LEGAL & COMPANY INFORMATION
Privacy Policy
Cognisphere Global Ltd (“Cognisphere”, “we”, “us” or “our”) respects your privacy and is committed to handling personal data lawfully, fairly, transparently and securely.
This policy explains how we collect and use personal data when you visit our website, contact us, create or use an account, access a dashboard or online product, participate in a demonstration or early-access programme, receive marketing from us, or otherwise interact with Cognisphere.
1. Who we are
Cognisphere Global Ltd is a private company limited by shares registered in England and Wales.
- Company number: 17369721
- Registered office: 6th Floor, 37 Lombard Street, London, EC3V 9BQ, United Kingdom
- Website: https://cognisphere.co.uk
- Privacy contact: info@cognisphere.co.uk
For the personal data described in this policy, Cognisphere will usually act as a data controller. Where we process personal data solely on the documented instructions of a business customer through a product, platform, hosted environment or managed service, we may instead act as that customer’s data processor. In that situation, the customer is normally responsible for its own privacy policy and our processing is governed by contractual data-processing terms.
2. Scope and applicable law
This policy is drafted to support compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003 (PECR). Where the EU GDPR applies because Cognisphere offers goods or services to, or monitors the behaviour of, people in the European Economic Area (EEA), we also apply the relevant EU GDPR requirements.
Local data-protection or e-privacy laws may impose additional requirements in particular European countries. Where those laws apply, Cognisphere will comply with them in addition to this policy.
3. Personal data we may collect
3.1 Information you provide directly
- Identity and business contact data, such as your name, job title, organisation, business email address, telephone number and location.
- Enquiry and consultation data, including information you submit through contact forms, booking forms, emails or meetings.
- Account data, where account functionality is enabled, such as username, business email, organisation, role, account status, authentication settings and account preferences.
- Customer and project data, including requirements, proposals, contracts, support requests, service communications and project documentation.
- Billing and transaction data, where applicable. Payment-card information may be collected directly by a payment provider rather than stored by Cognisphere.
- Content you choose to upload or submit to a dashboard, product or support channel.
- Marketing preferences, event registrations, early-access registrations and feedback.
- AI-feature content, where available, such as prompts, instructions, uploaded materials and generated outputs. Product-specific policies or contractual terms may provide further information.
3.2 Information collected automatically
- Technical data, such as IP address, browser type, device information, operating system and approximate location derived from network information.
- Security and authentication records, including login events, failed login attempts, session identifiers, access logs, audit trails and security alerts.
- Usage data about how you navigate the website, dashboard or product, including pages or features accessed and interaction timestamps.
- Cookie and similar-technology data, subject to our Cookie Policy and your choices where consent is required.
3.3 Information from other sources
- Business information from your employer or organisation when it creates or administers your account.
- Information from service providers, integration partners, referral partners or professional advisers.
- Publicly available business information, such as corporate websites, professional directories, company registers and professional profiles, where lawful and relevant to B2B engagement.
- Information from analytics, security and fraud-prevention providers, where enabled and lawful.
4. Why we use personal data
| Purpose | Typical personal data | Why we may use your information |
|---|---|---|
| Respond to enquiries, arrange consultations and prepare proposals | Contact, enquiry and business information | Contract / steps before contract; legitimate interests in responding to business enquiries |
| Create and administer user accounts and dashboards | Identity, contact, account, authentication and role data | Contract; legitimate interests in secure service administration |
| Provide contracted products and services | Account, customer, project, usage and support data | Contract; legitimate interests; legal obligation where applicable |
| Secure our website, systems and users | Technical, authentication, audit and security data | Legitimate interests in network and information-system security; legal obligation where applicable |
| Improve products, usability and service quality | Usage data, feedback, support information and limited analytics | Legitimate interests, or consent where required for storage/access technologies |
| Manage billing, accounting, tax and legal records | Identity, contact, billing and transaction records | Contract; legal obligation; legitimate interests in establishing or defending legal claims |
| Send B2B marketing and relevant product updates | Business contact details, interests, preferences and engagement history | Legitimate interests where permitted; consent where required by PECR, EU e-privacy rules or other applicable law |
| Manage events, demonstrations and early access | Contact, registration, participation and feedback data | Contract / steps before contract; legitimate interests; consent where appropriate |
| Comply with legal, regulatory and sanctions obligations | Identity, business, transaction and compliance data | Legal obligation; legitimate interests where appropriate |
| Develop or operate AI-enabled features where offered | Prompts, instructions, uploaded content, usage and outputs | Contract; legitimate interests; consent where required for a specific optional use |
Where we rely on legitimate interests, we consider whether the processing is necessary and whether our interests are overridden by your rights and freedoms. You have an absolute right to object to direct marketing.
