What we hold,
where, and who can ask for it back.
This page is written for the people who have to sign off on us — a DPO, a general counsel, a works council. Nothing here is aspirational; where something isn't finished, we say so.
Data stays where it's made.
EU-only hosting with an EU-only hardware security module (HSM). EU-originated data and keys never leave the region.
US-originated data is stored and keyed in a US-East region.
GCC-originated data is stored and keyed in-region, in Dubai.
India-originated data is stored and keyed in-region, in Mumbai, consistent with the Digital Personal Data Protection Act, 2023.
We capture the event, not the content.
That a deliverable was approved, by whom, when, against which clause. Not the conversation around it. Attachments only when explicitly linked to a contractual object.
Three reasons, and only one is legal. A system recording how people work is a monitoring system under German and Austrian law and needs a works council agreement before it can be switched on — narrow capture makes that negotiable. Purpose-limited collection keeps our published governance true. And a registrar that harvests everything it sees isn't neutral, which is the entire basis of our position.
We don't sell or license customer data, and there is no secondary-use product on our roadmap that we haven't asked you about first.
We keep a cleared, pending, blocked, or expired record for as long as it has evidentiary value to you and your counterparties — typically the life of the contractual relationship plus the statutory limitation period that applies in the corridor the payout was made in. Once that window closes, the underlying event data is deleted; the fact that a check ran, and its outcome, may be retained in aggregate for audit continuity.
Ask for your record. Correct it. Object to it.
This request route is live today — not a roadmap item, in any market we operate in, India included. We verify identity before acting on any request, and we'll tell you where things stand rather than leave you waiting silently. A self-service portal follows.
In Germany and Austria, a system that records how employees work is a monitoring system under local labour law and needs a works council agreement (Betriebsvereinbarung) before it goes live. Because we capture the event and not the conversation around it, the scope of what needs sign-off is narrow and specific — we provide the capture-scope documentation your works council needs to review before rollout, and we don't switch on anything broader without that agreement in place.
India's Digital Personal Data Protection Act, 2023 (DPDP Act) makes consent the default legal basis for processing personal data and gives Data Principals the right to access, correct, and erase their data — the request route above is the same one that handles India; we haven't built a separate portal for it.
We're appointing a Grievance Officer for India specifically, as the Act requires once our first India-based cohort goes live, and any personal data breach touching India-originated data gets reported to the Data Protection Board of India and to the people affected — not just logged internally. Cross-border transfer of India-originated data follows the government's rules for the destination corridor, not our own risk appetite.
- Cloud infrastructure and database — region-pinned per corridor (EU, US, UAE, India).
- Transactional email delivery, for confirmations and account notifications.
- Payments infrastructure, for account-ownership confirmation.
A named, current sub-processor list is available on request at contact@cognitiva.systems.
We don't hold a formal security certification yet. We're building the control set our first cohort needs first, and we'll publish certification status here as audits complete — not before.
Verifying guardian consent at scale means processing children's data at scale.
That's high-risk processing. It requires a data protection impact assessment (DPIA), and we're completing one before guardian-consent verification goes live for the first cohort — we'd rather tell you that now than have your DPO ask.
Where a minor is involved, we verify guardian consent, capacity, and any applicable youth-work conditions directly — not assumed from a parent's email.
How we're held accountable to this page is covered on Governance — our oversight structure, and how our Public Benefit Corporation mandate ties into it.