Effective and last updated
Most privacy policies describe an ambition. This one describes an audit. Everything below was checked against the site’s own code and the responses it actually sends.
Controller
Who is responsible
Cognivy, the operator of cognivy.io, decides why and how any personal data described here is processed, and is the controller for it. Contact for all privacy matters: hello@cognivy.io. Put Privacy in the subject line.
Start here
What Cognivy does not collect
This list is longer than the one after it, which is the point. As of the date above, on the public pages of this site:
- No cookies of any kind are set, including analytics and advertising cookies.
- No data is written to localStorage or sessionStorage.
- No analytics, session-replay, heatmap, fingerprinting or advertising technology runs. There is no Google Analytics, no tag manager, no pixel.
- There are no third-party scripts, embedded videos, remote fonts or tracking images.
- There is no contact form, newsletter form or comment system on the site.
- Nothing is sold, rented or shared with data brokers or advertisers.
Consent banners exist because a site wants to set cookies that are not necessary for the service you asked for. Cognivy sets none, so there is nothing to consent to and a banner would be decoration. If that changes, this policy changes first and you will be asked properly before anything non-essential is stored.
The short list
What is collected
- Server and delivery logs. Like any website, requests reach a hosting provider, which records technical information such as your IP address, the page requested, timestamps, and your browser and device type. This happens automatically and is needed to serve pages, keep the site available and defend it against abuse.
- Anything you put in an email. If you write to us, we hold your message, your email address and our reply, so that we can help you and keep a record of what was agreed.
That is the whole list. There is no third item today: nothing on this site can be bought yet, so no purchase record exists and no payment data of any kind has been collected. What that will look like when paid access launches is set out further down this page, kept separate so this section stays a description of what happens now.
The choices you make in setup and in the diagnostic, such as the provider, the assessment name and your test date, are carried in the web address while you use the site. Your browser sends that address to our hosting provider when it requests a page, so those choices may appear temporarily in the delivery logs described above. Cognivy does not write them to browser storage or save them in a database. Closing the tab removes them from the page; any delivery-log copy follows the hosting provider’s retention period.
Why, and on what basis
Purposes and lawful bases
- Delivering and securing the site using server logs. Our legitimate interest in running a working, available site that resists abuse. The data is technical and is not used to build a profile of you.
- Answering your message when you email us. Our legitimate interest in responding to people who contact us.
There is no processing here that relies on consent, because nothing non-essential is stored on your device.
Who else touches it
Hosting and processors
- Vercel hosts and delivers this site. Its systems handle the requests described above and generate the delivery logs.
- Our email provider carries messages you send to us and our replies.
Two, and no others. No payment processor is engaged, because there is nothing to pay for yet, and none has been chosen. When one is, it will be named here before it handles anything.
Each of these processes data only to perform its function for Cognivy, under its own terms and security obligations. Cognivy does not use third-party advertising or cross-site tracking, and there is no advertising network involved in this site at all.
Retention
How long it is kept
- Delivery logs are short-lived and kept only for the period our hosting provider retains them.
- Emails are kept for as long as needed to deal with your query and to keep a reasonable record of it afterwards.
Not yet in effect
When paid access launches
Nothing in this section describes anything happening today. It is here so that the change is written down before it happens rather than after, and so the sections above can be read as a straight account of the present. Everything below takes effect only once access can actually be bought.
- Purchase records will be collected. A record that you are entitled to access and when it was bought.
- A payment processor will be engaged to handle checkout and card details. Cognivy will receive a confirmation of the purchase, not your card number, and will name the processor in the section above.
- The lawful basis will be performance of our agreement with you for providing access and handling refunds, alongside our legal obligations for keeping business records. Where an email concerns a purchase, that agreement becomes the basis for answering it.
- Purchase records will be kept for as long as accounting and tax rules require, which is longer than the refund window.
This policy will be updated on the day paid access opens, and the effective date at the top of the page will change with it. Until you see that date move, nothing here is in force.
Where it goes
International transfers
Pages are served from a global network, so a request may be handled at the location nearest you. Our hosting and email providers are international companies and may process data, including delivery logs, in countries other than your own. Where they do, they are required to apply appropriate legal safeguards for that transfer under their own data-processing terms.
Security
Security
The site is served over HTTPS only, with HTTP requests permanently redirected and strict transport security enabled. The smaller reason it is secure is technical; the larger reason is that the public site collects almost nothing, so there is very little to lose. No system is perfectly secure, and Cognivy claims no security certification.
Your rights
Your rights
Depending on where you live, you may have the right to ask for a copy of the personal data held about you, to have it corrected, to have it deleted, to restrict or object to how it is used, and to receive it in a portable form. Where processing relies on consent, you can withdraw that consent at any time.
Email hello@cognivy.io and we will deal with it. Please write from the address you used with us, so we can be reasonably sure the request is yours. There is no charge, and we do not require a form.
One honest caveat: for a visitor who has never emailed us or bought anything, we hold no information that identifies you beyond the technical delivery logs described above, so there is usually nothing to retrieve or delete.
Escalation
Complaints
If you are unhappy with how a privacy request was handled, tell us first and we will try to put it right. You also have the right to complain to the data protection authority in your country. In the EU and EEA that is your national supervisory authority, and you can complain either where you live, where you work, or where the problem happened.
Age
Children
Cognivy is built for adults preparing for workplace assessments. It is not directed at children, not intended for school entrance exams, and we do not knowingly collect personal data from children.
Changes
Changes to this policy
When this policy changes materially, the date at the top changes with it. The specific changes that would trigger a rewrite are known and listed: introducing accounts and sign-in, storing your progress in a database, sending transactional or marketing email, adding any analytics, and naming the payment processor once checkout details are finalised. Each of those adds data we do not hold today, and none of them will arrive quietly.
Questions about any of this go to hello@cognivy.io.