Privacy Policy
Network Sunday Global Limited (company number 07832813, trading as CogniScale)
Registered office: Queensbury House, 106 Queens Road, Brighton, BN1 3XF.
Effective from: 28 September 2026 (v1.3). This Policy first took effect on 1 June 2026; Google-data and product-identity disclosures were clarified on 11 September 2026 and corrected on 14 September 2026; further accuracy corrections were made on 28 September 2026.
This update explains the existing platform and Google connections more clearly. It does not authorise new access to your data or change the permissions you have granted.
CogniScale is a transformation consultancy. Formula AI Control Centre is our software platform, operated by Network Sunday Global Limited, trading as CogniScale. Our Google application is registered under the name CogniScale.
This Privacy Policy explains, in plain English, what personal data Network Sunday Global Limited (trading as CogniScale, "we", "us", "CogniScale") collects from you, why we collect it, how we use it, and the rights you have over it. It applies to people who visit the CogniScale website (cogniscale.com), people who use the Formula AI Control Centre platform, and people whose data flows through the platform on behalf of a customer organisation.
If anything in this Policy is unclear, contact us at [email protected].
1. Who we are and how to contact us
| Field | Detail |
|---|---|
| Legal entity | Network Sunday Global Limited, company number 07832813, trading as CogniScale |
| Company registration | Registered in England and Wales |
| Registered office | Queensbury House, 106 Queens Road, Brighton, BN1 3XF |
| Privacy contact | [email protected] |
| Data protection lead | Tim Bond, Founder |
For complaints we cannot resolve directly, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at https://ico.org.uk or by calling 0303 123 1113. Data subjects in the EU may complain to their local supervisory authority. Data subjects in California or other US states with state privacy laws may exercise the rights set out under those laws. See section 12.
2. The two roles we play
CogniScale operates in two distinct legal roles. One person, such as an employee at a customer organisation, may be governed by both roles at the same time, in different capacities.
- As a Data Controller, CogniScale controls account and service-administration data: who has an account, what organisation they belong to, billing data, and aggregated platform telemetry, as described in section 3.
- As a Data Processor, CogniScale processes customer work content, including workspace knowledge and the contents of inference requests, only on the customer's instructions, as described in our Data Processing Agreement. The customer organisation is the Data Controller for this data; we act as the Processor.
This Privacy Policy describes both roles. Sections 3–8 cover our account and service administration; section 6a specifically covers connected Google data, and section 9 explains local working information. Section 10 summarises our Processor role. The full processor obligations are set out in our Data Processing Agreement at https://cogniscale.com/dpa.
3. The personal data we collect as Controller
We collect three categories of personal data when we act as Controller.
Account-administration data, when you create an account:
- Your full name
- Your email address
- Your organisation name (if you sign up under a customer organisation)
- Your role within that organisation
- Supabase handles platform sign-in credentials on our behalf
- Available sign-in methods, including any multi-factor authentication, depend on your account configuration
Billing data, when your organisation subscribes:
- Your organisation's billing contact name and email
- Your organisation's company name and address
- Your VAT number or local tax identifier (where applicable)
- Payment-method tokens issued by our payment processor. We never see the underlying card number. See section 6 on Stripe.
Platform telemetry, while you use the platform:
- IP address and user agent of the device you are signing in from
- Sign-in and sign-out timestamps
- Service usage information needed to operate and support the platform
We record this information to operate the platform reliably and to bill correctly. Task content, including inference request content, is processed separately for the requested AI work and is governed by our Processor role; see section 10. We do not use platform telemetry to track you across third-party websites.
Conversation content, information read from authorised connections and local working context used by an AI task are separate from account-administration data. Where we process that content on a customer's behalf, we act as Processor; that does not mean the content is never processed. See sections 6a, 9 and 10.
4. The legal basis on which we collect each kind of data
| Data | Why we collect it | Legal basis (UK / EU GDPR) |
|---|---|---|
| Account-administration data | To create and operate your account | Performance of a contract (the Terms of Service you accepted at sign-up) |
| Billing data | To bill your organisation for the subscription | Performance of a contract |
| Platform telemetry (operational) | To run the platform reliably, detect abuse, debug errors | Legitimate interest in operating a secure, reliable service |
| Platform telemetry (aggregated analytics) | To understand which features customers use most, to plan product improvements | Legitimate interest, balanced against the minimal privacy impact of aggregated, non-identifying data |
| Marketing communications | To send you product updates and occasional offers, only if you have opted in | Consent (you can withdraw at any time via the unsubscribe link or your account settings) |
| Audit logs of platform usage | To detect security incidents, support compliance audits, fulfil regulatory obligations | Legitimate interest in operating a secure service; in some cases, legal obligation |
You have the right to object to any processing based on legitimate interest. See section 8 (Your rights).
