Privacy Policy
Version 1.0 Last updated: [PLACEHOLDER: date]
This notice explains what personal data Cortex collects, why, on what legal basis, who it is shared with, how long it is kept, and what rights you have. It covers website visitors, people who complete the Cortex AI Audit, people who book a call, Portal users, people we interview during an engagement, and business contacts we approach.
Contents
- Who we are
- Scope, and the difference between controller and processor
- What we collect and why
- Automated decision making
- How we use artificial intelligence
- Who we share data with
- International transfers
- How we protect data
- How long we keep data
- Your rights
- Backups and deletion
- Children
- Changes to this notice
- Contact
1. Who we are
Cortex is an organisational intelligence practice operated by Cason Consulting MB, a small partnership (mažoji bendrija) registered in the Republic of Lithuania.
| | | |---|---| | Controller | Cason Consulting MB, trading as Cortex | | Registered address | J. Savickio St. 4-7, LT-01108 Vilnius, Lithuania | | Company registration code | 307655812 | | VAT number | Not VAT registered at the date of this document | | Contact for data protection | [PLACEHOLDER: contact email] | | Website | [PLACEHOLDER: domain] |
Data protection officer
We have not appointed a data protection officer. Article 37 of the General Data Protection Regulation requires one where the controller is a public authority, where the core activities consist of processing operations that by their nature, scope or purposes require regular and systematic monitoring of data subjects on a large scale, or where the core activities consist of large scale processing of special category data or of data relating to criminal convictions. None of those applies to us. We are a small practice, we do not monitor people on a large scale, and we do not process special category data as a core activity.
We keep this assessment under review and will appoint a data protection officer, and publish their contact details here, if the position changes. Questions about personal data reach the person responsible for data protection at Cortex directly at [PLACEHOLDER: contact email], and we answer within the thirty day period set out in section 9.
[PLACEHOLDER: if a data protection officer or an Article 27 representative is appointed, replace this section with their name and contact details.]
Data protection questions are handled directly by the practice at [PLACEHOLDER: contact email].
2. Scope, and the difference between controller and processor
This notice covers personal data we process as a controller, meaning that we decide why and how it is processed. That is the case for:
- visitors to our website,
- people who complete the Cortex AI Audit,
- people who book or attend a consultation call,
- people who write to us,
- people who hold a Cortex Portal account,
- business contacts at organisations we approach.
Where we act as a processor
During a paid engagement, most of the personal data inside a client's workspace is processed on that client's instructions. The client is the controller and Cortex is the processor. That applies to interview recordings and transcripts, the findings and quotations extracted from them, documents the client uploads, and the personal data flowing through any system we build for them.
What this means if you are an interviewee. If you are an employee of a Cortex client and you take part in an interview, your employer is the controller of that interview. Your employer decided that the interviews would happen, chose who takes part, and instructs us on what to do with the material. Cortex processes it for them under a written Data Processing Agreement and does not use it for its own purposes.
You can exercise your rights against your employer, and you can also write to us and we will help. Where a request reaches us that concerns material we hold as a processor, we pass it to the client without undue delay and assist them in answering it. We do not decide such a request ourselves.
Section 3.5 sets out the details of interview processing, including the protections that apply to you specifically.
Where a client's own customers are involved
Where we build a system that processes personal data belonging to a client's customers, staff or suppliers, the client is the controller of that data. Their own privacy notice governs it. Our role is set out in the Data Processing Agreement with that client.
3. What we collect and why
3.1 Website visitors
You can read the website without giving us anything. The site sets no non essential cookies and shows no consent banner, because there is nothing to consent to. The Cookie Policy explains this in detail.
