top of page

Data Protection Policy

1. Purpose
Cognisession ("Company", "we", "our", or "us") is committed to protecting the privacy, confidentiality, integrity, and availability of personal information entrusted to us.
This Data Protection Policy establishes the principles, responsibilities, and procedures for collecting, processing, storing, accessing, sharing, and disposing of personal data across all Cognisession operations.
This Policy applies to:

  • Employees

  • Directors

  • Consultants

  • Independent Experts

  • Contractors

  • Vendors

  • Business Partners

  • Affiliates

  • Temporary Staff

  • Any person authorized to access Cognisession systems or personal information

2. Objectives
The objectives of this Policy are to:

  • Protect personal information from unauthorized access.

  • Maintain confidentiality of user information.

  • Ensure responsible handling of personal data.

  • Establish clear responsibilities.

  • Reduce the risk of data breaches.

  • Promote transparency and accountability.

  • Comply with applicable data protection laws.

3. Scope
This Policy applies to all personal information collected through:

  • Website

  • Mobile Applications

  • Consultation Bookings

  • Educational Courses

  • Marketplace Services

  • E-commerce Orders

  • Payment Processing

  • Customer Support

  • Marketing Activities

  • Social Media

  • Email Communications

  • Community Platforms

  • Expert Onboarding

4. Definitions
Personal Data
Any information relating to an identified or identifiable individual.
Examples include:

  • Name

  • Email Address

  • Mobile Number

  • Date of Birth

  • Address

  • Government-issued identification (where legally required)

  • Consultation information

  • Purchase history

  • Device information

  • IP address

  • Account details

Sensitive Information
Certain information may require enhanced protection depending on applicable law, including information voluntarily shared by users during consultations that could reveal highly personal circumstances.
Such information shall be handled with additional safeguards and only to the extent necessary for providing requested services.
5. Data Protection Principles
Cognisession shall process personal data in accordance with the following principles:

  • Lawfulness

  • Fairness

  • Transparency

  • Purpose Limitation

  • Data Minimization

  • Accuracy

  • Storage Limitation

  • Integrity

  • Confidentiality

  • Accountability

6. Lawful Collection
Personal information shall only be collected:

  • With appropriate notice to the user.

  • For legitimate business purposes.

  • With consent where required by law.

  • Through lawful means.

  • In accordance with applicable regulations.

7. Categories of Information Collected
Cognisession may collect:
Identity Information

  • Full Name

  • Username

  • Profile Photo

Contact Information

  • Email Address

  • Mobile Number

  • Postal Address

Consultation Information

  • Birth details

  • Questionnaire responses

  • Uploaded documents

  • Consultation notes

  • Preferences voluntarily shared by users

Transaction Information

  • Orders

  • Invoices

  • Payments

  • Booking history

Technical Information

  • Device information

  • Browser information

  • Operating system

  • IP address

  • Cookies

  • Analytics data

Marketing Preferences

  • Newsletter subscriptions

  • Communication preferences

  • Event registrations

8. Purpose of Processing
Personal information may be processed to:

  • Deliver consultations

  • Process bookings

  • Provide educational services

  • Deliver digital products

  • Ship physical products

  • Improve website functionality

  • Respond to customer inquiries

  • Verify identities where appropriate

  • Prevent fraud

  • Improve security

  • Maintain business records

  • Comply with legal obligations

  • Conduct internal analytics

  • Improve customer experience

9. Consent Management
Where consent is required:

  • Consent shall be informed and voluntary.

  • Individuals may withdraw consent where permitted by law.

  • Withdrawal of consent may affect our ability to provide certain services.

  • Records of consent shall be maintained where appropriate.

