Cognitify

// Effective · 2026-09-01

Data Processing Agreement

This Data Processing Agreement (the “DPA”) forms part of the Terms of Service between Cognitify OÜ (registry code 17533456, Sepapaja 6, 15551 Tallinn, Estonia — “Cognitify”, the “Processor”) and the customer identified in the applicable workspace (the “Customer”, the “Controller”). It is concluded automatically when the Customer accepts the Terms of Service — no separate signature is required — and it governs all personal data that Cognitify processes on the Customer’s behalf in the course of providing the Services. Where this DPA conflicts with the Terms of Service on a data-protection matter, this DPA prevails. Capitalised terms not defined here have the meaning given in the Terms of Service; “GDPR”, “personal data”, “processing”, “controller”, “processor”, “data subject”, and “personal data breach” have the meanings given in Regulation (EU) 2016/679.

01

1. Roles and Scope

For workspace data — the contacts, leads, deals, documents, bookings, form and survey submissions, and conversations the Customer and its users bring into or collect through the Services (“Customer Personal Data”) — the Customer is the controller (or a processor acting on behalf of its own controllers, in which case it warrants that its instructions to Cognitify are authorised by the relevant controller), and Cognitify is the processor. This DPA does not apply to data for which Cognitify is itself the controller (account, billing, and website data), which is governed by our Privacy Policy.

02

2. Instructions

Cognitify processes Customer Personal Data only on the Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by European Union or Member State law — in which case Cognitify informs the Customer of that legal requirement before processing, unless the law prohibits it. The Terms of Service, this DPA, and the Customer’s configuration of the Services (workspace settings, connected channels, agent configuration, enabled features) constitute the Customer’s complete documented instructions. Cognitify will inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law.

03

3. Confidentiality

Cognitify ensures that every person it authorises to process Customer Personal Data is bound by a contractual or statutory obligation of confidentiality, and that access is limited to what each role requires. Conversation and workspace content is accessed by Cognitify staff only for support, security, and abuse prevention.

04

4. Security (Annex II)

Cognitify implements and maintains the technical and organisational measures described on our Security page at cognitify.ai/pages/security/, which constitutes Annex II to this DPA — including database-enforced tenant isolation (row-level security on every table), encryption in transit and at rest, role-based access control, an append-only cryptographically chained audit trail, and tested backups. We may update these measures as technology evolves, but never in a way that materially reduces the overall level of protection during a subscription period.

05

5. Subprocessors (Annex III)

The Customer grants Cognitify general authorisation to engage subprocessors. The current list, with each provider’s role and processing locations, is published at cognitify.ai/pages/subprocessors/ and constitutes Annex III to this DPA. Before a new subprocessor processes Customer Personal Data, we update that page and give customers at least 14 days’ notice. The Customer may object on reasonable data-protection grounds within that period; if we cannot offer a workaround (such as not deploying the subprocessor for the Customer’s workspace), the Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees.

Cognitify imposes on every subprocessor, by written contract, data-protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for its subprocessors’ performance.

06

6. International Transfers

Customer Personal Data is hosted in Microsoft Azure’s West Europe region (the Netherlands); replicas and backups stay inside the European Union. Where a subprocessor entails a transfer outside the EEA, the transfer relies on a European Commission adequacy decision or on the EU Standard Contractual Clauses (Commission Decision 2021/914 — Module Two or, where the Customer acts as a processor, Module Three), which are incorporated into this DPA by reference with Annex I below serving as their annexes. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum issued by the ICO is incorporated, with its tables deemed completed by the parties’ details and Annex I. For transfers subject to Swiss law, the Clauses apply with the adaptations required by the Swiss FDPIC.

07

7. Assistance

  • Data subject rights — taking into account the nature of the processing, Cognitify assists the Customer with appropriate technical and organisational measures to answer data subjects’ requests (access, rectification, erasure, restriction, portability, objection): the Services provide export, correction, and deletion tooling, and any request a data subject sends to Cognitify directly is forwarded to the Customer without undue delay;
  • Security, breach notification, DPIAs — Cognitify assists the Customer in complying with Articles 32–36 of the GDPR, taking into account the nature of the processing and the information available to Cognitify, including providing the information a Customer reasonably needs for a data protection impact assessment of its use of the Services;
  • Records — Cognitify maintains a record of processing activities carried out on behalf of its customers as required by Article 30(2).
08

8. Personal Data Breach

Cognitify notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provides the information required by Article 33(3) of the GDPR as it becomes available — the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Notification is not an acknowledgement of fault or liability.

09

9. Audits

Cognitify makes available to the Customer the information necessary to demonstrate compliance with Article 28 of the GDPR — starting with this DPA, the Security page, and available control evidence — and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates. Audits require 30 days’ written notice, run at most once per 12 months (except after a personal data breach affecting the Customer or where a supervisory authority requires one), take place during business hours without disrupting the Services, and are subject to confidentiality. Where a request can be satisfied by documentation or existing evidence, the parties start there.

