General Privacy Policy
This General Privacy Policy (the “Policy”) explains how personal information is collected, used, disclosed, stored and protected in connection with the cognipeer suite, including its websites, products, applications, APIs and related services.
The Services are provided by BİLSATEK YAZILIM VE TEKNOLOJİ ANONİM ŞİRKETİ, operating under the cognipeer brand (“cognipeer”, “we”, “us” or “our”), registered at Çifte Havuzlar Mah. Eski Londra Asfaltı Cad., Kuluçka Mrk. A1 Blok No: 151/1C, İç Kapı No: B35, Esenler/İstanbul, Türkiye.
This Policy provides the privacy framework shared across the suite. The product-specific policies linked above explain additional processing activities, integrations and controls relevant to each product.
1. Scope and Suite Structure
This Policy applies to personal information processed in connection with:
- cognipeer Studio, the suite's AI agent, application and workflow development product;
- cognipeer Pulse, the suite's persistent AI workspace and connected assistant product;
- cognipeer Console, the suite's AI operations, governance and observability product;
- cognipeer websites, support channels, business communications and account administration; and
- other cognipeer products or services that expressly refer to this Policy.
The exact information processed depends on the product, feature, deployment, workspace settings and integrations you or your organisation choose to use.
This Policy does not replace the privacy notices of third-party services, customer-operated portals or customer organisations. Those parties may process information under their own terms and privacy notices.
For customer-operated on-premises deployments, the customer may control the deployment and determine additional processing practices. The customer's own privacy notice and agreement with cognipeer may therefore also apply.
2. Our Role and Your Organisation's Role
cognipeer is primarily offered to businesses and other organisations, although certain Services may also be used by individuals.
Customer-controlled content
When a customer organisation uses cognipeer to process prompts, conversations, files, connected-service information, traces, knowledge sources or other workspace content, that organisation generally determines why and how the information is processed. In that context, cognipeer generally acts as a processor or service provider on the customer's instructions.
Business, account and service data
cognipeer acts as a controller for information used to operate the Services, administer accounts and customer relationships, maintain security, communicate with users, provide support, manage subscriptions and comply with legal obligations.
Administrators
Organisation, tenant and workspace administrators may manage users, roles, permissions, products, integrations, providers, devices and organisation-controlled content. They may be able to access, export, restrict or delete information within their administrative scope.
If you use cognipeer through an organisation, requests concerning organisation-controlled content should generally be directed to that organisation first. We will assist the organisation where required by applicable law and contract.
3. Information We Process
Depending on the products and features used, we may process the following categories of information.
Account and organisation information
Names, email addresses, profile details, account identifiers, authentication information, workspace or tenant membership, roles, permissions, invitations, plan information and account settings.
Customer Content
Prompts, messages, instructions, files, documents, conversations, knowledge sources, agent and workflow configurations, model inputs and outputs, tasks, memory, meeting information, traces and other information submitted to or generated through the Services.
Connected-service information
Account identifiers, profile metadata, permissions, encrypted credentials, webhook or synchronisation information, and content retrieved from or sent to services that you or your organisation choose to connect.
Provider and configuration information
Model providers, storage systems, data sources, vector providers, endpoints, settings, project information and encrypted credentials required to operate customer-selected connections.
Usage, security and diagnostic information
IP addresses, user agents, request and session identifiers, timestamps, feature activity, model and token usage, latency, errors, logs, traces, approval records, audit events and security information.
Billing and business information
Subscription, plan, licence, usage, invoice, order and payment-provider identifiers, together with business communications and support requests. Payment-card information may be processed directly by an authorised payment provider rather than stored by cognipeer.
4. How Information Is Collected
We may collect information:
- directly from you when you create an account, communicate with us, submit content or configure the Services;
- from your employer, customer organisation, workspace administrator or another authorised user;
- from authentication providers and connected third-party services that you authorise;
- automatically through the operation, security and diagnostic functions of the Services; and
- from service providers supporting hosting, security, communications, billing and customer support.
Product-specific policies explain additional sources relevant to each suite product.