| What | Why | Legal basis | How long | |---|---|---|---| | Cookieless analytics. Page path, referrer, country, browser and device type, screen size, and aggregate counts. Collected by Plausible and Vercel Web Analytics. No cookie is set, no identifier is stored on your device, and no profile is built. | To understand which pages are read and where visitors come from, so we can improve the site | Legitimate interest (Art 6(1)(f)): understanding how our own website is used. Our interest in basic aggregate statistics is not outweighed by your interests, because no cookie or device identifier is used and no individual is identified | Aggregate statistics only. No personal record to delete | | Server logs. IP address, timestamp, request path, response status, user agent, and referrer, recorded by our hosting provider | To keep the service running, to investigate errors, and to detect and stop abuse | Legitimate interest (Art 6(1)(f)): operating and securing our own service | [PLACEHOLDER: hosting provider log retention period] | | Error reports. Where a page fails, a technical error report is sent to Sentry. It carries the error, the page, the browser, and a truncated stack trace. Filters strip anything matching transcript or prompt content before the report is sent | To find and fix faults | Legitimate interest (Art 6(1)(f)): keeping our service working | [PLACEHOLDER: Sentry retention period] | | Bot protection. Cloudflare Turnstile runs on the audit form. It receives your IP address, browser and device signals and a challenge token, and returns a pass or fail result to us. It is configured without pre-clearance, so it sets no cookie on your device | To stop automated submissions of a free form that triggers a paid model call and an email | Legitimate interest (Art 6(1)(f)): preventing abuse of and fraud against our service. Turnstile is chosen specifically because it is privacy preserving and does not profile visitors | Cloudflare's own retention. We keep only the pass or fail result with the submission |
Cloudflare processes Turnstile data as our processor under the Cloudflare Data Processing Addendum, which incorporates the European Commission's Standard Contractual Clauses. See [PLACEHOLDER: link to the Cloudflare privacy policy and Turnstile privacy addendum in force at publication].
Analytics scripts run on the marketing pages only. No analytics script runs on /report, /portal or /admin, because a page view event carrying a report URL would leak operating data into an analytics service.
3.2 Cortex AI Audit respondents
The audit is thirty one questions across six steps. Nothing reaches our servers until you ask for the report. During the six steps your answers live only in your own browser tab, in sessionStorage. When you press to see your score, your answers are sent to a stateless route that computes the score in memory, returns it, and stores nothing. The single write to our database happens when you submit the gate.
| What | Why | Legal basis | How long | |---|---|---|---| | Your answers to the thirty one questions, including your sector, headcount band, revenue band, hours estimates, rates and free text | To compute your score and produce your written report | Consent (Art 6(1)(a)), given by the unticked checkbox at the gate | 24 months from your last contact with us | | Your work email address | To send you the report and, if you ask, to discuss it | Consent (Art 6(1)(a)) | 24 months from your last contact with us | | Your company name, and the role you gave | To identify the report and to hold the conversation you asked for | Consent (Art 6(1)(a)) | 24 months from your last contact with us | | Your computed scores, the five component scores, the economics, the band and the internal tier | These are your report | Consent (Art 6(1)(a)) | 24 months from your last contact with us | | The generated report itself, as structured data and as text | To deliver it, to serve it at your share link, and to have it in front of us if you ask for a conversation | Consent (Art 6(1)(a)) | 24 months from your last contact with us | | The exact consent wording you agreed to, and the timestamp | To be able to demonstrate what you consented to, as Art 7(1) requires. When the wording changes, older records still show what was actually agreed | Legal obligation (Art 6(1)(c)) read with Art 7(1), and our legitimate interest in being able to demonstrate compliance | 24 months from your last contact with us | | A salted hash of your IP address, your user agent, and how long you took to complete the form | To enforce rate limits, detect automated submissions and detect abuse. The IP address is hashed, not stored in the clear | Legitimate interest (Art 6(1)(f)): preventing abuse of and fraud against a free, unauthenticated service that costs us money on each use | 24 months, with the row | | Quality flags derived from your submission, such as whether the email domain is a free provider or a role address, or whether the company name looks implausible | To prioritise our own follow up and to filter out junk | Legitimate interest (Art 6(1)(f)): running our own business | 24 months, with the row |
What we promise, in writing.
- There is no marketing sequence. You receive one email containing your report. There is no reminder chain, no drip campaign and no newsletter. This is a commitment in our Terms of Service and it is enforced by the fact that no email sequencing exists in the platform.
- We do not sell your answers, and we do not share them with anyone outside Cortex other than the processors named in section 6 who deliver the service.
- Your answers are not used to train any model.
- We contact you again only if you ask us to, or where you booked a call and we need to arrange or follow up on it.
Your share link. The report is published at a private URL containing a long random token. We store only a SHA-256 hash of that token, never the token itself and never the database row identifier. The page is excluded from search engines by a noindex, nofollow, noarchive header and is not in the sitemap. The link is not guessable, but it is not password protected: anyone you forward it to can read it. The page carries your company name, your role and your own figures, and carries no email address and no personal name. We can revoke a link on request or on our own initiative, and we rate limit reads on each token.
