Studio Privacy Policy
This cognipeer Studio Privacy Policy (the “Studio Policy”) explains how personal information is collected, used, disclosed, stored and protected when you use cognipeer Studio, including its websites, applications, APIs, agent-building tools, portals, web chat and related services (collectively, “Studio”).
Studio is provided by BİLSATEK YAZILIM VE TEKNOLOJİ ANONİM ŞİRKETİ, operating under the cognipeer brand (“cognipeer”, “we”, “us” or “our”), registered at Çifte Havuzlar Mah. Eski Londra Asfaltı Cad., Kuluçka Mrk. A1 Blok No: 151/1C, İç Kapı No: B35, Esenler/İstanbul, Türkiye.
Studio is a platform for designing, deploying and managing AI agents, applications, prompts, tools, knowledge sources, workflows, portals and conversational experiences.
1. Relationship with the General Privacy Policy
This Studio Policy supplements the cognipeer General Privacy Policy, which explains the privacy principles and practices shared across the cognipeer suite.
The General Privacy Policy covers shared matters including the legal entity responsible for the Services, controller and processor roles, common purposes, legal grounds, international transfers, security, individual rights and contact information.
This Studio Policy provides additional detail about information and processing specific to Studio. If a signed customer agreement or Data Processing Agreement applies, it may contain additional or different commitments.
2. Scope
This Studio Policy applies to personal information processed by cognipeer in connection with Studio.
It does not govern:
- third-party model providers, data sources, integrations, websites or products that you or your organisation configure or connect;
- Customer Content processed entirely within a customer-operated on-premises deployment where cognipeer does not determine or control the processing; or
- independent websites, applications or services that link to Studio but are operated by another organisation.
Third-party services are governed by their own terms and privacy policies. For customer-operated deployments, the operating customer is responsible for providing any additional privacy notice required for its configuration and use.
3. Our Role and Your Organisation's Role
Studio is primarily offered to businesses and other organisations.
Customer Content
The customer organisation generally determines why and how prompts, conversations, files, knowledge sources, agent configurations and other workspace content are processed. cognipeer generally processes that content on the customer's instructions as a processor or service provider.
Business and account information
cognipeer acts as a controller for information used to operate Studio, administer accounts, maintain security, communicate with users, provide support, manage subscriptions and meet legal obligations.
Workspace administrators
Workspace administrators may manage members, roles, permissions, agents, applications, tools, portals, data sources, model providers, credentials, usage and other workspace resources. They may be able to access, export, restrict or delete information within their administrative scope.
Portal and web-chat operators
A customer that publishes a Studio portal or web chat determines the purpose of collecting information from its users or contacts and is responsible for appropriate notices, permissions, legal grounds and lawful use.
If you use Studio through an organisation, direct requests about organisation-controlled content to that organisation first. We will assist the organisation with verified requests as required by law and contract.
4. Information We Process
4.1 Account and workspace information
We may process:
- name, surname, email address, profile details, account settings, roles, permissions and workspace membership;
- password hashes, authentication tokens, personal access token metadata, email-verification and password-reset information;
- organisation or workspace names, identifiers, settings, licences, plans, limits and subscription status;
- consent or acknowledgement records, including recorded acceptance dates; and
- information received through an authorised sign-in provider, including Google Sign-In.
4.2 Agents, applications, prompts and tools
We may process content used to build and operate Studio resources, including:
- agent or peer names, descriptions, system prompts, avatars, model choices, reasoning settings, tools, actions, data sources and visibility settings;
- application, workflow, prompt, template, output-format and version information;
- custom tool and MCP definitions, endpoints, authentication settings, inputs, outputs, status and execution errors;
- agent state, approval requests, pending actions, generated documents, diagrams, slides and other smart content; and
- sharing settings for users, groups, portals, galleries and public resources.
These configurations may contain confidential, personal or sensitive information. Customers are responsible for deciding what information is appropriate to include.
4.3 Conversations, messages, contacts and memory
We may process:
- conversation titles, dates, sources, states, metadata, sessions and bookmarks;
- user, assistant and system messages, prompts, responses, feedback, errors, attachments and usage information;
- user and contact identifiers associated with conversations;
- personal facts and preferences stored as agent memory, including automatically extracted or consolidated memory where enabled; and
- source references and retrieved knowledge used to generate a response.
Where user memory is enabled, Studio may analyse recent conversation content with a configured AI model to add, update, consolidate or delete memory facts. Users or administrators may manage memory through available controls.
4.4 Portal and web-chat information
When a person interacts with a customer-published portal or embedded web chat, Studio may process:
- a contact email address or another identifier requested by the portal operator;
- messages, files, feedback, session information, conversation metadata and generated responses;
- portal, hook, agent and source identifiers; and
- technical information required to maintain access to the conversation.
The customer operating the portal determines its purpose, audience, agent behaviour and connected providers. Contact that customer for questions about its use of your information.
