SECURITY & DATA

What we hold,
where, and who can ask for it back.

This page is written for the people who have to sign off on us — a DPO, a general counsel, a works council. Nothing here is aspirational; where something isn’t finished, we say so.

IN-REGION STORAGE AND KEYS

Data stays where it’s made.

EU

Dublin

EU-only hosting with an EU-only hardware security module (HSM). EU-originated data and keys never leave the region.

US

US-East

US-originated data is stored and keyed in a US-East region.

GCC

UAE · Dubai

GCC-originated data is stored and keyed in-region, in Dubai.

WHAT WE CAPTURE

We capture the event, not the content.

That a deliverable was approved, by whom, when, against which clause. Not the conversation around it. Attachments only when explicitly linked to a contractual object.

Three reasons, and only one is legal. A system recording how people work is a monitoring system under German and Austrian law and needs a works council agreement before it can be switched on — narrow capture makes that negotiable. Purpose-limited collection keeps our published governance true. And a registrar that harvests everything it sees isn’t neutral, which is the entire basis of our position.

We don’t sell or license customer data, and there is no secondary-use product on our roadmap that we haven’t asked you about first.

RETENTION

We keep a cleared, pending, blocked, or expired record for as long as it has evidentiary value to you and your counterparties — typically the life of the contractual relationship plus the statutory limitation period that applies in the corridor the payout was made in. Once that window closes, the underlying event data is deleted; the fact that a check ran, and its outcome, may be retained in aggregate for audit continuity.

ACCESS, CORRECTION, AND OBJECTION

Ask for your record. Correct it. Object to it.

This request route is live today — not a roadmap item. We verify identity before acting on any request, and we’ll tell you where things stand rather than leave you waiting silently. A self-service portal follows.

WORKS COUNCIL POSTURE — DACH

In Germany and Austria, a system that records how employees work is a monitoring system under local labour law and needs a works council agreement (Betriebsvereinbarung) before it goes live. Because we capture the event and not the conversation around it, the scope of what needs sign-off is narrow and specific — we provide the capture-scope documentation your works council needs to review before rollout, and we don’t switch on anything broader without that agreement in place.

SUB-PROCESSORS

  • Cloud infrastructure and database — region-pinned per corridor (EU, US, UAE).
  • Transactional email delivery, for confirmations and account notifications.
  • Payments infrastructure, for account-ownership confirmation.

A named, current sub-processor list is available on request at contact@cognitiva.systems.

CERTIFICATION STATUS

We don’t hold a formal security certification yet. We’re building the control set our first cohort needs first, and we’ll publish certification status here as audits complete — not before.

MINORS

Verifying guardian consent at scale means processing children’s data at scale.

That’s high-risk processing. It requires a data protection impact assessment (DPIA), and we’re completing one before guardian-consent verification goes live for the first cohort — we’d rather tell you that now than have your DPO ask.

Where a minor is involved, we verify guardian consent, capacity, and any applicable youth-work conditions directly — not assumed from a parent’s email.

GOVERNANCE

How we’re held accountable to this page is covered on Governance — our oversight structure, and how our Public Benefit Corporation mandate ties into it.

Security & Data — Storage, Capture Scope, and Subject Rights | Cognitiva