DRAFT TEMPLATE FOR COGNOSIC TO COMPLETE. This is a starting point, not legal advice. Everything in [square brackets] needs to be filled in, confirmed or deleted. Please have it reviewed by your legal adviser before publishing. The "Note for Cognosic" boxes are guidance, so delete them before publishing.
Privacy policy
Last updated: [DD Month YYYY]
This privacy policy explains how Cognosic AS ("Cognosic", "we", "us" or "our") collects and uses personal data when you visit cognosic.com (the "Website"), request a demo, or otherwise contact us. Section 11 explains how we use cookies.
Note for Cognosic: this policy covers the Website and your sales and marketing contacts. Personal data processed inside the Cosmos platform on behalf of institutions (staff, course and curriculum data) is normally covered by your customer agreement and data processing agreement, not this policy. See section 10.
1. Who is responsible for your data
Cognosic AS is the data controller for the personal data described in this policy.
- Company: Cognosic AS
- Organisation number: [000 000 000]
- Address: [Street address, postcode, Bergen, Norway]
- Email: [privacy@cognosic.com / hello@cognosic.com]
[If you have appointed a Data Protection Officer (DPO), add their name and contact details here. Otherwise, delete this line.]
2. What personal data we collect
2.1 Data you give us
When you fill in our Request a demo form, we collect:
- your full name
- your email address
- your institution
- your role (for example programme director or quality assurance)
- any message you choose to include
- your confirmation that you agree to be contacted
When you email us or contact us another way, we collect the information you include in your message, such as your name, contact details and what you have written.
[Add other ways you collect data, for example newsletter sign-ups, event registrations, webinars or recruitment. Delete any that do not apply.]
2.2 Data collected automatically
When you visit the Website, we collect limited technical and usage data:
- Google Analytics (only with your consent). If you accept analytics cookies, we use Google Analytics, provided by Google Ireland Limited, to understand how visitors use the Website. It uses cookies to collect information such as the pages you visit, how long you stay, how you arrived at the Website, your browser and device type, and your approximate location. Google Analytics does not store your full IP address. If you do not accept analytics cookies, Google Analytics sets no cookies and receives only limited signals that do not identify you, through Google Consent Mode.
- Privacy-friendly analytics. We also use [Umami], an analytics tool that does not use cookies and does not identify individual visitors. It collects aggregated information such as pages viewed, referring website, approximate country, browser and device type.
- Technical logs. Our hosting providers process technical data such as IP address, browser type and the time of your request. This is needed to deliver the Website securely and to prevent abuse.
For more on cookies, see section 11, Cookies.
3. How we use your data and our legal basis
We process personal data only where the EU General Data Protection Regulation (GDPR), as incorporated into Norwegian law by the Personal Data Act (personopplysningsloven), gives us a legal basis.
- Responding to your demo request and scheduling a meeting. Data: Form details. Legal basis: Steps taken at your request before entering into a contract (Art. 6(1)(b)) and/or your consent (Art. 6(1)(a)).
- Answering questions you send us. Data: Message content, contact details. Legal basis: Our legitimate interest in responding to enquiries (Art. 6(1)(f)).
- Following up on a possible collaboration with your institution. Data: Name, contact details, institution, role, correspondence. Legal basis: Our legitimate interest in developing business relationships (Art. 6(1)(f)).
- [Sending newsletters or product updates]. Data: [Email address]. Legal basis: [Your consent (Art. 6(1)(a)), which you can withdraw at any time].
- Understanding how the Website is used, with Google Analytics. Data: Analytics cookies and usage data. Legal basis: Your consent (Art. 6(1)(a)), which you can withdraw at any time by clicking Manage cookies in the footer.
- Understanding how the Website is used, with cookieless analytics. Data: Aggregated analytics data. Legal basis: Our legitimate interest in improving the Website (Art. 6(1)(f)).
- Keeping the Website secure and working. Data: Technical logs. Legal basis: Our legitimate interest in running a secure website (Art. 6(1)(f)).
