Privacy Policy

Last updated: January 2025

1. Introduction

Cogniphai ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered pharmaceutical research platform and related services (collectively, the "Services").

This policy applies to all users of our Services, including visitors to our website, registered account holders, and organizations using our platform. By using our Services, you agree to the collection and use of information in accordance with this policy.

We are committed to compliance with applicable data protection laws, including the Health Insurance Portability and Accountability Act (HIPAA), the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant privacy regulations.

2. Information We Collect

We collect several types of information from and about users of our Services:

2.1. Information You Provide Directly

  • Account Information: Name, email address, organization name, job title, phone number, and billing information
  • Research Data: Clinical trial data, research documents, regulatory submissions, pharmaceutical data, and other content you upload or process through our platform
  • Communication Data: Information you provide when contacting us for support, including support tickets, chat transcripts, and email correspondence
  • Profile Information: Preferences, settings, and any other information you choose to provide

2.2. Information Collected Automatically

  • Usage Data: Information about how you interact with our Services, including pages visited, features used, time spent, and actions taken
  • Device Information: IP address, browser type and version, operating system, device identifiers, and mobile network information
  • Log Data: Server logs, including access times, error reports, and system performance data
  • Cookies and Tracking Technologies: See Section 9 for detailed information about our use of cookies and similar technologies

2.3. Information from Third Parties

  • Information from integrated third-party services (with your authorization)
  • Publicly available information from pharmaceutical databases and regulatory sources
  • Information from business partners and service providers

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1. Service Provision

  • Provide, maintain, and improve our AI-powered pharmaceutical research platform
  • Process and analyze your research data using our specialized AI agents
  • Enable access to features and functionality of our Services
  • Process transactions and manage your account

3.2. Communication

  • Send you technical notices, updates, security alerts, and support messages
  • Respond to your comments, questions, and requests
  • Provide customer service and technical support
  • Send marketing communications (with your consent, where required)

3.3. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), we process your personal data based on the following legal grounds:

  • Contract Performance: To fulfill our contractual obligations to you
  • Legitimate Interests: To improve our Services, ensure security, and prevent fraud
  • Consent: Where you have provided explicit consent for specific processing activities
  • Legal Obligations: To comply with applicable laws and regulations

3.4. Analytics and Improvement

  • Monitor and analyze trends, usage patterns, and activities
  • Conduct research and development to improve our AI models and Services
  • Detect, prevent, and address technical issues and security threats
  • Develop new features and functionality

Important: We do not use your proprietary research data, clinical trial information, or regulatory submissions to train our AI models. Your research data is processed solely for the purpose of providing our Services to you.

4. Data Security

We implement comprehensive, industry-standard security measures to protect your information from unauthorized access, alteration, disclosure, or destruction:

4.1. Encryption

  • Data in Transit: TLS 1.3 encryption for all data transmitted between your devices and our servers
  • Secure access controls and authentication mechanisms to protect stored data

4.2. Access Controls

  • Multi-factor authentication (MFA) for account access
  • Role-based access controls (RBAC) to limit data access to authorized personnel only
  • Regular access reviews and permission audits
  • Secure authentication mechanisms and password policies

4.3. Infrastructure Security

  • HIPAA-compliant infrastructure and processes
  • Regular security audits, vulnerability assessments, and penetration testing
  • Intrusion detection and prevention systems
  • Secure data centers with physical access controls

4.4. Monitoring and Incident Response

  • Comprehensive audit logging of all data access and modifications
  • 24/7 security monitoring and threat detection
  • Incident response procedures and breach notification protocols
  • Regular security training for all personnel

While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your information to the best of our ability.

5. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following limited circumstances:

5.1. With Your Consent

We may share your information with third parties when you have provided explicit consent for such sharing.