5. How we use your data
We use the data we collect as Controller for these specific purposes, and no others:
- To operate the platform. Sign you in, route your inference requests, store your workspace metadata, deliver the features you have signed up for.
- To bill you. Send invoices, take payment, send dunning notices for failed payments.
- To support you. Answer your tickets, investigate issues you have reported, provide onboarding help.
- To keep the platform secure. Detect suspicious sign-in patterns, prevent abuse, investigate security incidents, comply with our own incident-response obligations.
- To improve the platform. Understand which features are used and which are confusing, from aggregated telemetry. Access to customer content for any other purpose is controlled by the relevant feature and support permissions, not a general licence to read it.
- To send you marketing communications, but only if you have opted in. You can unsubscribe at any time without affecting any other part of our service to you.
- To comply with our legal obligations. Respond to lawful regulatory requests, comply with anti-money-laundering and tax obligations, defend ourselves in legal proceedings.
We do not:
- Sell your personal data to anyone.
- Share your personal data with advertisers.
When CogniScale sends Customer content to an AI provider using CogniScale's own business accounts, Anthropic's and OpenAI's published business terms say they do not use that content to train their models. If a user connects their own AI subscription instead, that subscription's own terms apply, including any training setting the user has chosen. CogniScale does not use Customer content to train CogniScale's own AI or machine-learning models.
6. Who we share your data with
We share personal data only with parties who need it to provide the platform, and only under appropriate legal terms.
The full list of sub-processors is at https://cogniscale.com/sub-processors. The categories below summarise.
AI model providers (when you make an inference request through us): Anthropic and, on selected routes, OpenAI, Google Cloud (Gemini), Mistral AI, Fireworks AI, Cerebras and Groq. Anthropic and OpenAI process prompts in the United States. Which provider receives your content depends on the model your organisation has chosen and whether that route is in use. See https://cogniscale.com/sub-processors for the routes currently confirmed.
Infrastructure providers that host the platform: Supabase (main application database in London, AWS eu-west-2, and platform sign-in), Railway (client-facing AI router and gateway, colleague memory, sign-in, support and document-signing services; task content passes through the router to the AI provider your organisation chooses; these services run in Railway's EU region in Amsterdam, measured 28 September 2026 at 12:52), Netlify (web application and application-function hosting, UK region as last configured), GitHub (organisation workspace and colleague content storage) and Cloudflare R2 (encrypted database backups in the EU).
Operational services for running the business: Google Workspace (our internal email, calendar and document storage), Stripe (subscription billing and payment processing where that route is used), Resend (transactional email, where configured), Zoom (meetings with CogniScale staff, where you meet our staff through Zoom) and Slack (messages with CogniScale staff, where you message our staff through Slack).
Connector services that you authorise, when you connect them from your platform settings, may include Gmail, Google Drive, Google Calendar, Slack and GitHub. These are services you have a relationship with. When you connect your own account, you authorise CogniScale Helper to access it on your behalf using your account permissions. CogniScale's own use of some of these vendors, such as our GitHub storage or Google Workspace, is a separate relationship and is listed above where it processes customer information.
Professional advisors (lawyers, accountants, auditors), bound by professional confidentiality, when their advice or audit needs the data.
Regulators, when we are legally required to disclose data, for example in response to a court order, a lawful regulatory request or a regulatory audit.
An acquirer, in the event of a merger or sale of the business, subject to the acquirer being bound to the same data-protection commitments we have made to you in this Policy.
We do not share your personal data with anyone outside these categories without your explicit consent.
