Cognitify

// Чинна з · 2026-09-01

Політика конфіденційності

This Privacy Policy explains how Cognitify OÜ (registry code 17533456), a private limited company registered in Estonia ("Cognitify", "we", "us" or "our"), collects, uses, shares and protects your personal data when you visit https://cognitify.ai (the "Website") or use our services (together, the "Services"). For the purposes of the EU General Data Protection Regulation (GDPR), Cognitify OÜ is the data controller responsible for your personal data. We are committed to processing your data lawfully, fairly and transparently, and to respecting your rights. If you do not agree with this Policy, please do not use the Services.

01

Who We Are (Data Controller)

Cognitify OÜ is the controller of the personal data processed under this Policy. You can reach us about any privacy matter using the details below.

Cognitify OÜ — registry code 17533456Sepapaja 6, 15551 Tallinn, EstoniaEmail: privacy@cognitify.ai

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the GDPR. Privacy enquiries are handled at the contact above.

02

Personal Data We Collect

Depending on how you interact with us, we may process the following categories of personal data:

  • Identity and contact data — name, email address, phone number, company name, and any details you include when you contact us or join a waitlist;
  • Usage and technical data — IP address, device and browser type, operating system, pages viewed, referring URLs, and similar information collected automatically;
  • Communications — the content of messages you send us and our correspondence with you;
  • Consent and preferences — your cookie and marketing choices;
  • Business messaging data — if you message a business that uses Cognitify Agents on a connected channel, the content of your conversation is processed on that business’s behalf (see “Our Products” and “Business Messaging Channels” below).

We do not intentionally collect special categories of personal data (such as health, biometric, or political data), and we ask that you do not send such data to us.

03

How We Collect Your Data

  • Directly from you — when you fill in a form, join a waitlist, email us, or otherwise communicate with us;
  • Automatically — through cookies and similar technologies when you use the Website (see "Cookies and Analytics" below);
  • From third parties — for example analytics and infrastructure providers acting on our behalf.
04

Why We Use Your Data and Our Legal Bases

We only process your personal data where we have a lawful basis under Article 6 of the GDPR:

  • Performance of a contract — to provide the Services you request and respond to your enquiries;
  • Legitimate interests — to operate, secure, and improve the Website and Services, understand how they are used, and prevent fraud and abuse, where these interests are not overridden by your rights;
  • Consent — to set non-essential cookies and send marketing communications where required; you may withdraw consent at any time;
  • Legal obligation — to comply with applicable laws, accounting requirements, and lawful requests from authorities.
05

Cookies and Analytics

We use Google Analytics to understand how the Website is used. Analytics and other non-essential cookies are set only after you give consent through our cookie banner, and consent defaults to denied until you choose. You can change or withdraw your choice at any time via the “Cookie settings” link in the footer of every page (which reopens the banner) or in your browser settings. The full per-cookie breakdown — names, purposes, and lifetimes — is in our Cookie Policy at cognitify.ai/pages/cookie-policy/.

We also use Cloudflare Web Analytics, provided by Cloudflare, Inc. as our processor, to count page views. It is a cookieless measurement: it stores no identifier on your device, reads none from it, and does not follow you across other websites. Because it does not access information stored on your device and does not build a profile of you, it is not gated behind the cookie banner — it runs on every visit, including visits where you decline analytics cookies. It processes only the technical data your browser sends with any page request: the page address, the referring page, basic device and browser information, and general location derived from your IP address.

06

Our Products: When We Act as a Processor

Cognitify builds business software: Cognitify CRM and Cognitify Agents — AI assistants that answer business messaging (website chat, Instagram, Facebook Messenger, Telegram). A business that signs up decides what data enters its workspace and why. For workspace data — the business’s contacts, leads, documents, and the conversations its customers have with it — that business is the data controller, and Cognitify OÜ acts as a data processor on the business’s documented instructions, under our Data Processing Agreement (cognitify.ai/pages/data-processing-agreement/), which is part of our Terms of Service.

This Policy describes the processing for which Cognitify is the controller: the Website, our marketing, and the account data of people who sign up for and administer our products. If you are a customer or correspondent of a business that uses Cognitify products, that business’s own privacy notice governs your data; we process it only on the business’s behalf. You can still write to privacy@cognitify.ai — where we act as a processor, we will pass your request to the business without undue delay and help it respond.

07

Business Messaging Channels (Instagram, Messenger, Telegram)

A business using Cognitify Agents can connect its own messaging channels: its Facebook Page and Instagram professional account (through Meta’s APIs, with the business’s explicit authorisation) and its Telegram bot. Once a channel is connected, we receive from the platform, on the business’s behalf: channel identifiers (such as the Page or Instagram account ID), platform-scoped identifiers of the people who message the business, and the content and metadata of those messages.

  • Purpose — deliver each conversation into the business’s workspace and, where the business enables it, generate AI-assisted replies sent in the business’s name (see “AI Processing” below);
  • Meta data — data received from Meta Platforms is handled in accordance with the Meta Platform Terms and Developer Policies; channel access tokens are stored encrypted and used solely to operate the connected channel;
  • Retention — conversation data is kept for the business until the business deletes it, disconnects the channel, or closes its workspace, or until a verified deletion request is honoured;
  • Deletion — how to have this data deleted, including data received from Meta, is described on our Data Deletion page at cognitify.ai/pages/data-deletion/.
08

AI Processing

Parts of our products are AI-assisted: agents draft or send replies to messages, summarise conversations, and answer questions from documents a business uploads. To do this, the relevant content is processed by large-language-model services acting as our subprocessors — by default Microsoft’s Azure OpenAI Service — or, where a business connects its own AI provider account, by the provider that business chose.

