Console Privacy Policy
This cognipeer Console Privacy Policy (the “Console Policy”) explains how personal information is collected, used, disclosed, stored and protected when you use cognipeer Console, including its dashboard, APIs, AI gateway, provider management, model inference, tracing, files, vector services, guardrails and related services (collectively, “Console”).
Console is provided by BİLSATEK YAZILIM VE TEKNOLOJİ ANONİM ŞİRKETİ, operating under the cognipeer brand (“cognipeer”, “we”, “us” or “our”), registered at Çifte Havuzlar Mah. Eski Londra Asfaltı Cad., Kuluçka Mrk. A1 Blok No: 151/1C, İç Kapı No: B35, Esenler/İstanbul, Türkiye.
Console is a multi-tenant operational, governance and observability platform for organisational AI workloads.
1. Relationship with the General Privacy Policy
This Console Policy supplements the cognipeer General Privacy Policy, which explains the privacy principles and practices shared across the cognipeer suite.
This Console Policy provides additional detail about processing specific to tenant administration, AI gateways, providers, API tokens, inference, tracing, guardrails, files, vectors, audit and governance.
If a signed customer agreement or Data Processing Agreement applies, it may contain additional or different commitments.
2. Scope
This Console Policy applies to personal information processed by cognipeer in connection with Console.
It does not govern:
- third-party AI, infrastructure, storage, vector, search or data providers configured by a customer;
- customer applications that send information to Console, except for cognipeer's processing described here;
- customer-operated on-premises deployments to the extent that the customer determines and controls the processing; or
- independent websites or services operated by another organisation.
3. Our Role and Your Organisation's Role
Customer Content
The customer generally determines why and how prompts, model outputs, files, vectors, traces, guardrail inputs, configurations and other tenant content are processed. cognipeer generally processes that content on the customer's instructions as a processor or service provider.
Business and account information
cognipeer acts as a controller for information used to create tenants and accounts, operate and secure Console, communicate with users, manage licences, provide support and meet legal obligations.
Tenant administrators
Owners and administrators may manage users, roles, projects, API tokens, providers, models, files, vectors, prompts, guardrails, tracing and other tenant resources. They may access, export, restrict or delete information within their authority.
Customer applications
Customers are responsible for privacy notices, permissions, lawful grounds and data-subject handling for information their applications submit through Console APIs.
If your information was submitted by a Console customer, direct your request to that customer first.
4. Multi-Tenant Data Organisation
In cognipeer-hosted Console, tenant metadata is maintained separately from tenant-scoped operational data. Each tenant has a tenant-specific database for users, API tokens, projects, providers, model usage, traces, files, guardrails and related records.
Requests are associated with tenant, user, project and token context where applicable. Logical tenant isolation is designed to prevent one tenant from accessing another tenant's information.
On-premises customers may operate a different supported database or storage configuration under their own infrastructure controls.
5. Information We Process
5.1 Tenant, account and profile information
We may process:
- company or tenant name, slug, database identifier, owner, licence type, licence status, licence dates and enabled features;
- user name, email address, role, tenant membership, project access, account status, invitation information and authentication provider;
- password hashes, password-change information, directory identifiers and session-token claims; and
- communications and support information.
Enterprise authentication may use customer-configured LDAP, OIDC or SAML identity information.
5.2 Sessions and API tokens
Console may process:
- signed session-token claims used to enforce tenant, role, licence and feature access;
- API-token label, hash, prefix, owner, tenant, optional project, creation date, last-used date and expiration date; and
- authentication success, failure, denial, revocation and security events.
Plaintext API tokens are intended to be shown only when created. Console stores a cryptographic hash for later verification.
5.3 Projects, providers and credentials
We process project identifiers and provider configuration used for models, embeddings, vectors, files, data sources, speech, OCR, search and related services.
Provider records may include:
- provider type, driver, label, status, settings, metadata and creator;
- API keys, secrets, endpoints, cloud credentials or other authentication material; and
- error and lifecycle information.
Provider credentials managed by Console are stored in encrypted form and decrypted in memory when required for an authorised operation.
5.4 Model inference and embedding information
When customers use Console model APIs or dashboard features, we may process:
- prompts, system instructions, chat messages, embedding input, tool definitions and model parameters;
- completion text, tool calls, embeddings, response metadata and provider errors;
- model, provider, route, request identifier, status and latency;
- input, output, cached and total token counts; and
- user, API token, tenant, project, source and actor attribution.