6a. Google account data in Formula AI Control Centre
What we access and why
Google connections are optional. Access depends on the Google services you connect, the permissions granted and the features configured for your organisation. The permission screen lists the access requested. A Google Workspace administrator may also need to approve access.
| Google information | How the platform uses it |
|---|---|
| Account identity, including your Google email address | Identify which account is connected and associate it with your platform account. |
| Gmail message content, subjects, senders, recipients, dates, labels and relevant attachments | Find and summarise messages, prepare replies and organise mail for authorised tasks. Mail actions depend on the permissions and tools available in your deployment. |
| Calendar event titles, times, descriptions, locations and attendees | Prepare meeting briefings and read, create or update events for authorised tasks. |
| Content and details of Google Drive files selected for the application or created through it | Read, create or update working documents. The standard connection uses selected-file access, not permission to read the whole Drive. |
A separately configured organisation-wide connection has a different access scope. It requires explicit authorisation and a documented purpose; the standard Google connection is not blanket permission to read every employee's mailbox or files.
The table above describes the connection as designed. Ask us to confirm the exact OAuth scopes currently requested for your connection, since these can change as connector work continues.
AI processing and connection services
Relevant Google content may be included in prompts and tool results sent to the AI provider handling an authorised task. This supports functions such as summaries, replies and meeting preparation. AI processing is distinct from training an AI model. It is also distinct from where the source file is stored: information read on your computer can be processed by an external AI service.
The AI service used for a task depends on the account and configuration agreed during onboarding. The demonstrated Claude connection uses a Claude Team subscription, not only the Anthropic API. When your organisation supplies its own AI account, the account's provider terms and privacy settings also apply. The fact that a task starts on your computer does not mean the AI processing stays on that computer.
Arcade manages authorisation for the platform's Google connections. Netlify hosts the application services that handle the connection response and provide credentials to authorised sessions. Supabase stores connection records, including the connected account, granted permissions, expiry information and an access token. Authorised tools on the user's device obtain a credential and call Google for the requested task. Relevant results may then be sent to the AI service handling that task. These services do not need your Google password.
Signing into Formula AI Control Centre with Google is separate from connecting Gmail, Calendar or Drive. Google sign-in uses Supabase authentication to associate your Google identity with your platform account; it does not by itself grant access to your mailbox or files.
Saved outputs and Workspace Brain information
Google source data remains in the connected Google service. An authorised task can also create a saved draft, summary, document or note containing Google-derived information. The Workspace Brain is a planned guided enterprise upgrade, configured per organisation and intended to draw on its members' connected accounts without IT set-up. It is not yet active for customers. When active, selected information may be retained as organisational context for authorised work. Local working files, the organisation's knowledge repository and platform service records are different storage locations and can have different access and retention settings.
Google-derived information is subject to the same limited-purpose restrictions as the source data. Connecting an account does not authorise unrestricted sharing with other people, use for unrelated purposes or permanent copying of the account. Organisation-wide access and shared knowledge must be scoped to the authorised use and permitted recipients.
Limited Use and human access
CogniScale's use and transfer of information received from Google APIs is governed by the Google API Services User Data Policy, including its Limited Use requirements, and the Google Workspace user data and developer policy.
We use Google data only to provide the authorised, user-facing functions described in this notice. We do not sell Google data, use it for advertising or credit decisions, or use it to train general-purpose AI models. These restrictions also apply to information derived from Google data. Transfers to service providers are limited to providing those functions with consent, security purposes or legal requirements. Any transfer as part of a business acquisition requires the user's explicit prior consent.
Staff and contractors may access Google content only with documented permission to assist with specific data, where necessary for security or legal obligations, or in aggregated and anonymised form for permitted internal operations. General consultancy work, marketing and product research do not give staff permission to browse connected mailboxes or files. These Google-specific restrictions take precedence over the general descriptions of use and sharing elsewhere in this notice.
Retention, revocation and deletion
Access credentials support the active connection. Saved customer outputs and Workspace Brain information follow the customer's documented retention instructions and the applicable Google restrictions. The operational-record and backup periods in section 11 are separate from permission to retain Google content; they do not authorise keeping Google data longer than its permitted purpose or applicable limits.
You can revoke access in your Google Account's third-party connections settings. Revocation prevents further access through that authorisation, but does not by itself delete earlier outputs, local files or information already saved in the organisation's systems.
To request deletion of Google data or Google-derived information held by CogniScale, email [email protected] with the connected account and organisation. Do not send passwords, access tokens or verification codes. We handle the request under the rights and response process in section 8 and, for customer-controlled data, work with the organisation under its Data Processing Agreement. This includes identifying retained outputs and relevant service-provider copies. Locally held files and the customer's own systems may also require deletion by the user or the organisation's administrator. Any retention required by law is explained as part of the response.
