Privacy
policy.
What we collect, why we collect it, how long we keep it, and what you can ask us to do about it. Analytics stay off until you allow them, and every right in this policy can be exercised with one email.
We collect what we need to answer you, deliver work, and run the site. Analytics and marketing storage are denied until you consent, and you can withdraw consent at any time. Client project data is kept for the engagement plus seven years for tax and legal reasons; enquiries are kept for two years. You can ask for access, correction, or deletion at hello@cognimit.com and we answer within 30 days.
Introduction
Cognimit Technologies LLP (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit cognimit.com and when you use our product engineering, software development, applied AI, and related technology services.
Read it carefully. By accessing or using our website and services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with it, do not access or use our services.
Information we collect
Personal information you provide
We collect information you give us voluntarily when you:
- Fill out a contact form or a project brief form
- Subscribe to our newsletter or blog updates
- Request a product consultation or a technical quote
- Communicate with us by email, phone, or WhatsApp
- Register for events, webinars, or workshops
- Apply for a job or a developer role
- Engage us for product engineering, software development, AI, SaaS, or design services
That information may include:
- Full name
- Email address
- Phone number
- Company name and job title
- Project details and requirements
- Business information
- Payment information, for contracted services
- Resume and professional information, for job applications
Information collected automatically
When you visit our website we automatically collect certain information about your device and browsing activity:
- IP address
- Browser type and version
- Operating system
- Referring URLs
- Pages viewed and time spent on pages
- Click patterns and navigation paths
- Device identifiers
- Location data at city or country level
- Cookies and similar technologies
Information from third parties
We may receive information about you from:
- Social media platforms, if you interact with our pages
- Business partners and referral sources
- Public databases and directories
- Marketing and analytics providers
How we use your information
Service delivery
- Provide, maintain, and improve our product engineering, software development, AI, SaaS, and digital technology services
- Process and fulfil service requests, project briefs, and consultations
- Communicate about projects, deliverables, timelines, and milestones
- Provide support, technical assistance, and answers to enquiries
- Send project updates, invoices, and service communications
- Deliver fractional CTO, dedicated developer, and team augmentation engagements
Business operations
- Analyse website usage and improve the experience
- Develop new services and features
- Conduct market research and business analysis
- Manage our business relationships
- Maintain security and prevent fraud
Marketing and communications
- Send newsletters and marketing communications, with your consent
- Inform you about services, events, webinars, and case studies
- Personalise your experience on our website
- Run targeted advertising campaigns
Legal and compliance
- Comply with legal obligations and regulatory requirements
- Enforce our Terms of Service and other agreements
- Protect our rights, privacy, safety, and property
- Respond to legal requests and prevent illegal activity
Lawful basis for processing
Under the General Data Protection Regulation (GDPR) and the Digital Personal Data Protection Act, 2023 (DPDPA), we process personal data only where we have a valid lawful basis. The basis for each category of processing is set out below.
Consent
We rely on your freely given, specific, informed, and unambiguous consent for:
- Marketing emails, promotional offers, and newsletters
- Setting and reading analytics cookies on your device, such as Google Analytics
- Adding you to our blog or newsletter mailing lists
- Targeted advertising campaigns
Contract performance
Processing necessary to perform a contract with you, or to take steps at your request before entering one:
- Delivering product engineering, software development, AI, SaaS, and related technology services
- Project communication on deliverables, timelines, and milestones
- Processing service requests, technical consultations, and project briefs
- Sending invoices, receipts, and service communications
- Providing fractional CTO, dedicated developer, and team augmentation engagements
Legitimate interest
Processing necessary for our legitimate business interests, where those interests are not overridden by your rights and freedoms:
- Improving website experience and performance
- Business analytics, market research, and internal reporting
- Maintaining the security and integrity of our systems, and preventing fraud
- Managing and developing business relationships
Legal obligation
Processing necessary to comply with a legal obligation:
- Maintaining tax records, invoices, and financial documentation under Indian tax law
- Complying with the Information Technology Act, 2000 and the DPDPA 2023
- Responding to lawful requests from law enforcement and regulators
- Retaining records as mandated by applicable Indian and international regulation
Consent and consent withdrawal
Where we rely on consent, you can withdraw it at any time. Withdrawal is as easy as giving consent in the first place.
Cookie consent and Google Consent Mode v2
Our website implements Google Consent Mode v2. Analytics, functional, and marketing storage are denied by default. No non-essential cookies are set on your device until you allow them through the consent banner shown on your first visit. Full detail is in our Cookie Policy.
How to withdraw consent
- Reopen the cookie preferences panel from the footer or from the Cookie Policy page, and switch categories off
- Choose “Reject all” on the consent banner or in the panel
- Clear your browser cookies and site data, which resets your preferences
- Send a withdrawal request to hello@cognimit.com
- Use the unsubscribe link included in every marketing email
Effect of withdrawal
Withdrawal does not affect the lawfulness of processing carried out before it. We stop the relevant processing promptly once you withdraw. Strictly necessary cookies cannot be switched off, because the site cannot function without them.
Data retention
We keep personal information only for as long as needed for the purposes in this policy, unless a longer period is required or permitted by law.
