Privacy Notice
Last updated 3 October 2026
Cognix is a small software studio based in Hyderabad, India. We collect very little about you, we use it only to answer your enquiry and deliver work you ask for, and we do not sell it. This notice explains exactly what that means in practice.
The short version: when you send the enquiry form we store what you typed, plus the timestamp and IP address, so we can reply and so we can tell real enquiries apart from spam. That is it. There are no advertising or tracking cookies on this site.
1. Who is responsible for your data
The data controller is Cognix, Hyderabad, Telangana, India, operated by Mohammed Anas, Founder. For any question about this notice, or to exercise any of the rights in section 8, write to cognix.info@gmail.com.
We are a sole-founder studio, not a large organisation. Correspondence about privacy goes to the founder directly and is answered personally.
2. What we collect and why
| What we collect | Why we collect it | Basis |
|---|---|---|
| Name | So we know who we are replying to | Your consent (you typed it and ticked the box) |
| Email address | To reply to your enquiry | Your consent |
| Company name (optional) | To understand your context before the call | Your consent |
| Phone number (optional) | Only if you choose WhatsApp or a phone call as your reply channel. Never required. | Your consent |
| Service interest and budget range (optional) | To scope your enquiry and suggest a package | Your consent |
| Your message / requirements | To understand what you need and prepare a written scope | Your consent |
| Marketing opt-in choice | To know whether we may email you updates. Recorded separately from the enquiry itself. | Your consent |
| IP address and browser user-agent | Security: rate limiting, abuse prevention and diagnosing failed submissions | Our legitimate interest in keeping the service working and free of abuse |
| Timestamp of the enquiry | Security: detecting automated submissions; operational record | Our legitimate interest in preventing abuse |
We do not ask for your date of birth, government identifiers, financial account details, health information or any other sensitive category, and you should not send them to us through this site.
3. What we do not do
- We do not sell, rent or trade your information to anyone.
- We do not send marketing email unless you separately tick the optional marketing box. That box is never pre-ticked.
- We do not run advertising or tracking cookies on this website.
- We do not use your enquiry for automated decision-making that produces a legal or similarly significant effect about you.
- We do not publish your name, company or enquiry as a case study without asking you first and getting your written agreement.
4. Cookies and analytics
This site sets no advertising cookies and no third-party tracking cookies. If we later add privacy-respecting analytics, this notice will be updated before that happens, and any non-essential analytics will be loaded only after you agree to it.
5. Who else processes your data
We keep the number of third parties small. As at the date above, the categories are:
| Provider category | What they do | Where |
|---|---|---|
| Cloud hosting and CDN | Serves this website and stores enquiry records | Global network; may include servers outside India |
| Transactional email | Delivers the notification that a new enquiry has arrived | Global; provider-dependent |
| Bot protection | When enabled, distinguishes human visitors from automated submissions | Global; provider-dependent |
| Calendar booking | If and when a booking link is published, to schedule a call you requested | Provider-dependent |
Where a provider processes personal data on our behalf, we rely on their contractual data-processing terms. Because these are internationally-operated services, your information may be transferred to and stored in countries outside India. We choose providers with established security programmes, but we cannot guarantee that any provider's systems will never be breached — no one honestly can.
We may also disclose information where we are legally required to, for example in response to a valid court order or a lawful request from a public authority.
6. How long we keep it
| Record | How long | Why that long |
|---|---|---|
| Enquiries that never became a project | Up to 3 years from the last contact | Long enough to answer a follow-up, short enough to be defensible; then deleted |
| Active client project records | The contract term, then the period required for tax and company record-keeping | Legal record-keeping obligations |
| Invoices and payment records | As required by applicable tax and company law | We are required to keep them |
| Server security logs (IP, user-agent) | Short-lived, and no longer than needed for abuse investigation | Proportionality |
When the retention period ends, records are deleted rather than archived indefinitely. The exact statutory intervals are confirmed with our accountant, and this table is updated when they change.
7. How we protect it
- The site is served over HTTPS only, with HTTP Strict Transport Security enabled.
- A strict Content-Security-Policy with no inline script and no third-party script origins, so injected code has nowhere to run.
- Enquiry data is stored in an access-controlled database. Access requires authenticated credentials held by the founder.
- Form submissions are rate-limited, and protected by a honeypot, a submission-timing check and, when enabled, a bot challenge.
- We never ask for card numbers, bank credentials or passwords through this website. Phase one has no online checkout at all.
- Database credentials and API keys are held as encrypted environment secrets, never in the website source.
No system is perfectly secure, and we will not claim otherwise. What we commit to is the process: if a breach affects your personal data, we will notify affected individuals and the relevant authority without undue delay, and tell you what happened in plain language.
8. Your rights
Subject to applicable law, you may ask us to:
- Access the personal data we hold about you, and receive a copy.
- Correct anything inaccurate.
- Erase your data, where we are not required to keep it.
- Withdraw consent at any time. Withdrawing consent does not affect the lawfulness of what we did before you withdrew it.
- Object to or restrict processing based on our legitimate interests.
- Complain to the relevant data-protection authority in your country.
To exercise any of these, email cognix.info@gmail.com with enough detail for us to find your record. We aim to respond within 30 days. There is no charge for a reasonable request.
Grievance Officer
Mohammed Anas, Founder, Cognix, Hyderabad, Telangana, India — cognix.info@gmail.com. If you are in India and are not satisfied with our response, you may escalate to the Data Protection Board of India.
9. Children
This site is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has sent us information, contact us and we will delete it.
10. Changes to this notice
If we change how we handle personal data, this page is updated and the date at the top changes. If a change is significant, we will say so clearly rather than quietly reissuing the document.
11. A note on legal review
This notice describes what we genuinely do. It is written to be accurate rather than to score compliance points, and it does not claim certification under any framework. If your organisation requires a signed data-processing agreement before engaging us, ask and we will put one in place.