7. Where your data is processed, and international transfers
Our production application database is in the United Kingdom. Some hosted processing and AI inference may occur in the United States; the applicable provider and transfer mechanism depend on the route, and are documented in the sub-processor list.
Some of our sub-processors are based in the United States. For personal data flowing from the UK or EU to a US-based sub-processor, we rely on the following legal mechanisms in order of priority:
- The EU-US Data Privacy Framework (DPF) and its UK Extension, where the sub-processor is self-certified under the DPF.
- The EU Standard Contractual Clauses (Module 2: Controller-to-Processor) together with the UK International Data Transfer Addendum (IDTA), where the DPF is unavailable or has been challenged. We will identify the transfer mechanism and, where a Transfer Impact Assessment applies, the available assessment summary for each service that processes personal data outside the UK or EEA, on request.
Where personal data is transferred outside the UK, EEA, or other adequacy-recognised jurisdictions, we intend one of these mechanisms to apply. The transfer mechanism for each sub-processor is documented in the sub-processor list.
8. Your rights
Under UK GDPR and EU GDPR you have the following rights. We will respond to a verified request within 30 days (extendable by a further 60 days for complex requests, with notice to you).
| Right | What it means | How to exercise it |
|---|---|---|
| Access | You can ask for a copy of the personal data we hold about you as Controller | Email [email protected] from the email address on your account |
| Rectification | You can ask us to correct inaccurate or incomplete personal data | Email [email protected] |
| Erasure (the "right to be forgotten") | You can ask us to delete your personal data, subject to our legal-retention obligations | Email [email protected] |
| Restriction of processing | You can ask us to stop processing your data temporarily (for example, while you contest its accuracy) | Email [email protected] |
| Data portability | You can ask for your personal data in a structured, commonly used, machine-readable format | Email [email protected] |
| Objection | You can object to processing we are doing on the basis of legitimate interest | Email [email protected], we will tell you whether we accept the objection and why |
| Withdraw consent | Where we rely on consent, you can withdraw it at any time | Use the unsubscribe link in any marketing email, or email [email protected] |
| Complain to a supervisory authority | If we have not handled your request properly, you can complain to a regulator (ICO in the UK, your national data-protection authority in the EU) | https://ico.org.uk/make-a-complaint or your local authority |
| Not be subject to fully-automated decisions with legal effect | Our platform does not make automated decisions with legal or similarly significant effect on you without human review | Email [email protected] if you believe an automated decision was made |
We do not charge for responding to a rights request unless it is manifestly unfounded or excessive (for example, repetitive requests for the same data within a short window). Where we do charge, we charge a reasonable fee based on administrative cost and tell you in advance.
9. Local working information and the Personal Brain
Some users of the platform install CogniScale Helper on their device. It stores the personal brain on the user's own machine, including session memories, candid notes, drafts and any wiki entries the user has chosen to keep private.
The Personal Brain is intended as the user's private working space. The Workspace Brain is a planned guided enterprise upgrade and is not yet active for customers. Local storage and AI processing are different: when an authorised AI session reads local notes, files or saved context, relevant content can be included in the information processed by the AI service used for that session.
Where CogniScale or its service providers process this content to provide the platform, this notice applies. A file being stored locally is not a claim that its contents never leave the device. The user controls their own backups; any separately chosen backup service has its own privacy terms.
This explanation does not grant new permission to publish private notes or copy them into an organisation's shared knowledge. Sharing and access remain subject to the user's authorisation and the organisation's agreed configuration. Changes to those purposes or permissions require the applicable notice and consent, not merely an update to this page.
10. Customer data: where we are Processor, not Controller
When you use the platform as part of a customer organisation, much of the data flowing through the platform is customer data for which the customer organisation is the Data Controller and we act as the Data Processor. This includes:
- The contents of your conversations with AI agents
- The workspace knowledge and wiki entries created within your organisation's workspaces
- The audit logs of agent activity within the organisation
- The connectors and integrations configured for the organisation
Our processing of customer data is governed by our Data Processing Agreement at https://cogniscale.com/dpa, which is automatically incorporated into the Terms of Service your organisation accepted when subscribing.
Under that agreement, we process customer data only on the controller's documented instructions, notify the customer organisation of confirmed breaches within 24 hours and assist with data-subject rights requests. When CogniScale sends Customer content to an AI provider using CogniScale's own business accounts, Anthropic's and OpenAI's published business terms say they do not use that content to train their models. If a user connects their own AI subscription instead, that subscription's own terms apply, including any training setting the user has chosen. We do not currently hold SOC 2 or ISO 27001 certification. We will share independent reports when they become available.
