Suite product privacy

cognipeer Pulse Privacy Policy.

How personal information is processed across Pulse timelines, files, memory, tasks, connected work services, meetings, voice features and optional device execution.

cognipeer Pulse

Pulse Privacy Policy

Effective date: 22 July 2026 Last updated: 22 July 2026

This cognipeer Pulse Privacy Policy (the “Pulse Policy”) explains how personal information is collected, used, disclosed, stored and protected when you use cognipeer Pulse, including its websites, applications, APIs, workspace features, integrations, device agents, voice features and meeting features (collectively, “Pulse”).

Pulse is provided by BİLSATEK YAZILIM VE TEKNOLOJİ ANONİM ŞİRKETİ, operating under the cognipeer brand (“cognipeer”, “we”, “us” or “our”), registered at Çifte Havuzlar Mah. Eski Londra Asfaltı Cad., Kuluçka Mrk. A1 Blok No: 151/1C, İç Kapı No: B35, Esenler/İstanbul, Türkiye.

Pulse is a workspace-based AI assistant that provides a persistent timeline, files, memory, background tasks, approvals, integrations, voice interactions, meeting assistance and optional device-based execution.

1. Relationship with the General Privacy Policy

This Pulse Policy supplements the cognipeer General Privacy Policy, which explains the privacy principles and practices shared across the cognipeer suite.

This Pulse Policy provides additional detail about information and processing specific to Pulse, particularly connected work services, Google user data, timeline content, memory, tasks, meetings, voice and device agents.

If a signed customer agreement or Data Processing Agreement applies, it may contain additional or different commitments.

2. Scope

This Pulse Policy applies to personal information processed by cognipeer in connection with Pulse.

It does not govern:

  • third-party products and services that you connect to Pulse;
  • independent websites or services operated by another organisation; or
  • customer-operated on-premises deployments to the extent that the customer determines and controls the processing.

Third-party services remain subject to their own terms and privacy policies. For customer-operated deployments, the customer is responsible for providing any additional privacy notice required for its configuration and use.

3. Our Role and Your Organisation's Role

Customer Content

For content submitted through an organisation-managed workspace, the customer organisation generally determines why and how that content is processed. cognipeer generally processes it on the customer's instructions as a processor or service provider.

Business and account information

cognipeer acts as a controller for information used to operate Pulse, administer accounts, maintain security, communicate with users, manage subscriptions and meet legal obligations.

Organisation administrators

Workspace and organisation administrators may manage membership, settings, permissions, integrations, devices, security controls and content within their administrative scope. They may be able to access, export, restrict or delete information associated with a managed account.

If you use Pulse through an organisation, direct questions about organisation-controlled content to that organisation first.

4. Information We Process

4.1 Account, profile and organisation information

We may process:

  • name, email address, avatar, timezone, account status, authentication source and workspace membership;
  • organisation and workspace names, identifiers, roles, permissions, settings, invitations and plan information;
  • profile information you choose to provide, including “About Me” text and context entries; and
  • password hashes, session identifiers, password-reset records, personal access token metadata, device-token hashes and authentication revision data.

4.2 Timeline, memory and task information

We may process:

  • messages, prompts, instructions, assistant responses, reactions, feedback and attachments;
  • conversation summaries and runtime state used to maintain continuity;
  • memory facts and context added, updated or deleted by you or the Service;
  • task prompts, status, outputs, errors, tool calls, approvals and execution history;
  • scheduled, delayed, webhook-triggered and recurring task information; and
  • generated artefacts, code changes, notices and links between timeline items and files.

4.3 Files and shared resources

We may process files, folders, generated artefacts, file names, paths, MIME types, sizes, ownership, sharing permissions and related metadata. Files may be uploaded directly, generated by Pulse, imported from a connected service or transferred to or from an authorised device.

4.4 Integration information

When you connect a third-party service, we may process:

  • account identifiers, display name, email address, avatar and provider profile metadata;
  • granted permissions and scopes;
  • encrypted access and refresh tokens, token expiration, connection status, synchronisation timestamps and error information;
  • webhook or subscription identifiers, verification data, expiration information and synchronisation state; and
  • content and metadata retrieved from or sent to the connected service at your direction.

Optional integrations may include Google, Microsoft 365, GitHub, Notion, Trello, email systems, collaboration tools, enterprise systems, storage services, databases, APIs and Model Context Protocol services.

4.5 Voice and meeting information

Where enabled, we may process:

  • voice-session identifiers, audio streams, transcripts, language, platform, status and technical session metadata;
  • meeting URLs, platform, schedule, join and leave times, participant names and presence intervals;
  • recordings where enabled, transcripts, summaries, instructions and bot status; and
  • notification settings and meeting-authentication information.

The person or organisation enabling these features is responsible for providing legally required notice and obtaining any required consent before recording or transcription begins.

4.6 Device and local execution information

If you connect a device agent, we may process device identifiers, device name, platform, capabilities, connection state, task instructions, outputs, transferred files, model-usage information, errors and security events.

