Privacy Policy (Australia)
How we handle the information you trust us with.
Last updated: 2 September 2026
1. Who we are, scope and version
This policy is issued by Cognis SpA ("Cognis", "we", "us"), a company incorporated under the laws of the Republic of Chile, Chilean Tax ID (RUT) 78.403.042-3, with its principal place of business in Santiago, Chile. Cognis supplies AI-agent services to businesses and operates remotely from Chile. This is Version 1.0 of the Privacy Policy for Australia, in force from 2 September 2026, and it governs how Cognis handles personal information in connection with its Australian clients, the users they authorise, the visitors of cognis.cl and the individuals whose information Cognis processes on a client's behalf. Cognis handles personal information in accordance with the Australian Privacy Principles ("APPs") of the Privacy Act 1988 (Cth) to the extent they apply to it, and in any event applies the practices described in this policy. Privacy contact: antonio@cognis.cl.
2. Our two roles
Cognis acts in two distinct capacities. On our own behalf, Cognis decides how and why to handle the information of its Clients and Users (account, billing, use of the Platform) and the information of visitors of cognis.cl and of those who try the public demo. On behalf of our Clients, Cognis processes, under each Client's instructions, the information of third parties that the Client connects: the visitors of the Client's website and the authors of reviews on the Client's Google Business Profile, among the categories described in section 6. In those cases the Client is the party responsible for the information, and the relationship is governed by clause 10 of the Terms of Service (Australia).
3. Information we collect: Clients and Users
Account data: name, email address, company, role, avatar, and creation and access dates. Billing data: business name, ABN and GST registration status where provided, billing address and billing email; the payment history stores amounts, statuses and document references, never card details, which are handled directly by the payment provider. Knowledge Base: description of the business, tone, audience, products, competitors, keywords, logo, colours, catalogue and the documents the Client uploads, whose text is processed and indexed so the Agents can use it. Integration credentials: OAuth tokens and API keys, stored encrypted with AES-256-GCM. Usage and audit data: access events, actions, configurations, technical logs including IP address and browser, and notification subscriptions. Communications: conversations with Jarvis, support requests and the content of the emails Cognis sends to the Client.
4. Information we collect: visitors of cognis.cl and the demo
On cognis.cl we use Google Analytics 4 and Microsoft Clarity to understand how the site is used and to improve it; Clarity records session replays and heat maps of navigation (section 15). The language preference is kept in the browser's local storage. If a visitor uses the demo or the contact form, we collect the email address provided, the website address submitted for analysis and, depending on the form, name, phone and interest. To produce the analysis, the demo reads the public content of the site indicated, takes screenshots and processes them with artificial-intelligence models; the result is stored together with the visitor's email and in a temporary cache per analysed address. Publicly available business-level information discovered in these analyses (for example the domain, platform and social profiles of a business website) may be added to an internal business catalogue. The IP address is used only to limit abuse of the service.
5. Direct marketing and the Spam Act
Cognis does not purchase contact details of Australian individuals and does not send unsolicited commercial electronic messages to Australian addresses. Any commercial electronic message Cognis sends in connection with Australia complies with the Spam Act 2003 (Cth): it is sent with consent, identifies Cognis as the sender and contains a functional unsubscribe facility. Unsubscribe requests are processed promptly and the address is kept on a permanent suppression list whose sole purpose is to make sure it is not contacted again. Service and account emails (for example billing notices, security notices and the outputs of the Agents the Client subscribed to) are not marketing.
6. Information we handle on behalf of our Clients
Depending on the Agents and Integrations the Client activates, Cognis processes on the Client's behalf: (a) the Client's site content and store catalogue through Cognis's public Shopify app, whose permissions are limited to blog content, products, themes, discounts and files (the app does not request access to the store's customer records, orders, draft orders or checkout data, so Cognis does not receive the personal information of the Client's shoppers through it); (b) the Client's WordPress or external website, through the official Cognis plugin, which publishes posts, serves the frequently-asked-questions page and can install the Microsoft Clarity measurement snippet; (c) behaviour of the visitors of the Client's website: session replays and heat maps hosted by Microsoft Clarity, of which Cognis ingests only aggregated daily metrics, plus aggregated Google Analytics 4 metrics; (d) search queries and pages from the Client's Google Search Console; (e) public reviews of the Client's Google Business Profile, including the author's name and the text, to prepare responses that the Client controls; and (f) AI-assistant visibility measurements: to measure whether the Client's brand appears in AI assistants, Cognis sends brand- and market-related questions to AI providers (section 8); these probes carry the Client's brand and topics, not the personal information of identifiable individuals. The Client, as the party responsible for this information, defines the purposes; Cognis processes it only to deliver the contracted Service, under clause 10 of the Terms of Service (Australia). The Client is responsible for giving its own visitors and customers the privacy notices the law requires of it, in particular where Clarity session measurement is enabled on its website.
