KOGNITECH

Last updated 27 August 2026

These are working documents, not reviewed by counsel. They describe accurately what the product does with data today, so that there is something concrete to review and sign. Anything marked [REVIEW] is a decision for a lawyer, not for us.

Privacy Policy

This policy covers Kognitech OS, the operational system we provide to organizations. In it, your employer is the controller of the data and KOGNITECH is the processor: we hold and process it on their instructions. If you are a worker and want your record corrected or removed, ask your employer first — they decide, and we act on their instruction.

What we hold

Identity of your workers
Name, work email, phone, job title, employment status, start date, emergency contact.
Roles and access
Role, data scope, which Apps they may open, desktop and mobile access.
Work records
Project and crew assignment, memberships, attendance and check-ins.
Location
GPS coordinates recorded at a site check-in, and geofence events — only where your organization has enabled it, and always with the worker notice described below.
Site evidence
Photos taken on site, including any location metadata the device attaches, and the markup added to them.
Safety records
Completed forms, signatures, reported hazards, near misses and incidents.
Documents
Files your organization uploads: contracts, drawings, permits, certificates.
Internal communication
Messages sent inside your organization through the product.
Audit trail
Who did what and when, including every time Kognitech support opened your data.

Why we hold it

Only to provide the service to your organization: to run their operation, to keep the safety and compliance records the law requires of them, and to support them when something breaks. We do not sell data, we do not advertise, and we do not train any model on your data.

Electronic monitoring

Where an organization turns on GPS-verified check-in, the product shows every affected worker a written notice describing what is recorded and for how long, and records their acknowledgement. Location is captured at a check-in event, not continuously. Retention is set by the organization between 7 and 365 days and is applied automatically. This mirrors the requirements of Ontario's written policy on electronic monitoring. [REVIEW: confirm the wording against ESA s. 41.1.1 for the provinces where you sell.]

Where it lives

On infrastructure in the United States (see sub-processors below). Personal data of workers in Canada therefore crosses a border, and your organization should say so in their own privacy notice. [REVIEW: transfer mechanism.]

How long

For as long as your organization is a customer, plus the recovery window in the contract. The exception already implemented is location evidence, which is deleted on the schedule the organization sets. [REVIEW: a retention schedule per data category is still to be agreed — today, other categories are kept for the life of the account.]

Who can see it

Inside your organization: whoever their roles and permissions allow, which they control. From KOGNITECH: nobody, until your organization's data is opened under a named support grant — an individual Kognitech person, with a written reason, a maximum duration of four hours, recorded in your organization's own audit trail, not only ours. Your administrators can read that trail at any time.

Contact

Privacy questions: privacy@kognitech.io

Terms of Service

What we provide

Access to Kognitech OS for the organization named in the order, for the Apps and modules named in it, for the term named in it. Apps not named in the order are not part of the service, even if they are visible.

Your data is yours

You own everything you put in. We claim no rights over it beyond what is needed to run the service for you. On termination you may export it, and we delete it after the recovery window. [REVIEW: today the export covers the main operational tables; a full export including files and configuration is in progress and should be a contractual commitment only once it is complete.]

Availability

We aim for the service to be available during your working hours and we will tell you about planned work in advance. We do not offer a contractual uptime guarantee today, because we do not yet run the monitoring that would let us measure one honestly. Saying otherwise would be a number we could not stand behind. [REVIEW: an SLA once monitoring is in place.]

Support

Email support during business hours (Eastern Time), at support@kognitech.io. Response targets are set in the order. [REVIEW: out-of-hours cover for field operations that start at 6am.]

Fees

As set out in the order: a one-time set-up fee and a recurring subscription, invoiced in Canadian dollars. Invoicing is handled outside the product today. Late payment may lead to suspension after written notice. [REVIEW: notice period and interest.]

Confidentiality and security

Each side keeps the other's confidential information confidential. Our technical measures are described in the Data Processing Terms below. We will notify you without undue delay of any breach affecting your data.

Limits

[REVIEW: limitation of liability, indemnities, governing law — these are the clauses your counsel will want to write, not us.]

Ending it

Either side may end the agreement at the end of the term with written notice. You may export your data before and during the recovery window that follows.

Data Processing Terms

These terms apply where KOGNITECH processes personal data on your behalf. You are the controller; we are the processor.

Scope and instructions

We process personal data only to provide the service and only on your documented instructions, which include your use of the product's own settings. If we ever think an instruction breaks the law, we will tell you rather than follow it quietly.

Sub-processors

Sub-processorWhat it doesWhere
SupabaseDatabase, file storage and authenticationUnited States
VercelApplication hosting and edge deliveryUnited States
ResendTransactional email (invitations, password resets)United States

We will give you notice before adding a new sub-processor, and you may object.

Technical and organizational measures

[REVIEW: we do not hold SOC 2 or ISO 27001 today, and we do not claim to. If your procurement requires one, that is a conversation to have before signing, not after.]

Your people's rights

If one of your workers asks for access, correction or deletion, you decide and we help you carry it out. We will not answer such a request directly without your instruction.

Breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with what we know and what we are doing about it.

Return and deletion

On termination, you may export your data during the recovery window; after it, we delete it. [REVIEW: the deletion routine covers the operational tables and the file tree today; completing it across every table is tracked work and should be certified in writing before this clause is relied on.]