4.5 Files and attachments
Studio may process uploaded and generated files, including file name, MIME type, size, storage key, uploader, creation date, inline content and links to conversations or other resources.
Files may be stored in customer-selected object storage, such as Amazon S3, Azure Blob Storage or local storage used for a customer-operated deployment.
4.6 Knowledge sources, vectors and embeddings
When customers build a knowledge base, Studio may process:
- documents, websites, API responses, database content, files and other configured source material;
- source URLs, titles, descriptions, document text, chunks, item identifiers and ingestion timestamps;
- OCR content and related language or model settings;
- numerical embeddings and metadata stored in a configured vector provider; and
- synchronisation status, timestamps and errors.
Source content may be sent to a customer-selected embedding, OCR or model provider. Storage and search systems may include customer-configured object storage, PostgreSQL with pgvector, Elasticsearch, Azure AI Search, MongoDB vector search or another supported provider.
4.7 Provider and integration credentials
Customers may configure model providers, tools, APIs, data sources, storage providers and vector databases. Studio may process provider names, endpoints, settings, API keys, access tokens, account identifiers and other credentials required to operate those connections.
Application-managed credentials are stored in encrypted form where supported and decrypted in memory when needed for an authorised request.
4.8 Usage, analytics and diagnostic information
We may process:
- model name, input and output token counts, total tokens, credits used, latency, status and timestamps;
- tool input, output, status and errors;
- HTTP request and diagnostic logs, IP address, user agent, request identifiers and security events;
- feature events such as messages sent, conversations created, feedback submitted, approval decisions and resources created or opened; and
- account or workspace identifiers associated with usage.
4.9 Billing and transaction information
For paid Services, we may process plan, subscription, credit balance, usage, order, payment-request, customer and subscription identifiers. Authorised payment providers process payment-card and payment-method information under their own privacy policies. cognipeer does not need to store full payment-card numbers where payment is handled directly by the payment provider.
4.10 Information received from others
We may receive information from your organisation, workspace administrators, users who invite or share with you, portal operators, connected data sources, authentication providers, payment providers and service providers supporting infrastructure, security, delivery and support.
5. How We Use Information
We use personal information to:
- provide, maintain, personalise and improve Studio;
- create and manage accounts, workspaces, roles, permissions, subscriptions and licences;
- build, run, test, publish and version agents, applications, prompts, tools, portals and workflows;
- process conversations, files, memory, knowledge sources, retrieval, embeddings and generated content;
- route customer-selected content to configured AI, storage, vector, OCR, search and integration providers;
- authenticate requests, secure credentials, enforce permissions and prevent fraud or abuse;
- provide support and send transactional, security, account and Service communications;
- measure usage, calculate credits and charges, understand product performance and enforce plan limits;
- diagnose errors, maintain reliability, audit activity and protect users and Studio;
- comply with law, respond to valid legal requests and enforce agreements; and
- create aggregated or de-identified information that does not reasonably identify an individual.
Studio does not provide a product feature that uses Customer Content to train a general-purpose cognipeer AI model. Customer-selected model providers may process prompts, content and outputs under the customer's configuration and the provider's applicable terms.
6. AI Processing and Automated Actions
Studio may send customer-selected prompts, instructions, conversation context, files, retrieved source content and tool results to configured AI providers to generate responses, memory operations, embeddings, classifications, plans or other Output.
Studio supports tools and approval workflows that may perform actions in connected systems. Customers determine agent instructions, provider configuration, tool permissions and required approvals.
Studio is not intended to be the sole basis for decisions that produce legal or similarly significant effects on individuals. Customers using Studio for employment, credit, healthcare, education, access or another high-impact context are responsible for establishing an appropriate legal ground, transparency, testing, human oversight and appeal process.
7. Google Sign-In Data
When you choose Google Sign-In, Studio receives the account information authorised through that sign-in flow, such as your Google account identifier, email address, name and basic profile information.
Studio uses this information to:
- authenticate you;
- create or link your Studio account;
- display your profile;
- maintain account security; and
- provide account support.
Studio does not use Google Sign-In data for advertising, creditworthiness, lending or data-broker purposes.
Google Sign-In data may be disclosed to infrastructure and security providers acting on our behalf, your organisation where it administers your account, or as required by law. cognipeer personnel may access it only as needed to operate and secure Studio, provide support or comply with law.
You may remove Studio's Google authorisation through your Google Account permissions . You may also contact hello@cognipeer.com to request deletion of account information, subject to verification, your organisation's instructions and applicable retention obligations.
cognipeer Studio’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements.
8. How We Disclose Information
We may disclose personal information to:
- Your organisation and authorised users: according to roles, sharing settings, portal configuration and customer instructions.
- Portal operators and participants: when you submit information through a customer-operated portal or choose to share content.
- AI, integration and data providers: providers selected by the customer for model inference, embeddings, OCR, search, tools, APIs, data sources, storage and vector processing.
