Cognifai AI Ltd ("Cognifai", "we", "us") provides conversation analytics services to regulated firms. We are registered in England & Wales under company number 16624957, with our registered office at 124 City Road, London, United Kingdom, EC1V 2NX. We are registered with the Information Commissioner's Office (ICO) as a data controller under registration number ZC183522. For any privacy matter, contact us at info@cognifai.uk.
This policy explains how we handle personal data in two distinct situations: when you interact with our website, and when we process call recordings on behalf of our clients.
When you submit our review request form, we collect the information you provide: your name, role, company name, work email address, team size, and anything you choose to tell us in the free-text field. We use this to respond to your enquiry, scope the engagement, and communicate with you about our services. Our lawful basis is legitimate interests (responding to a business enquiry you initiated) and, where an engagement follows, steps taken to enter into a contract.
Our website does not use advertising trackers or analytics cookies. The site and form are hosted by Netlify, whose infrastructure records standard server logs (such as IP addresses) for security and operational purposes.
The core of our service involves analysing recorded customer calls and chat transcripts supplied by our clients. For this data, our client is the data controller and Cognifai acts as a data processor, handling recordings only on the client's documented instructions under a signed Data Processing Agreement (DPA).
Our standing commitments for call data: recordings and transcripts are transferred via secure portal; processed only by subprocessors bound by GDPR-standard contractual terms; never used to train AI models; customer names are never reproduced in our reports (conversations are referenced by timestamp); accessible only to personnel who need access to deliver the engagement; and permanently deleted within 30 days of report delivery, or earlier on the client's instruction.
Call recordings and chat transcripts may contain personal data of our clients' customers and staff, including names, contact details, policy information and, where disclosed on a call, health information. Where special category data is present, the client remains responsible for establishing the controller-side lawful basis; our processing is limited to the analysis they instruct, under the safeguards above. If you are a customer of one of our clients and wish to exercise your data rights over a call recording, please contact the firm you spoke to; we will support our client in fulfilling your request.
We do not sell personal data, and we do not share it with third parties for their own marketing. We use a small, fixed set of subprocessors, each bound by contractual terms consistent with UK GDPR:
Analysis runs through Amazon Bedrock inside our own AWS account. Bedrock does not share inputs or outputs with third-party foundation model providers, who have no access to prompts, outputs or service logs. Foundation model providers are therefore not subprocessors of your data. Our public website and enquiry form are hosted by Netlify, as described in section 2; no conversation data is ever processed by Netlify and it is not a subprocessor of client conversation data. The full conversation-data list, with purposes and locations, is published at Trust & Data Handling and forms part of our DPA. Clients are notified in advance of any change to it.
All storage and analysis takes place in the United Kingdom, in AWS eu-west-2 (London). Call audio is transcribed via Deepgram’s EU endpoint, where processing occurs within EU-based AWS regions currently located in Germany. Transfers from the UK to the European Economic Area are permitted under UK adequacy regulations, so no additional transfer mechanism is required. A UK region is on Deepgram’s roadmap, indicatively for early 2027. No committed date has been given to us, and we intend to adopt it if and when it becomes available.
Where any other processing takes place outside the UK, we ensure an adequate level of protection through UK adequacy regulations or appropriate safeguards such as the UK International Data Transfer Agreement or Addendum.
Call recordings, chat transcripts and derived conversation-level data are deleted within 30 days of report delivery. Enquiry data is retained for as long as needed to manage our relationship with you and for a reasonable period afterwards, after which it is deleted. Review reports delivered to clients are retained by the client as controller of their own records.
We apply technical and organisational measures appropriate to the sensitivity of the data we handle, including encrypted transfer, access controls, and deletion procedures. No system is perfectly secure, but the handling commitments in section 3 are contractual, not aspirational.
Under UK GDPR you have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where consent is the basis of processing. To exercise any of these in respect of data we control, email info@cognifai.uk. You also have the right to complain to the Information Commissioner's Office (ico.org.uk), although we would welcome the chance to resolve any concern directly first.
We may update this policy from time to time. The date at the top reflects the latest revision, and material changes will be flagged to active clients directly.