Withdrawing consent, and deletion. Every report email carries this line:
Reply with the word delete and we remove your answers, your report and your email address within thirty days.
You can also write to [PLACEHOLDER: contact email]. Withdrawing consent does not affect the lawfulness of what we did before you withdrew it, and it does not un-send the report you already received. Section 11 explains how deletion interacts with backups.
Do not enter personal data about other people into the audit form. It asks about how your organisation operates and not about individuals.
3.3 People who book a consultation
| What | Why | Legal basis | How long | |---|---|---|---| | Booking data. Your name, email address, the time you chose, your time zone, and anything you write in the booking form. Collected through the Cal.com embed and passed to us by webhook | To schedule and hold the call | Steps taken at your request before entering into a contract (Art 6(1)(b)) | Engagement plus 24 months, or 24 months from the call if no engagement follows | | A booking reference we generate and pass into the embed | To match the booking to your audit submission without matching on your email address | Legitimate interest (Art 6(1)(f)): joining our own records accurately | With the booking record | | The call recording and the transcript, produced by Fathom | To have an accurate record of what was discussed, so that our follow up and our proposal reflect what you actually said rather than what we remembered | Consent (Art 6(1)(a)) for the recording, given by you on the call. The underlying processing of the discussion is a pre-contract step under Art 6(1)(b) | Engagement plus 12 months for the transcript. Recording per the engagement plus twelve months, matching the transcript retention; configured on the Fathom account | | Our own notes and the prepared call sheet | To prepare for and follow up on the call | Steps taken at your request before entering into a contract (Art 6(1)(b)) | Engagement plus 24 months |
Recording. Every call opens with a spoken consent line. If you do not want the call recorded, say so and the call proceeds without recording. Refusing recording costs you nothing and changes nothing about the call. You may also withdraw consent during the call, and we will stop and delete the recording.
We record because recording rules are national and both the Lithuanian and the Spanish positions require that participants are informed. We ask rather than merely inform.
Cal.com. The booking embed loads only after you click to show available times. Until then, nothing is loaded from Cal.com and no Cal.com cookie is set. From the moment you click, Cal.com sets its own cookies and processes your data under its own privacy notice. The Cookie Policy explains this.
3.4 Cortex Portal users
Portal accounts exist only by invitation, for people at organisations we work with.
| What | Why | Legal basis | How long | |---|---|---|---| | Account data. Your name, work email address, role, and the workspace you belong to | To give you an account and to know who is in a client workspace | Contract (Art 6(1)(b)), or our legitimate interest (Art 6(1)(f)) in administering the engagement where the contract is with your employer rather than with you | Engagement plus 24 months | | Sign in events. Timestamp, outcome, IP address, browser and device, and the magic link token as a hash | To let you in, to show you your own session list, and to detect unauthorised access | Contract (Art 6(1)(b)) and legitimate interest (Art 6(1)(f)): securing accounts | 24 months (in the audit log) | | Session data. Session identifier, device, approximate location from IP, and last seen time | To keep you signed in, to time box sessions, and to let you revoke a session you do not recognise | Contract (Art 6(1)(b)) | Until the session ends, then in the audit log for 24 months | | Your actions in the Portal. Documents you upload, actions you tick, the sequence you approve, a proposal you accept, and a finding you flag | To run the engagement, and to record what was agreed | Contract (Art 6(1)(b)) | Engagement plus 24 months | | Proposal acceptance record. Your typed name and role, the statement you ticked, the hashed snapshot of the exact document, the timestamp, a hash of your IP address and your user agent | To evidence that a specific person accepted a specific version of a specific document at a specific time | Contract (Art 6(1)(b)) and legal obligation (Art 6(1)(c)) to keep accounting and contractual records | [PLACEHOLDER: statutory retention period under Lithuanian accounting and archives law] |
Magic link. Portal sign in uses a single use link valid for fifteen minutes, sent to your email address. There is no password. Keep the link private, because within its window it is the credential.