5. Marketing communications
We may send relevant B2B communications about Cognisphere services, products, events or insights where permitted by law. We will provide a clear way to opt out of direct marketing. Where consent is required, we will obtain it before sending the communication.
You can opt out at any time by using the unsubscribe mechanism in the communication or by contacting info@cognisphere.co.uk. Opting out of marketing does not prevent us from sending service, account, security or contractual communications that are necessary for an existing relationship.
6. Cookies and similar technologies
We use cookies and similar storage or access technologies for purposes such as security, session management, account authentication, preferences and, where enabled, analytics or marketing. Some technologies are necessary for the service to function. Others are optional and are controlled through our consent or preference mechanism where applicable.
Please read our Cookie Policy to manage available choices.
7. Account, dashboard and security data
Where account functionality is available, we process information needed to authenticate users, assign roles and permissions, maintain sessions, prevent misuse and investigate security events. We may record administrative actions and material account events in audit logs.
Passwords should be stored only in securely hashed form. Cognisphere will never ask you to disclose your password by email. We may require multi-factor authentication or other security controls for particular products or roles.
8. Customer content and processor activities
Business customers may upload or connect data to Cognisphere products. Depending on the service, that data may include personal data for which the customer is the controller and Cognisphere acts as processor. The relevant service agreement and Data Processing Agreement will define the subject matter, duration, nature and purpose of processing, data types, data-subject categories, confidentiality, security, subprocessors, international transfers, assistance obligations and deletion or return arrangements.
Customers must ensure that they have a lawful basis and appropriate authority to provide personal data to Cognisphere and to instruct us to process it.
9. AI and automated decision-making
Cognisphere does not currently intend to make solely automated decisions about website visitors that produce legal effects or similarly significant effects. Where a future product uses automated decision-making or profiling of that kind, we will provide additional information about the logic involved, significance and expected consequences, and we will implement the safeguards required by applicable law.
Where required, safeguards may include meaningful information, the ability to obtain human intervention, to express a point of view and to contest a decision. Product-specific policies may apply to particular AI or agentic features.
10. Sharing personal data
We may share personal data only where necessary and proportionate with categories of recipients such as:
- cloud hosting, infrastructure and cybersecurity providers;
- email, CRM, communications, collaboration and customer-support providers;
- analytics and consent-management providers where enabled;
- payment, accounting and financial-service providers;
- professional advisers, including accountants, lawyers, insurers and auditors;
- authorised specialist delivery personnel and contractors who are subject to confidentiality and access controls;
- business customers that administer user accounts for their personnel;
- law-enforcement, regulators, courts or public authorities where disclosure is required or permitted by law;
- a buyer, investor or successor in connection with a genuine corporate transaction, subject to appropriate confidentiality and data-protection measures.
We do not sell personal data to advertisers.
11. International data transfers and remote access
Cognisphere is registered in the United Kingdom and may use internationally distributed service providers and authorised delivery personnel. Personal data may therefore be stored in, transferred to, or remotely accessed from countries outside the United Kingdom and, where EU GDPR applies, outside the EEA.
Certain authorised service-delivery and technical-support functions may be performed from India. Where a restricted transfer occurs, we use an appropriate transfer mechanism and safeguards as required, which may include the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, EU Standard Contractual Clauses, applicable adequacy arrangements, transfer risk assessments and supplementary technical or organisational measures.
