Privacy & Cookie Policy

How Cognidox handles your personal data and uses cookies

Last updated: 13 July 2026

1. Who We Are

Cognidox Limited is the data controller responsible for the personal data described in this policy. We are a document management software company based in Cambridge, UK, and a wholly owned subsidiary of Recur Software Technologies Inc.

Cognidox Limited
Eagle Labs, 28 Chesterton Road
Cambridge CB4 3AZ, United Kingdom

Company Number: 06506232
ICO Registration Number: ZA4444747
Data protection contact: privacy@cognidox.com

2. What We Collect

Information you provide directly

Information submitted through our website forms, demo requests, support channels, or contractual engagement, including your name, email address, job title, company name, phone number, and message content. Where you speak with our sales or account team by video call, we (or our call-recording provider) record and transcribe the call. We tell you this before the call takes place, and you can ask us not to record.

Information collected automatically

When you visit our website, we may collect technical data including your IP address, browser type, device information, pages visited, time on site, and interaction data. This is collected through cookies and similar technologies (see Section 7).

Information from third parties

We may receive personal data from business contact databases, publicly available professional profiles (such as LinkedIn), event organisers, and referral partners. This includes sales-intelligence and data-enrichment providers (such as Apollo and Clay), and in some cases business email addresses are inferred rather than provided by you. Where we obtain data from third-party sources, we will inform you of the source within a reasonable period and no later than one month. We provide this information at first contact through our first contact privacy notice.

3. Why We Use It and Our Legal Basis

The following table sets out our processing purposes and the legal basis for each. Where we rely on legitimate interests, we have conducted a balancing assessment, and you may request a copy by contacting us.

 

Legal Basis

Purpose

UK GDPR Article

Contract

Providing our services, managing accounts, processing orders

Article 6(1)(b)

Legitimate interests

B2B marketing where reasonably expected; improving services; analytics; fraud prevention; analysing customer and deal records, including call transcripts and notes, to build customer archetypes and an Ideal Customer Profile that inform our marketing and outbound strategy (this analysis may, on this occasion or from time to time, be carried out by Recur Software Technologies Inc, our US parent company 

Article 6(1)(f)

Consent

Marketing emails to individuals (where soft opt-in does not apply); non-essential cookies

Article 6(1)(a)

Legal obligation

Tax, accounting, and regulatory compliance

Article 6(1)(c)

Recognised legitimate interests

Processing within DUAA 2025 specified purposes, where applicable

Article 6(1) as amended

 

For email marketing to individual subscribers, we comply with the Privacy and Electronic Communications Regulations (PECR) 2003. Where you are an existing customer and we are marketing similar products or services, we may rely on the soft opt-in exemption. Where we send business-to-business marketing to corporate subscribers (such as limited companies and limited liability partnerships), PECR permits this without prior consent, and we always identify ourselves and give you an easy way to opt out. Where you are an individual subscriber (such as a sole trader, an unincorporated partnership, or a personal email address), we rely on your consent or the soft opt-in. You can unsubscribe at any time.

4. Who We Share It With

We never sell your personal data. We share it with the following categories of recipients; all bound by data processing agreements:

  • CRM and marketing platforms (currently HubSpot)
  • Website hosting and infrastructure providers
  • Analytics services
  • Email delivery services
  • Sales-intelligence and data-enrichment providers
  • Email-sending infrastructure providers
  • Workflow automation providers
  • AI providers used to help draft and analyse communications.
  • Professional advisers (legal, accounting, audit)
  • Recur Software Technologies Inc (our parent company) for group administration, and to analyse customer and deal data, including call transcripts and notes, to shape our marketing and go-to-market strategy. 

We conduct vendor security assessments before engaging any new processor.

5. International Transfers

Some of our service providers are based outside the UK and EEA. Where we transfer personal data internationally, we ensure appropriate safeguards are in place, including:

  • UK adequacy regulations recognising the destination as providing adequate protection
  • The UK International Data Transfer Agreement (IDTA)
  • Standard Contractual Clauses approved by the UK Information Commissioner
  • The UK Extension to the EU-US Data Privacy Framework (where applicable)

We conduct transfer risk assessments in line with ICO guidance.

6. How Long We Keep It

We retain personal data only for as long as necessary, or as required by law.

Data Category

Retention Period

Marketing contact data

24 months after the last meaningful engagement

Customer account data

Duration of contract plus 6 years

Support and correspondence records

3 years from last interaction

Website analytics data

24 months

Financial and invoicing records

7 years (legal requirement)

At the end of the applicable retention period, personal data is securely deleted or anonymised.

 For our outbound prospecting, we apply the following retention periods: cold prospect data is deleted after 12 months with no engagement, and call recordings (audio) are deleted after 90 days. How long we keep the transcript and notes of a call depends on why it took place: if you are a prospect and do not go on to have a business relationship with us, we delete the transcript within 24 months; if you are, or become, a customer, we keep the transcript and notes for the duration of our relationship and for up to 6 years afterwards, to manage that relationship and to meet our legal, regulatory, contractual and accounting obligations and to resolve any disputes. Separately, we keep a minimal suppression record indefinitely so that we do not contact you again after you opt out. Where we share customer and deal data, including call transcripts and notes, with Recur Software Technologies Inc for go-to-market analysis, Recur retains that data only for the duration of that work and deletes it within 30 days of it ending. Aggregate outputs that contain no personal data may be retained by Recur afterwards .

