| Policy Owner | Mike Boyd |
|---|---|
| Policy Approver | Alan Hsiao |
| Review Frequency | Annual |
| Last Review Date | 30/06/2025 |
| Classification | High |
Document version control
| Amendments | Amendments | Amendments |
|---|---|---|
| Version | Date | Comments |
| 1.0 | 30/06/2025 | Updated in preparation for ISO internal audit |
PRIVACY POLICY
This policy is issued by Cognitivo on behalf of itself and its affiliates (together, “Cognitivo”, “we”, “us” and “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your (individuals outside our organisation with whom we interact, including customers, visitors to our sites, users of our apps, and other users of our services together, “you”) information when you use our AI-powered services, including our website, applications, APIs, and related services (collectively, the "Services"). By using our Services, you agree to the terms of this Privacy Policy. The terms used in this policy are explained in Appendix 2 of this policy. In addition to the Australian Privacy Act, individual located in the European Union may also have rights under EU based rules known as the General Data Protection Regulation (GDPR). The GDPR has given more rights to individuals located in the EU and more obligations to organisation’s holding their personal information. Details of additional rights of individuals located in the EU and how we meet them are outlined in Appendix 1 of this policy. This policy is not limited to current customers, but it also relates to all other individuals who deal with us for any business purpose. Please note this policy may be updated from time to time to ensure compliance to applicable laws, you can always find the most up-to-date version on our website.
1 About Cognitivo
We help clients develop coherent digital strategies, skills and apply relevant technologies required win in the digital age. Businesses face entirely new ways of operating and engaging customers leading to exciting new opportunities and threats. Building an organisation that fosters safe experimentation within wider strategic goals will be one of the keys to success. We believe the key ingredient and hardest part of digital transformation is getting the right mindset at the top of the house and having that permeate into the culture of your organisation. Our collaborative approach aims to help you build the right strategy, skills and organisation to be able to execute on a digital agenda that is your own.
2 Your privacy is very important to us
At Cognitivo, the privacy of our customer’s data is critical concern. This policy is laid out in an easy to understand way so that all our customers and partners can clearly understand our position on data privacy and our commitment to protecting the data we collect.
3 What personal data do we collect and how?
3.1 Collection of personal data and its sources
We may collect personal data about you from the following sources:
- Data you provide: We may collect your personal data when you provide it to us (e.g., where you contact us via email or telephone, or by any other means).
- Registration details: We may collect or obtain your personal data when you use, or register to use, any of our sites, apps, or services.
- Data you make public: We may collect or obtain your personal data that you noticeably choose to make public, including via social media (e.g., we may collect information from your social media profile(s), if you make a public post about us).
- App data: We may collect or obtain your personal data when you download or use any of our apps or services.
- Site data: We may collect or obtain your personal data when you visit any of our sites or use any features or resources available on or through a site.
- Third party information: We may collect or obtain your personal data from third parties who provide it to us (e.g. financial institutions, banks).
3.2 Creation of personal data
We may also create personal data about you, such as records of your interactions with us, details of your purchase history, details of services used or availed, where applicable.
3.3 Categories of personal data we may collect, create or process.
We may process the following categories of personal data about you:
- Identify information given name(s), preferred name, gender, date of birth / age.
- Contact details: correspondence address, contact number(s), email address.
- Consent records: records of any consent you may have given, together with the date and time, means of consent and any related information.
- Purchase details: records of purchases and prices.
- Payment details: invoice records, payment records, billing address, payment method, bank account number or credit card number, cardholder or accountholder name, card or account security details, card ‘valid from’ date, and card expiry date, SWIFT details, payment amount, payment date, IBAN and cheques records.
- Data relating to our sites and apps: device type, operating system, browser type, browser settings, IP address, dates and times of connecting to a site, pixel tags, app usage statistics, App settings, dates and times of connecting to an app, and other technical communications information (some of which may constitute personal data), username, password, account login details, usage data, aggregate statistical information;
- Employer details: where you interact with us in your capacity as an employee, the name, address, telephone number and email address of your employer, to the extent relevant.
- Views and opinions: any views and opinions that you choose to send to us, or publicly post about us on social media platforms.