- Contact enquiries: 2 years, or until you ask us to delete them
- Client project data: for the duration of the engagement plus 7 years for legal and tax purposes
- Marketing data: until you unsubscribe or request deletion
- Website analytics: up to 26 months, the Google Analytics default
- Job applications: 1 year, unless you are hired
After the retention period we securely delete or anonymise the information.
Your rights and choices
Depending on your location and the law that applies to you, you have the following rights.
Access and portability
- Request access to the personal information we hold about you
- Receive a copy in a structured, commonly used format
Correction and update
- Request correction of inaccurate or incomplete information
- Update your information through your account settings or by contacting us
Deletion
- Request deletion of your personal information
- We may retain certain records where the law requires it or where we have a legitimate business need
Restriction and objection
- Request restriction of processing
- Object to processing for direct marketing
- Opt out of marketing communications at any time
To exercise any of these rights, write to hello@cognimit.com. We respond within 30 days of receipt.
Data security
We apply technical and organisational measures to protect personal information against unauthorised access, alteration, disclosure, or destruction:
- TLS/SSL encryption for data in transit
- Encrypted data storage
- Regular security reviews and vulnerability assessments
- Access controls and authentication
- Staff training on data protection
- Backup and disaster recovery procedures, verified by restoring them
No method of transmission over the internet or electronic storage is completely secure. We work to protect your information but cannot guarantee absolute security.
International transfers and sub-processors
Delivering our services may involve transferring, storing, and processing personal data outside India. The third parties involved are:
- Vercel. Website hosting, with servers in the United States and other global locations.
- Google Analytics 4. Website analytics, processed on Google servers primarily in the United States.
- Turso. Database hosting, on globally distributed edge locations.
We apply safeguards to those transfers:
- Standard Contractual Clauses approved by the relevant regulators
- Adequacy decisions where they apply
- Contractual requirements that processors meet equivalent data protection standards
For detail on the safeguards in place, write to hello@cognimit.com.
Data breach notification
If a personal data breach is likely to create a risk to your rights and freedoms, we act under the DPDPA 2023 and other applicable law:
- Regulatory notification. We notify the Data Protection Board of India within 72 hours of becoming aware of a qualifying breach.
- Individual notification. We notify affected Data Principals without undue delay, in clear terms.
Our notifications state:
- The nature and scope of the breach
- The categories and approximate volume of data affected
- Measures taken or proposed to address the breach and limit its effects
- Contact details for further questions
We maintain an internal breach register and run a post-incident review after every event.
Children's privacy
Our services are not intended for anyone under the age of 18, and we do not knowingly collect personal information from children. If we learn that we hold information about a child under 18, we delete it promptly. If you are a parent or guardian and believe your child has given us personal information, contact us immediately.
Contact and grievance officer
For questions, concerns, or requests about this Privacy Policy or our data practices, contact us at hello@cognimit.com or +91 93270 57103. Our registered office address is listed at the top of this page and on our trust and compliance page.
Grievance officer — IT Act, 2000, Rule 5(9)
- Name: Deepak Nishad
- Email: hello@cognimit.com
- Resolution timeline: within 30 days of receipt of the grievance
Any grievance about the processing of your personal information can be sent to the grievance officer at the address above. The grievance officer addresses it expeditiously, and in any case within 30 days of receipt.
Legal compliance
This Privacy Policy is written to comply with:
- Information Technology Act, 2000 (India)
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- Digital Personal Data Protection Act, 2023, for Indian Data Principals
- Consumer Protection Act, 2019 (India)
- General Data Protection Regulation, for users in the EEA
- California Consumer Privacy Act, for California residents
- Other applicable data protection law
Regional rights and supervisory authorities
We contract against the data-protection regime that governs your data, not only India's. Where you are located determines which additional rights apply and which authority you may complain to.
- European Union and EEA. GDPR (EU 2016/679).
- United Kingdom. UK GDPR & Data Protection Act 2018.
- California, United States. CCPA / CPRA.
- Canada. PIPEDA.
- Australia. Privacy Act 1988 & APPs.
- New Zealand. Privacy Act 2020.
- Singapore. PDPA 2012.
- United Arab Emirates. Federal Decree-Law 45 of 2021 (PDPL).
- Saudi Arabia. PDPL.
- India. DPDP Act 2023.
What that means in practice
- EEA and UK. Rights of access, rectification, erasure, restriction, portability, and objection, plus the right to withdraw consent and to lodge a complaint with your national supervisory authority or the Information Commissioner's Office in the UK. Transfers out of the EEA or UK rely on Standard Contractual Clauses or the UK International Data Transfer Addendum.
- California. Rights to know, delete, correct, and opt out of sale or sharing, and the right not to be discriminated against for exercising them. We do not sell personal information and do not share it for cross-context behavioural advertising.
- Canada, Australia, New Zealand, Singapore, UAE and Saudi Arabia. Access and correction rights under the applicable statute, with complaints available to the relevant regulator in your jurisdiction.
- Client engagement data. Where we process personal data on your instructions as part of a client engagement, we act as processor rather than controller, under a data processing agreement that names every sub-processor and requires your written consent before another is added.
To exercise any of these rights, write to hello@cognimit.com. We respond within 30 days, or sooner where the applicable law requires it.
Acknowledgment and changes
By using our website and services you acknowledge that you have read and understood this Privacy Policy and agree to its terms. When we revise it, the effective date and document version at the top of this page change, and material changes are announced on the website.