// Effective · 2026-10-21
Privacy Policy
This Privacy Policy explains how Cognitify OÜ (registry code 17533456), a private limited company registered in Estonia ("Cognitify", "we", "us" or "our"), collects, uses, shares and protects your personal data when you visit https://cognitify.ai (the "Website") or use our services (together, the "Services"). For the purposes of the EU General Data Protection Regulation (GDPR), Cognitify OÜ is the data controller responsible for your personal data. We are committed to processing your data lawfully, fairly and transparently, and to respecting your rights. If you do not agree with this Policy, please do not use the Services.
Who We Are (Data Controller)
Cognitify OÜ is the controller of the personal data processed under this Policy. You can reach us about any privacy matter using the details below.
Cognitify OÜ — registry code 17533456Sepapaja 6, 15551 Tallinn, EstoniaEmail: privacy@cognitify.aiWe have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the GDPR. Privacy enquiries are handled at the contact above.
Personal Data We Collect
Depending on how you interact with us, we may process the following categories of personal data:
- Identity and contact data — name, email address, phone number, company name, and any details you include when you contact us or join a waitlist;
- Usage and technical data — IP address, device and browser type, operating system, pages viewed, referring URLs, and similar information collected automatically;
- Communications — the content of messages you send us and our correspondence with you;
- Consent and preferences — your cookie and marketing choices;
- Business messaging data — if you message a business that uses Cognitify Agents on a connected channel, the content of your conversation is processed on that business’s behalf (see “Our Products” and “Business Messaging Channels” below).
We do not intentionally collect special categories of personal data (such as health, biometric, or political data), and we ask that you do not send such data to us.
How We Collect Your Data
- Directly from you — when you fill in a form, join a waitlist, email us, or otherwise communicate with us;
- Automatically — through cookies and similar technologies when you use the Website (see "Cookies and Analytics" below);
- From third parties — for example analytics and infrastructure providers acting on our behalf, and, for business contacts, the sources described under “Business Contact Information We Collect for Our Own Sales” below.
Why We Use Your Data and Our Legal Bases
We only process your personal data where we have a lawful basis under Article 6 of the GDPR:
- Performance of a contract — to provide the Services you request and respond to your enquiries;
- Legitimate interests — to operate, secure, and improve the Website and Services, understand how they are used, and prevent fraud and abuse, where these interests are not overridden by your rights;
- Consent — to set non-essential cookies and send marketing communications where required; you may withdraw consent at any time;
- Legal obligation — to comply with applicable laws, accounting requirements, and lawful requests from authorities.
Business Contact Information We Collect for Our Own Sales
Cognitify runs its own sales on its own products. Where we use the enrichment features of Cognitify CRM ourselves, we are the controller, and we may obtain business contact information about you — your job title, employer, work email address and phone number, links to your professional profiles, and your country and city — from the emails you sent us, from your employer’s public website, from public business registers, and from commercial business-data providers with which we hold an account. We do not collect photographs of people, personal (non-work) contact details, or special categories of personal data this way.
- Purpose and legal basis — identifying and contacting companies for which our products and services are relevant: our legitimate interests in business-to-business sales (Article 6(1)(f) of the GDPR), which we have assessed against your interests; where the law requires consent for an electronic marketing message, we rely on consent instead;
- Source — we record where each item came from and tell you when we first contact you, and in any case within one month of obtaining the data;
- Retention — such data is deleted once we have had no interaction with you for 12 months;
- Your right to object — you may object at any time at privacy@cognitify.ai. We then stop, erase the data, and keep only a non-readable marker (a salted cryptographic hash of your identifiers) so that we do not collect it again.
Cookies and Analytics
We use Google Analytics to understand how the Website is used. Analytics and other non-essential cookies are set only after you give consent through our cookie banner, and consent defaults to denied until you choose. You can change or withdraw your choice at any time via the “Cookie settings” link in the footer of every page (which reopens the banner) or in your browser settings. The full per-cookie breakdown — names, purposes, and lifetimes — is in our Cookie Policy at cognitify.ai/pages/cookie-policy/.
We also use Cloudflare Web Analytics, provided by Cloudflare, Inc. as our processor, to count page views. It is a cookieless measurement: it stores no identifier on your device, reads none from it, and does not follow you across other websites. Because it does not access information stored on your device and does not build a profile of you, it is not gated behind the cookie banner — it runs on every visit, including visits where you decline analytics cookies. It processes only the technical data your browser sends with any page request: the page address, the referring page, basic device and browser information, and general location derived from your IP address.
