Last updated: 13 July 2026
Cognidox Limited is the data controller responsible for the personal data described in this policy. We are a document management software company based in Cambridge, UK, and a wholly owned subsidiary of Recur Software Technologies Inc.
Cognidox Limited
Eagle Labs, 28 Chesterton Road
Cambridge CB4 3AZ, United Kingdom
Company Number: 06506232
ICO Registration Number: ZA4444747
Data protection contact: privacy@cognidox.com
Information submitted through our website forms, demo requests, support channels, or contractual engagement, including your name, email address, job title, company name, phone number, and message content. Where you speak with our sales or account team by video call, we (or our call-recording provider) record and transcribe the call. We tell you this before the call takes place, and you can ask us not to record.
When you visit our website, we may collect technical data including your IP address, browser type, device information, pages visited, time on site, and interaction data. This is collected through cookies and similar technologies (see Section 7).
We may receive personal data from business contact databases, publicly available professional profiles (such as LinkedIn), event organisers, and referral partners. This includes sales-intelligence and data-enrichment providers (such as Apollo and Clay), and in some cases business email addresses are inferred rather than provided by you. Where we obtain data from third-party sources, we will inform you of the source within a reasonable period and no later than one month. We provide this information at first contact through our first contact privacy notice.
The following table sets out our processing purposes and the legal basis for each. Where we rely on legitimate interests, we have conducted a balancing assessment, and you may request a copy by contacting us.
|
Legal Basis |
Purpose |
UK GDPR Article |
|
Contract |
Providing our services, managing accounts, processing orders |
Article 6(1)(b) |
|
Legitimate interests |
B2B marketing where reasonably expected; improving services; analytics; fraud prevention; analysing customer and deal records, including call transcripts and notes, to build customer archetypes and an Ideal Customer Profile that inform our marketing and outbound strategy (this analysis may, on this occasion or from time to time, be carried out by Recur Software Technologies Inc, our US parent company |
Article 6(1)(f) |
|
Consent |
Marketing emails to individuals (where soft opt-in does not apply); non-essential cookies |
Article 6(1)(a) |
|
Legal obligation |
Tax, accounting, and regulatory compliance |
Article 6(1)(c) |
|
Recognised legitimate interests |
Processing within DUAA 2025 specified purposes, where applicable |
Article 6(1) as amended |
For email marketing to individual subscribers, we comply with the Privacy and Electronic Communications Regulations (PECR) 2003. Where you are an existing customer and we are marketing similar products or services, we may rely on the soft opt-in exemption. Where we send business-to-business marketing to corporate subscribers (such as limited companies and limited liability partnerships), PECR permits this without prior consent, and we always identify ourselves and give you an easy way to opt out. Where you are an individual subscriber (such as a sole trader, an unincorporated partnership, or a personal email address), we rely on your consent or the soft opt-in. You can unsubscribe at any time.
We never sell your personal data. We share it with the following categories of recipients; all bound by data processing agreements:
We conduct vendor security assessments before engaging any new processor.
Some of our service providers are based outside the UK and EEA. Where we transfer personal data internationally, we ensure appropriate safeguards are in place, including:
We conduct transfer risk assessments in line with ICO guidance.
We retain personal data only for as long as necessary, or as required by law.
|
Data Category |
Retention Period |
|
Marketing contact data |
24 months after the last meaningful engagement |
|
Customer account data |
Duration of contract plus 6 years |
|
Support and correspondence records |
3 years from last interaction |
|
Website analytics data |
24 months |
|
Financial and invoicing records |
7 years (legal requirement) |
At the end of the applicable retention period, personal data is securely deleted or anonymised.
For our outbound prospecting, we apply the following retention periods: cold prospect data is deleted after 12 months with no engagement, and call recordings (audio) are deleted after 90 days. How long we keep the transcript and notes of a call depends on why it took place: if you are a prospect and do not go on to have a business relationship with us, we delete the transcript within 24 months; if you are, or become, a customer, we keep the transcript and notes for the duration of our relationship and for up to 6 years afterwards, to manage that relationship and to meet our legal, regulatory, contractual and accounting obligations and to resolve any disputes. Separately, we keep a minimal suppression record indefinitely so that we do not contact you again after you opt out. Where we share customer and deal data, including call transcripts and notes, with Recur Software Technologies Inc for go-to-market analysis, Recur retains that data only for the duration of that work and deletes it within 30 days of it ending. Aggregate outputs that contain no personal data may be retained by Recur afterwards .