5.2. Service Providers

We may share information with trusted third-party service providers who assist us in operating our platform, conducting our business, or serving our users. These service providers are bound by strict confidentiality agreements and are only permitted to use your information for the specific purposes we authorize. Categories of service providers include:

  • Cloud hosting and infrastructure providers (e.g., AWS - Amazon Web Services)
  • Payment processors for billing and transaction management
  • Customer support and communication tools
  • Email service providers (e.g., AWS SES) for communications and notifications
  • Analytics and monitoring services for service improvement
  • Security and compliance services

5.3. Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, or regulatory agencies). We will only disclose the minimum amount of information necessary to comply with such requests.

5.4. Protection of Rights

We may share information to protect our rights, privacy, safety, or property, or that of our users or others, including to prevent fraud or other illegal activities.

5.5. Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information. See Section 15 for more details.

6. Your Rights

Depending on your location and applicable laws, you may have certain rights regarding your personal information. We are committed to helping you exercise these rights:

6.1. Access Rights

You have the right to access and receive a copy of your personal data that we hold. You can request access through your account settings or by contacting us at privacy@cogniphai.com.

6.2. Rectification Rights

You have the right to request correction of inaccurate or incomplete information. You can update most information directly through your account settings.

6.3. Deletion Rights

You have the right to request deletion of your personal data, subject to certain exceptions (e.g., legal obligations, ongoing contracts). We will honor deletion requests in accordance with applicable law.

6.4. Objection and Restriction Rights

You have the right to object to processing of your data or request restriction of processing in certain circumstances, such as when you contest the accuracy of your data or object to processing for direct marketing purposes.

6.5. Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another service provider, where technically feasible.

6.6. Withdrawal of Consent

Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

6.7. Exercising Your Rights

To exercise any of these rights, please contact us at privacy@cogniphai.com. We will respond to your request within 30 days and may require verification of your identity to protect your privacy. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.

7. GDPR Compliance

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable national data protection laws.

7.1. Data Controller

Cogniphai acts as a data controller for the personal information we collect and process directly from you. For certain processing activities, we may act as a data processor on behalf of your organization, in which case a separate Data Processing Agreement (DPA) will govern that relationship.

7.2. Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR:

  • Article 6(1)(b) - Contract: Processing necessary for the performance of a contract with you
  • Article 6(1)(f) - Legitimate Interests: Processing necessary for our legitimate business interests, such as improving our Services and ensuring security
  • Article 6(1)(a) - Consent: Processing based on your explicit consent
  • Article 6(1)(c) - Legal Obligation: Processing necessary to comply with legal obligations

7.3. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. See Section 10 for detailed retention periods.

7.4. Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee our data protection practices. You can contact our DPO at dpo@cogniphai.com or by mail at the address provided in Section 19.

7.5. International Transfers

When we transfer personal data from the EEA to countries outside the EEA, we ensure appropriate safeguards are in place. See Section 12 for detailed information about international data transfers.

8. HIPAA Compliance

Cogniphai is committed to compliance with the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations. When we process Protected Health Information (PHI) on behalf of covered entities or business associates, we do so in accordance with HIPAA requirements.

8.1. Business Associate Agreements

When we act as a Business Associate under HIPAA, we enter into Business Associate Agreements (BAAs) with covered entities. These agreements establish the permitted and required uses and disclosures of PHI and ensure compliance with HIPAA's Privacy and Security Rules.

8.2. Safeguards for PHI

We implement administrative, physical, and technical safeguards to protect PHI, including:

  • Access controls limiting PHI access to authorized personnel only
  • Encryption of PHI in transit
  • Audit controls to track access to PHI
  • Workforce training on HIPAA requirements
  • Policies and procedures for handling PHI

8.3. Minimum Necessary Standard

We follow the "minimum necessary" standard, accessing and using only the minimum amount of PHI necessary to accomplish the intended purpose.

8.4. Breach Notification

In the event of a breach of unsecured PHI, we will notify affected covered entities and individuals in accordance with HIPAA breach notification requirements. See Section 16 for our general breach notification procedures.