3.5 Interviewees during an engagement
If you are an employee of a Cortex client and you take part in an interview during a Cortex Diagnostic, this section is for you. Your employer is the controller. Cortex is the processor. Your employer decided that these interviews would take place and instructs us on what to do with the material. We process it only on their documented instructions under a Data Processing Agreement.
| What | Why | Legal basis | How long | |---|---|---|---| | Your name, role and team | So the client's interview plan and the coverage record make sense | Determined by the client as controller, typically their legitimate interest (Art 6(1)(f)) in understanding their own operations, or contract with you as an employee | Engagement plus 12 months | | The interview recording and the transcript, produced by Fathom | So that findings can be traced to what somebody actually said | Consent (Art 6(1)(a)) for the recording itself | Engagement plus 12 months, then deleted | | Quotations and facts extracted from the transcript, with the position in the transcript they came from | So that every figure in a roadmap traces to a sentence somebody said | Determined by the client as controller | Engagement plus 12 months |
Before the interview you receive a one page privacy notice. At the start of the interview there is an explicit recorded consent line.
You can refuse the recording. If you do not consent, say so and the interview proceeds without recording, or does not proceed. Refusing is not a disadvantage and we do not report a refusal as a problem.
Off the record. At any point in the interview you can say that a passage is off the record. A passage marked off the record is excluded from extraction, is never quotable, and does not appear in any finding.
Your employer never reads the transcript. This is worth stating plainly, because it is the protection that matters most to an interviewee and it is enforced technically rather than by policy.
Interview transcripts are never visible to the client through the Cortex Portal. Not at any tier, not on request, not ever. There is no database policy that would allow a client session to read a transcript, a transcript chunk or an extracted quotation. They are unreachable from a client account, not merely hidden in the interface.
What the client sees is the finished analysis: the findings, the roadmap and the figures. Where a quotation is used to support a finding, it is used only where it does not identify the speaker, and the client can ask us to remove any quotation.
Your rights. Address them to your employer as controller. You can also write to us at [PLACEHOLDER: contact email] and we will pass the request on without undue delay and help answer it. Where you ask us to delete your recording and transcript, we will tell the client and act on their instruction, and we will tell you what happened.
3.6 People who write to us
| What | Why | Legal basis | How long | |---|---|---|---| | Your name, email address and the content of your message, sent through the contact form or by email | To read your message and reply to it | Steps taken at your request before entering into a contract (Art 6(1)(b)) where you are enquiring about our services, otherwise our legitimate interest (Art 6(1)(f)) in answering correspondence addressed to us | 24 months from the last message in the exchange, unless it becomes part of an engagement record |
Every message is read by the practice. There is no support queue and no automatic responder. We reply within two working days.
3.7 Business contacts at prospective clients
We approach organisations we think we can help. Where we do, we may process business contact details.
| What | Why | Legal basis | How long | |---|---|---|---| | Business contact data. Your name, your business role, your business email address, your organisation and its publicly available details, and a note of why we think there is a fit. Sourced from public professional sources such as your organisation's website, a public professional profile, or a business register | To make a relevant business to business approach about services relevant to your professional role | Legitimate interest (Art 6(1)(f)): promoting our services to organisations that plausibly need them, in a business to business context, using business contact details, about a matter within the recipient's professional responsibility. We have carried out a balancing assessment and can provide it on request | 12 months from the last contact, or immediately on objection |
We approach in a business to business capacity only. We do not process the personal contact details of individuals, we do not buy contact lists, and we do not run automated bulk outreach sequences.
You have an absolute right to object. Where you object to direct marketing, we stop immediately and we do not need to weigh anything. Reply to any message with the word stop, or write to [PLACEHOLDER: contact email]. We record the objection so it is not repeated, and that record is the only thing we retain.
Where you ask us to erase your details entirely rather than record an objection, we do that instead, accepting that we might contact you again in future because we no longer hold the record that says not to.
4. Automated decision making
We do not make any decision about you that is based solely on automated processing and that produces legal effects concerning you or similarly significantly affects you. Article 22 of the GDPR therefore does not apply to our own products.
To be precise about what is automated:
- The Leverage Score is computed automatically. It is arithmetic on your own answers using published, fixed weights. It produces a document. It does not decide anything about you.
- The internal tier is computed automatically. The audit computes a tier of
strong,conditionalornot_justifiedfrom your answers. The tier only changes what the report shows. Anot_justifiedresult means the report contains no payback table and no booking link, and instead says what would change the result and what you could do without us. It does not affect your access to anything, your standing with us, or any right or legal position you hold. - The report prose is generated automatically, by a language model, from figures that were computed in code before the model was called. Section 5 explains this.
