Legal
Privacy Policy
Last updated: 25 June 2026 · Effective immediately
1. About Cognity
Cognity (“we”, “us”, “our”) is an AI-powered onboarding platform operated by Cognity Pty Ltd, registered in Victoria, Australia. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our service at cognity.com.au and our API (collectively, the “Service”).
We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and where applicable the EU General Data Protection Regulation (GDPR).
2. Data We Collect
We collect the following categories of data:
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, organisation name | You, at sign-up via Clerk |
| Chat messages | User questions and AI responses within onboarding sessions | Your end users, via the SDK |
| Anonymised user IDs | Hashed, opaque identifiers (never plain email / name) used to count monthly active users | Your application, via the SDK |
| Page paths | URL paths where onboarding events occurred (e.g. /onboarding/step-2) | Your end users, via the SDK |
| Document content | Product documentation you upload for AI training | You, via the dashboard |
| Billing data | Subscription status, last-4 of card (held by Stripe, not us) | Stripe |
| Usage data | Trigger counts, MAU counts per billing month | Automatically generated |
3. How We Use Your Data
- To provide and operate the Service (AI onboarding conversations)
- To enforce plan limits and process billing via Stripe
- To send transactional emails (welcome, payment alerts, limit warnings)
- To generate anonymised analytics about onboarding performance
- To detect abuse and maintain security
- To comply with legal obligations
We do not sell or share your personal data or your end-users' data with third parties for advertising purposes.
4. Sub-Processors
We rely on the following third-party sub-processors. Each is bound by their own privacy and data-processing terms.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google (Gemini) | AI language model for onboarding conversations | USA |
| Pinecone | Vector database for document embeddings | USA |
| Neon | Serverless PostgreSQL database | USA |
| Clerk | Authentication and user management | USA |
| Upstash Redis | Rate-limiting and short-term caching | USA / EU |
| Vercel | Dashboard hosting and edge network | USA / Global |
| Stripe | Payment processing and subscription management | USA |
| Resend | Transactional email delivery | USA |
5. Data Retention
- Chat sessions and messages: retained for 24 months from the date of creation, then permanently deleted.
- Activity events and page paths: retained for 24 months.
- Anonymised MAU records: retained for 24 months for billing audit purposes.
- Uploaded documents: retained until you delete them from the dashboard, or until your account is closed.
- Account data: retained while your account is active and for up to 30 days after closure (to support recovery).
You may request deletion of your data at any time by emailing privacy@cognity.com.au.
6. Australian Privacy Principles
We comply with the 13 Australian Privacy Principles under the Privacy Act 1988 (Cth), including:
- APP 1: We have this open and transparent Privacy Policy.
- APP 3: We only collect data that is reasonably necessary.
- APP 6: We use personal information only for the primary purpose for which it was collected, or with your consent.
- APP 8: When we disclose data to overseas sub-processors, we take reasonable steps to ensure they uphold comparable privacy protections.
- APP 11: We take reasonable technical and organisational measures to protect personal information from misuse, interference, loss, and unauthorised access or disclosure.
- APP 12 & 13: You can request access to, or correction of, your personal information by contacting us.
7. GDPR Rights (EU/EEA Users)
If you are located in the EU or EEA, you have the following additional rights:
- Right of access: request a copy of the personal data we hold about you.
- Right to erasure: request deletion of your personal data (“right to be forgotten”).
- Right to data portability: receive your data in a machine-readable format.
- Right to rectification: request correction of inaccurate data.
- Right to restriction: request that we restrict processing of your data.
- Right to object: object to processing based on legitimate interests.
To exercise any right, email privacy@cognity.com.au. We will respond within 30 days.
8. Cookies and Tracking
Our website uses a single first-party cookie (cog_cookie_ok) to remember your cookie notice preference. We do not use third-party tracking or advertising cookies. Authentication cookies are set by Clerk.
9. Security
We implement industry-standard security measures including TLS encryption in transit, hashed API keys, and access controls. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
10. Contact Us
For privacy enquiries, access requests, or complaints, contact our Privacy Officer at:
Cognity Pty LtdEmail: privacy@cognity.com.au
Victoria, Australia
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email (to your registered address) or by posting a prominent notice on our website. Continued use of the Service after the effective date constitutes acceptance of the updated policy.