How CognitivZen collects, uses, shares and protects personal information through this website and our business relationships.
Working draft. This policy has not yet been reviewed by legal counsel. Please have it approved, and the bracketed items confirmed, before the site goes live.
CognitivZen (“CognitivZen”, “we”, “us”, “our”) is a digital engineering services company with offices in San Jose, California, United States, and Hyderabad, India. This policy applies to cognitivzen.com and to personal information we handle in the course of marketing, sales and client relationships.
For information we process on behalf of a client under a services agreement, that client is the controller and their own privacy notice governs. We act as a processor and handle the information only on their documented instructions.
Data controller contact: marketing@cognitivzen.com. [Confirm the correct legal entity name, registered address, and whether an EU/UK representative or Data Protection Officer must be named.]
We do not ask for, and ask that you do not send us, sensitive categories of personal data — health information, government identifiers, payment card numbers, or similar — through this website.
We do not sell personal information, and we do not use it to make decisions about you by automated means alone.
Where the UK GDPR or EU GDPR applies, we rely on the following bases:
We share personal information only with:
We operate from the United States and India, so information you give us may be transferred to and processed in either country. Where information is transferred out of the UK, the European Economic Area or another region with transfer restrictions, we put appropriate safeguards in place — ordinarily the relevant Standard Contractual Clauses together with a transfer risk assessment. [Confirm the safeguards actually in place and where copies can be requested.]
We keep personal information only as long as we need it for the purpose it was collected, then delete it or anonymise it. Enquiry records are ordinarily retained for [period to confirm]; client relationship and contractual records for as long as the relationship continues and afterwards for the period required by tax, accounting and limitation rules.
CognitivZen maintains an information security programme certified to ISO/IEC 27001 and reports against SOC 2 Type II criteria. Measures include access control on a need-to-know basis, encryption in transit, logging and monitoring, supplier due diligence, staff training and an incident response process. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Depending on where you live, you may have the right to:
If you are a California resident, you also have the rights to know, delete, correct, and to opt out of sale or sharing under the CCPA as amended by the CPRA. We do not sell or share personal information as those terms are defined, and we will not discriminate against you for exercising any right.
To exercise a right, write to marketing@cognitivzen.com. We will respond within the period the applicable law allows, and may need to verify your identity first.
We use cookies and similar technologies that are strictly necessary for the site to work, and — where you consent — analytics cookies that help us understand how the site is used. You can control cookies through your browser settings; blocking necessary cookies may stop parts of the site working. [Confirm the analytics and marketing tools in use, and whether a consent banner is required for the site’s audience.]
This website is intended for business audiences. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.
We may update this policy from time to time. The “last updated” date at the top shows when it last changed, and material changes will be signalled on this page.
Questions about this policy or about how we handle personal information: marketing@cognitivzen.com, or write to us at our San Jose or Hyderabad office.