How to contest a result. If you think the score or the tier is wrong, tell us and a person will look at it. Write to [PLACEHOLDER: contact email], or use the link on the report page. We will review your submission, explain how the result was produced, correct the underlying answers where they were recorded incorrectly, and re-run the report where that is appropriate. Where the free text answers contradict the computed result, we can override it. A person always decides.
Systems we build for clients. Where we build a system for a client that could make or materially inform a decision about an individual, whether that system amounts to automated decision making under Article 22, and whether it falls into a high risk category under the AI Act, is assessed for that build with that client. The client is the controller and the deployer, and the obligations sit with them. This notice does not cover those systems.
5. How we use artificial intelligence
What the engine does
We use large language models to draft documents. The engine writes the prose of the audit report, drafts the question script for the first conversation, extracts findings and supporting quotations from interview transcripts, and drafts the roadmap, proposals and client updates.
Numbers are computed, not generated
Every figure is calculated in code before a model is called. The model receives the computed figures and is not permitted to introduce, alter or recalculate one. An automated guard checks the output for numbers that did not come from the computation and rejects it if it finds any.
A person reviews before a client sees it
No AI generated draft reaches a client without review by the practice. The audit report is the exception to individual review, because it is produced on demand from computed figures under a reviewed, version controlled methodology. The Terms of Service, Part D, says what the audit report is and what weight to give it.
The model provider
Model inference is performed by Anthropic, acting as our processor under a data processing agreement.
- No training. Anthropic's commercial terms exclude the use of the material we send for training models. Nothing from an engagement, and nothing from an audit submission, is used to train any model.
- Zero data retention. We request zero data retention on our account, so that inputs and outputs are not retained by the provider beyond what is needed to return the response. [PLACEHOLDER: confirm zero data retention is enabled on the Anthropic account in use, and state the retention that actually applies.]
- Where inference happens. Model inference may be performed outside the European Union unless an EU processing option is configured on the plan in use. [PLACEHOLDER: state the inference region actually configured, and whether the EU inference option is enabled. Until this is verified end to end, this notice must continue to say that inference may occur outside the EU.] This is the only point at which client text leaves infrastructure we control, and section 7 sets out the transfer mechanism.
What is sent to the model
Audit answers and the computed report structure, interview transcript text and its extracted structure, and the drafting instructions. Untrusted text is passed inside delimited blocks so that it cannot alter the instructions, and no model output is ever used as a link, an identifier or a branch in our code.
Marking of AI generated documents
Regulation (EU) 2024/1689 (the AI Act), as amended by Regulation (EU) 2026/1744, requires at Article 50 that AI generated output be marked in a machine readable format. Documents we generate carry machine readable metadata identifying them as AI generated together with the engine version that produced them, and the audit report states on its face that it was written by a language model from computed figures. [PLACEHOLDER: state the marking implementation actually shipped.]
6. Who we share data with
We do not sell personal data. We do not share it for anyone else's marketing. We share it with the service providers below, each of which processes it on our instructions under a written data processing agreement, and with professional advisers, insurers and authorities where we are required or entitled to.