8.5. Individual Rights Under HIPAA

Individuals have certain rights regarding their PHI, including the right to access, amend, and receive an accounting of disclosures. These rights are typically exercised through the covered entity, but we will assist covered entities in fulfilling these obligations.

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect and store information about your use of our Services. This section explains what cookies are, how we use them, and your choices regarding cookies.

9.1. What Are Cookies?

Cookies are small text files that are placed on your device when you visit a website. They are widely used to make websites work more efficiently and provide information to website owners.

9.2. Types of Cookies We Use

  • Essential Cookies: Required for the Services to function properly. These cannot be disabled.
  • Functional Cookies: Remember your preferences and settings to enhance your experience.
  • Analytics Cookies: Help us understand how visitors interact with our Services to improve performance.
  • Performance Cookies: Collect information about how you use our Services to optimize functionality.

9.3. Third-Party Cookies

We may also use third-party cookies from service providers for analytics, advertising, and other purposes. These third parties may use cookies to collect information about your online activities across different websites.

9.4. Managing Cookies

Most web browsers allow you to control cookies through their settings. You can set your browser to refuse cookies or to alert you when cookies are being sent. However, disabling certain cookies may limit your ability to use some features of our Services.

Cookie expiration periods: Session cookies expire when you close your browser. Persistent cookies remain for up to 12 months, after which they are automatically deleted. You can manage cookie preferences through your browser settings.

10. Data Retention and Deletion

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

10.1. Retention Periods

  • Account Information: Retained for the duration of your account plus 7 years after account closure for legal and business purposes
  • Research Data: Retained according to your organization's data retention policies or until you request deletion, subject to legal requirements
  • Communication Records: Retained for 3 years after the last communication
  • Usage and Analytics Data: Retained in aggregated, anonymized form for 2 years
  • Legal and Compliance Records: Retained as required by applicable law, which may be 7-10 years depending on the specific legal requirement

10.2. Deletion Procedures

When you request deletion of your data or when retention periods expire, we will securely delete or anonymize your personal information using industry-standard methods. However, we may retain certain information if:

  • Retention is required by law or legal obligations
  • Retention is necessary for legitimate business purposes (e.g., resolving disputes, enforcing agreements)
  • Data has been anonymized and cannot be linked back to you

10.3. Backup and Archive Data

Data stored in backup or archive systems may be retained for additional periods but will be deleted in accordance with our retention schedule. We ensure that backup data is subject to the same security measures as active data.

11. California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with certain rights regarding your personal information.

11.1. Right to Know

You have the right to request that we disclose:

  • The categories of personal information we have collected about you
  • The categories of sources from which we collected your personal information
  • The business or commercial purpose for collecting or selling your personal information
  • The categories of third parties with whom we share your personal information
  • The specific pieces of personal information we have collected about you

11.2. Right to Delete

You have the right to request deletion of your personal information, subject to certain exceptions (e.g., completing transactions, detecting security incidents, complying with legal obligations).

11.3. Right to Opt-Out

We do not sell your personal information. If we were to sell personal information in the future, California residents would have the right to opt-out of such sales.

11.4. Non-Discrimination

We will not discriminate against you for exercising your CCPA rights, including by denying services, charging different prices, or providing a different level of service.

11.5. Exercising Your CCPA Rights

To exercise your CCPA rights, please contact us at privacy@cogniphai.com with "CCPA Request" in the subject line. We will verify your identity before processing your request and respond within 45 days (or as required by law).

12. International Data Transfers

Your information may be transferred to, and maintained on, computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from those in your jurisdiction.

12.1. Transfer Safeguards

When we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries outside these regions, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions recognizing certain countries as providing adequate data protection
  • Other legally recognized transfer mechanisms

12.2. Data Processing Locations

Our primary data processing facilities are located in the United States (specifically in AWS data centers in the US East and US West regions). We may also use service providers located in other countries. All transfers are subject to appropriate safeguards as described above.

12.3. Your Consent

By using our Services, you consent to the transfer of your information to our facilities and those of our service providers as described in this Privacy Policy.