The European Commission renewed the UK’s adequacy status in December 2025, allowing personal data within scope to flow from the EEA to the UK without additional transfer safeguards. If EU GDPR applies to Cognisphere and an EEA representative is required under Article 27, the representative’s details will be published in this policy before the relevant processing begins.
You may request further information about relevant transfer safeguards by contacting info@cognisphere.co.uk.
12. How long we keep personal data
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements. Typical periods are:
| Category | Typical retention approach |
|---|---|
| Enquiries and prospective-client communications | Usually up to 24 months after the last meaningful interaction, unless a customer relationship or legal need requires longer. |
| Account profile and administration data | For the life of the account and then for a limited period required for closure, security, contractual or legal purposes. |
| Security and audit logs | Typically 12 months, or longer where needed to investigate an incident, protect systems or meet contractual requirements. |
| Customer contracts, invoices and core accounting records | Normally six years or another period required by tax, accounting or legal obligations. |
| Marketing records | Until you opt out or we determine the information is no longer relevant. Minimal suppression information may be retained to ensure we respect an opt-out. |
| Support records | Typically up to 24 months after closure, unless needed for a contract, dispute or security investigation. |
| Customer content processed as processor | As specified in the relevant service agreement or Data Processing Agreement, including deletion or return after termination. |
| Cookie and similar-technology data | As shown in the current Cookie Policy and consent manager. |
We may retain information for longer where required by law, necessary to establish or defend legal claims, or required to investigate fraud, misuse or security incidents. Where possible, data may be anonymised so it no longer identifies an individual.
13. Your data-protection rights
Depending on the circumstances and applicable law, you may have rights to:
- be informed about how your personal data is used;
- request access to personal data we hold about you;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data in certain circumstances;
- request restriction of processing in certain circumstances;
- receive certain personal data in a portable format and ask us to transfer it where the right applies;
- object to processing based on legitimate interests;
- object at any time to the use of personal data for direct marketing;
- withdraw consent at any time where we rely on consent, without affecting processing already carried out lawfully;
- receive safeguards in relation to qualifying automated decisions, where applicable.
Rights are not absolute and may be subject to legal conditions or exemptions. We may need to verify your identity before acting on a request.
To exercise a right, contact info@cognisphere.co.uk. We will respond within the time required by applicable law.
14. Data-protection complaints
If you believe that Cognisphere has not handled your personal data appropriately, you can make a data-protection complaint to us at info@cognisphere.co.uk.
We will acknowledge a data-protection complaint within 30 days, take appropriate steps to investigate it, keep you informed where appropriate, and communicate the outcome without undue delay.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; telephone 0303 123 1113; website ico.org.uk/make-a-complaint.
If the EU GDPR applies to you, you may also have the right to complain to a supervisory authority in the EEA country where you live, work, or believe an infringement occurred.
15. Security
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected according to risk and may include access controls, least-privilege permissions, encryption, secure development practices, logging, backups, vulnerability management, supplier controls and incident-response procedures.
No internet service can be guaranteed to be completely secure. You are responsible for protecting your credentials and for notifying us promptly if you believe an account or device has been compromised.
16. Children
Our website and business services are intended primarily for organisations and adult professional users. We do not knowingly offer the general website or business dashboard directly to children. If a future product is designed for children or is likely to be accessed by them, we will carry out the additional assessments and protections required by applicable law and provide appropriate privacy information.
17. Changes to this policy
We may update this Privacy Policy to reflect changes in our services, products, technologies, suppliers or legal obligations. The current version will be published on our website with the date of the latest update. Where a change materially affects how we use personal data, we will take appropriate steps to bring it to the attention of affected users.
18. Contact us
Privacy enquiries, rights requests and data-protection complaints should be sent to info@cognisphere.co.uk.
Cognisphere Global Ltd
6th Floor, 37 Lombard Street, London, EC3V 9BQ, United Kingdom
Company number: 17369721
Registered in England and Wales.