This section explains how we use cookies and similar technologies on cognidox.com. It covers what cookies are, which ones we use, why we use them, and how you can control them. This section fulfils our obligations under the Privacy and Electronic Communications Regulations (PECR) as amended by the Data (Use and Access) Act 2025.
Cookies are small text files placed on your device when you visit a website. They allow the site to recognise your device and remember information about your visit. PECR also applies to similar technologies such as tracking pixels, local storage, and device fingerprinting. In this policy, we use the term “cookies” to cover all of these.
We group the cookies on our website into the following categories:
|
Category |
What they do |
Consent required? |
Examples |
|
Strictly necessary |
Essential for the website to function, such as session management, security, and load balancing. Without these, the site would not work properly. |
No |
Session cookies, CSRF tokens |
|
Analytics |
Help us understand how visitors use our website by collecting information about pages visited, time on site, and navigation paths. Where these are first-party, anonymised, and used solely for statistical purposes, they may qualify for the DUAA 2025 analytics exemption. |
See note below |
Google Analytics, HubSpot analytics |
|
Marketing |
Used to track visitors across websites, deliver targeted advertising, and measure campaign effectiveness. |
Yes - always |
HubSpot tracking, ad platform cookies |
|
Functionality |
Remember choices you make such as language preferences or region settings to provide a more personalised experience. |
No (if adapting to device preferences only) |
Language, region preferences |
The Data (Use and Access) Act 2025 introduced a new exemption for analytics cookies used solely for statistical purposes. Where our analytics cookies meet the following conditions, we may use them without consent:
Where analytics cookies do not meet all of these conditions (for example, where they feed into advertising targeting or cross-site tracking), we will obtain your consent before activating them.
If you wish to object to our use of analytics cookies that operate under this exemption, you can do so through the cookie settings on our website or by contacting us at security@cognidox.com.
When you first visit our website, you will see a cookie banner that lets you choose whether to accept or reject non-essential cookies. The banner provides equal prominence to both options, as required by PECR.
You can change your preferences at any time by clicking the cookie settings link in the footer of our website. You can also control cookies through your browser settings, though this may affect how some features work.
We do not use cookie walls. You can access our website and its content regardless of whether you accept or reject non-essential cookies.
Some cookies on our website are set by third-party services that we use, such as HubSpot and Google Analytics. These third parties may collect information about your activity on our site and across other websites. We are responsible under PECR for cookies that we instigate, even where they are technically set by a third party.
For information about how these third parties handle your data, please refer to their own privacy policies.
Session cookies are deleted when you close your browser. Persistent cookies remain on your device for a set period or until you delete them. Our analytics cookies are retained for up to 24 months. Marketing cookies set by third parties are subject to the retention periods specified in their own policies.
We implement appropriate technical and organisational measures to protect personal data, including:
We also analyse the personal data we hold about our customers and prospects, including the substance of sales and account calls captured in call transcripts and notes, to build company-level customer archetypes and an Ideal Customer Profile. This analysis may, on this occasion or from time to time, be carried out by Recur Software Technologies Inc, our US parent company, using AI-assisted analysis tools, and produce aggregate, company-level profiles rather than any decision about you personally.
Under UK GDPR, you have the following rights:
To exercise any right, contact privacy@cognidox.com. We will respond within one month.
If you are dissatisfied with how we handle your data, please contact us first at privacy@cognidox.com. We operate a formal procedure for handling data protection complaints, and we will acknowledge your complaint promptly and respond without undue delay. You also have the right to complain to the Information Commissioner's Office:
Information Commissioner’s Office
Wycliffe House, Water Lane,
Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk | Telephone: 0303 123 1113
In the event of a personal data breach posing a risk to your rights and freedoms, we will notify the ICO without undue delay and within 72 hours where feasible. Where the breach is likely to result in a high risk, we will also notify affected individuals directly.
Our website may contain links to third-party sites. We are not responsible for their privacy practices and encourage you to read their policies before providing personal data.
Our services are designed for business use and are not directed at children under 18. We do not knowingly collect personal data from children.
We may update this policy from time to time. Material changes will be communicated through our website. The date at the top indicates when it was last updated.
Applicable legislation: UK GDPR | Data Protection Act 2018 | PECR | Data (Use and Access) Act 2025
Receive instant blog updates, straight to your inbox
Copyright 2026 Cognidox Ltd | Company Number: 06506232 | VAT number: GB 930970714