13. Children's Privacy

Our Services are not intended for individuals under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately at privacy@cogniphai.com. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to delete that information promptly.

We comply with the Children's Online Privacy Protection Act (COPPA) and other applicable laws regarding children's privacy.

14. Third-Party Services

Our Services may contain links to third-party websites, services, or applications that are not owned or controlled by Cogniphai. This Privacy Policy does not apply to third-party services.

We are not responsible for the privacy practices of third-party services. We encourage you to review the privacy policies of any third-party services you access through our platform.

14.1. Integrated Services

We may integrate with third-party services to enhance functionality. When you authorize such integrations, you may be sharing information with those third parties. Their use of your information is governed by their own privacy policies.

14.2. Service Providers

We use third-party service providers to help us operate our Services. These providers are contractually obligated to protect your information and use it only for the purposes we specify. Categories of service providers include:

  • AWS (Amazon Web Services) for cloud hosting and infrastructure services
  • Payment processing providers for secure transaction handling
  • Email service providers (AWS SES) for communications and notifications
  • Analytics and monitoring services for service performance and security
  • Customer support platforms for assistance and issue resolution

15. Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction.

We will notify you via email and/or a prominent notice on our website of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information.

Any successor entity will be bound by the terms of this Privacy Policy and will be required to protect your information in accordance with applicable data protection laws.

16. Data Breach Notification

In the event of a data breach that compromises your personal information, we will notify affected users and relevant authorities in accordance with applicable law.

16.1. Notification Procedures

  • HIPAA Breaches: We will notify affected covered entities within 60 days as required by HIPAA
  • GDPR Breaches: We will notify relevant supervisory authorities within 72 hours and affected individuals without undue delay
  • General Breaches: We will notify affected users as required by applicable state and federal laws

16.2. Breach Response

In the event of a breach, we will:

  • Immediately investigate and contain the breach
  • Assess the scope and impact of the breach
  • Notify affected parties and authorities as required by law
  • Take steps to prevent future breaches
  • Provide information about steps affected individuals can take to protect themselves

17. Data Processing Agreements

When we process personal data on behalf of our customers (acting as a data processor), we enter into Data Processing Agreements (DPAs) that govern the processing relationship.

Our standard DPA includes provisions for:

  • Scope and purpose of processing
  • Security measures and safeguards
  • Data subject rights and assistance
  • Sub-processor requirements
  • Data breach notification procedures
  • Data return and deletion obligations

For Business Associate Agreements (BAAs) under HIPAA, please contact us at privacy@cogniphai.com.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:

  • Posting the updated Privacy Policy on this page with a new "Last updated" date
  • Sending you an email notification to the address associated with your account
  • Displaying a prominent notice on our website or through our Services

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of our Services after any changes constitutes acceptance of the updated Privacy Policy.

If we make material changes that significantly affect your rights, we will provide additional notice and, where required by law, obtain your consent.

19. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

19.1. General Privacy Inquiries

Email: privacy@cogniphai.com
Address: Cogniphai
1041 N Dupont Hwy #1556
Dover, DE 19901
United States

19.2. Data Protection Officer (GDPR)

Email: dpo@cogniphai.com
Address: Cogniphai
1041 N Dupont Hwy #1556
Dover, DE 19901
United States

19.3. Privacy Officer

Email: privacy@cogniphai.com
Address: Cogniphai
1041 N Dupont Hwy #1556
Dover, DE 19901
United States

19.4. Exercising Your Rights

To exercise your privacy rights (access, deletion, portability, etc.), please contact us at privacy@cogniphai.com with your request. We will respond within the timeframes required by applicable law.

19.5. Complaints

If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with your local data protection authority:

  • EEA: Contact your local supervisory authority (list available at edpb.europa.eu)
  • UK: Information Commissioner's Office (ICO) at ico.org.uk
  • United States: Federal Trade Commission (FTC) at ftc.gov or your state's Attorney General's office