Privacy policy (GDPR-Compliant)
Effective Date: March 9, 2026
This Privacy Policy describes how and when CogniSpectix collects, uses and shares your information when you use our services. When you use CogniSpectix, you agree to the collection, transfer, manipulation, storage and other uses of your information as described in this Privacy Policy.
We value your privacy and are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679.
This Privacy Policy describes how and when CogniSpectix collects, uses and shares your information when you use our services. When you use CogniSpectix, you agree to the collection, transfer, manipulation, storage and other uses of your information as described in this Privacy Policy.
We value your privacy and are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679.
1. Data We Collect
We strive to collect as little personal information as possible. When you use our application, we may collect the following:
- Country-level geolocation — derived from your IP address (the full IP address is not stored or logged). This is used solely for basic security (e.g., fraud/abuse prevention), enforcing territorial restrictions, and aggregated anonymized analytics.
- Email Address — only if you voluntarily provide it (e.g., for account creation, password recovery, or deletion requests).
- Authentication via Google ("Sign in with Google")
— if you select the option to sign in using your Google account, we receive the following information directly from Google:
- A unique user identifier (sub / Google ID) — always received (required for authentication).
- Email address — if you grant the email scope.
2. Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
- Consent – by voluntarily providing your email, you consent to its use for the limited purposes stated.
- Legitimate Interest — we derive and use country-level geolocation (without storing full IP addresses) for essential purposes: security and fraud prevention, enforcing service availability restrictions (e.g., territorial rules), and basic aggregated analytics. These interests are balanced against your rights — we minimize data, do not store identifiable IP data, and limit use to what is strictly necessary.
- Performance of a contract — to provide authentication and secure access to the Application, including via Google OAuth (processing of Google ID and related data is necessary to fulfill the login and account management functions).
3. How Your Data Is Used
We use your information only to:
- Provide core app functionality
- Respond to password recovery or deletion requests
- Improve security and monitor technical performance
4. Data Sharing and Transfers
We do not share, sell, or trade your personal data with third parties.
Our servers are located in Germany. Any data collected is processed and stored there.
Our team members or service providers who may have access to this data for legitimate reasons may be located in Germany or other countries with adequate data protection.
Data received via Google OAuth (such as unique user identifier and granted profile/email information) is processed by Google LLC (USA). These transfers are safeguarded under Google's participation in the EU-US Data Privacy Framework (or Standard Contractual Clauses where applicable).
Data received via Google OAuth (such as unique user identifier and granted profile/email information) is processed by Google LLC (USA). These transfers are safeguarded under Google's participation in the EU-US Data Privacy Framework (or Standard Contractual Clauses where applicable).
5. Your Rights Under GDPR
You have the following rights regarding your personal data:
We will respond to your request within one month of receipt (this period may be extended by two further months for complex requests, in which case we will inform you within the first month). We may ask for additional information to confirm your identity before processing the request.
- Access – Request a copy of the data we hold about you.
- Rectification – Request correction of inaccurate or incomplete data.
- Erasure – Request deletion of your data ("right to be forgotten").
- Restriction – Request limitation of how we process your data.
- Objection – Object to our use of your data for specific purposes.
- Data Portability – Request your data in a machine-readable format.
- Consent withdraw – at any time (where processing is based on consent) without affecting the lawfulness of processing before withdrawal.
- Lodge a complaint – with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or where the alleged infringement occurred.
We will respond to your request within one month of receipt (this period may be extended by two further months for complex requests, in which case we will inform you within the first month). We may ask for additional information to confirm your identity before processing the request.
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by applicable law. After that period, the data is securely deleted or irreversibly anonymized.
Specific retention periods are as follows:
- Email address (if you voluntarily provided it): Retained until you delete your account, request erasure, or withdraw consent — unless we are legally obliged to keep it longer (for example, for tax, accounting, or dispute resolution purposes — up to 10 years under German commercial and tax law).
- Google OAuth data (unique user identifier / sub): Retained as long as your account remains active (for authentication and account management purposes). Upon account deletion or erasure request, this data is removed promptly (subject to any legal retention obligations). We do not retain unnecessary profile details (e.g., name or picture) beyond initial account setup if not needed for functionality.
- Country-level geolocation data (derived from IP address, full IP never stored): Retained for up to 12 months for security, fraud prevention, enforcement of territorial restrictions, and aggregated anonymized analytics. After this period, it is deleted or fully anonymized.
- Technical and session data (browser type/version, operating system, session timestamps, etc.): Retained only for the duration of your active session or up to 90 days for performance monitoring, stability analysis, and security purposes.
7. Local Data Processing
When you use the application to manage your knowledge base, all the content you create is processed locally in your browser. This information does not pass through our servers or get stored by us.
8. Cookies and Similar Technologies
We use cookies and similar tracking technologies on our website and application to enhance your experience, analyze usage, and ensure security. Cookies are small files stored on your device that help us:
Consent and Control:
Cookie Duration:
- Necessary Cookies: Essential for core functionality, such as maintaining sessions, logging in, and navigating the app. These do not require consent.
- Analytics Cookies: Collect anonymized information about how users interact with our app, including page views, session duration, and error tracking. These help us improve performance, stability, and security. Analytics are usually performed via third-party services such as Google Analytics. No personally identifiable information is shared without your consent.
Consent and Control:
- Before using analytics or advertising cookies, we will ask for your consent via a cookie banner.
- You can choose to accept all cookies or allow only necessary cookies.
- You can withdraw or modify your consent at any time through the cookie banner or by adjusting your browser settings.
Cookie Duration:
- Session Cookies: deleted when you close your browser.
- Persistent Cookies: may remain on your device for a specified period (e.g., up to 2 years) to help remember your preferences and improve your experience.
- Third-party cookies may have their own storage periods; please refer to the respective provider’s privacy policy.
9. Territorial Restrictions
CogniSpectix and its services are not available to citizens or residents of the Russian Federation.
Due to Russian Federal Law No. 152-FZ “On Personal Data” (as amended effective July 1, 2025), we do not provide access or use of the service to RF residents.
By using CogniSpectix, you confirm that you are not a citizen/resident of the Russian Federation and are not using it from Russian territory.
Violation of this restriction is a material breach and results in immediate termination of access without notice or refund.
10. Contact
If you have any questions about this Privacy Policy or want to exercise your rights, please contact:
Email: [email protected]
Data Controller: Anton Susov (founder of CogniSpectixtm)
Email: [email protected]
Data Controller: Anton Susov (founder of CogniSpectixtm)