3.4 Sensitive personal data
The privacy act protects your sensitive personal data like information about your religion, ethnicity, health or biometrics. If we need this type of data, we will ask for your permission except otherwise allowed by law.
4. How do we use your personal data?
We use collected data to:
- Provide, maintain, and improve our AI Services.
- Train and refine AI models (with anonymized data where possible).
- Respond to user inquiries and provide support.
- Detect and prevent fraud or misuse.
- Comply with legal obligations. The purposes for which we may process personal data, subject to applicable law, include:
- Provision of services to you: providing you with services that you have requested; providing you with promotional items at your request; and communicating with you in relation to those services.
- Our Sites and Apps: operating and managing our sites and our apps; communicating and interacting with you via our sites and our apps; and notifying you of changes to any of our sites, our apps, or our services.
- Communications: communicating with you via any means (including via email, telephone, text message, social media, post or in person) news items and other information in which you may be interested, subject to ensuring that such communications are provided to you in compliance with applicable law; maintaining and updating your contact information where appropriate; and obtaining your prior, opt-in consent where required.
- Communications and IT operations: management of our communications systems; operation of IT security systems, and IT security audits.
- Financial management: sales, finance, corporate audit, and vendor management.
- Surveys: engaging with you for the purpose of obtaining your views on our services or other matters, on the products and services of third parties.
- Security: physical security of our premises (including records of visits to our premises; and CCTV recordings); and electronic security (including login records and access details).
- Legal proceedings: establishing, exercising and defending legal rights.
- Legal compliance: compliance with our legal and regulatory obligations under applicable law.
- Improving our sites, apps, services: identifying issues with our sites, our apps, or our services; planning improvements to our sites, our apps, or our services; and creating new sites, apps, or services.
5. Who we may share your personal data?
5.1 Disclosure of personal data to third parties
We may disclose your personal data to other entities for legitimate business purposes and in accordance with applicable law. Those include:
- We may outsource certain organisation functions e.g. information technology support, direct marketing etc; subject to binding contractual obligations of confidentiality
- Our party service providers, cloud computing solutions or data storage service providers.
- Legal and regulatory authorities, upon request, or for the purpose of reporting any actual or suspected breach of applicable law or regulation.
- Accountants, auditors, lawyers and other outside professional advisors to Cognitivo, subject to binding contractual obligations of confidentiality.
- Any relevant party, law enforcement agency or court, to the extent necessary for the establishment, exercise or defense of legal rights.
- Any relevant third-party acquirer(s), in the event that we sell or transfer all or any relevant portion of our business or assets (including in the event of a reorganization, dissolution or liquidation); and
5.2 International transfer of personal data
We may send your data overseas to service providers or other third parties who operate or hold data outside Australia but where we do this, we ensure that reasonable steps are taken in data handling and security arrangements. Please note this also means that other may have different laws and data protection compliance requirements to those that apply in Australia.
6. Keeping your data secure and maintaining accuracy of your data
6.1 Securing Data
We have implemented appropriate technical and organisational security measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other unlawful or unauthorised forms of processing, in accordance with applicable law. Few of measures are listed below:
| Staff education | We train and remind our staff of their obligations with regard to your data. |
|---|---|
| Taking precautions with overseas transfers and third parties | When we send information overseas or use third parties that handle or store data, we ensure that appropriate data handling and security arrangements are in place. |
| System security | When you transact with us on the internet via our website or mobile apps we encrypt data sent from your computer to our systems. |
| Building security | We have protection in our buildings against unauthorised access such as alarms, cameras and guards (as required). |
| Destroying data when no longer required | Where practical, we keep information only for as long as required (for example, to meet legal requirements or our internal needs). |
6.2 Maintaining Data Accuracy
We take every reasonable step to ensure that:
- Your personal data that we process are accurate and, where necessary, kept up to date; and
- any of your personal data that we process that is inaccurate (having regard to the purposes for which they are processed) are erased or rectified without delay. From time to time, we may ask you to confirm the accuracy of your personal data.
7. Cookies and similar technologies
When you visit a site or use an app we may place cookies onto your device, or read cookies already on your device, subject always to obtaining your consent, where required, in accordance with applicable law. We use cookies to record information about your device, your browser and, in some cases, your preferences and browsing habits. We may process your personal data through cookies and similar technologies.
