and automate creator payouts through our licensed payment providers, and use it only for those purposes. You can ask us to limit its use to those purposes.

Right to Non-Discrimination:

  • No discrimination for exercising CCPA rights
  • No denial of service
  • No different pricing (except reasonably related to value)

14.3 How to Exercise Rights

Contact Methods:

Email: privacy@cognitiva.systems
Subject Line: "[RIGHT NAME] Request - [Your Name]"
Include: Full name, email address, account details (if applicable)

Identity Verification:

To prevent unauthorized access:

  • We may request additional identifying information
  • Account holders: Login verification
  • Non-account holders: Email confirmation or ID verification
  • Processing may be delayed if identity cannot be confirmed

Response Time:

  • GDPR: 30 days (extendable to 90 days if complex)
  • CCPA: 45 days (extendable to 90 days if necessary)
  • Urgent requests: Flagged for expedited handling

No Fee:
First request is free. Excessive or repetitive requests may incur reasonable administrative fee.

Authorized Agent (CCPA):

California residents may designate an authorized agent:

  • Provide signed permission
  • Agent must verify your identity and their authority
  • We may contact you directly to confirm

SECTION 15: SECURITY MEASURES

15.1 Technical Safeguards

Encryption:

  • Data in transit: TLS 1.3
  • Data at rest: AES-256
  • Database encryption
  • Backup encryption

Access Controls:

  • Multi-factor authentication (MFA) required
  • Role-based access control (RBAC)
  • Least privilege principle
  • Regular access reviews
  • Automated session termination

Network Security:

  • Firewall protection
  • Intrusion detection systems (IDS)
  • Distributed Denial of Service (DDoS) mitigation
  • Virtual Private Cloud (VPC) isolation
  • Network segmentation

Application Security:

  • Secure development lifecycle
  • Code review and testing
  • Vulnerability scanning
  • Penetration testing (annual)
  • Bug bounty program

15.2 Organizational Safeguards

Personnel:

  • Background checks for security-sensitive roles
  • Confidentiality agreements
  • Security awareness training
  • Incident response training
  • Segregation of duties

Vendor Management:

  • Vendor security assessments
  • Data Processing Agreements (DPAs)
  • Regular audits
  • Subprocessor approval process

Physical Security:

  • Data centers with 24/7 monitoring
  • Biometric access controls
  • Video surveillance
  • Environmental controls
  • Redundant power and cooling

15.3 Incident Response

Breach Detection:

  • 24/7 security monitoring
  • Automated anomaly detection
  • Log analysis
  • Threat intelligence integration

Breach Response:

  1. Contain: Isolate affected systems
  2. Assess: Determine scope and impact
  3. Notify: Affected individuals, authorities (if required)
  4. Remediate: Fix vulnerabilities
  5. Review: Post-incident analysis

Notification Timeline:

  • GDPR: to the supervisory authority within 72 hours, unless the breach is unlikely to result in a risk to people (Art. 33)
  • CCPA: Without unreasonable delay
  • Affected individuals: without undue delay where the breach is likely to result in a high risk to them (Art. 34)

What We Tell You:

  • Nature of breach
  • Categories and approximate number affected
  • Likely consequences
  • Measures taken
  • Contact point for questions

SECTION 16: COOKIES AND TRACKING

16.1 Cookie Categories

Strictly Necessary:

  • Session management
  • Authentication
  • Security features
  • Load balancing

Strictly necessary cookies cannot be declined, because the site does not work without them.

Performance/Analytics:

  • Google Analytics (anonymized IP)
  • Error tracking
  • Feature usage metrics

Can Decline: YES, but impacts product improvement.

Functional:

  • Language preferences
  • Interface customization
  • Saved settings

Can Decline: YES, but impacts user experience.

Marketing:

  • Conversion tracking
  • Retargeting pixels
  • Social media integrations

Can Decline: YES, no impact on core functionality.

16.2 Cookie Control

Banner: Displayed on first visit with granular consent options.

Manage Settings: Available at privacy-settings page anytime.

Do Not Track: We respect DNT signals from browsers.

Third-Party Cookies:
We limit third-party cookies to essential service providers.