Local-device operations may access files, applications, browser sessions, terminal commands or other resources only where the relevant capability has been enabled and authorised for that device and workspace.

4.7 Usage, diagnostics, logs and tracing

We may collect:

  • IP address, user agent, request and session identifiers, timestamps, connection events and diagnostic logs;
  • feature usage, task counts, token usage, model usage, latency, errors and service status;
  • security, authentication, integration, device and administrator audit events; and
  • optional agent traces, including session identifiers, model and tool events, errors, timing and token counts.

Where configured by the customer, agent tracing may be sent to cognipeer Console for observability.

4.8 Information received from others

We may receive information from your employer, organisation, workspace administrator, another user who invites you, connected services, meeting participants and providers supporting authentication, infrastructure, security, delivery and customer support.

5. How We Use Information

We use personal information to:

  1. provide, maintain, personalise and improve Pulse;
  2. maintain the persistent timeline, runtime state, memory, files and workspace context;
  3. execute requested tasks, tools, integrations, approvals, voice interactions and meeting workflows;
  4. authenticate users, maintain sessions, manage memberships and enforce permissions;
  5. process files, generate content, retrieve relevant information and deliver AI-assisted features;
  6. operate integrations and synchronise authorised data;
  7. provide support and service, security and account communications;
  8. monitor reliability, diagnose errors, measure usage and enforce plan limits;
  9. prevent fraud, abuse, unauthorised access and security incidents;
  10. comply with law, enforce agreements and protect rights, safety and property; and
  11. create aggregated or de-identified information.

Pulse does not provide a product feature that uses Customer Content to train a general-purpose cognipeer model. Customer-selected AI providers may process content sent to their models under the customer's configuration and the provider's terms.

6. AI Processing and Automated Actions

Pulse sends relevant instructions and context to configured AI model providers to generate responses, summaries, classifications, plans, embeddings or tool decisions. Context may include messages, files, retrieved integration content, memory, task state and tool results.

Pulse may recommend, prepare or perform external actions. Approval requirements depend on the product configuration, workspace policies and permissions established by you or your organisation. Some scheduled or automated workflows may operate under previously authorised instructions.

Pulse is not intended to make legally significant decisions about individuals without appropriate human oversight.

7. Google User Data

This section applies when you choose to connect a Google Account to Pulse. Google connections are optional and begin only after you complete the Google OAuth flow and grant the requested permissions.

7.1 Google data requested and why

Google OAuth scope Data accessed Purpose and operations
userinfo.email and userinfo.profile Google account identifier, email address, name and profile image Identify and display the connected account and maintain the connection selected by the user.
gmail.modify Messages, threads, headers, bodies, labels and attachments Search and read email, manage labels, import attachments, and compose, send, reply to or forward email at the user's request.
calendar.events Event details, attendees, dates, times, recurrence, locations, reminders and conference information Read, create, update or delete events and add Google Meet details at the user's request.
calendar.calendarlist.readonly Calendar names, identifiers, timezones, access roles and primary-calendar status Allow the user to select and work with calendars available to the connected account.
drive Drive file and folder names, metadata, content, permissions and change information Search, read, export, import, upload, create, rename, move, update, trash and share files or folders at the user's request.

7.2 How Pulse accesses Google data

Pulse accesses Google data through documented Google APIs using encrypted OAuth credentials. Access tokens may be refreshed while the connection remains active.

Where enabled, Pulse may register expiring push-notification channels for Gmail, Calendar or Drive. Pulse stores channel and resource identifiers, verification data, expiration timestamps and synchronisation cursors needed to retrieve authorised changes.

7.3 How Pulse uses Google data

Relevant Google data may be:

  • displayed in the Pulse timeline or integration results;
  • provided as context to a configured AI model to answer a request or carry out a workflow;
  • summarised, transformed or linked to a task, timeline item, memory or generated artefact;
  • imported into Pulse Files when requested;
  • used to prepare or perform an email, calendar or file action requested or authorised by the user; or
  • processed for security, troubleshooting, abuse prevention or legal compliance.

Pulse will not use a new category of Google user data, or use existing Google user data for a materially different purpose, without updating its disclosures and obtaining additional consent where required.

7.4 Storage and retention of Google data

While a Google Account is connected, Pulse stores the connected account identifier, profile metadata, granted scopes, encrypted OAuth tokens, token expiration, connection status and webhook synchronisation metadata.

Google content retrieved for a request may be processed transiently. It may persist in Pulse when an authorised user or workflow imports a file or attachment, includes content in a message or task result, creates a summary or memory, or otherwise saves an output in the workspace.

Disconnecting Google removes locally stored integration credentials and associated webhook records from the active database. It does not automatically delete content already imported or saved in Pulse, audit records or actions already completed in Google.

7.5 Sharing and transfer of Google data

We do not sell Google user data. We do not use or transfer Google user data for advertising, retargeting, personalised advertising, creditworthiness, lending or data-broker purposes.