5. How We Use Information
We use personal information to:
- provide, maintain and operate the cognipeer suite;
- create and administer accounts, organisations, workspaces, tenants, roles and permissions;
- perform user instructions and configured AI, tool, integration and workflow operations;
- process conversations, files, memory, knowledge sources, retrieval, traces and generated content;
- route authorised requests to customer-selected model, storage, vector, search, OCR and integration providers;
- authenticate users, protect credentials, enforce access controls and prevent fraud or abuse;
- provide support and send transactional, security, account and service communications;
- measure usage, calculate applicable charges, enforce plan limits and understand service performance;
- diagnose errors, maintain reliability, audit activity and investigate security incidents;
- comply with law, respond to valid legal requests and enforce agreements; and
- create aggregated or de-identified information that does not reasonably identify an individual.
cognipeer does not provide a product feature that uses Customer Content to train a general-purpose cognipeer AI model. Customer-selected AI providers may process information sent to their services under the customer's configuration and the provider's applicable terms.
6. Legal Grounds for Processing
The legal ground depends on the information, purpose, relationship and jurisdiction involved.
Türkiye
Where the Turkish Personal Data Protection Law No. 6698 applies, personal data may be processed on one or more applicable grounds, including explicit consent where required, performance or establishment of a contract, compliance with a legal obligation, establishment, exercise or protection of a right, and cognipeer's legitimate interests where those interests do not harm the fundamental rights and freedoms of the data subject.
European Economic Area and United Kingdom
Where the GDPR or UK GDPR applies, we rely on one or more of:
- Contract: where processing is necessary to provide the Service requested by you or your organisation.
- Legitimate interests: to operate, secure, support and improve the Services, administer business relationships and prevent misuse, balanced against individual rights.
- Consent: for optional processing or connected features where consent is required.
- Legal obligation: to comply with applicable legal, accounting, tax, regulatory and lawful-request requirements.
- Vital interests or public interest: where applicable and permitted by law.
Where cognipeer acts as a processor, the customer organisation determines the relevant legal ground for Customer Content.
7. AI Processing and Automated Actions
cognipeer products may send prompts, instructions, files, retrieved information, conversation context, tool results or other authorised content to configured AI providers to generate responses, summaries, classifications, plans, embeddings, evaluations or tool decisions.
Depending on the product and configuration, an AI-assisted workflow may prepare or perform actions in connected services. Those actions may require approval, operate automatically under an organisation's authorised policy, or be disabled.
cognipeer is not intended to serve as the sole basis for decisions that produce legal or similarly significant effects on individuals. Users and customer organisations are responsible for establishing appropriate transparency, testing, lawful grounds, human oversight and review processes for consequential uses.
8. How We Disclose Information
We may disclose personal information to:
- Your organisation and authorised users: according to roles, permissions, sharing settings and customer instructions.
- Customer-selected providers: AI, embedding, storage, vector, search, OCR, data-source, tool and integration providers configured by you or your organisation.
- Service providers: hosting, database, storage, analytics, communications, billing, security, observability and support providers acting for us.
- Professional advisers: legal, audit, insurance and other advisers subject to appropriate duties of confidentiality.
- Authorities and protected parties: where reasonably necessary to comply with law or valid legal process, enforce agreements or protect rights, safety and security.
- Corporate-transaction recipients: in connection with a proposed or completed financing, merger, acquisition, restructuring or sale of assets, subject to appropriate safeguards.
A product-specific policy may provide further detail about recipients relevant to a particular integration or feature.
9. Sale and Advertising
We do not sell personal information or Customer Content to data brokers. We do not use Customer Content or information received through connected services for targeted advertising, retargeting, creditworthiness or lending decisions.
Product-specific policies may include additional restrictions required by the connected provider, including the Google API Services User Data Policy for relevant Pulse features.
10. International Transfers
cognipeer, its customers and relevant service providers may process information in countries other than the country where the information was collected. Those countries may have different data-protection laws.
Where required, international transfers are supported by recognised legal mechanisms and safeguards. Depending on the applicable law, these may include adequacy decisions, contractual safeguards, standard contractual clauses, the UK International Data Transfer Addendum, transfer mechanisms recognised under Turkish data-protection law or another lawful method.
Customer-selected providers and customer-operated deployments may determine additional processing locations and transfer arrangements.
11. Retention and Deletion
We retain personal information only for as long as reasonably necessary to provide the Services, follow customer instructions, maintain security and audit records, resolve disputes, enforce agreements and comply with applicable law.
