Skip to content

Legal

Privacy Policy

What CogniHR collects, why, who else touches it, and what you can ask us to do about it.

Last updated AllCognix AI Technologies Pvt Limited

1.Who we are, and which role we play

CogniHR is a hiring and HR platform operated by AllCognix AI Technologies Pvt Limited. This policy explains what we do with personal data, and it covers two different relationships.

When a company uses CogniHR to hire, that company is the controller of the candidate and employee data it puts into the platform. It decides what to collect, why, and for how long. We are its processor: we handle that data on its instructions and for no other purpose.

When you visit this website or hold a CogniHR account, we are the controller of the small amount of data that involves — your name, work email, and the record of your sign-ins.

If you are a candidate and want your data corrected or removed, the fastest route is the company you applied to; they control that record. Write to us at [email protected] and we will pass the request on and support them in fulfilling it.

2.What we collect

From account holders

  • Name, work email address and username.
  • Role and permissions within the customer's workspace.
  • Authentication events — sign-in times and the IP address a request arrived from, used for rate limiting and to investigate suspicious activity.
  • Plan, credit balance and billing history.

From candidates and employees, on a customer's behalf

  • Contact details, résumé or CV, cover letter, work history, education, skills and any profile links supplied with an application.
  • Assessment submissions, including the code written for a coding exercise, its output and the resulting score.
  • Interview scheduling details, notes and stage history.
  • Onboarding documents uploaded by or for the person — identity and eligibility documents, signed offer letters, task completion.
  • Survey responses, where a customer runs engagement or feedback surveys.

Automatically

  • Server logs: request path, response status, timing, IP address and user agent, kept for operations and abuse prevention.
  • The strictly necessary cookie described in our Cookie Policy. We do not run advertising, analytics or tracking cookies on this site.

3.Why we process it, and on what basis

  • To provide the service — running searches, sending assessment invitations, grading submissions, moving applicants through stages, generating offers and onboarding tasks. Basis: performance of our contract with the customer, and the customer's own lawful basis for the candidate data it controls.
  • To keep accounts secure — authentication, rate limiting, audit logging. Basis: legitimate interest in protecting the service and the data in it.
  • To bill — subscriptions and usage-based credits. Basis: contract and legal obligation.
  • To support customers — responding to a request that requires us to look at an account. Basis: legitimate interest.

We do not sell personal data. We do not use candidate data to train our own models, and we do not use one customer's data to serve another.

4.Automated processing and AI

Parts of the product use large language models — the in-product assistant, screening summaries, generated job descriptions and assessment questions. Content sent to those providers is limited to what the feature needs, and is sent through their API rather than a consumer product.

Coding assessments are graded by executing the submitted code against test cases in a sandbox and comparing the output. The score is a measurement, not an opinion.

No hiring decision is made by the platform. Scores, summaries and rankings are presented to a person, who decides. If a candidate wants to know how a score was reached, the customer can show the test cases and the submitted output.

5.Who we share it with

We share personal data with the subprocessors below, each engaged under a contract that restricts them to processing on our instructions. This list is current as of the date at the top of this page.

Subprocessors
SubprocessorWhat it doesWhere it processes
Amazon Web ServicesApplication and relational database hostingEU (eu-west-2, London)
MongoDB AtlasPrimary application datastore, résumé and document storagePer deployment
UpstashRedis cache, background job queue and rate limitingPer deployment
ResendTransactional email — invitations, offers, remindersUnited States / EU
StripeSubscription and credit paymentsUnited States / EU
OpenAIAssistant responses, screening summaries, generated contentUnited States
Google (Gemini)Assistant responses and content generationUnited States
Judge0Executing candidate code submissions in a sandboxUnited States / EU
TavilyWeb search used by the assistant when researching a roleUnited States
People Data LabsCandidate sourcing and profile enrichmentUnited States

Beyond these, we disclose personal data only where the law requires it, or to protect the rights and safety of people using the service. If we are ever compelled to hand over customer data, we will tell the customer unless we are legally barred from doing so.

If we are acquired or merge, data may transfer as part of that transaction. Customers will be told before it happens and before any change of purpose.

6.International transfers

Some subprocessors process data outside the country where it was collected, including in the United States. Where personal data leaves the UK or the European Economic Area, we rely on the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, together with the technical measures described in our Security page. A customer who needs data to stay in one region should raise it before signing; deployment location is configurable.

7.How long we keep it

Customers control the retention of the records they upload and can delete them at any time. Our own defaults, which apply where the customer has not set something shorter:

Retention periods
DataKept for
Applicant records and résumésFor as long as the customer's account is active, then 90 days after termination
Assessment submissions and scoresSame as the applicant record they belong to
Onboarding documentsFor the duration of employment, unless the customer deletes them sooner
Account and authentication recordsFor as long as the account exists, then 90 days
Audit and delivery logs13 months
Billing recordsAs required by tax law, typically 7 years

Deleted records are removed from the live system immediately and from backups within 35 days.

8.Your rights

Depending on where you live, you may have the right to:

  • Ask what personal data is held about you, and get a copy.
  • Have inaccurate data corrected.
  • Have data erased, where there is no overriding obligation to keep it.
  • Object to or restrict processing based on legitimate interest.
  • Receive your data in a portable format.
  • Withdraw consent, where processing relies on consent.
  • Complain to your data protection authority.

To exercise any of these against a CogniHR account, write to [email protected]. We respond within 30 days. If the request concerns data a customer uploaded, we will route it to that customer, because they hold the decision.

9.Children

CogniHR is a workplace product and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child's data has reached the platform, write to [email protected] and we will remove it.

10.Changes to this policy

When this policy changes, the date at the top of the page changes with it. For a change that materially affects how we handle personal data, we will notify account holders by email at least 30 days before it takes effect.

Questions about this policy

Write to [email protected] and we will respond within 30 days. For anything that needs a conversation, the contact page reaches the same team.