Table of Contents

Privacy policy

About this privacy policy

Cohesion Insight, Inc. ("Cohesion Insight," "we," "us," or "our") respects your privacy. This Privacy Policy describes how we collect, use, disclose, and protect personal information when you visit our website, sign up for or use our AI operations and intelligence platform (the "Service"), or interact with us. By using the Service, you acknowledge that you have read and understood this Privacy Policy.

This policy is written for the SMB operators and their teams who use the Service, for individuals whose personal information may be processed through the Service on behalf of a customer, and for visitors to our website. Different sections apply depending on your relationship with us. Terms not defined here have the meanings given in our Terms of Service.

Read-only ingestion of Connected Systems. When a customer authorizes the Service to connect to their marketing, finance, CRM, or other business systems ("Connected Systems"), the Service ingests data from those systems in read-only mode. Cohesion Insight does not write to, modify, or delete data in Connected Systems, and Cohesion Insight does not use its Connected System access to initiate transactions, send communications, or take action on the customer's behalf in those systems.

Customer-owned AI agents. A customer may authorize an AI agent that the customer owns and operates to connect to the Service. That agent is treated as another Connected System: it authenticates using the customer's own credentials in the customer's other systems and may consume Cohesion Insight recommendations as inputs and then act in the customer's own systems using the customer's own permissions. Any action the customer's agent takes in the customer's systems is the customer's action, not Cohesion Insight's.

Information we collect

We collect the following categories of information.

Information you provide to us

  • Account and contact information: name, business email address, phone number, company name, company address, job title, and login credentials.
  • Billing information: billing name and address, payment card information (processed by our payment processor; we do not store full card numbers), and tax identification where required.
  • Communications: messages, questions, feedback, and other content you send to us through the Service, email, chat, forms, or support channels.
  • Optional profile information: company size, industry, and other details you choose to share.

Information collected from your use of the Service

  • Usage data: actions you take in the Service, features you use, pages you visit, timestamps, referring pages, session duration, and similar telemetry.
  • Device and connection data: IP address, browser type and version, operating system, device identifiers, language settings, and time zone.
  • Cookies and similar technologies: as described in the Cookie Policy at cohesioninsight.ai/cookie-policy.

Information ingested from Connected Systems
When a customer authorizes the Service to connect to Connected Systems, the Service ingests data from those systems, in read-only mode, as configured by the customer. This can include information about the customer's business, their customers, their transactions, and their operations.

We refer to this data collectively as "Customer Data." Customer Data may include personal information about the customer's own end customers, prospects, or contacts ("Customer-of-Customer Personal Information").

Where Customer Data includes personal information about individuals other than the customer, the customer is the controller of that personal information and Cohesion Insight is the processor, acting on the customer's instructions and only to the extent needed to provide the Service to the customer. If you are an individual whose personal information is included in Customer Data, please contact the customer that provided your information. We can only respond to requests from you directly to the extent permitted by our agreement with the customer.

How we use information

We use information for the following purposes and on the following legal bases (where GDPR or similar law applies).

Purpose

Description

Legal basis under GDPR

Providing the Service

Creating and managing accounts; delivering features; generating AI Outputs; providing Managed Services

Contract

Billing and payment

Processing subscriptions, invoices, taxes, and refunds

Contract

Communications

Sending administrative messages, service announcements, security alerts, and responses to requests

Contract; legitimate interests

Product improvement

Analyzing usage, evaluating performance, debugging, and improving the Service and models (using aggregated and de-identified data by default)

Legitimate interests

Security and fraud prevention

Monitoring for abuse, protecting the Service, and enforcing our policies

Legitimate interests; legal obligation

Marketing

Sending promotional emails about our products (you can opt out)

Consent (where required) or legitimate interests

Legal compliance

Complying with law, responding to lawful requests, and enforcing agreements

Legal obligation

AI model training

We do not use identifiable Customer Data to train foundation models offered to other customers unless the customer has expressly opted in. We may use aggregated, anonymized, and de-identified data derived from Customer Data to develop, evaluate, and improve the Service. Customers may opt out of any model-improvement use of their Customer Data by writing to privacy@cohesioninsight.ai.