Processors and subprocessors
| Provider | What it does | What it processes | Location | Transfer mechanism | |---|---|---|---|---| | Vercel | Hosting, application delivery and serverless functions | Everything passing through the site, server logs | Functions pinned to an EU region. Company established in [PLACEHOLDER: Vercel contracting entity and its country] | [PLACEHOLDER: transfer mechanism for Vercel, being either an intra EU arrangement, Standard Contractual Clauses, or the EU-US Data Privacy Framework where the contracting entity is certified] | | Supabase | Database, authentication and file storage | Audit submissions, Portal accounts, engagement content, transcripts, documents | EU, Ireland | [PLACEHOLDER: transfer mechanism for Supabase, being either an intra EU arrangement or Standard Contractual Clauses] | | Anthropic | Model inference for report writing, extraction and drafting | Audit answers, computed figures, transcript text, drafting instructions | [PLACEHOLDER: Anthropic inference region and whether the EU option is enabled] | [PLACEHOLDER: transfer mechanism for Anthropic, being Standard Contractual Clauses or the EU-US Data Privacy Framework where the entity is certified. State which applies] | | Resend | Transactional email, including report delivery and Portal notices | Email addresses, email content | [PLACEHOLDER: Resend processing region] | [PLACEHOLDER: transfer mechanism for Resend] | | Cal.com | Scheduling the consultation call | Name, email, chosen time, time zone, anything you write in the booking form | [PLACEHOLDER: Cal.com processing region] | [PLACEHOLDER: transfer mechanism for Cal.com] | | Fathom | Recording and transcription of calls and interviews | Voice recordings and transcripts of calls and interviews | [PLACEHOLDER: Fathom processing region] | [PLACEHOLDER: transfer mechanism for Fathom] | | Cloudflare | Turnstile bot protection on the audit form | IP address, browser and device signals, challenge token | Global network, EU points of presence | Cloudflare Data Processing Addendum incorporating the Standard Contractual Clauses. [PLACEHOLDER: confirm the version of the addendum in force] | | Sentry | Error monitoring | Technical error reports with transcript and prompt content filtered out before sending | [PLACEHOLDER: Sentry processing region, EU region available] | [PLACEHOLDER: transfer mechanism for Sentry] | | Upstash | Rate limiting | Salted hashes of IP addresses and request counters | [PLACEHOLDER: Upstash region, or state that rate limits run in the primary database instead] | [PLACEHOLDER: transfer mechanism for Upstash, if used] | | Plausible | Cookieless website analytics | Aggregate page statistics, no cookie, no device identifier | [PLACEHOLDER: Plausible hosting region, EU hosted] | [PLACEHOLDER: transfer mechanism for Plausible] | | Vercel Web Analytics | Cookieless website analytics | Aggregate page statistics, no cookie, no device identifier | With Vercel, above | As Vercel, above |
Fonts are self hosted. We serve web fonts from our own domain. No request is made to Google Fonts or to any other font service, so your IP address is not disclosed to one.
We keep the subprocessor list current. Clients receive advance notice of a change to the list of processors handling their engagement material, as the Data Processing Agreement provides. The table above changes when the list changes and the date at the top of this notice changes with it.
A current subprocessor list and copies of the data processing agreements are available on request before any engagement begins.
Others we may share with
- Professional advisers, being our lawyers, accountants and auditors, where they need it and under a duty of confidence.
- Authorities, where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend a legal claim.
- A successor to our business, where the practice is sold or transferred, under the same protections.
7. International transfers
Client material is held in the European Union. Databases, file storage and the functions that process them run in an EU region. No client data is replicated outside the European Economic Area, with one exception that we name rather than omit.
The exception is model inference. Text sent to the model provider for analysis and drafting is processed and returned. Depending on the region configured on the plan in use, that processing may take place outside the European Union. That is the only point at which client text leaves infrastructure we control.
Where personal data is transferred outside the European Economic Area, we rely on one of the following, and we state which for each provider in the table in section 6:
- an adequacy decision of the European Commission for the receiving country,
- the EU-US Data Privacy Framework, where the receiving organisation is certified under it,
- the European Commission's Standard Contractual Clauses, supplemented where necessary by additional technical and organisational measures identified through a transfer impact assessment.
[PLACEHOLDER: complete the transfer mechanism column in section 6 for every provider, record a transfer impact assessment for each transfer outside the EEA, and confirm the current certification status of any provider relied on under the EU-US Data Privacy Framework, before publication.]
You can ask us for a copy of the safeguards in place for a specific transfer. Write to [PLACEHOLDER: contact email].
8. How we protect data
A summary. The full technical position is on our security page at /security.
- Location. Databases, file storage and the processing functions run in an EU region.
- Isolation. Each client has a workspace, and isolation is enforced by row level security in the database, before the application sees a row. A query issued from one workspace cannot return another workspace's row. There is one exception, the Cortex operator role, and every action it takes is written to an append only log.
- Encryption. Data is encrypted in transit using TLS and at rest by our infrastructure providers.
- Authentication. The operator account requires a password plus mandatory two factor authentication and cannot be reset by email. Client accounts use single use magic links valid for fifteen minutes, over PKCE, confirmed by a POST rather than by loading a link. Sessions are time boxed on both sides and can be listed and revoked.
- Files. Three private storage buckets. Files are never executed and never rendered inline. Download links are signed and expire in five minutes, are never emailed and are never logged.
- Logging discipline. Transcript text, prompt bodies, model output, email addresses, signed URLs and tokens are never written to application logs. Error reports are filtered before they leave.
