Template for review — not legal advice

This document is a template published by CogniLead GmbH, which is in formation and not yet registered. Until incorporation completes, it cannot be executed as a binding agreement — treat it as a draft for review, not a signable contract. CogniLead does not provide legal advice; have your Data Protection Officer and legal counsel review it, and confirm the contracting entity’s registration, before relying on it in production. Last updated: 2026-06-03.

Legal · Privacy

Privacy Policy.

This policy explains what data CogniLead collects about you when you use cognilead.ai, why we collect it, how long we keep it, and what rights you have over it. CogniLead is a managed cold-email deliverability engine: you supply the lead data (via the dashboard or the /api/v1/leads API) and CogniLead runs email outbound on your behalf. The recipient addresses you reach with outbound are covered by our outbound hygiene commitments below, not a separate data agreement.

1. Who we are

CogniLead is a product operated by Medishift (a Switzerland-based entity; CogniLead GmbH is in formation). The service is offered at cognilead.ai. The controller for the personal data described in this policy is the operating entity above.

For any privacy-related question, write to privacy@cognilead.ai. For data-protection matters specifically, write to dpo@cognilead.ai.

2. What we collect

We collect three categories of personal data about our users:

a. Account data

  • Email address
  • Display name
  • OAuth provider identifier when you sign in with Github or Google
  • Workspace name you choose during onboarding
  • Plan and billing identifiers when you subscribe to a paid tier

b. Operational data

  • API request logs: HTTP method, path, status code, source IP, user-agent — persisted to the api_calls table for debugging and abuse prevention
  • Session cookies necessary to keep you signed in
  • CSRF tokens used to protect form submissions

c. Outbound campaign data

When you run outbound campaigns, CogniLead handles the recipient addresses you supply (through the dashboard or the /api/v1/leads API), the messages you send, and the resulting delivery, bounce, reply, suppression, and unsubscribe records. We process this data only to operate your campaigns and to enforce outbound hygiene: honouring suppression lists and RFC 8058 one-click unsubscribe. We do not build, enrich, or rank a company universe ourselves, and we do not source recipient addresses for you — you supply the leads.

We rely on two grounds for processing the personal data described above:

  • Contract performance. Account data and session cookies are necessary to provide the SEO generation and outbound service you have asked us to provide.
  • Legitimate interest. Operational logs, abuse prevention, security monitoring, and limited outbound communications to our own business prospects rely on our legitimate interest in operating the service safely and reaching relevant contacts. Every outbound message carries a working one-click unsubscribe, and you can object at any time using the contact details below.

We do not use consent (Article 6(1)(a)) as the primary lawful basis for any of the categories above; we do not run any consent-based tracking. If we ever introduce a feature that requires consent, you will be asked explicitly and may withdraw at any time.

4. Retention

  • Account data: kept until your account is deleted, then a 30-day grace window for recovery before hard deletion.
  • API request logs: 90 days, after which they are aggregated for security analytics and the raw rows are dropped.
  • Financial records: 7 years, as required by Swiss accounting and tax law (CO 958f). This is the only retention period that survives account deletion.
  • Outbound campaign records: the text of a sent email is deleted automatically after 365 days (subject, dates and outcomes stay for reporting); suppression and unsubscribe entries are kept indefinitely so we never re-contact someone who opted out. Addresses that complained, or that we were asked to erase, are kept only as a one-way hash.
  • Verification and delivery logs: 90 days.
  • Backups: 30-day rolling snapshots (see Security). A deletion request propagates to backups within one full rotation cycle.

5. Sub-processors

We use the following sub-processors to deliver the service. We share only the data each one needs to perform its function.

  • Supabase — authentication, multi-tenant Postgres database, and row-level security, hosted in Switzerland (eu-central-2).
  • Fly.io — application hosting (Frankfurt, EU).
  • Amazon SES — delivery of outbound email from sender mailboxes that are not yet on dedicated sending infrastructure, bounce/complaint notifications, and notification email the application sends itself (such as waitlist sign-up notices to our team). Processed in the United States (us-east-1).
  • Resend — account emails (sign-up confirmation, sign-in links, password recovery), sent on behalf of our authentication provider. Sent from Resend's eu-west-1 (Ireland) sending region.
  • Cloudflare — DNS for CogniLead's sender domains and forwarding of inbound mail (replies) addressed to them.
  • Stripe — billing (activated only when paid plans are enabled).
  • phi-cloud — our LLM provider. It powers the personalisation of outbound messages. CogniLead does not use phi-cloud's HIPAA / patient-data tier and sends it no health data.

Outbound campaign email is sent from pooled sender mailboxes, through mail servers CogniLead operates or through a contracted mailbox provider. No mailbox provider processes personal data today; if we contract one, it will be named here before it does.

6. International transfers

Account data, operational logs, and outbound campaign records are stored in our primary database region. To run the service we share the minimum necessary data with the sub-processors listed above, some of which operate globally distributed infrastructure.

When SEO content is generated or an outbound message is personalised, the relevant prompt and context are sent to our LLM provider, phi-cloud. Where personal data crosses a border to reach a sub-processor, we rely on appropriate safeguards such as Standard Contractual Clauses.

7. Your rights

Depending on where you live, you may have the following rights over your personal data:

  • Access — request a copy of what we hold about you.
  • Rectification — correct anything that is wrong.
  • Erasure — ask us to delete your data.
  • Portability — receive your data in a machine-readable format.
  • Restriction — limit how we use your data.
  • Objection — object to processing based on legitimate interest.
  • Withdrawal — withdraw any consent you may have given.

We honor these requests within 30 days. To exercise any of them, email privacy@cognilead.ai. If you received an outbound message sent through CogniLead and simply want it to stop, use the one-click unsubscribe in that message and you will be added to the sender's permanent suppression list. The unsubscribe page also has a Delete my data button that erases your address and the emails sent to it from the sender's records immediately; replying “please delete my data” or “stop emailing me” to the message is honoured automatically as well. Where applicable, you also have the right to lodge a complaint with your data-protection authority.

8. Cookies

We use strictly necessary cookies only: a session cookie that keeps you signed in, and a CSRF token that protects form submissions. We do not use analytics cookies, marketing cookies, advertising pixels, third-party tracking tags, or fingerprinting. There is no cookie banner because there is nothing to opt out of.

9. Security

We treat security as part of the product. TLS 1.3 for all traffic, MFA enforced on the dashboard, Postgres Row Level Security keyed on tenant identifier, and daily encrypted backups in a separate region. The full posture is documented at /legal/security.

10. Changes

We will give you at least 30 days notice for any material change to this policy, by email to the address on your account and by a visible notice on the dashboard. Non-material changes (typos, clarifications) are published silently with an updated date at the top of this page.

11. Contact

Privacy questions: privacy@cognilead.ai.
Data-protection matters: dpo@cognilead.ai.

Privacy Policy — CogniLead