8. Direct marketing
We may process your personal data by contacting you via email, telephone, direct mail or other communication formats to provide you with information regarding services that may be of interest to you. If we provide services to you, we may send information to you regarding our services, upcoming promotions and other information that may be of interest to you, using the contact details that you have provided to us and always in compliance with applicable law. You may unsubscribe from our promotional email list at any time by simply clicking on the unsubscribe link included in every promotional email we send. After you unsubscribe, we will not send you further promotional emails, but we may continue to contact you to the extent necessary for the purposes of any services you have requested.
9. Accessing, updating and correcting your personal data
9.1 Accessing your data
You can ask for access to your personal data (for example what transactions you’ve made) by contacting us. We try to make your information available within 30 days of your request. Before we give you the information, we’ll need to confirm your identity.
9.2 Deny or limit your request for access
In certain circumstances we’re allowed to deny your request or limit the access we provide. For example, we might not provide you with access to commercially sensitive information. Whatever the outcome, we’ll write to you explaining our decision.
9.3 Correcting your data
You can ask us to correct any inaccurate data we hold or have provided to others by contacting us. If the data that is corrected is data we have provided to others, you can ask us to notify them of the correction. If we’re able to correct your data, we’ll inform you when the process is complete.
9.4 Disagreement on data correction required
If we disagree with you that data should be corrected, we’ll let you know in writing our reasons. You can ask us indicating your view that the data is inaccurate, misleading, incomplete, irrelevant or out-of-date. We will take reasonable steps to comply with such a request.
10. Your choice of interaction
Where feasible and permitted by law, you can interact with Cognitivo anonymously or use a pseudonym, but this means that you may not be able to use or acquire all of our services.
11 Contact us or find out more
If you have any questions regarding this privacy policy or our treatment of your personal information, or complain, or if you would like to access or amend your personal information, please contact us at contact@cognitivo.com.au. If you contact us to make a complaint, we will consider your complaint promptly and contact you to seek to resolve the matter. We shall assign a reference number, and we will keep you updated on the progress we’re making towards fixing the problem. However, if we’re unable to provide a final response within 45 days we’ll contact you to explain why and discuss a timeframe to resolve the complaint. You are also entitled under the Privacy Act to make a complaint to the Australian Privacy Commissioner if you have concerns about how we handle your personal data. For more information about the Australian Privacy Principles, you can contact the Office of the Australian Information Commissioner (privacy generally)
APPENDIX ONE: Additional rights for individuals located in the European Union
The European Union (EU) General Data Protection Regulation (GDPR) has provided few more rights to individuals located in the EU and more obligations to organisations holding their personal information. As such, if you are located in the EU, GDPR requires us to provide you with more information about how we collect, use, share and store your personal information as well as advising you of your rights as a ‘data subject’. If you are located in the EU and have an enquiry relating to your rights under the GDPR, please contact contact@cognitivo.com.au.
11.1 Special Categories of Personal Information
The GDPR provides additional protection for personal information about your racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, biometric data (for example your fingerprints), or data concerning your health, sex life or sexual orientation. We will only process this type of personal information with your consent or where otherwise lawfully permitted.
11.2 Data Retention
We take every reasonable step to ensure that your Personal Data are only processed for the minimum period necessary for the purposes set out in this policy.
11.3 Data Minimisation
We take every reasonable step to ensure that your Personal Data that we Process is limited to the Personal Data reasonably necessary in connection with the purposes set out in this policy.
11.4 Lawful basis for processing personal data
In processing your personal data in connection with the purposes set out in this policy, we may rely on one or more of the following legal bases, depending on the circumstances: Consent: We may process your personal data where we have obtained your prior, express consent to the processing. Contractual necessity: We may process your personal data where the processing is necessary in connection with any contract that you may enter with us. Compliance with applicable law: We may process your personal data where the Processing is required by applicable law. Vital interests: We may process your personal data where the processing is necessary to protect the vital interests of any individual; or Legitimate interests: We may process your personal data where we have a legitimate interest in carrying out the processing for the purpose of managing, operating or promoting our business, and that legitimate interest is not overridden by your interests, fundamental rights, or freedoms.