- Meeting legal obligations, for example bookkeeping. Data: [Invoicing and contract data]. Legal basis: Legal obligation (Art. 6(1)(c)).
Note for Cognosic: check the demo-request row against how you actually use the form. The form's checkbox says visitors agree that Cognosic may contact them and store their details as described in this policy.
We do not sell your personal data, and we do not use it for automated decision-making or profiling that has legal or similarly significant effects on you.
4. Who we share your data with
We share personal data only with service providers who help us run our business. They act as data processors under an agreement with us and may use the data only on our instructions. We list them below by category. To get the names of the specific providers, email us at [privacy@cognosic.com].
- Website platform, hosting and database providers. What they do: Run the Website, deliver it to your browser and store form submissions. Location: EEA and USA.
- Google Ireland Limited (Google Analytics). What they do: Website analytics, only with your consent. Location: Ireland, with possible transfers to the USA.
- [Umami Software, Inc.]. What they do: Privacy-friendly website analytics. Location: [EU / USA].
- Email and document providers. What they do: Email and documents. Location: [EEA / USA].
- CRM provider. What they do: Managing contacts and sales conversations. Location: [EEA / USA].
Note for Cognosic: under GDPR you can list most recipients by category, as above, but you must be able to name them to anyone who asks. Keep an internal list of the actual providers. Optise can give you its list of sub-processors for the website, and your own team knows which email, CRM and other tools you use. Keep Google Analytics named, because it sets cookies and uses some data for its own purposes. Delete rows that do not apply, and set the locations for your own tools.
We may also disclose personal data if the law requires it, or to protect our rights, for example in a legal dispute.
5. Transfers outside the EEA
Some of our service providers are based outside the European Economic Area (EEA), for example in the United States. When we transfer personal data outside the EEA, we make sure it is protected, for example because:
- the European Commission has decided that the country protects personal data adequately (including the EU–US Data Privacy Framework, where the provider is certified), or
- we use the European Commission's Standard Contractual Clauses, with extra safeguards where needed.
You can contact us for more information about the safeguards we use.
6. How long we keep your data
We keep personal data only as long as we need it for the purposes above:
- Demo requests and enquiries: [up to 24 months after our last contact], unless we enter into an agreement with your institution.
- Customer and contract correspondence: [for the length of the agreement and up to X years after it ends].
- Accounting records: as long as the Norwegian Bookkeeping Act (bokføringsloven) requires, normally five years.
- Newsletter subscriptions: [until you unsubscribe].
- Google Analytics data: [14 months], after which Google deletes it automatically.
- Technical logs: [up to X days].
Note for Cognosic: these periods are examples. Set periods that match how you actually work. The Google Analytics period must match the data retention setting in your GA4 property (Admin > Data collection and modification > Data retention), which can be 2 or 14 months.
7. Your rights
Under data protection law, you have the right to:
- access the personal data we hold about you
- have inaccurate data corrected
- have your data deleted, where we no longer have a reason to keep it
- restrict how we process your data
- object to processing based on our legitimate interests, including direct marketing
- data portability, where processing is based on consent or a contract
- withdraw your consent at any time, where processing is based on consent. This does not affect processing already carried out.
To use any of these rights, email us at [privacy@cognosic.com]. We will reply within one month.
8. Complaints
If you believe we process your personal data unlawfully, you can complain to the Norwegian Data Protection Authority (Datatilsynet) at www.datatilsynet.no. We would appreciate the chance to resolve your concern first, so please contact us.
9. Security
We use appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access. These include [encryption in transit, access controls and working with reputable service providers].
10. Data in the Cosmos platform
When institutions use Cosmos, they decide what data is processed in the platform. For that data, the institution is normally the data controller and Cognosic processes it on the institution's behalf, under a data processing agreement. If you are a staff member or student at an institution using Cosmos and have questions about your data, please contact your institution first.
Note for Cognosic: confirm this matches your customer agreements and DPA. If you publish a separate platform privacy notice or DPA, link to it here.