Retention depends on factors including:
- the type, sensitivity and volume of the information;
- the product, deployment and customer configuration;
- whether the information is active content, a deleted record, a backup, an audit record, a security log or billing information;
- the status and duration of the account or customer relationship;
- unresolved support, security, contractual or legal matters; and
- applicable legal, accounting, tax and regulatory obligations.
The suite does not necessarily apply one universal automatic expiration period to all conversations, files, memory, traces, task results, knowledge sources or other Customer Content. Product-specific policies explain relevant controls and retention behaviour in greater detail.
When retention is no longer required, we delete, destroy or de-identify information as appropriate. Removal from backups and distributed systems may occur on a delayed cycle, and certain information may be retained where required for security, legal or audit purposes.
12. Security
We use administrative, technical and organisational measures designed to protect personal information against unauthorised access, use, alteration, disclosure or loss.
Depending on the product, deployment and configuration, these measures may include tenant or workspace scoping, role-based permissions, hashed passwords and tokens, encrypted application credentials, transport security, validation, logging, monitoring and incident-management practices.
Customers and users are responsible for protecting their credentials, selecting appropriate providers, limiting permissions, configuring sharing and integrations carefully, reviewing automated actions and promptly reporting suspected unauthorised access.
No method of transmission or storage can guarantee absolute security.
13. Choices and Controls
Depending on your product, role and workspace configuration, you may be able to:
- update account or profile information;
- manage workspace membership, roles and permissions;
- manage, export or delete selected conversations, files, tasks, memory, agents, tools, traces or other resources;
- connect or disconnect third-party services and revoke authorisation through the provider;
- manage provider credentials, tokens, devices and sharing settings;
- approve or reject protected actions; and
- ask a workspace or tenant administrator to access, correct, export, restrict or delete organisation-controlled information.
Some requests may require assistance from an administrator or cognipeer. Contact us where the required control is not available.
14. Privacy Rights
Subject to applicable law, you may have rights to learn whether and how your personal information is processed, access information, correct inaccurate information, request deletion, restrict or object to processing, receive portable information, withdraw consent and complain to a competent data-protection authority.
Rights in Türkiye
Where Law No. 6698 applies, you may have the right to learn whether your personal data is processed, request information about processing, learn the purpose of processing and whether information is used consistently with that purpose, know recipients in Türkiye or abroad, request correction, request erasure or destruction where the applicable conditions are met, request notification of certain corrections or deletion to recipients, object to results produced exclusively through automated analysis and request compensation for damage caused by unlawful processing.
Rights in the EEA and United Kingdom
Where the GDPR or UK GDPR applies, you may have rights of access, rectification, erasure, restriction, objection, data portability, withdrawal of consent and rights relating to certain automated decision-making. You may also lodge a complaint with your local supervisory authority.
Submitting a request
To exercise a privacy right, email hello@cognipeer.com and identify the relevant cognipeer product, workspace, tenant or account.
We may verify your identity and authority, coordinate with the relevant customer organisation, ask for additional information needed to process the request or retain information where an applicable exception applies.
Where cognipeer acts as a processor for an organisation, the organisation may need to respond to the request directly. We will provide reasonable assistance as required by applicable law and contract.
16. Children's Privacy
The cognipeer suite is designed primarily for businesses, organisations and users aged 18 or over. It is not directed to children.
We do not knowingly collect personal information from children in violation of applicable law. Customers must not deploy or configure a cognipeer product for children without completing the legal, contractual, notice, consent and safeguarding requirements applicable to that use.
Contact us if you believe a child's personal information has been submitted unlawfully.
17. Changes to This Policy
We may update this Policy to reflect changes in the cognipeer suite, applicable law or our privacy practices.
When changes are made, we will update the “Last updated” date and provide additional notice where required.
If a change materially affects how previously collected information is used, we will provide notice and obtain additional consent where required by applicable law.
18. Contact
For privacy questions, requests or complaints, contact:
BİLSATEK YAZILIM VE TEKNOLOJİ ANONİM ŞİRKETİ
Operating under the cognipeer brand
Çifte Havuzlar Mah. Eski Londra Asfaltı Cad.
Kuluçka Mrk. A1 Blok No: 151/1C
İç Kapı No: B35, Esenler/İstanbul, Türkiye
Email: hello@cognipeer.com