16.3 Analytics Details

Google Analytics:

  • IP anonymization enabled
  • Demographics/interest reports disabled
  • Data retention: 14 months
  • Data sharing with Google: disabled

Purpose: Understand how users interact with our site to improve experience.

Opt-Out: https://tools.google.com/dlpage/gaoptout


SECTION 17: CHILDREN'S PRIVACY

17.1 Age Restrictions

Minimum Age: 18 years or age of majority in your jurisdiction.

Verification: Self-certification during signup.

Enforcement: Suspension upon discovery of underage users.

17.2 Parental Rights

If we learn we have collected data from a child:

  1. Account suspended immediately
  2. Data deleted within 30 days
  3. Parent/guardian notified (if contact info available)
  4. No further processing

Parent Contact: privacy@cognitiva.systems with "Child Privacy" subject line.

17.3 Campaign Content Involving Minors

If campaigns target/involve minors (educational, youth programs):

Client Obligations:

  • Obtain required parental consents
  • Verify age-appropriate content
  • Comply with COPPA/local equivalents
  • Flag minor-related content

Our Safeguards:

  • Enhanced anonymization
  • Manual content review
  • Restricted data sharing
  • No AI training on minor-related content (unless educational research with ethics approval)

SECTION 18: CHANGES TO THIS POLICY

18.1 Update Process

Review Frequency: At least annually

Triggers for Updates:

  • Regulatory changes
  • Business model changes
  • New processing activities
  • Security incident learnings
  • User feedback

18.2 Notification

Material Changes:

  • Email notification to account holders
  • Prominent banner on website
  • 30 days before effective date
  • Option to object or close account

Non-Material Changes:

  • Updated policy posted
  • "Last Updated" date changed
  • No proactive notification

18.3 Continued Use

Continued use after effective date constitutes acceptance of updated policy.

Objection:
If you object to material changes:

  • Close your account before effective date
  • Request data export
  • Data deleted per Section 13

SECTION 19: CONTACT AND COMPLAINTS

19.1 Privacy Team Contact

General Inquiries:
Email: privacy@cognitiva.systems
Response Time: 48 hours for urgent, 5 business days for general

Data Subject Rights Requests:
Email: privacy@cognitiva.systems
Subject: "[RIGHT NAME] Request"
Response Time: 30 days (GDPR), 45 days (CCPA)

EU Representative:
Email: eu-datarights@cognitiva.systems

Security Issues:
Email: security@cognitiva.systems
Response Time: 24 hours for critical issues

19.2 Supervisory Authority Complaints

EEA/UK Residents:

You have the right to lodge a complaint with your Data Protection Authority:

Lead Supervisory Authority:
Cognitiva Systems Inc. has no EU establishment, so there is no lead supervisory authority. You can complain to the authority in your country:

Find Your Local DPA:
https://edpb.europa.eu/about-edpb/about-edpb/members_en

UK:
Information Commissioner's Office (ICO)
https://ico.org.uk/make-a-complaint/

19.3 California Attorney General

California Residents:

CCPA violations may be reported to:

California Attorney General
Privacy Unit
https://oag.ca.gov/contact/consumer-complaint-against-business-or-company


SECTION 20: DEFINITIONS

Anonymization: Irreversible transformation preventing re-identification.

Controller: Entity determining purposes and means of processing.

Personal Data: Information relating to identified or identifiable individual.

Processing: Any operation on personal data (collection, storage, use, etc.).

Processor: Entity processing data on behalf of controller.

Special Category Data: Sensitive data under GDPR Article 9 (health, biometric, etc.).


EFFECTIVE DATE

This Privacy Policy is effective as of 15 April 2026.


END OF PRIVACY POLICY

Document Version: 2.0
Last Reviewed: 15 April 2026
Next Review: April 16, 2027


QUICK REFERENCE

Your Rights:

  • Access your data
  • Correct inaccurate data
  • Delete your data
  • Opt-out of data sales
  • Object to processing

Contact:

Key Points:

  • We license anonymized data (Section 11.7)
  • We train AI on anonymized data (Section 4.4)
  • You can opt-out (may limit features)
  • Data revenue funds competitive pricing
  • Anonymized data retained indefinitely

Transparency:

  • No hidden data uses
  • Clear revenue model
  • Client opt-out available
  • Annual public reporting
← All legal documents
Privacy Policy | Cognitiva