Privacy Policy
Last updated: 20 July 2026
This policy is under final legal review and may be updated before it is finalised.
This Privacy Policy explains how Cogent2 Limited ("Cogent²", "we", "us") collects and uses personal data when you visit our website at cogent2.com, contact us, or use our platform and services. We are committed to protecting your personal data and handling it responsibly.
1. Who we are
Cogent² is a trading name of Cogent2 Limited, a company registered in England and Wales (company number 15512532), VAT registration number GB467500095, with its registered office at Appleton House, 25 Rectory Road, Nottingham NG2 6BE, United Kingdom. For the personal data described in this policy about website visitors, enquirers and account users, Cogent2 Limited is the data controller. You can contact us about privacy at privacy@cogent2.com.
2. Controller and processor: two roles
We handle personal data in two distinct roles:
- As a controller, for personal data about our website visitors, people who contact us, sales leads, and the users of our platform (for example their name, email address and account activity). This policy governs that data.
- As a processor, for the personal data our business customers route through our platform and services. There, our customer is the controller and we act on its instructions under a data processing agreement. That processing is governed by our Data Processing Agreement, not by this policy.
3. The personal data we collect, and why
Website visitors
When you visit cogent2.com we use essential cookies and an anti-bot check to keep the site secure and working, and, on our contact page, a functional cookie set by our third-party live-chat provider if you use the chat. We do not use third-party advertising or analytics tracking on the marketing site. See our Cookie Policy for detail.
Enquiries and sales contact
If you contact us or request information, we collect the details you provide, such as your name, email address, company and the content of your message, so we can respond and, where relevant, discuss our services with you. We rely on this to answer you and to pursue a potential business relationship.
Platform account users
If you use our platform, we collect the account and identity data needed to run it: your name, email address, the account or accounts you belong to, your role, authentication data, and records of your activity and the content you create in the product (for example prompts, chat history, saved work and support or bug reports). We use this to provide, secure, support, and improve the service, and to administer your account.
Customer data routed through the platform
When a customer connects its systems to our platform, personal data belonging to that customer's own contacts (for example order and delivery details) may pass through our service. We act as a processor for that data on the customer's instructions. By design we do not persist raw payload data from the integration platform: incoming data passes through a redaction pipeline that strips credential-shaped and PII-shaped fields before anything is stored, and we sample data structure only, never values. Files handled by our EDI service are stored whole for a short period to be validated, translated and delivered, then deleted (see section 9).
4. AI features
Some features use artificial intelligence to help interpret and answer questions about integrations. When you use these features, the content you provide (for example your question and any material you choose to include) is sent to our AI sub-processor to generate your response. That content is used only to produce your response and is not used by the AI provider to train its models under the terms we contract on. Separately, where personal data from a customer's connected systems passes through our integration platform, it goes through the redaction described in section 3 before storage. Our AI sub-processor is named on our Sub-processors page.
5. Cookies
We describe the cookies we set, and how to control them, in our Cookie Policy.
6. Our lawful bases
Where the UK GDPR or EU GDPR applies, we rely on the following lawful bases:
- Contract: to provide the platform and services to you or the organisation you belong to.
- Legitimate interests: to run, secure, and improve our website and services, to prevent abuse and fraud, and to respond to enquiries and pursue business relationships. We balance these against your rights.
- Consent: for any non-essential cookies or optional communications, where required. You can withdraw consent at any time.
- Legal obligation: to meet our legal, accounting and regulatory duties.
7. Who we share it with
We do not sell your personal data. We share it only with the sub-processors and service providers who help us run the platform, each engaged under data-protection terms. The current list, with each provider's purpose and location, is on our Sub-processors page. In addition, if you use the live chat on our contact page, your message and contact details are processed by our third-party live-chat provider so we can respond. We may also disclose personal data where required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition or sale of our business.
8. International transfers
We host our application, database and EDI file storage in the EU region. Some of our sub-processors are located in the United States. Where we transfer personal data outside the UK or EEA, we rely on an appropriate safeguard, being an adequacy decision or data-bridge where available (including the EU-US Data Privacy Framework and its UK Extension for a certified provider), or otherwise the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, together with any additional measures identified by a transfer risk assessment. Our redaction and data-minimisation measures reduce the personal data exposed in those transfers. You can request a copy of the relevant safeguards, such as the applicable Standard Contractual Clauses or the UK International Data Transfer Agreement, by emailing privacy@cogent2.com.
9. How long we keep it
We keep personal data only for as long as we need it for the purposes above, then delete or anonymise it. In practice, for example: EDI files are deleted on a rolling 30-day basis; integration run logs and history are kept for short operational windows (in the order of days to a month); AI conversation content is stripped after a limited period; and administrative and audit records are pruned on defined schedules. Records tied to a legal or regulatory obligation are kept for the period the law requires. We can provide the current retention detail on request.
10. Your rights
Subject to the applicable law, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to how we process it;
- receive your data in a portable format;
- withdraw consent where we rely on it; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise any of these, email privacy@cogent2.com. We will respond within one month, and may extend this by up to two further months for complex or high-volume requests, telling you if we do. We may need to verify your identity first.
11. Complaints
If you have a concern, please contact us first so we can try to resolve it. You also have the right to complain to a supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk). If you are in the EEA, you may complain to your local data protection authority.
12. California residents
If you are a California resident, you have rights under the California Consumer Privacy Act, as amended, including the right to know, delete, and correct your personal information, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined in that law. To exercise these rights, contact privacy@cogent2.com. We will not discriminate against you for exercising them.
13. Australia
Where the Australian Privacy Act 1988 (Cth) applies, we handle personal information in accordance with the Australian Privacy Principles, including in relation to any cross-border disclosure.
14. Children
Our website and services are intended for businesses and are not directed to children. We do not knowingly collect personal data from children.
15. Changes to this policy
We may update this policy from time to time. We will change the "last updated" date above and, where the change is significant, take reasonable steps to bring it to your attention.
16. Contact us
Cogent2 Limited, Appleton House, 25 Rectory Road, Nottingham NG2 6BE, United Kingdom.
Email: privacy@cogent2.com.