Automated decision-making

The Service generates AI Outputs, including recommendations, predictions, and insights. AI Outputs are decision support and do not make legally significant or similarly significant decisions about you on their own. Customers are responsible for how they use AI Outputs.

How we share information

We do not sell personal information. We share information only as described below.

  • Service providers and sub-processors: cloud hosting providers, database and infrastructure providers, analytics providers, payment processors, communications and email providers, customer support tools, and other vendors that process information on our behalf under written contracts. A current list of sub-processors is available at cohesioninsight.ai/subprocessors and is updated as our vendor list changes.
  • Connected Systems and integrations at your direction: when you authorize the Service to connect to a third-party system, information flows to and from that system as configured by you.
  • Customers (for Customer Data): if we receive information as part of Customer Data, we share it with, and process it on behalf of, the applicable customer.
  • Corporate transactions: in connection with a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, information may be transferred to the successor entity, subject to this Privacy Policy or a policy substantially similar.
  • Affiliates: we may share information with parent, subsidiary, or commonly controlled entities for the purposes described in this Privacy Policy.
  • Legal and safety: we may disclose information to comply with law, respond to subpoenas or court orders, cooperate with law enforcement, protect our rights and property, enforce our agreements, or respond to emergencies involving risk of harm.
  • Aggregated and de-identified data: we may share aggregated or de-identified data that cannot reasonably be used to identify you.

Cookies and similar technologies

We and our service providers use cookies, web beacons, local storage, and similar technologies to operate the Service, remember preferences, secure sessions, understand usage, and support marketing. Details about the categories of cookies we use, the specific cookies set on our website, and how to control cookies are set out in the Cookie Policy at cohesioninsight.ai/cookie-policy.

Do Not Track. Because there is no common industry standard for Do Not Track browser signals, the Service does not currently respond to them. Where required by law, we honor Global Privacy Control (GPC) or similar opt-out signals.

Your rights

Depending on where you live, you may have rights over your personal information, including:

  • Access — a copy of the personal information we hold about you.
  • Correction — to correct inaccurate or incomplete information.
  • Deletion — to have your information deleted, subject to exceptions.
  • Portability — to receive a copy of your information in a portable format.
  • Objection or restriction — to object to, or restrict, certain processing.
  • Withdrawal of consent — to withdraw consent where we rely on it.
  • Non-discrimination — not to be discriminated against for exercising these rights, where a right against discrimination applies.

To exercise these rights, email privacy@cohesioninsight.ai. We may need to verify your identity before responding. If your personal information is part of Customer Data submitted by a customer, please direct your request to that customer. We will assist the customer in responding as required by our agreement with them.

You may also lodge a complaint with a supervisory authority in your jurisdiction.

Notice to California residents

Under the California Consumer Privacy Act (CCPA) as amended by the CPRA:

Categories of personal information collected. Over the preceding 12 months, we have collected the following categories of personal information: identifiers (such as name, email, IP address, and account identifiers); commercial information (such as subscription and billing records); internet or other electronic network activity information (such as usage and device data); geolocation data (approximate, derived from IP address); professional or employment-related information (such as job title and company); and inferences drawn from the above.

Sources of personal information. We collect personal information directly from you when you sign up, use the Service, or contact us; automatically when you interact with the Service; from our service providers (such as our payment processor and analytics providers); and, where applicable, from your employer or the customer that provided your information to us.

Business or commercial purposes. We collect personal information for the business purposes described in Section 2 of this Privacy Policy.

Categories of third parties to whom personal information was disclosed. Over the preceding 12 months, we have disclosed personal information for a business purpose to the following categories of third parties: cloud hosting and infrastructure providers; analytics providers; payment processors; communications and email providers; customer support tool providers; other vendors described in our Sub-processors List; the customer that provided the Customer Data (where the information is part of Customer Data); affiliates; professional advisors; and government authorities where required by law.

Sale or sharing. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined by California law.

Retention. We retain each category of personal information for the periods described in Section 8. We retain personal information for as long as needed to provide the Service and for a reasonable period afterward for legal, audit, and dispute-resolution purposes.

Rights. California residents may request access, correction, deletion, and to limit the use of sensitive personal information. We do not knowingly collect sensitive personal information beyond account credentials and payment information used for the Service, and we do not use or disclose sensitive personal information beyond what is permitted without a right to limit under CCPA Section 7027. Requests may be made by emailing privacy@cohesioninsight.ai.

