Privacy Policy
Last updated: 18 August 2026
This Privacy Policy explains how Ignacio Correia, Lda., trading as SuperCognit ("SuperCognit", "we", "us" or "our") collects, uses and protects personal data when you visit supercognit.com, use the SuperCognit platform, or interact with AI agents operated on it. We are based in Portugal and process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Portuguese data protection law (Lei n.º 58/2019).
1. Who is responsible for your data
Ignacio Correia, Lda., trading as SuperCognit (NIPC / VAT PT517951924), with registered office at Rua do Matadouro 19, 8100-689 Loulé, Portugal, is the entity responsible under this policy. For any question about this policy or how we handle personal data, contact legal@supercognit.com. Because we are established in the European Union, no Article 27 GDPR representative is required. Our supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD).
2. Two roles: controller and processor
Our platform involves two distinct data-protection roles:
- SuperCognit as controller. For data about our own website visitors, account holders, Creators and Organization members — registration, billing, support, security and analytics data — we decide how and why the data is processed, and this policy applies directly.
- SuperCognit as processor. When End Users talk to an AI agent operated by one of our customers (through a chat page, embedded widget, custom domain, WhatsApp, Telegram or API), the customer who operates that agent is the data controller of the conversation and any data the End User provides. We process that data only on the customer's instructions, under our Terms of Service and, where applicable, a Data Processing Addendum incorporating the European Commission's Standard Contractual Clauses (available on request). We have no direct relationship with End Users; see section 13.
3. Personal data we collect
- Account data — name, email address, password hash or Google sign-in identifiers, avatar, workspace membership and roles, language and preferences.
- Billing data — subscription plan, invoices, VAT information and payment status. Card details are collected and stored by our payment processor (Stripe); we never see full card numbers. For Creators: payout details and earnings records.
- Notification contact data — your email address and, if you opt in, your mobile phone number for SMS service notifications (see section 6).
- Content you submit — agent configurations, prompts, uploaded knowledge files, imported website content, chat messages you send when using or testing agents, and inbox/CRM records in your workspace.
- Channel identifiers — where you or your End Users connect through messaging channels: WhatsApp phone numbers, Telegram user IDs and display names, and message metadata needed to route and deliver messages.
- Browser-automation credentials — credentials and cookies you deliberately store in the encrypted vault for browser runs. These are encrypted at rest and used only to execute the runs you configure.
- Usage and device data — IP address, browser and device information, pages visited, referring URLs, feature usage events, API request logs and error diagnostics.
- Support and communications data — messages you exchange with us by email or in-product, and records of consent.
4. Why we process it and on what legal basis
| Purpose | Examples | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Providing the Services | Accounts, workspaces, running agents and conversations, channels, billing, payouts, support | Contract (Art. 6(1)(b)) |
| Security and abuse prevention | Authentication, fraud and abuse detection, rate limiting, audit logs, protecting the platform and other customers | Legitimate interests (Art. 6(1)(f)) |
| Product analytics and improvement | Understanding feature usage, diagnosing errors, improving the platform | Legitimate interests (Art. 6(1)(f)); consent where required for non-essential cookies (Art. 6(1)(a)) |
| Service notifications | Usage alerts, billing notices, security notices, by email and opt-in SMS | Contract (Art. 6(1)(b)); consent for SMS (Art. 6(1)(a)) |
| Marketing communications | Product news you have subscribed to | Consent (Art. 6(1)(a)), withdrawable at any time |
| Legal compliance | Tax and accounting records, responding to lawful requests, enforcing terms | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
5. AI processing and model providers
- Conversations with agents, and relevant excerpts of the knowledge sources configured for them, are sent to our third-party AI model providers (including Anthropic and, depending on configuration, other providers such as OpenAI) to generate responses. These providers act as subprocessors.
- We do not use your content or your End Users' conversations to train AI models, and our model providers are contractually restricted from using content submitted through our accounts to train theirs. We may use anonymized, aggregated statistics that identify no one to operate and improve the platform.
- Agent conversations are retained so that workspace owners can review them (inbox, analytics, billing) — see section 9. Where a customer enables features such as conversation memory or knowledge retrieval, the processing happens on that customer's instructions.
- Chat interfaces indicate that you are talking to an AI system, in line with the EU AI Act's transparency requirements.
6. Service notifications (email and SMS)
We send service notifications about your account — for example usage-budget alerts, top-up confirmations, billing and invoice notices and payment-failure warnings — by email and, where you have opted in by providing your mobile number and actively checking the consent box under Profile → Notifications in your account, by SMS text message. SMS is optional and is never a condition of purchasing or using the Services.