Our Products: When We Act as a Processor
Cognitify builds business software: Cognitify CRM and Cognitify Agents — AI assistants that answer business messaging (website chat, Instagram, Facebook Messenger, Telegram). A business that signs up decides what data enters its workspace and why. For workspace data — the business’s contacts, leads, documents, and the conversations its customers have with it — that business is the data controller, and Cognitify OÜ acts as a data processor on the business’s documented instructions, under our Data Processing Agreement (cognitify.ai/pages/data-processing-agreement/), which is part of our Terms of Service.
This Policy describes the processing for which Cognitify is the controller: the Website, our marketing, and the account data of people who sign up for and administer our products. If you are a customer or correspondent of a business that uses Cognitify products, that business’s own privacy notice governs your data; we process it only on the business’s behalf. You can still write to privacy@cognitify.ai — where we act as a processor, we will pass your request to the business without undue delay and help it respond.
If a Business Using Cognitify Holds Business Information About You
Businesses that use Cognitify CRM keep records of the companies and people they work with, or wish to work with. Where a business enables our enrichment features, it may collect business contact information about you — such as your job title, your employer, your work email address and phone number, and links to your professional profiles — from the emails you sent to that business, from your employer’s public website, from public business registers, and from commercial business-data providers with which that business holds its own account. The business decides whether to do this and is the controller of that data; Cognitify acts as its processor and records the source of each item, so that the business can tell you where your data came from.
To learn the source of your data, to object to its use, or to have it erased, contact that business. If you cannot identify it, write to privacy@cognitify.ai: we will route your request to the business concerned and help it respond. When a business erases your data or marks you as “do not enrich”, its workspace keeps only a non-readable marker — a salted cryptographic hash of your identifiers — so that the data is not collected again.
Cognitify does not collect photographs of people for its customers: a person’s photograph appears in a workspace only if a user of that business uploaded it, and we perform no facial recognition or other biometric processing of images. Cognitify does not scrape social networks.
Business Messaging Channels (Instagram, Messenger, Telegram)
A business using Cognitify Agents can connect its own messaging channels: its Facebook Page and Instagram professional account (through Meta’s APIs, with the business’s explicit authorisation) and its Telegram bot. Once a channel is connected, we receive from the platform, on the business’s behalf: channel identifiers (such as the Page or Instagram account ID), platform-scoped identifiers of the people who message the business, and the content and metadata of those messages.
- Purpose — deliver each conversation into the business’s workspace and, where the business enables it, generate AI-assisted replies sent in the business’s name (see “AI Processing” below);
- Meta data — data received from Meta Platforms is handled in accordance with the Meta Platform Terms and Developer Policies; channel access tokens are stored encrypted and used solely to operate the connected channel;
- Retention — conversation data is kept for the business until the business deletes it, disconnects the channel, or closes its workspace, or until a verified deletion request is honoured;
- Deletion — how to have this data deleted, including data received from Meta, is described on our Data Deletion page at cognitify.ai/pages/data-deletion/.
AI Processing
Parts of our products are AI-assisted: agents draft or send replies to messages, summarise conversations, and answer questions from documents a business uploads. To do this, the relevant content is processed by large-language-model services acting as our subprocessors — by default Microsoft’s Azure OpenAI Service — or, where a business connects its own AI provider account, by the provider that business chose. Where a business enables them, AI features also summarise the public text of a company’s website and read the signature block of emails that business received, in order to suggest business details for its records.
We do not use your personal data to train our own or anyone else’s AI models, and our default AI subprocessor is contractually barred from using it to train theirs. Conversation content is accessed by Cognitify staff only for support, security, and abuse prevention.
Subprocessors
We use a small set of infrastructure providers (subprocessors) to run the Website and our products. The current list:
- Microsoft (Azure) — cloud hosting, storage, and AI model hosting (Azure OpenAI Service);
- Cloudflare, Inc. — DNS, network security, cookieless web analytics, and PDF document rendering;
- Redis Ltd. (Redis Cloud) — realtime infrastructure (caching and queues);
- Google (Google Analytics) — Website analytics, only after cookie consent;
- Meta Platforms Ireland Ltd. — message delivery for connected Instagram and Facebook Messenger channels;
- Telegram — message delivery for connected Telegram channels;
- Stripe — payment processing for paid plans.