7. Why we collect, hold, use and disclose information
We collect, hold, use and disclose personal information for these purposes: to supply the Service the Client contracted, authenticate Users, provide support and send operational communications; to bill and to comply with tax and accounting obligations; to protect the security of the Platform, prevent fraud and keep audit trails; and to measure and improve cognis.cl and the Service, using aggregated or irreversibly de-identified information wherever improvement is the purpose. Cognis does not sell personal information, does not use the Knowledge Base, the Generated Content or the information processed on a Client's behalf to train general-purpose artificial-intelligence models, and does not allow its providers to do so.
8. Who we disclose information to
Cognis uses service providers that process information under its instructions, under data-processing and confidentiality agreements. For the Australian offer they are: Supabase (database and file storage, Brazil, São Paulo); Vercel (web application hosting, United States); Railway (execution of the Agents, United States); Cloudflare (network and security, United States); Anthropic (AI reasoning of the Agents, United States); OpenAI, Google, xAI and Perplexity, through Vercel AI Gateway (AI-assistant visibility probes, United States); Voyage AI (semantic indexes of the Knowledge Base, United States); Google (Search Console, Analytics 4 and Business Profile APIs, United States); Microsoft (Clarity website measurement and Bing indexing notices, United States); Shopify (the Client's store platform, Canada and United States); Resend (transactional email, United States); PayPal (subscription charges, United States and Australia); and FormSubmit (contact-form backup on cognis.cl, European Union). Web search engines used by the Agents receive only search queries, never Client data. Beyond these providers, Cognis discloses personal information only where the Client instructs it, where the individual consents, or where the law requires or permits it. Cognis gives Clients at least 15 days' notice of relevant changes to this list, per clause 10.4 of the Terms of Service (Australia).
9. Where the information lives: overseas handling
Cognis operates from Chile. The Service database and file storage are hosted by Supabase in São Paulo, Brazil. The web application and the Agents run on infrastructure of Vercel and Railway in the United States, and the other providers of section 8 operate mainly in the United States, with Shopify also in Canada and FormSubmit in the European Union. Personal information handled in connection with Australian clients is therefore held and processed outside Australia in those countries. Cognis takes the steps described in this policy to ensure those providers protect the information, including contractual data-processing terms with each provider, encryption and the security measures of section 10. In the Terms of Service (Australia), the Client expressly authorises this overseas handling for the information Cognis processes on its behalf.
10. Security
Principal measures: Integration credentials encrypted with AES-256-GCM with per-record derived keys; strict isolation between Clients through Row-Level Security in the database (multi-tenant architecture); HTTPS/TLS encryption in transit; HMAC signature verification and anti-replay protection on incoming webhooks; secure session cookies; internal access restricted to the personnel strictly necessary, with administrative actions logged; monitoring, security-event logging and periodic audits; and AI-specific defences, such as the sanitisation of instructions injected in third-party content. In case of an incident, Cognis can evidence the existence and operation of these measures.
11. Retention and deletion
Account, Knowledge Base and Generated Content: for the life of the Service and the 30-day export window after it ends. Free Trial expired without a subscription: the Service data may be permanently deleted from 7 days after the email notice. Outputs of an individually cancelled Agent: deleted from 7 days after the notice. Information processed on a Client's behalf: while the Client's Service is active, or until the Client deletes it from the Platform or asks for its deletion, without prejudice to the rights of the individuals concerned. Operation logs, sent emails and security audit trails: for the time necessary for support, security and proof of compliance. Billing and tax records: 7 years, as required by the Chilean tax law applicable to Cognis, de-identifying what is not mandatory. Suppression lists: permanent, because their sole purpose is not to contact again those who asked not to be contacted. Caches of public website information and searches: refreshed periodically, around 30 days. What is published on the Client's own infrastructure (its store, blog or Google Business Profile) remains under the Client's control.