- Analytics exclusion. No analytics script runs on
/report,/portalor/admin. - Never stored. Payment card details never touch our systems and are handled by the payment provider.
- Certifications. We hold no ISO 27001 certification and no SOC 2 report, and we claim none. The practice is small and those audits have not been run. What is described here is what is built, and it can be verified in a technical review before an engagement begins.
Breaches. Where a personal data breach occurs, we notify the State Data Protection Inspectorate within 72 hours where the threshold in Article 33 is met, and we notify affected people without undue delay where Article 34 applies. Where we are a processor, we notify the client controller without undue delay.
9. How long we keep data
| Data | Retention | From | |---|---|---| | Audit submissions, including answers, email, scores, report and consent record | 24 months | Your last contact with us | | Consultation booking records and our notes | Engagement plus 24 months, or 24 months from the call where no engagement follows | End of the engagement, or the call | | Call and interview recordings and transcripts | Engagement plus 12 months, then deleted | End of the engagement | | Findings, quotations, notes and deliverables in a workspace | Engagement plus 24 months | End of the engagement | | AI job payloads, being the inputs and outputs of an engine run | 12 months | The run | | Portal accounts and membership records | Engagement plus 24 months | End of the engagement | | Audit log, including sign in events, publishing events and operator actions | 24 months | The event | | Contact form and email correspondence | 24 months | The last message in the exchange | | Business contact records for outreach | 12 months, or immediately on objection | The last contact | | Objection and suppression records | Indefinitely, because the record is what stops us contacting you again | The objection | | Proposal acceptance records, contracts, invoices and accounting records | [PLACEHOLDER: statutory retention period under Lithuanian accounting and archives law] | The document | | Server logs | [PLACEHOLDER: hosting provider log retention period] | The request | | Error reports | [PLACEHOLDER: Sentry retention period] | The error |
Retention is applied by a scheduled deletion job rather than by anyone remembering to run it.
Where we are required by law to keep something for longer, for example an accounting record or a document needed to establish or defend a legal claim, we keep that document for the required period and delete the rest.
Where we are a processor, retention is set by the client controller in the Data Processing Agreement. The periods above are our defaults where the client does not specify otherwise.
10. Your rights
Under the General Data Protection Regulation you have the following rights over personal data we hold about you as a controller.
| Right | What it means | |---|---| | Access (Art 15) | Ask us to confirm whether we process your data, and get a copy of it together with information about how it is used | | Rectification (Art 16) | Have inaccurate data corrected and incomplete data completed | | Erasure (Art 17) | Have your data deleted where there is no longer a good reason for us to hold it, where you withdraw the consent it relied on, or where you object and we have no overriding ground | | Restriction (Art 18) | Ask us to stop using your data, while keeping it, for example while a dispute about its accuracy is resolved | | Portability (Art 20) | Receive the data you gave us, in a structured, commonly used and machine readable format, and have it sent to another controller where technically feasible. This applies to data processed on consent or on contract by automated means | | Objection (Art 21) | Object to processing based on our legitimate interest, on grounds relating to your particular situation. Where you object to direct marketing, we stop, with no balancing test | | Withdraw consent (Art 7(3)) | Withdraw consent at any time, as easily as you gave it. This does not affect the lawfulness of what we did before you withdrew | | Complain (Art 77) | Complain to a supervisory authority |
How to exercise them
By email. Write to [PLACEHOLDER: contact email]. Say what you want and give us enough information to find your records, which is usually the email address you used.
By replying "delete". If you completed the Cortex AI Audit, the fastest route is to reply to the report email with the word delete. That is a complete erasure request. We remove your answers, your report and your email address.
By replying "stop". If you received a business to business approach from us, reply with the word stop and we stop contacting you.
In the Portal. Portal users can see and correct their own profile, and can list and revoke their own sessions, at /portal/settings.
Our service level. We answer within thirty days. Where a request is complex or where we have received a number of requests from you, we may extend by up to two further months, and if we do we will tell you within the first thirty days and explain why. This is our commitment and it also matches the Article 12(3) requirement to respond without undue delay and in any event within one month.
Identity. Where we have reasonable doubt about who is making a request, we may ask for information to confirm it. We ask for the minimum needed and we do not use it for anything else.
Cost. Exercising your rights is free. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive, and we will explain why if that ever happens.
