This information explains how Cogniten handles personal data and the content that organisations entrust to it. It is written for our business customers and the people who use Cogniten on their behalf.
1. Who we are
Cogniten is operated by the operator named in the imprint, Switzerland ("Cogniten", "we"). We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
2. Data we process
- Account data — name, email address, a salted hash of the password (never the password itself), two-factor sign-in settings, workspace memberships and roles, and interface preferences.
- Customer Content — everything users submit or create in a workspace: questions and chats, uploaded documents and emails, the text extracted from them, generated files, client folders and their notes, and the results of analyses such as financial statement reviews.
- Usage and billing data — usage figures per workspace and user (such as the number of requests, storage used and estimated processing cost), subscription and seat information and billing details. We do not store payment card details.
- Acceptance records — which versions of the Terms and of this information were accepted or acknowledged, when, by which user and for which organisation, with the IP address and browser.
- Technical and security data — event data needed to operate and secure the Service (such as user and workspace identifiers, error codes and rate-limit counters) and an audit log of administrative actions.
- Feedback — messages and any screenshots users send through the feedback function, with the browser's user-agent string and the page they were sent from.
- Microsoft 365 add-in (if an organisation uses it) — the Microsoft tenant and account identifiers needed to sign in.
3. Why we process it
We process this data to provide, secure and support the Service, to measure usage against plan allowances, to communicate with users about the Service, to invoice subscriptions, to document the acceptance of the Terms and to meet legal obligations. The legal bases are the performance of the contract with the customer organisation, our legitimate interest in operating a secure and reliable service, and legal obligations. We do not sell personal data or Customer Content and do not use them for advertising.
4. Customer Content and our role
The customer organisation decides what information it submits to Cogniten. If it provides personal data or confidential information concerning third parties — such as clients, employees or business partners — it ensures that it is permitted to provide and process that information through the Service.
For Customer Content, Cogniten acts as a processor on behalf of the customer organisation, under the Data Processing Agreement. We process Customer Content only to provide the Service, keep it confidential, protect it as described in section 9 and handle it according to the agreement. For account, usage, billing, acceptance and security data, Cogniten is itself responsible.
5. AI-assisted processing
Cogniten uses selected external artificial-intelligence and technology infrastructure to provide its functions. Depending on the function used, the information necessary for it is processed by these providers, in particular:
- questions, instructions and the relevant conversation context, including client notes and chat summaries;
- files attached to a message, which may be processed in full, and emails opened in the Outlook add-in;
- passages retrieved from documents and chats the user may access, including candidate passages for ranking;
- the text of uploaded documents and of chats, to build search indexes, and scanned pages and images, to recognise their text;
- the content of financial statements submitted for review;
- files and data processed in a temporary calculation environment, where they may remain until it expires;
- web search queries formulated by the assistant, which are carried out by the provider or its search partners.
When the assistant opens a public web page, it does so from our servers, and the website receives the page address. The assistant is instructed not to include client names or confidential details in search queries or web addresses.
For searches in an organisation's knowledge, relevant passages are selected; the entire knowledge library is not sent with each request. Some functions also keep derived content in the workspace: client notes the assistant saves in a client folder, the summary of a chat that is continued in a new one, and the search indexes.
Training. Cogniten does not train general-purpose AI models with Customer Content and does not voluntarily enable Customer Content submitted through the production Service to be used for the general training of the AI models used to provide the Service.
Retention by providers. Depending on the function and configuration, selected infrastructure providers may temporarily process or retain limited request and response information for security, abuse prevention, service integrity or technical operation, subject to contractual and technical safeguards.
AI-generated output may contain errors and should be checked before it is relied on; see the Terms & Conditions.
6. Service providers
We work with carefully selected service providers (subprocessors), in particular for AI processing, application hosting and databases, file storage and sending emails, and — once online payment is offered — payment processing. They process data only on our behalf, according to our instructions and under data protection agreements. The subprocessor register describes them; customers can request further details.
7. International processing
Depending on the service and infrastructure used, information may be processed in Switzerland, in the EU/EEA and in other countries, including countries without an adequate level of data protection such as the United States. Where required, we use appropriate safeguards for such transfers, in particular standard contractual clauses recognised by the Federal Data Protection and Information Commissioner (FDPIC), or rely on an exception provided by law. Details are available on request.
8. Retention and deletion
- Customer Content is kept for as long as the workspace exists. Owners can set a retention period after which inactive chats are deleted (30 days, 90 days, one year or until deleted).
- Deleting a document removes the stored file, its extracted text and its search index entries.
- Deleting a chat removes its messages, files and analysis results. Some content is deleted separately: an answer forwarded to a colleague is a copy in the colleague's chat; a chat file kept in the knowledge stays there; client notes remain until they are deleted, and the summary of a continued chat remains with the new chat.
- Deleting an account or a workspace deletes its content. How Customer Content is returned or deleted at the end of an agreement is set out in the Data Processing Agreement. Where backups exist, residual copies are deleted in the regular backup cycle.
- Acceptance records and billing records are kept as evidence and under statutory retention periods (for accounting records, generally ten years). Usage statistics are deleted with the workspace.
9. Security
Cogniten implements appropriate technical and organisational measures designed to protect Customer Content and personal data against unauthorised access, alteration, loss and disclosure. They include encrypted connections (HTTPS), encryption of stored files, strict separation of workspaces, role-based access within a workspace, two-factor sign-in for owners and administrators of company workspaces (and for all members where an organisation requires it), salted password hashing, rate limiting of sign-in attempts, logging designed to exclude the content of questions, answers and documents, and an audit log of administrative actions. The Data Processing Agreement describes the measures in more detail. No electronic system can guarantee absolute security.
10. Your rights
Subject to applicable law, you may request access to your personal data, its rectification or deletion, a copy in a common format, and the restriction of its processing, and you may object to it. Where we process data on behalf of an organisation, please contact that organisation first; we support it in responding. You may also lodge a complaint with the FDPIC or, where the GDPR applies, with a supervisory authority in the EU.
11. Cookies and technical data
We use only functional cookies and similar storage: a session cookie that keeps users signed in, a session cookie for the Microsoft 365 add-in, and preference cookies (language, theme, sidebar). We use no advertising cookies and no third-party tracking or analytics.
12. Changes
We update this information as the Service and its infrastructure evolve. Each version is dated; material changes are announced in the Service.
13. Contact
For all questions about data protection and to exercise your rights: info@cogniten.ch.