If you are a data subject and your data is processed via the platform because your employer is a CogniScale customer, please direct rights requests to your employer in the first instance. We will assist them in responding to you.
11. How long we keep your data
Retention varies by data type and agreement. Contact [email protected] for the current schedule. Billing records are retained for six years from the end of the financial year they relate to, as UK law requires.
For customer data we hold as Processor, the retention period is set by the customer organisation in their Data Processing Agreement with us.
12. Rights for residents of California and other US states
If you are a resident of California, you have rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
- The right to know what categories of personal information we collect about you, the sources, the purposes, and the categories of third parties we share with.
- The right to delete personal information we have collected from you, subject to the same retention exceptions in section 11.
- The right to correct inaccurate personal information.
- The right to opt-out of the "sale" or "sharing" of your personal information. We do not sell or share your personal information as those terms are defined under the CCPA.
- The right to limit use of sensitive personal information. We do not use sensitive personal information for any purpose other than providing the service you signed up for.
- The right not to be retaliated against for exercising any of these rights.
To exercise CCPA rights, email [email protected]. We will verify your identity before responding.
Residents of other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others as they come into force) have equivalent rights under their state laws and may exercise them the same way.
13. Cookies and similar technologies
The CogniScale website does not currently set cookies or use session storage. When browser storage is available, the cookie banner stores your choice in local storage for up to 12 months. If storage is unavailable, the banner appears again on your next visit. The website does not currently load an analytics service. See the Cookie Policy at https://cogniscale.com/cookie-policy for instructions to clear this stored choice.
14. Security
We use hosted encryption and access controls to protect personal data. Ask [email protected] for the controls currently in operation, and see the Trust Centre at https://cogniscale.com/trust for our current security position.
If we suffer a personal data breach affecting your data, we will notify you and (where required) the supervisory authority within the timeframes set out in UK and EU GDPR. For customer data we process, the breach notification timeline to the customer organisation is 24 hours from confirmation, as set out in our Data Processing Agreement.
For the full description of our security posture, see the Trust Centre at https://cogniscale.com/trust.
15. Children's data
The platform is a business product aimed at adult professionals. We do not knowingly collect personal data from anyone under 16. If you believe we have collected data from a child, please email [email protected] and we will delete it promptly.
16. Changes to this Policy
We may update this Privacy Policy to reflect changes in our practices, our sub-processors, or applicable law. When we make a material change, we will:
- Update the version number and the effective date at the top of the document.
- Notify account holders before a material change takes effect, under our standard notice process.
- Provide a changelog describing what changed and why.
Continuing to use the platform after a change takes effect means you accept the updated Policy. If you don't accept it, you can close your account, and the data-retention provisions in section 11 apply.
17. Contact
For any privacy-related question, request or complaint:
- Email: [email protected]
- Company number: 07832813
- Postal address: Queensbury House, 106 Queens Road, Brighton, BN1 3XF
If you are unhappy with our response, you can contact the UK Information Commissioner's Office (ICO) at https://ico.org.uk or your local EU supervisory authority.
Document control
| Field | Value |
|---|---|
| Version | v1.3, 28 September 2026 accuracy correction |
| Effective from | 28 September 2026 (v1.3); first effective 1 June 2026 |
| Disclosure update | 11 September 2026: company/product identity, Google-data handling and local-storage versus AI-processing explanation; no new account permissions granted |
| Correction | 14 September 2026: replaced the former identity service with Supabase Auth for platform sign-in; corrected Netlify's hosting region to UK (London, eu-west-2); added the AI-account/onboarding-configuration disclosure and the database point-in-time-recovery and backup-deletion facts; changed "overwritten" to "deleted" for backups |
| Change log | v1.3, 28 September 2026: clarified provider training and device disclosures; narrowed sign-in, telemetry, supplier, transfer, rights, retention, cookie, security and change-notice descriptions to checked facts; removed unsupported source, address and certification claims. |
| Owner | Network Sunday Global Limited (company number 07832813, trading as CogniScale) |
| Registered office | Queensbury House, 106 Queens Road, Brighton, BN1 3XF |
| Contact | [email protected] |
| Next review | To be confirmed |