12. Access, correction and deletion requests
Any individual may ask for access to the personal information Cognis holds about them, ask for it to be corrected, or ask for it to be deleted. How: write to antonio@cognis.cl stating your name, a means of contact and what you are asking for; Cognis may ask for reasonable verification of identity. Cognis acknowledges and responds within a maximum of 30 days. There is no charge for making a request or for correcting information; if giving access involves an exceptional effort, Cognis will tell you before any reasonable cost applies. If Cognis declines a request it will say why, in writing, and how to complain (section 18). Where the information is processed on a Client's behalf, the individual may write to the same address and Cognis will coordinate with the Client responsible to respond within the same period; the individual may also go directly to that Client. Step-by-step deletion instructions are at app.cognis.cl/data-deletion.
13. Data breaches
If a security breach occurs (destruction, leak, loss, alteration or unauthorised access to personal information), Cognis records it internally, contains it and assesses the risk. Where the breach affects information Cognis processes on a Client's behalf, Cognis notifies the Client responsible without undue delay, with the information the Client needs to meet its own obligations. Where the Notifiable Data Breaches scheme of the Privacy Act 1988 (Cth) applies and the breach is likely to result in serious harm, the Office of the Australian Information Commissioner and the affected individuals are notified as that scheme requires.
14. Automated decisions and AI
Cognis's Agents run on large language models and operate autonomously: they generate and publish content, measure visibility, propose conversion improvements and draft responses to reviews. Their logic consists of processing the Client's Knowledge Base and the connected data with AI models under rules and thresholds configured by the Client; the intended consequences are commercial and communicational. The Agents do not make decisions that produce legal effects on individuals, or that affect them in a significantly similar way, without the possibility of human intervention. Any individual may object to automated processing that affects them, ask for an explanation, express their point of view and ask for human review, by writing to antonio@cognis.cl.
15. Cookies and website analytics
On the application app.cognis.cl only strictly necessary session cookies are used, for authentication. On the site cognis.cl we additionally use Google Analytics 4 (visit and navigation measurement), Microsoft Clarity (session replays and heat maps) and the Meta pixel (measurement of the results of Cognis's own advertising) to understand how the site is used and improve it; the language preference is kept in the browser's local storage. Cognis does not sell navigation data. To limit these measurements you can configure your browser to block or delete cookies, use the Google Analytics opt-out (tools.google.com/dlpage/gaoptout) or browse with tracking protections enabled. To ask for the deletion of data associated with your navigation, write to antonio@cognis.cl.
16. Google API data: Limited Use
When the Client connects Google services, Cognis requests only the permissions needed for the function the Client activates: read-only access to Google Search Console (webmasters.readonly) to show organic performance and orient content; notification of new content for indexing (indexing); read-only access to Google Analytics 4 (analytics.readonly) for aggregated metrics; and management of the Client's Google Business Profile and its reviews. Cognis's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: Google data is used only to provide the user-facing functionality the Client requested, it is not used to train artificial-intelligence models, it is not sold, it is not used for advertising, and it is not transferred to third parties except as strictly necessary to provide that functionality, to comply with the law or with the Client's consent. Tokens are stored encrypted. The Client can revoke access at any time from the Platform or from myaccount.google.com/permissions; on disconnection the tokens are deleted immediately and the associated data is deleted within the following 30 days.
17. Shopify data
Cognis's public app for Shopify requests permissions over blog content, products, themes, discounts and files, used exclusively to operate the contracted Agents (publishing content, optimising the store and reporting to the Client). The app does not request access to customers, orders, draft orders or checkout data. Cognis does not use Shopify data for other purposes, does not share it with third parties other than the providers of section 8 and does not train AI models with it. Cognis honours Shopify's mandatory privacy webhooks: on a shopper data request (customers/data_request) it responds to the store within 30 days with whatever information exists in its systems; on an erasure order (customers/redact) it deletes any shopper data that exists within 48 hours; and when the app is uninstalled (shop/redact) it deletes the store's credentials and data within 48 hours of Shopify's notice. Given the app's limited permissions, Cognis does not expect to hold shopper personal information for Australian stores. The Client can uninstall the app at any time from its store's admin.
18. Complaints
If you believe Cognis has mishandled your personal information, write first to antonio@cognis.cl; Cognis investigates and responds within 30 days. If you are not satisfied with the response, you may complain to the Office of the Australian Information Commissioner (OAIC, www.oaic.gov.au).
19. Changes and contact
Substantial changes to this policy are notified at least 15 days in advance to the Client's registered email address and published at app.cognis.cl/en/privacy with a new date and version; previous versions are available on request. Questions, requests and complaints: antonio@cognis.cl.
Cognis SpA · Santiago, Chile