11.5 Your legal rights
Subject to applicable law, you may have several rights regarding the processing of your Relevant Personal Data, including: The right not to provide your personal data to us (however, please note that we may be unable to provide you with the full benefit of our sites, our apps, or our services, if you do not provide us with your personal data – e.g., we may not be able to process your orders without the necessary details); The right to request access to, or copies of, your relevant personal data, together with information regarding nature, processing and disclosure of those relevant personal data. The right to request rectification of any inaccuracies in your relevant personal data. The right to request, on legitimate grounds: Erasure of your relevant personal data; or Restriction of processing of your relevant personal data. The right to object, on legitimate grounds, to the processing of your relevant personal data by us or on our behalf; The right to have certain relevant personal data in a portable form. The right to restrict automated decision making and profiling means that we should not make decisions based on automated score alone or you can object to an automated decision and ask that a person review is done. The right to withdraw that consent where we are processing based on your explicit consent (noting that such withdrawal does not affect the lawfulness of any processing performed prior to the date on which we receive notice of such withdrawal, and does not prevent the processing of your personal data in reliance upon any other available legal bases); and The right to lodge complaints with a Data Protection Authority regarding the Processing of your Relevant Personal Data by us or on our behalf. To exercise one or more of these rights, or to ask a question about these rights or any other provision of this policy, or about our processing of your personal Data, please use us on contact@cognitivo.com.au Please note that: We may require proof of your identity before we can give effect to these rights; and Where your request requires the establishment of additional facts (e.g., a determination of whether any processing is non-compliant with applicable law) we will investigate your request reasonably promptly, before deciding what action to take.
APPENDIX TWO: Definitions
“Personal Data” means information that is about any individual, or from which any individual is directly or indirectly identifiable, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that individual. “Process”, “Processing” or “Processed” means anything that is done with any Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. “Sensitive Personal Data” means Personal Data about race or ethnicity, political opinions, religious or philosophical beliefs, trade union membership, physical or mental health, sexual life, any actual or alleged criminal offences or penalties, national identification number, or any other information that may be deemed to be sensitive under applicable law. “Site” means any website operated, or maintained, by us or on our behalf. “App” means any application made available by us (including where we make such applications available via third party stores or marketplaces, or by any other means). “Cookie” means a small file that is placed on your device when you visit a website (including our Sites). “Data Protection Authority” means an independent public authority that is legally tasked with overseeing compliance with applicable data protection laws.
Reference clause to include into policy
- Information We Collect We may collect the following types of information: A. Personal Data
- Identifiers: Name, email, phone number, IP address, etc.
- Account Data: Username, password, payment details (if applicable).
- User Content: Inputs, queries, or data you provide to our AI models. B. Non-Personal Data
- Usage Data: How you interact with our Services (e.g., logs, session duration).
- Technical Data: Device type, browser, operating system, and cookies.
- AI Training Data: Anonymized and aggregated data to improve AI models (where permitted). C. Sensitive Data (if applicable) We do not intentionally collect sensitive data (e.g., health, biometric, or financial data) unless explicitly required and consented to by the user.
- How We Use Your Data We use collected data to:
- Provide, maintain, and improve our AI Services.
- Train and refine AI models (with anonymized data where possible).
- Respond to user inquiries and provide support.
- Detect and prevent fraud or misuse.
- Comply with legal obligations.
- Data Sharing & Disclosure We may share data with:
- Service Providers: Hosting, analytics, and payment processors.
- Legal Authorities: If required by law (e.g., court orders).
- Business Transfers: In case of mergers or acquisitions. We do not sell personal data to third parties.
- AI & Machine Learning Considerations
- Your inputs may be processed to improve AI accuracy but are anonymised where possible.
- You may opt out of data usage for AI training (where applicable).
- Data Retention & Security
- We retain data only as long as necessary.
- We implement encryption, access controls, and security best practices.
- International Data Transfers If data is transferred outside your country, we ensure safeguards like Standard Contractual Clauses (SCCs) or equivalent protections.
- Changes to This Policy We may update this policy and will notify users of material changes.