- Service providers: hosting, database, object storage, analytics, email, payment, security, support and similar providers acting for us.
- Professional advisers: legal, audit, insurance and other advisers subject to appropriate confidentiality duties.
- Authorities and protected parties: where reasonably necessary to comply with law or valid legal process, enforce agreements or protect rights, safety and security.
- Corporate-transaction recipients: in connection with a proposed or completed financing, merger, acquisition, restructuring or sale of assets, subject to appropriate safeguards.
We do not sell personal information. We do not use or share personal information for cross-context behavioural advertising.
9. International Transfers
cognipeer, customer organisations, selected model providers, integrations and service providers may process information in countries other than the country where the information was collected.
Where required, international transfers are supported by recognised safeguards such as adequacy decisions, contractual protections, Standard Contractual Clauses, the UK International Data Transfer Addendum, mechanisms recognised under Turkish data-protection law or another lawful method.
Customer-selected providers and customer-operated deployments may determine additional processing locations and safeguards.
10. Retention and Deletion
We retain personal information only for as long as reasonably necessary to provide Studio, follow customer instructions, maintain security and audit records, resolve disputes, enforce agreements and comply with law.
Retention depends on:
- the type, sensitivity and volume of the information;
- customer configuration and resource version limits;
- whether information is active content, a deleted record, a backup, a billing record, an audit log or a security record;
- the duration and status of the account and customer relationship;
- unresolved support, security, legal or contractual matters; and
- applicable legal, accounting, tax and regulatory obligations.
Conversations, messages, memory, files, tool logs, traces and knowledge sources do not necessarily have one universal automatic expiration period. Customers should configure and use available deletion controls according to their requirements.
When retention is no longer required, we delete or de-identify information. Removal from backups and distributed systems may occur on a delayed cycle.
11. Security
We use administrative, technical and organisational measures designed to protect personal information.
Depending on deployment and configuration, these measures may include workspace-scoped databases, role-based permissions, hashed passwords, encrypted application credentials, transport security, request validation, access controls and logging.
Customers are responsible for selecting appropriate providers, protecting credentials, configuring sharing and public portals carefully, limiting access and reviewing agent actions.
No transmission or storage system can guarantee absolute security.
12. Choices and Controls
Depending on your role and configuration, you may be able to:
- update account and workspace information;
- manage conversations, messages, memory, agents, tools, files, sources and portals;
- delete or export selected conversations, applications, agents, tools or other resources;
- manage sharing, visibility, roles, provider credentials and personal access tokens;
- provide or change feedback and approval decisions;
- configure or disable optional analytics in customer-operated deployments; and
- ask a workspace administrator to access, export, correct, restrict or delete organisation-controlled information.
Studio provides resource-level export and deletion capabilities, but a complete account export or self-service account deletion may require assistance from the workspace administrator or cognipeer. Contact us where the required control is unavailable.
13. Public and Shared Content
Customers may publish agents, applications, portals or web chats and share resources with users, groups or the public.
Information submitted to a public or shared experience may be visible to the portal operator, authorised workspace users, intended recipients or the public, depending on configuration.
Do not include secrets or personal information in a public resource unless you are authorised to do so and intend the information to be public.
Removing a public link or permission does not guarantee deletion of copies previously exported, downloaded or independently retained by a recipient.
15. Privacy Rights
The General Privacy Policy explains privacy rights that may be available under applicable law, including rights relating to access, correction, deletion, restriction, objection, portability, consent and complaints.
To exercise a privacy right concerning Studio, email hello@cognipeer.com and identify the relevant Studio account, workspace or portal.
We may verify your identity and authority, coordinate with the customer organisation or retain information where an applicable exception applies.
Where cognipeer acts as a processor, the customer organisation may need to respond to the request directly. We will provide reasonable assistance as required by law and contract.
16. Children's Privacy
Studio is a business service and is not directed to children under 18. We do not knowingly collect personal information from children in violation of applicable law.
Customers must not deploy a Studio portal, agent or web chat to children without completing the notices, consents, age controls, contractual requirements and safeguards required by applicable law.
Contact the relevant portal operator and hello@cognipeer.com if you believe a child's personal information has been submitted unlawfully.
17. Changes to This Policy
We may update this Studio Policy to reflect changes in Studio, applicable law or our privacy practices.
When changes are made, we will update the “Last updated” date and provide additional notice where required.
If a change materially affects how previously collected information is used, we will provide notice and obtain additional consent where required by applicable law.
18. Contact
For Studio privacy questions, requests or complaints, contact:
BİLSATEK YAZILIM VE TEKNOLOJİ ANONİM ŞİRKETİ
Operating under the cognipeer brand
Çifte Havuzlar Mah. Eski Londra Asfaltı Cad.
Kuluçka Mrk. A1 Blok No: 151/1C
İç Kapı No: B35, Esenler/İstanbul, Türkiye
Email: hello@cognipeer.com