We do not use your personal data to train our own or anyone else’s AI models, and our default AI subprocessor is contractually barred from using it to train theirs. Conversation content is accessed by Cognitify staff only for support, security, and abuse prevention.

09

Subprocessors

We use a small set of infrastructure providers (subprocessors) to run the Website and our products. The current list:

  • Microsoft (Azure) — cloud hosting, storage, and AI model hosting (Azure OpenAI Service);
  • Cloudflare, Inc. — DNS, network security, and cookieless web analytics;
  • Redis Ltd. (Redis Cloud) — realtime infrastructure (caching and queues);
  • Google (Google Analytics) — Website analytics, only after cookie consent;
  • Meta Platforms Ireland Ltd. — message delivery for connected Instagram and Facebook Messenger channels;
  • Telegram — message delivery for connected Telegram channels;
  • Stripe — payment processing for paid plans.

The authoritative list — with each provider’s processing locations and the change-notification procedure — is published at cognitify.ai/pages/subprocessors/. Before a new subprocessor processes customer personal data, we update that page and notify customers as our Data Processing Agreement provides.

010

Who We Share Your Data With

We do not sell your personal data. We may share it with:

  • Service providers (processors and subprocessors) — hosting, infrastructure, AI, and analytics providers who process data on our behalf under written data-processing terms (see “Subprocessors” above);
  • Professional advisers and authorities — where required to comply with the law, exercise or defend legal claims, or respond to lawful requests;
  • Successors — a buyer or successor entity in a merger, acquisition, or reorganisation, subject to this Policy.
011

Government and Legal Requests

If a government body, law-enforcement agency, or other public authority requests personal data from us, we review every request for legality before responding: we check that it has a valid legal basis, comes from an authority with proper jurisdiction, and is appropriately scoped.

  • Data minimisation — where we are required to respond, we disclose only the minimum information necessary to comply with the request;
  • Challenging unlawful requests — we challenge requests that we consider unlawful, overbroad, or improper through the available legal channels before disclosing anything;
  • Notice — where the law permits, we notify the affected business or individual before disclosure;
  • Record-keeping — we keep an internal record of any such requests, our legal assessment, and our responses.

As of the effective date of this Policy, we have not received any request for personal data from a public authority.

012

International Transfers

Some of our providers are located outside the European Economic Area (EEA). Where we transfer personal data outside the EEA, we rely on an adequacy decision of the European Commission or on appropriate safeguards such as the EU Standard Contractual Clauses. You may request a copy of the safeguards in place using the contact details above.

013

How Long We Keep Your Data

We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. When data is no longer needed, we delete it or irreversibly anonymise it.

Workspace data that we process on a business’s behalf is kept for as long as the business keeps it: it is deleted when the business deletes it, disconnects the source channel, or closes its account, and on verified deletion requests as described on our Data Deletion page. Rolling backups are purged automatically within 35 days. Limited audit and billing records may be kept longer where the law requires or permits it.

014

Your Rights Under the GDPR

Subject to the conditions set out in the GDPR, you have the right to:

  • Access — obtain confirmation of, and a copy of, the personal data we hold about you;
  • Rectification — have inaccurate or incomplete data corrected;
  • Erasure — ask us to delete your data (the "right to be forgotten");
  • Restriction — ask us to restrict processing in certain circumstances;
  • Data portability — receive your data in a structured, commonly used, machine-readable format;
  • Objection — object to processing based on legitimate interests, or to direct marketing;
  • Withdraw consent — withdraw any consent you have given, at any time, without affecting processing carried out beforehand.

To exercise any of these rights, contact us at privacy@cognitify.ai. We will respond within one month, as required by the GDPR. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.

015

Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit and at rest, access controls, and audit logging. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

016

Children's Privacy

The Services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children under the age of 13. If you believe a child has provided us with personal data, please contact us and we will delete it.

017

Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be posted on this page with a new effective date, and we will notify you of material changes where required by law.

018

US Residents (State Privacy Rights)

If a US state privacy law such as the California Consumer Privacy Act (CCPA/CPRA) applies to you: we do not sell or share your personal information as those laws define it, and we do not use it for cross-context behavioural advertising. The categories we collect are those listed under “Personal Data We Collect”; we collect them from you directly and automatically, use them for the purposes listed above, and disclose them only to the service providers listed under “Subprocessors”. Subject to applicable law, you may request access to, correction of, or deletion of your personal information, and you will not be discriminated against for exercising these rights. For workspace data of businesses using our products, we act as a “service provider” under written contract terms — direct your request to the business you interacted with, and we will help it respond. Requests: privacy@cognitify.ai.

019

Contact and Complaints

For any question about this Policy or how we handle your data, contact us:

Cognitify OÜ — registry code 17533456Sepapaja 6, 15551 Tallinn, EstoniaEmail: privacy@cognitify.ai

If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or with the supervisory authority in your country of residence. This Policy is governed by the laws of the Republic of Estonia and the GDPR.