Console usage records may contain the full model request and full provider response, including personal or sensitive information in prompts or outputs. Customers should minimise submitted information and configure access and retention appropriately.
5.5 Agent tracing and observability information
Console accepts batch, streaming and OpenTelemetry-compatible tracing data. Tracing may include:
- session, trace, span, thread, event and tool-execution identifiers;
- agent name, version, model, configuration, metadata, status, summary and tools used;
- event labels, actors, nested sections, request and response sizes, timings and token usage;
- tool inputs and outputs, prompts, responses and customer-defined metadata;
- error details, stack information and diagnostics; and
- source, user, API token, project and tenant attribution.
Trace data may contain full prompts, model responses, tool inputs, outputs and unstructured metadata. Customers should sanitise instrumentation and avoid submitting unnecessary credentials, secrets or sensitive personal information.
5.6 Guardrail and moderation information
Console may process content submitted to input or output guardrails for PII detection, word filtering, moderation, prompt-injection detection, custom policies or similar controls.
Guardrail records may include:
- evaluated input or output text;
- detected values, categories, severity, messages and findings;
- actions such as block, warn, flag or redact;
- guardrail identity, target, result, latency and attribution; and
- customer-created word lists, regular expressions and policy configuration.
Guardrails reduce certain risks but do not guarantee that all sensitive or prohibited content will be detected or removed.
5.7 Files and converted content
Console may process file content and metadata, including file name, MIME type, size, hash, object key, bucket, creator, provider, conversion status, metadata and derived text or Markdown.
File content may be stored in customer-configured Amazon S3, Azure Blob Storage, Google Cloud Storage, local storage or another supported provider.
5.8 Vectors and retrieval
Console may process:
- vector-provider and index configuration, dimensions, metrics, external identifiers and metadata;
- embeddings, document identifiers, metadata and vector-query input; and
- query results and operational status.
Actual vector data may be held by a customer-selected provider while Console stores provider and index metadata and coordinates authorised operations.
5.9 Prompts, evaluations and governance resources
Depending on enabled features, we may process prompt templates and versions, deployment configuration, test cases, expected and actual outputs, evaluation scores, red-team inputs and results, memory resources, policy configuration and related metadata.
5.10 Audit, usage and diagnostic information
We may process:
- actor type, user identifier, email address, API-token identifier, service, action, event, outcome and affected resource;
- request identifier, method, path, status code, IP address, user agent, timestamps and audit metadata;
- daily requests, errors, token counts, estimated costs, latency, service, source and usage units;
- cache, health, resilience, circuit-breaker and runtime diagnostics; and
- application and server logs needed for security, support and reliability.
5.11 Email and information received from others
We may process email addresses and message content needed for invitations, welcome messages, password resets, alerts and service communications. We may also receive information from tenant owners, administrators, identity providers, customer applications, API clients, tracing SDKs, connected providers and service providers.
6. How We Use Information
We use personal information to:
- provide, maintain, personalise and improve Console;
- create and administer tenants, projects, accounts, roles, licences, permissions and API tokens;
- route model, embedding, file, vector, search, speech, OCR and other authorised operations to configured providers;
- store and display model usage, traces, evaluations, guardrail results, files, prompts and governance information;
- authenticate requests, enforce tenant and project boundaries and protect credentials;
- calculate usage, estimated costs, latency, performance and licence consumption;
- provide observability, debugging, audit, security, alerting and support capabilities;
- prevent fraud, abuse, unauthorised access and security incidents;
- communicate account, service, security and transactional information;
- comply with law, respond to valid legal requests and enforce agreements; and
- create aggregated or de-identified information.
Console does not provide a product feature that uses Customer Content to train a general-purpose cognipeer model. Customer-selected AI providers may process prompts and outputs under the customer's configuration and the provider's terms.
7. AI Processing and Customer Responsibility
Console sends customer-selected requests to configured AI providers and returns provider output. Requests may include prompts, messages, files, retrieved context, tool definitions and guardrail instructions.
Customers determine which providers to use, what information to submit, which logs and traces to retain, what guardrails to apply and who may access the results.
Customers must establish appropriate notices, lawful grounds, data minimisation, human oversight and appeal processes for high-impact or legally significant uses.
