CogneraXAIIntelligence Engineered UnleashedSign in

Legal

Privacy Policy

Last updated 1 July 2026

This Privacy Policy explains how CogneraX AI (“CogneraX”, “we”, “us”) collects, uses, and protects personal data when you use CogneraXAI (the “Service”). It covers data about our customers (the real estate teams who subscribe) and — where we act as a processor on a customer’s behalf — the buyers and leads whose data flows through the Service.

1. Our role

For account data of our subscribers, CogneraX is the data controller. For the personal data of leads and buyers that a customer collects and processes through the Service (for example via WhatsApp, Meta lead ads, or the website widget), the customer is the controller and CogneraX acts as a processor under the customer’s instructions. If you are a buyer and want to exercise your rights, please contact the brokerage you interacted with; we will support them in responding.

2. Data we collect

  • Account data — name, work email, brokerage name, plan, and authentication details (we use passwordless magic-link sign-in).
  • Lead & conversation data — buyer names, phone numbers, messages, budgets, preferences, and lead scores that customers ingest or that buyers submit.
  • Property & business data — listings, agents, tasks, and pipeline records you add.
  • Usage & log data — feature usage, AI token counts for billing, IP address, device/browser information, and error diagnostics.
  • Cookies — strictly-necessary cookies for authentication and security. See “Cookies” below.

3. How we use data

  • To provide, operate, secure, and support the Service;
  • To generate AI replies, lead scores, and property matches on the customer’s behalf;
  • To meter usage and administer billing;
  • To detect, prevent, and investigate abuse, fraud, and security incidents;
  • To communicate service, security, and account notices;
  • To comply with legal obligations.

We do not sell personal data, and we do not use lead or conversation data to train third-party AI models.

4. Legal bases

Where the GDPR applies, we rely on: performance of a contract (to provide the Service), legitimate interests (to secure and improve the Service), consent (where required, e.g. certain messaging or cookies), and compliance with legal obligations. Under Egypt’s Personal Data Protection Law No. 151 of 2020, processing is carried out on the basis of the data subject’s consent or another lawful basis, with customers responsible for obtaining any consent required from their leads.

5. Sub-processors & sharing

We share data with a limited set of vendors who process it on our behalf under data-processing terms. Our current sub-processors are:

  • Supabase — managed database, authentication, and file storage; hosts Customer Data with tenant isolation via row-level security.
  • DeepSeek — AI model provider that generates replies, lead scores, and property matches from message content (your data is not used to train its models).
  • Meta Platforms — WhatsApp, Facebook, and Instagram messaging on the channels a customer connects.
  • Paymob — payment processing for paid subscriptions (card and wallet details are handled by Paymob, not stored by us).
  • Vercel — application hosting and CDN, plus cookieless product analytics (aggregate page views and events — no cookies, no cross-site tracking).
  • Sentry — error and performance monitoring (diagnostic and log data).
  • Upstash — distributed rate limiting on public endpoints, where enabled (operational reliability).

We notify customers of material changes to this list and, where required, provide an opportunity to object. We may also disclose data where required by law or to protect our rights, and in connection with a merger or acquisition (subject to this Policy).

6. International transfers

Your data may be processed in countries other than your own. Where required, we use appropriate safeguards (such as standard contractual clauses) for cross-border transfers.

7. Retention

We retain personal data for as long as your workspace is active and as needed to provide the Service, then delete or anonymise it within a reasonable period, unless a longer retention is required by law. Customers can delete leads and other records at any time from within the Service.

8. Security

We apply technical and organisational measures to protect data, including encryption in transit, tenant isolation via row-level security, scoped access to privileged keys, and rate limiting on public endpoints. No system is perfectly secure, but we work to protect your data and to notify affected parties of a material breach as required by law.

9. Your rights

Subject to applicable law, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights over account data, contact us at privacy@cogneraxai.com. For lead data held on a customer’s behalf, we will refer your request to the relevant customer (controller).

10. Cookies

We use strictly-necessary cookies to keep you signed in and to secure the Service. We do not use advertising cookies, and our product analytics are cookieless — they set no tracking cookies and do not follow you across sites. If we ever introduce cookie-based or otherwise non-essential cookies, we will present a consent choice before setting them.

11. Children

The Service is intended for business use and is not directed at children under 18. We do not knowingly collect personal data from children.

12. Changes

We may update this Policy from time to time. Material changes will be notified through the Service or by email, and the “Last updated” date above will change.

13. Contact

For privacy questions or requests, contact privacy@cogneraxai.com. See also our Terms of Service.