- Mobile information is never shared or sold to third parties or lead generators for any purpose. SMS opt-in consent and phone numbers are not shared with any third party. The only party that ever receives your number is the telecommunications carrier that transmits the message, acting solely as our processor on our instructions and never for any purpose of its own.
- Message frequency varies with your account activity. Message and data rates may apply, depending on your carrier and plan.
- What we collect and why. We store your mobile number, the moment you gave consent and the version of the consent wording you were shown, so that we can evidence consent if challenged (Art. 7(1) GDPR). The number is used only to deliver the notifications described above.
- You can withdraw consent at any time by replying STOP to any message, or removing your number in your account. Reply HELP for help, or contact legal@supercognit.com. Withdrawing consent does not affect the lawfulness of processing before withdrawal, and the same notifications continue to reach you by email.
- The full program disclosure — opt-in flow, verbatim consent wording, example messages and opt-out keywords — is published at supercognit.com/sms.
8. International data transfers
Some of our providers (including AI model providers, Stripe, Cloudflare and Meta) process data in the United States or other countries outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V GDPR: an adequacy decision of the European Commission (including, where the provider is certified, the EU–U.S. Data Privacy Framework) or the European Commission's Standard Contractual Clauses, together with additional technical and organisational measures where needed.
9. How long we keep data
| Data | Retention |
|---|---|
| Account and workspace data | While the account is active; deleted or anonymised after account deletion, subject to the periods below |
| Customer Content (agents, knowledge, conversations) | While the workspace exists and per the workspace owner's instructions; exportable for 30 days after termination, then deleted; accounts inactive for more than 12 months may be deleted after notice |
| Billing and tax records | Up to 10 years, as required by Portuguese tax law |
| Server and security logs | Typically 90 days; up to 1 year for security-relevant audit logs |
| Support correspondence | Up to 3 years after the matter is closed |
| Consent records (e.g. SMS opt-in) | For as long as the consent is relied on, plus limitation periods |
When data is no longer needed, we delete or irreversibly anonymise it. Backup copies are purged on the normal backup rotation cycle after deletion.
10. How we protect data
We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR), including: encryption in transit (TLS) for all traffic; encryption at rest for stored credentials and the browser-automation vault; hashed passwords; role-based access controls and workspace isolation; audited administrative access; SSRF and network egress protections around content ingestion and agent tools; and logging and monitoring of security events. No system is perfectly secure: if we become aware of a personal data breach likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, the affected persons or the affected customer (for data we process on a customer's behalf) without undue delay.
11. Your rights
Under the GDPR you have the right to access your personal data and obtain a copy, to rectify inaccurate data, to erase data, to restrict or object to processing (including processing based on legitimate interests and any direct marketing), to data portability, and to withdraw consent at any time without affecting prior processing. To exercise any of these rights, email legal@supercognit.com; we will respond within one month (extendable as permitted by the GDPR for complex requests) and may ask you to verify your identity. You also have the right to lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD — www.cnpd.pt) or with the supervisory authority of your EU country of residence or work.
13. If you talked to an AI agent built by one of our customers
When you chat with an AI agent on a customer's website, custom domain, WhatsApp or Telegram, the customer operating that agent is the data controller of your conversation, and their privacy notice applies. We process the conversation as that customer's processor: routing messages, generating AI responses via our model providers, and storing transcripts for the customer to review. We do not use your conversation for our own purposes, do not sell it, and do not train AI models on it. To exercise your data protection rights over such a conversation — access, deletion or otherwise — please contact the operator of the agent; if you contact us instead, we will forward your request to them where we can identify them, as we are not authorised to act on the controller's data ourselves.
14. Automated decision-making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you (Art. 22 GDPR). AI agents on the platform generate conversational responses; they are clearly identified as AI, and our Terms of Service prohibit customers from using them for such decisions without human supervision. Automated abuse-prevention systems (for example rate limiting or fraud screening) are always subject to human review on request.
15. Children
The platform is not directed at children. You must be at least 18 to create an account. In line with Portuguese law, information-society services may not rely on the consent of children under 13, and our Terms prohibit customers from directing agents at children under 13; if we learn that we hold personal data of a child collected in breach of this policy, we will delete it.
16. Changes to this policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date, and material changes will be additionally notified by email or in-product notice. Please review this page periodically.
17. Contact and complaints
For any privacy-related question, request or complaint, contact us at legal@supercognit.com. We aim to answer privacy complaints within 15 working days. You can always also contact the CNPD (www.cnpd.pt).