Console is not intended to be the sole basis for decisions producing legal or similarly significant effects on individuals.
8. How We Disclose Information
We may disclose personal information to:
- Your tenant and authorised users: according to roles, projects, permissions, token scope and customer instructions.
- Customer-selected providers: AI, embedding, vector, file, search, speech, OCR, data-source and other configured providers.
- Service providers: hosting, database, cache, storage, email, security, monitoring, support and similar providers.
- Customer applications and API clients: as required to return requested API responses, traces and usage information.
- Professional advisers: legal, audit, insurance and other advisers under confidentiality obligations.
- Authorities and protected parties: where reasonably necessary to comply with law, enforce agreements or protect rights, safety and security.
- Corporate-transaction recipients: in connection with a proposed or completed financing, merger, acquisition, restructuring or sale of assets.
We do not sell personal information or share it for cross-context behavioural advertising.
9. International Transfers
cognipeer, customers, customer-selected providers and service providers may process information in countries other than the country where you live.
Where required, transfers are supported by recognised safeguards, including adequacy decisions, contractual protections, Standard Contractual Clauses, the UK International Data Transfer Addendum, mechanisms recognised under Turkish law or another lawful method.
Customer-selected providers and on-premises deployments may determine additional processing locations and safeguards.
10. Retention and Deletion
We retain personal information only for as long as reasonably necessary to provide Console, follow customer instructions, maintain security and audit records, resolve disputes, enforce agreements and comply with law.
Retention depends on:
- the type, sensitivity and volume of information;
- tenant and project configuration;
- whether information is active content, usage data, a trace, audit record, backup, security log or billing record;
- the duration and status of the account and customer relationship;
- unresolved support, security, legal or contractual matters; and
- applicable legal, accounting, tax and regulatory requirements.
Model usage logs, traces, guardrail records, prompts, files and audit records do not necessarily have one universal automatic expiration period. Customers should establish appropriate retention and deletion practices for their use case.
When retention is no longer required, we delete or de-identify information. Backup deletion may occur on a delayed cycle.
11. Security
We use administrative, technical and organisational measures designed to protect personal information.
Depending on deployment and configuration, measures may include:
- tenant-specific data stores and logical tenant isolation;
- role, feature and project controls;
- hashed API tokens and passwords;
- HTTP-only session cookies;
- encrypted provider credentials;
- transport security and request validation;
- security headers and audit logging; and
- health monitoring and resilience controls.
Customers are responsible for protecting API tokens and credentials, limiting permissions, sanitising telemetry, selecting appropriate providers, configuring retention and revoking compromised access.
No transmission or storage system can guarantee absolute security.
12. Choices and Controls
Depending on your role, licence and tenant configuration, you may be able to:
- update profile and authentication information;
- create, expire or revoke API tokens;
- manage tenant users, invitations, roles, permissions and projects;
- create, disable, update or delete providers and credentials;
- manage models, prompts, files, vector indexes, guardrails, traces, evaluations and related resources;
- delete remote vector indexes or stored files through supported operations;
- control what customer applications submit and which providers receive it; and
- ask a tenant administrator to access, export, correct, restrict or delete tenant-controlled information.
Some records may require administrator or cognipeer assistance to export or delete.
13. Privacy Rights
The General Privacy Policy explains privacy rights that may be available under applicable law.
To exercise a right concerning Console, email hello@cognipeer.com and identify the relevant Console tenant.
We may verify your identity and authority, coordinate with the customer tenant or retain information where an applicable exception applies.
15. Children's Privacy
Console is a business service and is not directed to children under 18. We do not knowingly collect personal information from children in violation of applicable law.
Customers must not use Console to process children's information without an appropriate lawful basis, notices, consents, contractual protections and safeguards.
16. Changes to This Policy
We may update this Console Policy to reflect changes in Console, applicable law or our privacy practices.
We will update the “Last updated” date and provide additional notice where required.
17. Contact
For Console privacy questions, requests or complaints, contact:
BİLSATEK YAZILIM VE TEKNOLOJİ ANONİM ŞİRKETİ
Operating under the cognipeer brand
Çifte Havuzlar Mah. Eski Londra Asfaltı Cad.
Kuluçka Mrk. A1 Blok No: 151/1C
İç Kapı No: B35, Esenler/İstanbul, Türkiye
Email: hello@cognipeer.com
