Skip to content
Legal · Privacy

Privacy
policy.

What we collect, why we collect it, how long we keep it, and what you can ask us to do about it. Analytics stay off until you allow them, and every right in this policy can be exercised with one email.

Last updated 15 February 2026Document version 2.016 clauses
In short

We collect what we need to answer you, deliver work, and run the site. Analytics and marketing storage are denied until you consent, and you can withdraw consent at any time. Client project data is kept for the engagement plus seven years for tax and legal reasons; enquiries are kept for two years. You can ask for access, correction, or deletion at hello@cognimit.com and we answer within 30 days.

01

Introduction

Cognimit Technologies LLP (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit cognimit.com and when you use our product engineering, software development, applied AI, and related technology services.

Read it carefully. By accessing or using our website and services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with it, do not access or use our services.

02

Information we collect

Personal information you provide

We collect information you give us voluntarily when you:

  • Fill out a contact form or a project brief form
  • Subscribe to our newsletter or blog updates
  • Request a product consultation or a technical quote
  • Communicate with us by email, phone, or WhatsApp
  • Register for events, webinars, or workshops
  • Apply for a job or a developer role
  • Engage us for product engineering, software development, AI, SaaS, or design services

That information may include:

  • Full name
  • Email address
  • Phone number
  • Company name and job title
  • Project details and requirements
  • Business information
  • Payment information, for contracted services
  • Resume and professional information, for job applications

Information collected automatically

When you visit our website we automatically collect certain information about your device and browsing activity:

  • IP address
  • Browser type and version
  • Operating system
  • Referring URLs
  • Pages viewed and time spent on pages
  • Click patterns and navigation paths
  • Device identifiers
  • Location data at city or country level
  • Cookies and similar technologies

Information from third parties

We may receive information about you from:

  • Social media platforms, if you interact with our pages
  • Business partners and referral sources
  • Public databases and directories
  • Marketing and analytics providers
03

How we use your information

Service delivery

  • Provide, maintain, and improve our product engineering, software development, AI, SaaS, and digital technology services
  • Process and fulfil service requests, project briefs, and consultations
  • Communicate about projects, deliverables, timelines, and milestones
  • Provide support, technical assistance, and answers to enquiries
  • Send project updates, invoices, and service communications
  • Deliver fractional CTO, dedicated developer, and team augmentation engagements

Business operations

  • Analyse website usage and improve the experience
  • Develop new services and features
  • Conduct market research and business analysis
  • Manage our business relationships
  • Maintain security and prevent fraud

Marketing and communications

  • Send newsletters and marketing communications, with your consent
  • Inform you about services, events, webinars, and case studies
  • Personalise your experience on our website
  • Run targeted advertising campaigns

Legal and compliance

  • Comply with legal obligations and regulatory requirements
  • Enforce our Terms of Service and other agreements
  • Protect our rights, privacy, safety, and property
  • Respond to legal requests and prevent illegal activity
04

Lawful basis for processing

Under the General Data Protection Regulation (GDPR) and the Digital Personal Data Protection Act, 2023 (DPDPA), we process personal data only where we have a valid lawful basis. The basis for each category of processing is set out below.

Consent

We rely on your freely given, specific, informed, and unambiguous consent for:

  • Marketing emails, promotional offers, and newsletters
  • Setting and reading analytics cookies on your device, such as Google Analytics
  • Adding you to our blog or newsletter mailing lists
  • Targeted advertising campaigns

Contract performance

Processing necessary to perform a contract with you, or to take steps at your request before entering one:

  • Delivering product engineering, software development, AI, SaaS, and related technology services
  • Project communication on deliverables, timelines, and milestones
  • Processing service requests, technical consultations, and project briefs
  • Sending invoices, receipts, and service communications
  • Providing fractional CTO, dedicated developer, and team augmentation engagements

Legitimate interest

Processing necessary for our legitimate business interests, where those interests are not overridden by your rights and freedoms:

  • Improving website experience and performance
  • Business analytics, market research, and internal reporting
  • Maintaining the security and integrity of our systems, and preventing fraud
  • Managing and developing business relationships

Legal obligation

Processing necessary to comply with a legal obligation:

  • Maintaining tax records, invoices, and financial documentation under Indian tax law
  • Complying with the Information Technology Act, 2000 and the DPDPA 2023
  • Responding to lawful requests from law enforcement and regulators
  • Retaining records as mandated by applicable Indian and international regulation
06

Data retention

We keep personal information only for as long as needed for the purposes in this policy, unless a longer period is required or permitted by law.

  • Contact enquiries: 2 years, or until you ask us to delete them
  • Client project data: for the duration of the engagement plus 7 years for legal and tax purposes
  • Marketing data: until you unsubscribe or request deletion
  • Website analytics: up to 26 months, the Google Analytics default
  • Job applications: 1 year, unless you are hired

After the retention period we securely delete or anonymise the information.

07

Your rights and choices

Depending on your location and the law that applies to you, you have the following rights.

Access and portability

  • Request access to the personal information we hold about you
  • Receive a copy in a structured, commonly used format

Correction and update

  • Request correction of inaccurate or incomplete information
  • Update your information through your account settings or by contacting us

Deletion

  • Request deletion of your personal information
  • We may retain certain records where the law requires it or where we have a legitimate business need

Restriction and objection

  • Request restriction of processing
  • Object to processing for direct marketing
  • Opt out of marketing communications at any time

To exercise any of these rights, write to hello@cognimit.com. We respond within 30 days of receipt.