The authoritative list — with each provider’s processing locations and the change-notification procedure — is published at cognitify.ai/pages/subprocessors/. Before a new subprocessor processes customer personal data, we update that page and notify customers as our Data Processing Agreement provides.
Who We Share Your Data With
We do not sell your personal data. We may share it with:
- Service providers (processors and subprocessors) — hosting, infrastructure, AI, and analytics providers who process data on our behalf under written data-processing terms (see “Subprocessors” above);
- Professional advisers and authorities — where required to comply with the law, exercise or defend legal claims, or respond to lawful requests;
- Successors — a buyer or successor entity in a merger, acquisition, or reorganisation, subject to this Policy.
Government and Legal Requests
If a government body, law-enforcement agency, or other public authority requests personal data from us, we review every request for legality before responding: we check that it has a valid legal basis, comes from an authority with proper jurisdiction, and is appropriately scoped.
- Data minimisation — where we are required to respond, we disclose only the minimum information necessary to comply with the request;
- Challenging unlawful requests — we challenge requests that we consider unlawful, overbroad, or improper through the available legal channels before disclosing anything;
- Notice — where the law permits, we notify the affected business or individual before disclosure;
- Record-keeping — we keep an internal record of any such requests, our legal assessment, and our responses.
As of the effective date of this Policy, we have not received any request for personal data from a public authority.
International Transfers
Some of our providers are located outside the European Economic Area (EEA). Where we transfer personal data outside the EEA, we rely on an adequacy decision of the European Commission or on appropriate safeguards such as the EU Standard Contractual Clauses. You may request a copy of the safeguards in place using the contact details above.
How Long We Keep Your Data
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. When data is no longer needed, we delete it or irreversibly anonymise it.
Workspace data that we process on a business’s behalf is kept for as long as the business keeps it: it is deleted when the business deletes it, disconnects the source channel, or closes its account, and on verified deletion requests as described on our Data Deletion page. Rolling backups are purged automatically within 35 days. Limited audit and billing records may be kept longer where the law requires or permits it.
Your Rights Under the GDPR
Subject to the conditions set out in the GDPR, you have the right to:
- Access — obtain confirmation of, and a copy of, the personal data we hold about you;
- Rectification — have inaccurate or incomplete data corrected;
- Erasure — ask us to delete your data (the "right to be forgotten");
- Restriction — ask us to restrict processing in certain circumstances;
- Data portability — receive your data in a structured, commonly used, machine-readable format;
- Objection — object to processing based on legitimate interests, or to direct marketing;
- Withdraw consent — withdraw any consent you have given, at any time, without affecting processing carried out beforehand.
To exercise any of these rights, contact us at privacy@cognitify.ai. We will respond within one month, as required by the GDPR. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.
Security
We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit and at rest, access controls, and audit logging. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Children's Privacy
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children under the age of 13. If you believe a child has provided us with personal data, please contact us and we will delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be posted on this page with a new effective date, and we will notify you of material changes where required by law.
Change log: 2026-10-21 — added the section “If a Business Using Cognitify Holds Business Information About You” (enrichment features of our products, our role as processor, photographs of people) the section “Business Contact Information We Collect for Our Own Sales”, two AI-processing purposes (summarising public company-website text; reading email signatures), and PDF document rendering in Cloudflare’s role.
US Residents (State Privacy Rights)
If a US state privacy law such as the California Consumer Privacy Act (CCPA/CPRA) applies to you: we do not sell or share your personal information as those laws define it, and we do not use it for cross-context behavioural advertising. The categories we collect are those listed under “Personal Data We Collect”; we collect them from you directly and automatically, use them for the purposes listed above, and disclose them only to the service providers listed under “Subprocessors”. Subject to applicable law, you may request access to, correction of, or deletion of your personal information, and you will not be discriminated against for exercising these rights. For workspace data of businesses using our products, we act as a “service provider” under written contract terms — direct your request to the business you interacted with, and we will help it respond. Requests: privacy@cognitify.ai.
Contact and Complaints
For any question about this Policy or how we handle your data, contact us:
Cognitify OÜ — registry code 17533456Sepapaja 6, 15551 Tallinn, EstoniaEmail: privacy@cognitify.aiIf you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or with the supervisory authority in your country of residence. This Policy is governed by the laws of the Republic of Estonia and the GDPR.