Where we are a processor. If your request concerns interview material or other content inside a client workspace, we pass it to the client controller without undue delay and help them answer it. We will tell you that we have done so and who the controller is.
Complaining to a supervisory authority
You can complain to the Lithuanian supervisory authority:
Valstybinė duomenų apsaugos inspekcija
(State Data Protection Inspectorate)
L. Sapiegos g. 17, 10312 Vilnius, Lithuania
https://vdai.lrv.lt
[PLACEHOLDER: confirm the current postal address, telephone number and email of the VDAI at publication]
You can also complain to the supervisory authority in the EU or EEA country where you live or work, or where you think the problem happened. You do not have to come to Lithuania. Every EU and EEA country has one, and they cooperate with each other.
We would rather you told us first, at [PLACEHOLDER: contact email], so that we can put it right. You do not have to, and complaining to us does not affect your right to complain to an authority.
11. Backups and deletion
We want to be precise about this rather than promise something we cannot deliver.
Deletion is applied to live systems within thirty days. When you ask us to delete your data, and we have no overriding legal reason to keep it, we remove it from the live database and from live file storage within thirty days. Where an audit submission is deleted, an entry recording that a deletion was performed survives in the audit log, because we need to be able to show that we honoured the request. That entry does not contain your answers or your report.
Backups age out on their own schedule. Backups exist so that we can recover from a failure, and they are not selectively edited, because editing a backup destroys its integrity as a backup and risks the recovery it exists for.
| Backup | Retention | |---|---| | Point in time recovery of the database | 7 days | | Weekly export of file storage to EU object storage | 90 days | | Monthly database dump to EU object storage | 12 months |
Your data may therefore persist in a backup for up to twelve months after it has been deleted from the live systems. During that time it is encrypted, is not accessible to anyone in the ordinary course, and is used only to restore service after a failure. If a restore from backup ever reinstates data that was deleted on request, we re-apply the deletion immediately after the restore. We maintain a record of deletion requests specifically so that this can be done.
12. Children
Cortex is a business to business service. It is not intended for anyone under 18 and we do not knowingly collect personal data from children. The audit requires you to confirm that you are over 18 and acting for an organisation.
If you believe a child has given us personal data, tell us at [PLACEHOLDER: contact email] and we will delete it.
13. Changes to this notice
We update this notice when what we do changes. When we do:
- the version number and the "Last updated" date at the top change,
- where the change is material, we give at least thirty days' notice before it takes effect, by email to Portal users and to the contact we hold for a live engagement, and in the Portal,
- where a change affects processing that relies on your consent, we ask for consent again rather than relying on the old consent.
The date at the top of this notice also changes whenever the subprocessor table changes, so that the table can be relied on as current.
14. Contact
For anything about this notice, about your data, or to exercise a right:
Cortex
Cason Consulting MB
J. Savickio St. 4-7, LT-01108 Vilnius, Lithuania
[PLACEHOLDER: contact email]
Every message is read by the practice. We reply within two working days, and we answer a rights request within thirty days.
Related documents. Terms of Service at /terms. Cookie Policy at /cookies. Security page at /security. Clients receive a Data Processing Agreement.
Counsel review
These documents were drafted as working versions on 3 September 2026. They reflect the architecture, the data model and the data flows of the practice as designed on that date, and the regulatory position verified on that date.
They must be reviewed by Lithuanian counsel before publication, together with the Terms of Service, the Cookie Policy and the Data Processing Agreement. Specific matters flagged for counsel in this document: the assessment that no data protection officer is required (section 1), the legitimate interest balancing assessment for business to business outreach (section 3.7), the completion of the transfer mechanism table and the transfer impact assessments (sections 6 and 7), the statutory retention period for contractual and accounting records (section 9), and whether any engagement requires a data protection impact assessment under Article 35 read with the list published by the State Data Protection Inspectorate.
A record of processing activities under Article 30 must be maintained alongside this notice, and a Data Processing Agreement must be in place with every client and every processor named in section 6 before the first engagement.
Every
[PLACEHOLDER: ...]must be resolved before publication.
Cortex is a trading name of Cason Consulting MB.
Company code 307655812. Register of Legal Entities of the Republic of Lithuania.
J. Savickio St. 4-7, LT-01108 Vilnius, Lithuania. Not VAT registered.
hello@[domain]

