Privacy Policy
Last updated 30 July 2026 · review with a solicitor before launch
This policy explains what personal data Cognito Capital collects, why, and the rights you have under the EU General Data Protection Regulation (GDPR). Cognito Capital, based in Ireland, is the data controller.
1. Data we collect
- Account details you provide: name, email and sign-in method.
- Contact, newsletter and assessment enquiries, stored in our database.
- Subscription and payment records (processed by our payment provider; we do not store full card numbers).
- Limited technical data, including the network address used at sign-up, to enforce one account per person and per network.
- Identity and source-of-funds documentsfor transactions of €3,000 or more (passport or driver’s licence, and evidence of the source of funds), which we are required to collect under anti-money-laundering law.
2. Why we use it
To provide and secure the services, process payments, respond to you, run the products you use, and meet our legal obligations, including anti-money-laundering and record-keeping duties.
3. Who processes data for us
We use trusted providers who process data on our behalf:
- Clerk — account authentication.
- Stripe — payments (once enabled).
- Neon — database hosting (EU/US regions).
- Netlify / hosting — serving the site.
- An email provider for transactional and newsletter email.
Each has its own privacy terms and processes data under agreement with us.
4. Your rights
You can access, correct, download or delete the personal data on your account. Download and deletion are available from your account page; other requests can be made through the contact form. You may also object to or restrict certain processing, and complain to the Irish Data Protection Commission.
One exception: identity and source-of-funds documents collected for anti-money-laundering reasons must be kept for the period the law requires (generally five years), even if you delete your account. We remove them once that period ends.
5. Retention
We keep personal data only as long as needed for the purposes above or as the law requires, then delete it. AML records follow the statutory retention period noted above.
6. Security
Access is authenticated, sensitive actions are logged, verification documents are stored with restricted access, and data is transmitted over encrypted connections.
7. Cookies
We use only the cookies needed to run the site and keep you signed in. We do not sell your data.
8. Contact
For any privacy request or question, use the contact form on this site.