Google user data may be transferred only:

  • to infrastructure, storage and AI providers acting on our or the customer's behalf where needed for the requested feature;
  • to your organisation and users you direct us to share with;
  • for security and technical incident investigation;
  • to comply with applicable law or valid legal process; or
  • in a corporate transaction, subject to any consent required by Google policy or applicable law.

7.6 Human access to Google data

cognipeer personnel and contractors may access Google user data only:

  • with your affirmative permission for specific support;
  • where necessary to investigate abuse, a bug or a security incident;
  • where required by applicable law; or
  • where data is aggregated and used for lawful internal operations consistent with applicable privacy law.

7.7 Security, disconnection and revocation

Stored Google access and refresh tokens are protected using authenticated application-level encryption. Access is restricted by user, workspace and organisation context.

You can disconnect Google through Pulse Settings > Integrations. You can also revoke cognipeer's authorisation through your Google Account permissions .

To request deletion of Google-derived content saved in Pulse, use available deletion controls, ask your workspace administrator or contact hello@cognipeer.com.

cognipeer Pulse’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements.

8. How We Disclose Information

We may disclose personal information to:

  • Your organisation and authorised users: according to roles, sharing settings and instructions.
  • Service providers: hosting, database, storage, queue, email, push-notification, support, security, transcription and observability providers.
  • AI and integration providers: providers selected or enabled by you or your organisation.
  • Professional advisers: legal, audit, insurance and other advisers under confidentiality obligations.
  • Authorities and protected parties: where reasonably necessary to comply with law, enforce agreements or protect rights, safety and security.
  • Corporate-transaction recipients: in connection with a proposed or completed financing, merger, acquisition, restructuring or sale of assets.

We do not sell personal information or share it for cross-context behavioural advertising.

9. International Transfers

cognipeer, its customers, connected providers and service providers may process information in countries other than the country where you live.

Where required, transfers are supported by recognised safeguards, including adequacy decisions, contractual protections, Standard Contractual Clauses, the UK International Data Transfer Addendum, mechanisms recognised under Turkish law or another lawful method.

10. Retention and Deletion

We retain personal information only for as long as reasonably necessary to provide Pulse, follow customer instructions, maintain security and audit records, resolve disputes, enforce agreements and comply with law.

Retention depends on:

  • the type, sensitivity and volume of information;
  • whether it is active workspace content, integration data, a backup, audit record or security log;
  • workspace and customer configuration;
  • the duration and status of the customer relationship;
  • unresolved requests, incidents, disputes or legal holds; and
  • applicable contractual, legal, accounting and regulatory obligations.

Pulse does not apply one universal automatic expiration period to all messages, memories, tasks, files, integration content, meeting records or traces. Deletion from backups and distributed systems may occur on a delayed cycle.

11. Security

We use administrative, technical and organisational measures designed to protect personal information. Depending on deployment and feature, measures may include tenant and workspace scoping, role-based access, encrypted integration credentials, hashed passwords and tokens, transport security, validation, approval controls, audit logging and incident-management practices.

Users and customers are responsible for protecting credentials, configuring permissions, reviewing automated actions and promptly reporting suspected unauthorised access.

No transmission or storage system can guarantee absolute security.

12. Choices and Controls

Depending on your role and configuration, you may be able to:

  • update profile and context information;
  • manage or delete memory facts;
  • delete messages, files, tasks or other resources where controls are provided;
  • connect or disconnect integrations and revoke access at the provider;
  • approve or reject protected actions;
  • revoke personal access tokens, devices and push-notification registrations;
  • change meeting, voice, notification, sharing and security settings; and
  • ask an organisation administrator to access, export, correct, restrict or delete organisation-controlled content.

13. Privacy Rights

The General Privacy Policy explains privacy rights that may be available under applicable law.

To exercise a right concerning Pulse, email hello@cognipeer.com and identify the relevant account, workspace or organisation.

We may verify your identity and authority, coordinate with the relevant customer organisation or retain information where an applicable exception applies.

14. Cookies and Similar Technologies

Pulse may use cookies, local storage and similar technologies for authentication, security, preferences and Service operation.

Where non-essential analytics or similar technologies are used and consent is required, appropriate choices will be provided.

15. Children's Privacy

Pulse is a business service and is not directed to children under 18. We do not knowingly collect personal information from children in violation of applicable law.

Customers must not use Pulse to process children's information without an appropriate lawful basis, notices, consents, contractual protections and safeguards.

16. Changes to This Policy

We may update this Pulse Policy to reflect changes in Pulse, applicable law or our privacy practices.

We will update the “Last updated” date and provide additional notice where required.

17. Contact

For Pulse privacy questions, requests or complaints, contact:

BİLSATEK YAZILIM VE TEKNOLOJİ ANONİM ŞİRKETİ
Operating under the cognipeer brand

Çifte Havuzlar Mah. Eski Londra Asfaltı Cad.
Kuluçka Mrk. A1 Blok No: 151/1C
İç Kapı No: B35, Esenler/İstanbul, Türkiye

Email: hello@cognipeer.com