In plain language: We collect what we need to run the Platform and improve it for you — not to profile you for advertising. We don’t sell your personal data. We don’t use your private course content to train Lyra unless you opt in, and for Enterprise, University, and Firm tiers, no-training is hard-off. If you’re a learner taking a published course, the course provider is responsible for your data and we process it on their behalf. You have rights — access, correction, deletion, portability, objection. Email privacy@cogniate.ai.
1. Who We Are
Cogniate US, Inc. (Delaware) is the controller for most processing described in this Policy. For customers in Australia, Cogniate Pty Ltd (Sydney) is the contracting entity and controller.
When we act as processor. Where we process personal information on behalf of a business customer — including learner data in an Enterprise tenant — we act as a processor, and our Data Processing Addendum governs. Likewise, when a course creator or institution publishes a course on the Platform, we process learner information (such as enrolment, progress, and responses) on behalf of that creator or institution, which acts as the controller (or equivalent) for its learners and is responsible for learner-facing privacy notices and any required consents. Learners should contact their course provider in the first instance, or privacy@cogniate.ai.
2. Information We Collect
Information you provide: account information, billing details (card data is handled by our payment processor), profile, Content you create or upload, and communications with us.
Collected automatically: device, IP address, browser and OS, usage information, and cookie data.
From third parties: identity providers (Google, Microsoft, LinkedIn), payment processors, and Marketplace integrations.
Sensitive categories: we do not intentionally collect sensitive personal information. The Platform is not HIPAA-compliant infrastructure; do not upload protected health information without a Business Associate Agreement.
3. How We Use Your Information
| Purpose | Lawful basis (GDPR/UK GDPR) |
|---|---|
| Provide and operate the Platform | Contract |
| Authenticate and secure | Contract; Legitimate Interests; Legal Obligation |
| Process payments / Marketplace payouts | Contract; Legal Obligation (tax/AML) |
| Communicate about the service and material changes | Contract; Legitimate Interests |
| Improve and develop the Platform (privacy-preserving) | Legitimate Interests |
| Customer-facing analytics | Contract |
| Train Lyra — only where you opt in | Consent (default-off; Enterprise/University/Firm hard-off) |
| Detect fraud, abuse, and security threats | Legitimate Interests; Legal Obligation |
| Comply with legal obligations | Legal Obligation |
| Marketing of Cogniate's services (with opt-out) | Legitimate Interests; Consent where required |
| CSAM detection and reporting | Legal Obligation; Vital Interests |
4. Lyra, AI Providers, and Training
Training is off by default. Cogniate does not use your Content, Lyra inputs, or Lyra outputs to train Lyra unless you opt in. For Enterprise, University, and Firm-Licensed tiers, training is hard-off and tenant administrators cannot override it. Aggregated, de-identified telemetry may be used to operate and improve the Platform. Detail is in the AI Product Terms.
Third-party AI providers. We use third-party AI providers to process inputs and generate output. These providers act as subprocessors under our Data Processing Addendum; a current list is available on request from privacy@cogniate.ai. We do not permit these providers to train their models on your Content.
7. International Transfers
We are US-based; data is processed in the US, EU, Australia, and our subprocessors’ regions. EU-to-US transfers rely on Standard Contractual Clauses (and the UK IDTA and Swiss adapted SCCs), supplemented by technical and organisational measures. For Australian users: your information may be disclosed to overseas recipients, principally in the United States, and we take reasonable steps consistent with Australian Privacy Principle 8 to ensure overseas recipients handle it in accordance with the Australian Privacy Principles.
8. Retention
| Category | Retention |
|---|---|
| Account data | Active + 30 days post-termination; up to 90 days from backups |
| Customer Content | Active + 30-day export grace; deletion per Frictionless Exit |
| Billing/tax records | 7 years (or longer where law requires) |
| Support records | 3 years |
| Security/abuse logs | 12 months minimum; longer for active investigations |
| Marketing emails | Until unsubscribe + 12 months |
| Audit and provenance records | May be retained after content deletion in de-identified form, to preserve the integrity of verification and audit features |
9. Your Rights
Depending on your region, you may have the right to access, correct, delete, or port your personal information, to object to or restrict processing, to withdraw consent, and to lodge a complaint with your supervisory authority. Send requests to privacy@cogniate.ai; we respond within 30 days (extendable where the law allows).
California (CCPA/CPRA)
You have the rights to know, delete, and correct; to opt out of sale or sharing (we do not sell personal data); and to limit the use of sensitive personal information. We will not retaliate against you for exercising these rights.
Australia
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may request access to or correction of your personal information at any time. If you are dissatisfied with our response to a privacy complaint, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au). We comply with the Notifiable Data Breaches scheme and will notify affected individuals and the OAIC of eligible data breaches.
10. Children
The Platform is not directed at children under 13, and consumer accounts are not available to them (parental consent is required for users under 16 in the EU/EEA). We do not knowingly collect personal information directly from children. Children under 13 may access published courses only as learners through a school or educational institution operating under a Cogniate Enterprise agreement, where the institution has obtained the consents required by applicable law (including school-consent mechanisms under COPPA and equivalent Australian and European rules) and administers the learner accounts; in that case we process learner information on the institution’s behalf as described in Section 1. If you believe a child has provided us information outside these arrangements, email privacy@cogniate.ai so we can delete it.
11. Security
We maintain technical and organisational safeguards aligned with SOC 2 Type II and ISO 27001 practices, as detailed in our Data Processing Addendum. Where the law requires, we notify affected parties of personal data breaches within 72 hours of becoming aware. No system is completely secure; use a strong password, enable two-factor authentication, and report suspected unauthorised access.
12. Changes
We announce material changes to this Policy at least 30 days in advance, by posting here and by email or in-product notice.
13. Contact
Privacy requests: privacy@cogniate.ai
Data Protection Officer (appointed where required): legal@cogniate.ai
Cogniate US, Inc. · 614 N Dupont Hwy, Suite 210, Dover, DE 19901
Cogniate Pty Ltd · SE 135 L 2, 153 New South Head Rd, Edgecliff NSW 2027
Version 2.1 · Last updated: 13 August 2026 · Terms of Service