08

Cookies and similar technologies

Cookies are small text files stored on your device when you visit our website. We use them to keep the site working, to remember preferences you set, and to measure usage in aggregate.

We group them into four categories:

  • Strictly necessary. Routing, security, load balancing, and the record of this consent choice. These cannot be switched off.
  • Functional. Preferences you set, such as colour theme and language.
  • Analytics. Aggregated usage measurement through Google Analytics 4 (_ga, _ga_*) and Vercel Analytics, with IP addresses anonymised.
  • Marketing. Attribution and advertising measurement. Not currently in use, and denied unless that changes.

Analytics cookies are blocked until you consent. You can manage cookies through the preferences panel on this site, through your browser settings, or by using the Google Analytics opt-out browser add-on. Named cookies, retention periods, and the exact Consent Mode signals we set are documented in the Cookie Policy.

09

Data security

We apply technical and organisational measures to protect personal information against unauthorised access, alteration, disclosure, or destruction:

  • TLS/SSL encryption for data in transit
  • Encrypted data storage
  • Regular security reviews and vulnerability assessments
  • Access controls and authentication
  • Staff training on data protection
  • Backup and disaster recovery procedures, verified by restoring them

No method of transmission over the internet or electronic storage is completely secure. We work to protect your information but cannot guarantee absolute security.

10

International transfers and sub-processors

Delivering our services may involve transferring, storing, and processing personal data outside India. The third parties involved are:

  • Vercel. Website hosting, with servers in the United States and other global locations.
  • Google Analytics 4. Website analytics, processed on Google servers primarily in the United States.
  • Turso. Database hosting, on globally distributed edge locations.

We apply safeguards to those transfers:

  • Standard Contractual Clauses approved by the relevant regulators
  • Adequacy decisions where they apply
  • Contractual requirements that processors meet equivalent data protection standards

For detail on the safeguards in place, write to hello@cognimit.com.

11

Data breach notification

If a personal data breach is likely to create a risk to your rights and freedoms, we act under the DPDPA 2023 and other applicable law:

  • Regulatory notification. We notify the Data Protection Board of India within 72 hours of becoming aware of a qualifying breach.
  • Individual notification. We notify affected Data Principals without undue delay, in clear terms.

Our notifications state:

  • The nature and scope of the breach
  • The categories and approximate volume of data affected
  • Measures taken or proposed to address the breach and limit its effects
  • Contact details for further questions

We maintain an internal breach register and run a post-incident review after every event.

12

Children's privacy

Our services are not intended for anyone under the age of 18, and we do not knowingly collect personal information from children. If we learn that we hold information about a child under 18, we delete it promptly. If you are a parent or guardian and believe your child has given us personal information, contact us immediately.

13

Contact and grievance officer

For questions, concerns, or requests about this Privacy Policy or our data practices, contact us at hello@cognimit.com or +91 93270 57103. Our registered office address is listed at the top of this page and on our trust and compliance page.

Grievance officer — IT Act, 2000, Rule 5(9)

  • Name: Deepak Nishad
  • Email: hello@cognimit.com
  • Resolution timeline: within 30 days of receipt of the grievance

Any grievance about the processing of your personal information can be sent to the grievance officer at the address above. The grievance officer addresses it expeditiously, and in any case within 30 days of receipt.

15

Regional rights and supervisory authorities

We contract against the data-protection regime that governs your data, not only India's. Where you are located determines which additional rights apply and which authority you may complain to.

  • European Union and EEA. GDPR (EU 2016/679).
  • United Kingdom. UK GDPR & Data Protection Act 2018.
  • California, United States. CCPA / CPRA.
  • Canada. PIPEDA.
  • Australia. Privacy Act 1988 & APPs.
  • New Zealand. Privacy Act 2020.
  • Singapore. PDPA 2012.
  • United Arab Emirates. Federal Decree-Law 45 of 2021 (PDPL).
  • Saudi Arabia. PDPL.
  • India. DPDP Act 2023.

What that means in practice

  • EEA and UK. Rights of access, rectification, erasure, restriction, portability, and objection, plus the right to withdraw consent and to lodge a complaint with your national supervisory authority or the Information Commissioner's Office in the UK. Transfers out of the EEA or UK rely on Standard Contractual Clauses or the UK International Data Transfer Addendum.
  • California. Rights to know, delete, correct, and opt out of sale or sharing, and the right not to be discriminated against for exercising them. We do not sell personal information and do not share it for cross-context behavioural advertising.
  • Canada, Australia, New Zealand, Singapore, UAE and Saudi Arabia. Access and correction rights under the applicable statute, with complaints available to the relevant regulator in your jurisdiction.
  • Client engagement data. Where we process personal data on your instructions as part of a client engagement, we act as processor rather than controller, under a data processing agreement that names every sub-processor and requires your written consent before another is added.

To exercise any of these rights, write to hello@cognimit.com. We respond within 30 days, or sooner where the applicable law requires it.

16

Acknowledgment and changes

By using our website and services you acknowledge that you have read and understood this Privacy Policy and agree to its terms. When we revise it, the effective date and document version at the top of this page change, and material changes are announced on the website.

WhatsAppStart a chat