Kogniflow AS (“Kogniflow”, “we”, “us”) respects your privacy. This Policy applies to visitors to https://kogniflow.com, users and administrators of the Kogniflow Service, business contacts, prospective customers, and people who contact support. It should be read together with our Cookie Policy.
1. Scope and our roles
Kogniflow processes personal data in two distinct roles:
- As controller, when we decide why and how to process account, contracting, billing, website, security, support, and business-contact data.
- As processor or subprocessor, when we process data in accounting, payroll, documents, integrations, and other customer content on the documented instructions of a customer or an organization that customer administers.
The sections below distinguish these roles because they affect who answers privacy requests and who determines the purpose of processing.
2. Data we process as controller
Depending on your relationship with us, we may process:
- Identity and contact data, such as name, work email, telephone number, employer, role, and communication preferences.
- Account and authentication data, such as account identifiers, login events, identity-provider references, organization membership, permissions, and security status.
- Contract and billing data, such as subscription, order, invoice, payment status, tax, and administrative-contact information. Payment-card details are generally handled by our payment provider rather than stored by Kogniflow.
- Support and communication data, including messages, meeting details, requested demonstrations, feedback, and records needed to resolve an inquiry.
- Website and technical data, such as IP address, browser and device data, page requests, timestamps, diagnostic events, cookie choices, and security logs.
3. Purposes and legal bases
| Purpose | Typical legal basis |
|---|---|
| Create accounts, authenticate users, and deliver contracted services | Performance of a contract or steps requested before entering a contract |
| Administer customer relationships, subscriptions, invoices, and payments | Contract and legitimate interests in running our business |
| Answer inquiries, provide support, and manage beta or demo requests | Contract, pre-contract steps, or legitimate interests in responding |
| Protect accounts, detect misuse, investigate incidents, and maintain logs | Legitimate interests in securing the Service and complying with legal duties |
| Maintain and improve reliability and usability using limited usage information | Legitimate interests, balanced against user rights; consent where required |
| Send requested updates or optional marketing communications | Consent or legitimate interests where permitted; you may opt out at any time |
| Keep statutory records and respond to lawful requests | Compliance with legal obligations |
Where we rely on legitimate interests, we assess necessity, impact, and reasonable expectations. You may ask for more information about a specific assessment.
4. Sources of data
We collect data from you, your employer or organization administrator, the device and browser you use, identity providers you select, payment and communication providers, and public business sources where appropriate. We may also receive administrative contact data from an organization that invites you to the Service.
5. Recipients and service providers
We share controller data only where necessary with personnel, professional advisers, authorities where legally required, a buyer in a properly safeguarded corporate transaction, and service providers supporting hosting, security, authentication, communications, customer support, diagnostics, and payments. Providers may process only the data needed for their function and are subject to appropriate contractual obligations. Providers that may also process Customer Personal Data are listed on our Subprocessors page.
We do not sell personal data.
6. Data processed for customers
Customer content may contain personal data about employees, customers, suppliers, owners, directors, and other people represented in accounting, payroll, transaction, document, or business records. For this data, the customer or the organization it administers determines the purpose and legal basis. Kogniflow processes it only to provide and secure the Service under documented instructions and the Data Processing Agreement.
If your request concerns data submitted by a Kogniflow customer, please contact that customer first. The customer normally verifies and responds to the request. We will assist the customer as required by our DPA and applicable law.
Kogniflow uses selected infrastructure and artificial-intelligence providers to deliver analysis and supporting functionality. Data is disclosed only to the extent needed for the relevant service and subject to contractual privacy, confidentiality, and security requirements.
7. International transfers
We aim to process core service data in the European Economic Area where configured, but some providers or their support operations may process data in other countries. Where a transfer is not covered by an adequacy decision, we use an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses, and supplementary measures where required. See the Subprocessor register for relevant locations and mechanisms.
8. Retention
We keep controller data only as long as needed for the purpose collected. Criteria include the account or customer relationship, support needs, security and limitation periods, and statutory accounting or documentation requirements. Typical examples are:
- account data for the active account and a limited period after closure;
- support and sales correspondence while the inquiry is active and for follow-up;
- contract and accounting records for periods required by applicable law;
- security logs for a risk-based period appropriate to investigation and prevention; and
- optional marketing data until you opt out or the contact is no longer relevant.
Customer Personal Data follows the retention and deletion instructions in the DPA. Data may remain in protected backups until the relevant backup cycle expires.
9. Security
We maintain technical and organizational measures designed to protect personal data against accidental or unlawful loss, alteration, disclosure, or access. These include controls for access, data transmission and storage, monitoring, development, recovery, incidents, suppliers, and deletion. More information is available on our Security page. No system can eliminate every risk.
10. Your rights
Subject to applicable conditions and exceptions, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where Article 22 GDPR applies.
Contact us using the details below. We may need to verify your identity and clarify your request. We normally respond within one month, subject to extensions permitted by law. There is usually no fee, but we may charge a reasonable fee or refuse a manifestly unfounded or excessive request as permitted by law.
11. Cookies and website storage
We use limited browser storage and similar technologies for essential operation, security, language, and interface preferences. Optional technologies are used only as described in our Cookie Policy and, where required, after consent.
12. Changes to this Policy
We may update this Policy when our Service, processing, or legal obligations change. We will post the new effective date and provide additional notice where a change materially affects your rights or reasonable expectations.
13. Contact and complaints
The controller is Kogniflow AS, Rambergveien 1, 3115 Tønsberg, Norway. Send privacy questions or requests to support@kogniflow.com.
You may complain to the Norwegian Data Protection Authority (Datatilsynet) or the competent supervisory authority where you live or work. We encourage you to contact us first so we can try to resolve the concern.