Skip to content

Legal

Privacy Policy

Last updated: September 1, 2026

CogniSuite is a platform for managing confidential M&A transaction data. We understand the sensitivity of the information you entrust to us. This policy describes how we collect, use, and protect that data.

Data Controller

Kuberno Solutions LLC
c/o Inc Authority RA
390 North Orange Ave., Ste 2300-N
Orlando, FL 32801
United States

Registered in Florida, United States

Information We Collect

Account Information

Name, business email address, organization name, and job title. This information is required to create an account and manage access to deals.

Transaction Data

Documents, requests, responses, and communications uploaded to or generated within the platform. This includes confidential M&A transaction materials, due diligence documents, and related correspondence.

Usage Data

IP addresses, access timestamps, browser type, and activity logs. This information is collected for security purposes, audit trail requirements, and service optimization.

Payment Information

Payment processing is handled by Paddle.com, the merchant of record for CogniVault orders. We do not store, process, or see credit card numbers or bank account details. We receive only subscription status, transaction confirmations, and the billing identity Paddle associates with the account.

How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the CogniSuite platform
  • Manage user accounts and access permissions
  • Generate audit trails as required by clients and regulators
  • Detect and prevent security threats
  • Comply with legal obligations
  • Send service-related communications

We do not:

  • Sell your data to third parties
  • Use transaction data for advertising
  • Train AI models on your confidential documents
  • Share data with third parties except as described in this policy

Data Sharing

We share data only in the following circumstances:

Within Deals

Transaction data is shared with authorized participants within each deal according to the access permissions configured by deal administrators.

Service Providers

We use carefully selected third-party providers for infrastructure, payment processing, and support operations. These providers are bound by data processing agreements and process data only on our instructions.

Legal Requirements

We may disclose data when required by law, court order, or governmental authority. We will notify you of such requests where legally permitted.

Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you and ensure the receiving party is bound by equivalent data protection obligations.

Data Security

We protect your data with:

  • FIPS 140-3 validated encryption for data at rest and in transit
  • Per-deal encryption keys limiting exposure in case of compromise
  • SOC 2 Type II self-assessed infrastructure and processes (independent audit planned)
  • Email one-time codes to sign in, with optional passwords. Authenticator-app MFA is not required today
  • Audit logging of access and downloads

For detailed security information, see our Security page.

Data Retention

Active accounts: Data is retained for the duration of your subscription and any active deals.

After cancellation or non-payment: Deals are archived and you have 90 days to export, including each data room's full document set. After that window, documents and deal databases are permanently deleted. Audit logs and a content manifest (file names, sizes, and folder structure — no document content) are retained for 7 years.

Account deletion: Personal data is deleted with the deal data at the end of the 90-day export window, except where we must retain it (audit logs, the content manifest, and records needed for billing disputes or law). Transaction data associated with active deals of other parties is retained per those deals' retention policies.

Backups: Deleted data may persist in encrypted backups for up to 90 days before being overwritten.

International Data Transfers

CogniSuite currently operates infrastructure in the United States (AWS us-east-1). If we process personal data of people in the EEA or United Kingdom, we rely on Standard Contractual Clauses approved by the European Commission for that transfer. Region-specific data residency is not offered on self-serve plans.

Your Rights

Under GDPR and applicable privacy laws, you have the right to:

  • Access your personal data and obtain a copy
  • Rectify inaccurate or incomplete data
  • Erase your data (subject to legal retention requirements)
  • Restrict processing in certain circumstances
  • Port your data to another service in a structured format
  • Object to processing based on legitimate interests
  • Withdraw consent where processing is based on consent

To exercise these rights, contact privacy@cognisuite.ai. We will respond within 30 days.

Cookies

We use essential cookies to maintain your session and preferences. We do not use advertising cookies or third-party tracking. Analytics, where used, are privacy-preserving and do not track individuals.

Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email to account holders. Continued use of the service after changes constitutes acceptance.

Contact

Data Protection Officer:
privacy@cognisuite.ai
+1 727 238 1189

If you are in the European Economic Area or the United Kingdom, you have the right to lodge a complaint with the data protection supervisory authority in your country.