Authorized agents. Authorized agents may submit requests on your behalf. We may require verification of the agent's authority.

Notice to other U.S. state residents

Residents of certain other U.S. states (including Colorado, Connecticut, Delaware, Indiana, Iowa, Montana, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, and Virginia) may have rights under their state's comprehensive privacy law, which can include the right to access, correct, and delete personal information, the right to portability, the right to opt out of the sale of personal information, the right to opt out of targeted advertising, and the right to opt out of certain profiling.

We do not sell personal information as defined under any of these state laws, and we do not use personal information for targeted advertising. Where a state law provides a right to appeal a denial of a request, we will notify you of the outcome of your request and of your right to appeal, and we will respond to any appeal within the timeframe required by that law.

To exercise a state privacy right, email privacy@cohesioninsight.ai. We may need to verify your identity before responding.

Notice to residents of the EU, EEA, UK, and Switzerland

Controller and processor roles. For personal information about you as a Cohesion Insight customer or visitor, Cohesion Insight is the controller. For personal information included in Customer Data submitted by a customer, Cohesion Insight is the processor and the customer is the controller.

Legal bases. We process personal information under the legal bases described in Section 2.

International transfers. Cohesion Insight is established in the United States and personal information may be processed in the United States and other countries where we or our service providers operate. Where we transfer personal information from the EU, EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where necessary.

Data Processing Addendum. A Data Processing Addendum incorporating the Standard Contractual Clauses is incorporated into and forms part of the Terms of Service and is available at cohesioninsight.ai/dpa. A countersigned copy is available on request at privacy@cohesioninsight.ai.

EU/UK representative. Our representative in the European Union and the United Kingdom for purposes of Article 27 of the EU General Data Protection Regulation and the UK General Data Protection Regulation is [PROVIDER NAME, ADDRESS, AND CONTACT EMAIL]. You may contact them for matters relating to the processing of your personal information.

Not a HIPAA covered entity or business associate; not subject to GLBA

The Service is not designed to receive Protected Health Information as defined under the U.S. Health Insurance Portability and Accountability Act (HIPAA), and Cohesion Insight is not a HIPAA covered entity or business associate. Do not submit Protected Health Information to the Service.

Cohesion Insight is not a financial institution and is not itself subject to the U.S. Gramm-Leach-Bliley Act (GLBA). Where the Service ingests data from a customer's Connected System that includes non-public personal financial information, Cohesion Insight processes that information on the customer's behalf, in read-only mode, and applies the security and confidentiality standards described in the Security Policy and the Data Processing Addendum.

Data retention

We retain personal information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention practices:

  • Account information — for the life of the account plus a reasonable period afterward for legal and audit purposes.
  • Customer Data — as instructed by the customer under the Terms of Service and any Data Processing Addendum. On termination, we make Customer Data available for export for 30 days, after which we may delete it.
  • Billing and tax records — for the period required by applicable tax and financial-reporting laws.
  • Security and system logs — for a limited period consistent with security best practices.

When retention is no longer necessary, we securely delete or de-identify the information.

Security

We maintain administrative, technical, and physical safeguards designed to protect personal information. Our security program is described in the Security Policy at cohesioninsight.ai/security. No security measure is perfect, and we cannot guarantee absolute security. You are responsible for keeping your credentials secure and notifying us promptly at security@cohesioninsight.ai of any suspected unauthorized use.

Children

The Service is intended for business use by individuals 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact privacy@cohesioninsight.ai and we will investigate and delete as appropriate.

Third-party sites and services

The Service may link to third-party websites, applications, and services, and may integrate with Connected Systems that you authorize. We are not responsible for the privacy practices of third parties. Review their privacy policies before providing information.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by posting the updated policy on our website and, where appropriate, by email. The updated policy takes effect on the effective date stated at the top. Continued use of the Service after the effective date constitutes acceptance.

How to contact us

Cohesion Insight, Inc. Attention: Privacy Officer 2810 N Church St, STE 89393 Wilmington, DE 19802-4447 Email: privacy@cohesioninsight.ai

For security concerns: security@cohesioninsight.ai For legal notices: legal@cohesioninsight.ai