10. Data Accuracy
Reasonable efforts shall be made to ensure that personal information is accurate, complete, and up to date.
Users may request corrections to inaccurate information.
11. Access Control
Access to personal information shall be limited to individuals who require it for legitimate business purposes.
Access shall be granted according to the principle of least privilege.
Employees and experts shall only access information necessary to perform their assigned responsibilities.
12. Authentication
Systems containing personal information shall be protected through appropriate authentication mechanisms, including:

  • Strong passwords

  • Multi-factor authentication where available

  • Secure account management

  • Role-based access controls

13. Information Security
Cognisession implements reasonable technical and organizational safeguards, including:

  • HTTPS encryption

  • Secure cloud infrastructure

  • Firewall protection

  • Anti-malware systems

  • Regular software updates

  • Secure backups

  • Access logging

  • System monitoring

  • Encryption where appropriate

  • Security testing

While reasonable measures are implemented, no method of storage or transmission can guarantee absolute security.
14. Confidentiality
Every employee, expert, contractor, and consultant shall maintain the confidentiality of personal information.
Confidential information shall not be disclosed without authorization unless required by law.
15. Data Sharing
Personal information may be shared only when necessary with:

  • Payment service providers

  • Shipping partners

  • Cloud hosting providers

  • Analytics providers

  • Customer support providers

  • Independent experts providing booked services

  • Government authorities where legally required

Information shall not be sold to third parties.
16. International Transfers
Where personal information is transferred across national borders, Cognisession will take reasonable steps to ensure that appropriate safeguards are implemented in accordance with applicable laws.
17. Data Retention
Personal information shall be retained only for as long as necessary to:

  • Provide services

  • Meet legal obligations

  • Resolve disputes

  • Maintain business records

  • Enforce contractual rights

After the applicable retention period, data shall be securely deleted, anonymized, or otherwise disposed of in accordance with internal procedures.
18. Secure Disposal
When personal information is no longer required, it shall be securely disposed of using appropriate methods to reduce the risk of unauthorized access or recovery.
19. User Rights
Subject to applicable law, users may request to:

  • Access their personal information.

  • Correct inaccurate information.

  • Update information.

  • Delete information.

  • Withdraw consent where applicable.

  • Request information regarding how their data is processed.

Requests will be handled in accordance with applicable legal requirements.
20. Data Breach Management
Any suspected or confirmed data breach shall be reported internally without undue delay.
Cognisession will:

  • Assess the incident.

  • Contain the breach.

  • Investigate the cause.

  • Take corrective action.

  • Notify affected individuals or authorities where required by applicable law.

  • Document lessons learned.

21. Employee Responsibilities
All personnel must:

  • Protect confidential information.

  • Follow approved security procedures.

  • Use authorized systems only.

  • Report security incidents promptly.

  • Complete required security awareness training where applicable.

  • Avoid sharing passwords or credentials.

Failure to comply with this Policy may result in disciplinary action, suspension of access, termination of engagement, or legal action where appropriate.
22. Third-Party Service Providers
Third-party vendors that process personal information on behalf of Cognisession should be expected to maintain appropriate security and confidentiality standards consistent with applicable contractual obligations.
23. Training & Awareness
Cognisession encourages ongoing awareness of data protection and cybersecurity practices for employees, experts, and authorized personnel.
Training may include:

  • Data privacy principles

  • Password security

  • Phishing awareness

  • Secure handling of client information

  • Incident reporting procedures

24. Monitoring & Compliance
Cognisession may conduct periodic reviews and audits to assess compliance with this Policy and identify opportunities for improvement.
25. Policy Violations
Violations of this Policy may result in:

  • Verbal or written warnings

  • Mandatory retraining

  • Suspension of system access

  • Removal from the Platform

  • Termination of employment or contractual relationship

  • Legal action where appropriate

26. Policy Review
This Policy will be reviewed periodically and updated as necessary to reflect changes in legal requirements, technology, business operations, or security practices.
27. Contact
Questions regarding this Data Protection Policy or requests relating to personal information may be directed through the contact information published on the Cognisession website.
28. Acknowledgement
All personnel with access to Cognisession systems or personal information are expected to understand and comply with this Data Protection Policy.
By accessing Cognisession systems or processing personal information on behalf of Cognisession, you acknowledge your responsibility to protect personal data and uphold the principles outlined in this Policy.

bottom of page