Privacy Policy

Effective date: 1 July 2026 Version: 1.0

1. Who we are

Carys is an AI-powered analytics assistant operated by Cogitait Ltd ("Cogitait", "we", "us", "our"), a company registered in England and Wales.

Company Cogitait Ltd
Company number 15885573
Registered office 20 Wenlock Road, London, England, N1 7GU
Privacy contact info@cogitait.com
Telephone +44 (0) 20 3411 1990

For the personal data described in this policy, Cogitait Ltd is the data controller (UK GDPR and EU GDPR) and the responsible party (South Africa's POPIA).

Where you access Carys through an organisation that holds its own account with us (your employer or another business), that organisation controls the business data it connects to the platform, and this policy explains how we handle personal data as part of providing the service to them.

2. Scope

This policy applies to personal data we process when you:

It is written to meet our obligations under the UK GDPR and the Data Protection Act 2018, the EU GDPR, and South Africa's Protection of Personal Information Act, 2013 (POPIA). Where these laws differ, the stricter requirement applies.

This policy does not cover the underlying business datasets that a customer organisation connects to Carys for analysis. That data belongs to the customer, who determines how it is used; we process it only on their behalf and under our agreement with them (see §4 and §11).

3. The personal data we collect

Account and profile data — your name, work email address, organisation, role, and the credentials used to sign in.

Usage data — records of how you use the platform: the questions you ask, analyses you run, reports and exports you generate, actions you track, and related activity and audit logs. These allow us to operate the service, meter usage and credits, provide support, and improve the product.

Support and communications data — the content of messages you send us, and correspondence relating to enquiries, demos, and support.

Technical data — information your browser and device provide when you connect, such as IP address, device and browser type, and timestamps, together with the strictly necessary cookies described in §10.

Content you submit — the text of the questions and instructions you enter, which may incidentally contain personal data if you choose to include it.

We do not deliberately collect special-category data (for example health, race, or political views) as part of running the platform, and we ask that you do not enter such data into questions or connect it in a way that isn't necessary for your analysis.

We do not knowingly process the personal data of children; the platform is a business tool not directed at anyone under 18 (see §12).

4. How we use personal data, and our lawful bases

What we do Why Lawful basis (UK/EU GDPR)
Create and administer your account; authenticate you To provide the platform to you and your organisation Performance of a contract; legitimate interests
Run analyses, generate reports, meter usage and credits Core delivery of the service Performance of a contract
Keep the platform secure; maintain audit and access logs; prevent abuse To protect the service, our customers, and their data Legitimate interests; legal obligation
Provide support and respond to enquiries To help you and manage our relationship with you Performance of a contract; legitimate interests
Improve and develop the product To make Carys more useful and reliable Legitimate interests
Send service and administrative messages To keep you informed about the service you use Performance of a contract; legitimate interests
Comply with legal, tax, and regulatory duties Because the law requires it Legal obligation

Under POPIA, we process personal information because it is necessary to conclude or perform under a contract with you or your organisation, to pursue our legitimate interests, to comply with a legal obligation, or with your consent, in line with POPIA's conditions for lawful processing.

Where we rely on legitimate interests, we have balanced those interests against your rights and are satisfied the processing is proportionate. You can ask us for more detail, and you can object (see §9).

AI processing and your data

Carys uses AI models to analyse data and produce reports. Two commitments matter here:

5. Who we share personal data with

We do not sell your personal data. We share it only as needed to run the service, and always under appropriate contracts:

Each of these providers acts as our processor (POPIA: operator), processing personal data only on our documented instructions. A current list of the specific sub-processors we use is published at /sub-processors.

6. International transfers

We are based in the UK, and some of our providers operate in other countries, so your personal data may be transferred outside the UK, the EEA, or South Africa. When it is, we make sure it stays protected using a lawful transfer mechanism:

You can ask us for a copy of the relevant safeguards using the contact details in §1.

7. How long we keep personal data

We keep personal data only for as long as we need it:

When personal data is no longer needed, we delete it or irreversibly anonymise it. Specific retention periods are set out in our agreement with your organisation and are available on request.

8. How we protect personal data

Security is built into the platform. Our measures include encryption of data at rest and in transit, complete separation between customer organisations, role-based access control, invitation-only access with mandatory email verification, short-lived and rotated session tokens, network isolation of internal systems, continuous security scanning, and audit logging of key actions. Analytical work runs in isolated, temporary environments that are destroyed as soon as the work is done. No system is perfectly secure, but we work continuously to protect your data and to meet our legal obligations.

9. Your rights

Subject to the conditions and exemptions in the applicable law, you have the right to:

Under POPIA, you also have the right to object to processing, to request correction or deletion, and to submit a complaint to the Information Regulator; and you may not be subjected to unfair discrimination for exercising your rights.

To exercise any of these rights, contact us at info@cogitait.com. If you access Carys through your organisation, we may direct your request to them as the controller of their business data, or ask them to help us respond. We will respond within the timeframe the law requires and will not charge a fee unless the law allows it.

10. Cookies

Carys uses strictly necessary cookies only — the cookies required to sign you in, keep your session secure, and remember essential preferences. We do not use advertising, tracking, or third-party analytics cookies on the platform, so no cookie consent banner is required for it. Because these cookies are essential to the service, they cannot be switched off without breaking core functionality. If we introduce any non-essential cookies in future, we will update this policy and ask for your consent first.

11. If you use Carys through your organisation

When you use Carys as part of an organisation's account, that organisation is the controller of the business data it connects and of your use of the platform within its account. Your organisation's own privacy notice governs how it handles your data. For requests about that business data, please contact your organisation; we will support them as their processor.

12. Children

Carys is a business tool and is not intended for, or directed at, children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

13. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you. Please review it periodically.

14. How to contact us and how to complain

For any privacy question, or to exercise your rights, contact us at:

Cogitait Ltd — info@cogitait.com 20 Wenlock Road, London, England, N1 7GU

EU/EEA representative (GDPR Article 27): Clive Killops (Ireland), c/o Cogitait Ltd — info@cogitait.com. Individuals in the EU/EEA may contact our representative on any matter relating to the processing of their personal data.

If you are not satisfied with our response, you have the right to complain to a supervisory authority:

We would, however, appreciate the chance to address your concerns before you approach a regulator, so please do contact us first.