7. Cookies and Similar Technologies

 This section explains how we use cookies and similar technologies on cognidox.com. It covers what cookies are, which ones we use, why we use them, and how you can control them. This section fulfils our obligations under the Privacy and Electronic Communications Regulations (PECR) as amended by the Data (Use and Access) Act 2025.

7.1 What are cookies?

 Cookies are small text files placed on your device when you visit a website. They allow the site to recognise your device and remember information about your visit. PECR also applies to similar technologies such as tracking pixels, local storage, and device fingerprinting. In this policy, we use the term “cookies” to cover all of these.

7.2 Categories of cookies we use

We group the cookies on our website into the following categories:

Category

What they do

Consent required?

Examples

Strictly necessary

Essential for the website to function, such as session management, security, and load balancing. Without these, the site would not work properly.

No

Session cookies, CSRF tokens

Analytics

Help us understand how visitors use our website by collecting information about pages visited, time on site, and navigation paths. Where these are first-party, anonymised, and used solely for statistical purposes, they may qualify for the DUAA 2025 analytics exemption.

See note below

Google Analytics, HubSpot analytics

Marketing

Used to track visitors across websites, deliver targeted advertising, and measure campaign effectiveness.

Yes - always

HubSpot tracking, ad platform cookies

Functionality

Remember choices you make such as language preferences or region settings to provide a more personalised experience.

No (if adapting to device preferences only)

Language, region preferences

 

7.3 Analytics cookies and the DUAA 2025 exemption

The Data (Use and Access) Act 2025 introduced a new exemption for analytics cookies used solely for statistical purposes. Where our analytics cookies meet the following conditions, we may use them without consent:

  • They are used only to collect statistical information about how visitors use our website
  • The information collected is not combined with other data to identify individuals
  • The information is not shared with third parties for their own purposes
  • We provide you with a simple and free way to object

Where analytics cookies do not meet all of these conditions (for example, where they feed into advertising targeting or cross-site tracking), we will obtain your consent before activating them.

If you wish to object to our use of analytics cookies that operate under this exemption, you can do so through the cookie settings on our website or by contacting us at security@cognidox.com.

7.4 How to manage your cookie preferences

When you first visit our website, you will see a cookie banner that lets you choose whether to accept or reject non-essential cookies. The banner provides equal prominence to both options, as required by PECR.

You can change your preferences at any time by clicking the cookie settings link in the footer of our website. You can also control cookies through your browser settings, though this may affect how some features work.

We do not use cookie walls. You can access our website and its content regardless of whether you accept or reject non-essential cookies.

7.5 Third-party cookies

Some cookies on our website are set by third-party services that we use, such as HubSpot and Google Analytics. These third parties may collect information about your activity on our site and across other websites. We are responsible under PECR for cookies that we instigate, even where they are technically set by a third party.

For information about how these third parties handle your data, please refer to their own privacy policies.

7.6 How long do cookies last?

Session cookies are deleted when you close your browser. Persistent cookies remain on your device for a set period or until you delete them. Our analytics cookies are retained for up to 24 months. Marketing cookies set by third parties are subject to the retention periods specified in their own policies.

8. Data Security

We implement appropriate technical and organisational measures to protect personal data, including:

  • Encryption of data in transit (TLS) and at rest, where appropriate
  • Role-based access controls and multi-factor authentication
  • Regular security monitoring and vulnerability assessments
  • Vendor security assessments for all processors
  • Staff training on data protection and information security
  • Incident response procedures

9. Profiling

We also analyse the personal data we hold about our customers and prospects, including the substance of sales and account calls captured in call transcripts and notes, to build company-level customer archetypes and an Ideal Customer Profile. This analysis may, on this occasion or from time to time, be carried out by Recur Software Technologies Inc, our US parent company, using AI-assisted analysis tools, and produce aggregate, company-level profiles rather than any decision about you personally.

10. Your Rights

Under UK GDPR, you have the following rights:

  • Access: obtain a copy of the personal data we hold about you
  • Rectification: correct inaccurate or incomplete data
  • Erasure: request deletion of your data in certain circumstances
  • Restriction: limit how we use your data
  • Portability: receive your data in a structured, machine-readable format
  • Objection: object to processing based on legitimate interests or for direct marketing
  • Withdraw consent: withdraw at any time without affecting the lawfulness of prior processing

To exercise any right, contact privacy@cognidox.com. We will respond within one month.

11. Complaints

If you are dissatisfied with how we handle your data, please contact us first at privacy@cognidox.com. We operate a formal procedure for handling data protection complaints, and we will acknowledge your complaint promptly and respond without undue delay. You also have the right to complain to the Information Commissioner's Office:

Information Commissioner’s Office
Wycliffe House, Water Lane,
Wilmslow, Cheshire SK9 5AF

Website: ico.org.uk | Telephone: 0303 123 1113

12. Data Breaches

In the event of a personal data breach posing a risk to your rights and freedoms, we will notify the ICO without undue delay and within 72 hours where feasible. Where the breach is likely to result in a high risk, we will also notify affected individuals directly.

13. Third-Party Links

Our website may contain links to third-party sites. We are not responsible for their privacy practices and encourage you to read their policies before providing personal data.

14. Children’s Data

Our services are designed for business use and are not directed at children under 18. We do not knowingly collect personal data from children.

15. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated through our website. The date at the top indicates when it was last updated.


Applicable legislation: UK GDPR | Data Protection Act 2018 | PECR | Data (Use and Access) Act 2025