010

10. Return and Deletion

During the subscription term and for 30 days after termination, the Customer can export Customer Personal Data through the Services. After that window, Cognitify deletes Customer Personal Data, unless European Union or Member State law requires further storage. Rolling backups are purged automatically within 35 days. Deletion mechanics, including per-channel deletion requests, are described on our Data Deletion page.

011

11. US State Privacy Laws (Service-Provider Terms)

Where the California Consumer Privacy Act as amended by the CPRA, or a similar US state privacy law, applies to Customer Personal Data, Cognitify acts as the Customer’s “service provider” (or “processor”): we process personal information only for the business purpose of providing the Services under the Terms; we do not sell or share personal information; we do not retain, use, or disclose it outside the direct business relationship with the Customer or for any purpose other than the business purposes specified in this DPA; and we do not combine it with personal information we receive from other sources except as permitted for service providers. Cognitify certifies that it understands and will comply with these restrictions, will notify the Customer if it can no longer do so, and grants the Customer the right to take reasonable and appropriate steps to stop and remediate unauthorised use of personal information.

012

12. Health Data Annex (Medical, Dental, and Aesthetic-Medicine Customers)

This section applies where the Customer’s use of the Services involves data concerning health within the meaning of Article 4(15) and Article 9 of the GDPR — which is the normal case for clinics, dental practices, and medical cosmetology: the fact that a person has booked an appointment with such a provider is itself health data. It applies automatically when the Customer enables the medical workspace profile in the Services, and in any event whenever the Customer processes health data through them.

  • Lawful basis is the Customer’s — the Customer warrants that a valid Article 9(2) condition covers its processing: typically Article 9(2)(h) (provision of health or social care under the responsibility of a professional subject to the obligation of professional secrecy) for the care and appointment-administration contour, and explicit consent under Article 9(2)(a) for any marketing to patients. The Services provide consent-capture and evidence tooling; the Customer is responsible for the wording and validity of its own notices and consents;
  • Reinforced measures — workspaces with the medical profile run with mandatory multi-factor authentication for the Customer’s users, restricted messaging channels, and analytics disabled on the Customer’s hosted public pages, in addition to the Annex II measures;
  • DPIA assistance — large-scale processing of health data typically obliges the Customer to carry out a data protection impact assessment (Article 35(3)(b)); Cognitify provides the platform-side inputs described in Section 7;
  • Retention and erasure — statutory medical-record retention periods override erasure: where the Customer configures a legal hold reflecting the retention law that applies to it, erasure and retention tooling honour that hold, and Article 17(3)(b) applies;
  • AI boundaries — AI agents operated for medical-profile Customers are restricted to organisational assistance (scheduling, reminders, administrative answers) and must not be used for diagnosis, triage, or treatment recommendations; the Services are not a medical device and are not intended for clinical decision-making;
  • Excluded uses — the Services must not be used to host health data governed by the French HDS (hébergeur de données de santé) certification regime, or data subject to 42 CFR Part 2 (US substance-use-disorder records), and must not be used as a system of record for electronic health records.
013

13. Liability, Term, and Governing Law

Each party’s liability under this DPA is subject to the “Liability” section of the Terms of Service. This DPA takes effect on the Customer’s acceptance of the Terms, lasts as long as Cognitify processes Customer Personal Data, and is governed by the laws of the Republic of Estonia. If any provision is held invalid, the remainder stays in force.

014

Annex I — Details of Processing

  • Subject matter — provision of Cognitify CRM and Cognitify Agents: hosting, storage, transmission, display, and AI-assisted handling of workspace data as configured by the Customer;
  • Duration — the subscription term plus the 30-day export window and the 35-day backup purge cycle;
  • Nature and purposes — collection, storage, structuring, retrieval, use, and erasure of workspace data; delivery of conversations from connected channels; AI-assisted drafting and answering as configured by the Customer; no use for Cognitify’s own purposes and no AI-model training;
  • Categories of data subjects — the Customer’s contacts, leads, customers, and correspondents; visitors of the Customer’s hosted pages, forms, surveys, and chat widgets; the Customer’s own users and staff; for medical-profile Customers — the Customer’s patients and clients;
  • Categories of personal data — identity and contact data; business-relationship data (deals, notes, tasks, bookings); communications content and metadata from connected channels; documents the Customer uploads; technical data of hosted-page visitors;
  • Special categories — none, except where the Customer processes health data under the Health Data Annex (Section 12), in which case data concerning health as configured by the Customer;
  • Frequency — continuous, for the duration of the subscription;
  • Competent supervisory authority — the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), or the authority determined under Article 56 of the GDPR.
Cognitify OÜ — registry code 17533456Sepapaja 6, 15551 Tallinn, EstoniaEmail: privacy@cognitify.ai