Effective Date:
1. Controller and Scope
Coznix builds AI-powered software for knowledge-heavy operations. For data collected through this website and our marketing, Coznix is the data controller. When we process data inside a client's systems during a paid engagement, we act as a data processor on that client's behalf, governed by the engagement contract rather than this policy. Email us if you need our registered entity details and postal address for a formal request.
2. Information We Collect
- Name, email, and company: when you contact us, book a call, subscribe to our newsletter, or request a resource such as a guide or PDF.
- Your enquiry: the description you give of the problem you want solved.
- Client and project data: during an engagement: documentation, business process detail, and any credentials or access you provide.
- Billing details: company and contact information needed to invoice. Card and bank details are handled by our payment provider, not stored by us.
- Technical data: IP address, browser and device type, referring page, and pages visited, from normal server logs.
We do not seek out special-category data (health, biometric, political) and ask that you not send it. Credentials you share during an engagement are treated as sensitive: restricted to those who need them, and our access is removed when the work ends. We do not knowingly collect data from children under 16.
3. How We Use It
To respond to your enquiry and hold the conversation you requested; deliver the resource you asked for; send our newsletter where you subscribed; scope, deliver, and support engagements; invoice and keep required accounting records; operate, secure, and improve our website; and meet legal obligations.
Legal bases (GDPR): consent for marketing email and non-essential cookies; contract for services and resources you requested; legitimate interests for security, improvement, and business-to-business outreach relevant to your role; legal obligation for record-keeping.
We do not sell your personal information, do not share it for cross-context behavioural advertising, and do not use your data (or client data shared with us) to train our own or any third party's AI models.
4. Your Email Address
When you give us your email address: we will not sell, rent, lease, or trade it (the only exception is the business-transfer case in Section 6, where this policy continues to apply); we send only content relevant to what you requested; newsletter signup uses double opt-in; and every marketing email carries a working unsubscribe link. Unsubscribing does not stop transactional email such as invoices and project updates.
5. AI and Automated Processing
Our work is AI-focused, so to be explicit: we use third-party AI and LLM providers to build and operate client solutions. Where a solution routes data to such a provider, that flow is documented in the engagement and covered by a data processing agreement where required. We do not make automated decisions with legal or similarly significant effects on you without human involvement. Any chat assistant on this site is informational; do not enter confidential information or credentials into it.
8. International Transfers
We serve clients across North America, Europe, MENA, and Asia, so your data may be processed outside your country, including in the United States. Where GDPR or UK GDPR data leaves the EEA or UK, we rely on an appropriate transfer mechanism, usually the European Commission's Standard Contractual Clauses or an adequacy decision.
9. Retention
Enquiries that do not become engagements: up to 24 months. Newsletter subscribers: until you unsubscribe, plus a suppression record. Client and project records: through the engagement and any applicable support and legal claim periods. Invoices: as required by tax law. Server logs: a short rolling window, typically no more than 12 months.
10. Security
We use measures appropriate to the risk: encryption in transit, least-privilege access, restricted handling of client credentials, and confidentiality obligations on our team and subcontractors. No internet transmission or storage is 100% secure, so while we use commercially reasonable means to protect your data we cannot guarantee absolute security. We will notify you and the relevant authorities of a breach where the law requires it.
11. Your Rights
EEA/UK (GDPR): access, rectification, erasure, restriction of processing, objection to processing and to direct marketing, data portability, withdrawal of consent, and the right to complain to your local data protection authority.
California (CCPA/CPRA): the right to know what we collect and how we use and disclose it; to delete; to correct; to opt out of sale or sharing for cross-context behavioural advertising (we do neither); to limit use of sensitive personal information (we use it only to perform the services requested); and not to be discriminated against for exercising these rights. Authorised agents may act for you. Other US state privacy laws grant comparable rights, which we honour on the same basis.
Email info@coznix.com to exercise any right. We verify the request and respond within one month (GDPR) or 45 days (CCPA/CPRA), extendable where the law allows. Requests are free unless manifestly unfounded or excessive.
12. Third-Party Links
Our site may link to tools and sites we do not control. This policy does not cover them; read their policies before sharing information.
13. Changes
We may update this policy and will post the new version here with a revised effective date, communicating material changes more prominently where appropriate. Changes take effect when posted.
14. Contact
Email: info@coznix.com; Web: https://coznix.com/contact