Privacy
Privacy Policy
This policy explains how Cognidel collects, uses, stores, shares, protects, and transfers personal data across therapy, payments, learning, support, and platform operations. It is written to be stricter and more operationally realistic than a lightweight marketing privacy notice.
Effective June 26, 2026
Controller position and supported-country framing
- Cognidel determines the purposes and means of much of the personal data processed through the platform and therefore acts as a controller or similar primary decision-maker for that data, subject to the laws that apply.
- Therapists may also act as independent controllers, professionals, or legally accountable record keepers for certain therapy-related decisions and notes under the laws and ethical rules that apply to them.
- Cognidel therapy operations and therapist onboarding are currently limited to Kenya. Learning and resources may be accessed from other locations where lawful.
Who this policy covers
- This Privacy Policy applies to Cognidel website visitors, account holders, clients, therapists, learners, donors, buyers, support contacts, and other users whose personal data is processed through Cognidel.
- It covers personal data processed across therapy, learning, courses, resources, support, payments, therapist verification, account security, and operational administration.
- Where a specific feature, campaign, or provider requires an additional notice, that additional notice will apply alongside this policy.
Data Cognidel may collect
- Identity and account data, such as your name, email address, username, profile image, country, role, login history, and security metadata.
- Therapy and sensitive service data, such as booking records, participant permissions, intake submissions, notes, file uploads, care-related metadata, consent records, and support or safeguarding reports.
- Learning and product data, such as course enrolment, progress, quiz attempts, purchases, certificates, downloads, and related audit history.
- Payments and finance data, such as payer information, billing contact details, transaction reference, amount, currency, provider response state, refunds, reversals, payout records, and ledger activity.
- Technical and usage data, such as IP-derived region information, browser or device signals, session metadata, logs, cookies, anti-abuse indicators, and service diagnostics.
How Cognidel uses personal data
- To create and maintain accounts, authenticate access, secure the platform, and enforce role-based permissions.
- To provide bookings, therapy operations, session rooms, learning, certificates, support, resources, and product fulfilment.
- To reconcile payments, prevent fraud, investigate disputes, verify therapist eligibility, preserve operational integrity, and comply with lawful requests.
- To detect abuse, protect users, respond to incidents, and preserve records where necessary for safeguarding, enforcement, or legal defence.
- To communicate important operational messages, including sign-in notices, booking updates, payment receipts, reminders, support outcomes, and account actions.
Lawful grounds for processing
- Cognidel processes data where reasonably necessary to perform a contract with you, operate the service you requested, or take steps at your request before providing a service.
- Cognidel also processes data where necessary for legitimate interests such as fraud prevention, service security, moderation, dispute resolution, platform improvement, and legal defence, provided those interests are not overridden by rights that apply to you.
- Sensitive or therapy-related data may also be processed where you provide consent, where you intentionally submit the data into therapy services, where a therapist or service requirement makes that processing necessary, or where another lawful basis applies under relevant law.
- Cognidel may process or disclose data where required to comply with law, court process, law-enforcement requests, safeguarding obligations, or regulator demands.
Who Cognidel may share data with
- Authorised therapists, authorised participants, and internal administrators, but only to the extent required for a legitimate platform, therapeutic, security, or support purpose.
- Payment processors, hosting providers, infrastructure partners, email-delivery providers, customer-support tooling, identity providers, analytics or anti-abuse providers, and similar service providers acting on Cognidel instructions or under their own lawful duties.
- Courts, regulators, auditors, insurers, law-enforcement agencies, child-protection bodies, emergency responders, or professional authorities where disclosure is lawfully required or reasonably necessary to prevent serious harm.
- Prospective acquirers, funders, or professional advisers in a restructuring, merger, sale, or audit, subject to lawful confidentiality and use restrictions.
International transfers and data location
- Cognidel is delivered online and may involve processing in multiple countries through globally distributed infrastructure, support systems, payment systems, and communications providers.
- Cognidel does not promise that all data will remain in a single country or region unless and until a specific regional-processing control is expressly implemented and documented for that service.
- Where cross-border processing occurs, Cognidel seeks to use contractual, organisational, and technical safeguards appropriate to the nature of the data and the service being provided.
- Users in supported countries should assume that some account, log, messaging, payment, and operational records may be processed outside their home country.
- Where a third-party provider controls part of the infrastructure path, Cognidel may be limited by that provider regional architecture unless Cognidel has specifically configured and documented a stronger location restriction for the relevant service.
- By creating an account, submitting personal data, or using Cognidel services, you acknowledge that your personal data may be transferred to, stored in, or processed in countries outside your country of residence, including countries where privacy protections may differ from those in your home jurisdiction. Where consent is required by applicable law for that transfer, you provide that consent by using the service.
Therapy and sensitive records
- Therapy notes, intake material, session metadata, attachments, consent records, and related care records are treated as sensitive data and are subject to stricter access controls than general account information.
- Cognidel administrators do not have routine access to private therapy notes or session content. Any administrative access to sensitive records is limited to justified purposes such as safeguarding, abuse review, fraud investigation, therapist verification, legal compliance, or dispute handling.
- Cognidel does not permit unauthorised hidden observers, secret participant additions, or unlawful disclosure of therapy records through the platform.
Cookies, session controls, and analytics
- Cognidel uses cookies, local storage, and similar technologies to maintain sessions, remember preferences, secure sign-in, detect abuse, and support core functionality.
- Some technical data may also be used for diagnostics, reliability monitoring, fraud detection, and performance improvement.
- Blocking all cookies or storage controls may break authentication, payment, or protected feature access.
Retention and deletion
- Cognidel keeps data only for as long as reasonably necessary for the purpose for which it was collected, except where longer retention is required for legal, regulatory, tax, finance, safeguarding, fraud, audit, or dispute reasons.
- Deleting an account does not always mean immediate deletion of all associated records. Payment records, audit logs, moderation records, therapist verification records, and some care-related records may need to be retained.
- General account profile records may be retained while the account is active and for a reasonable period after closure, including where needed for fraud prevention, complaint handling, or service restoration.
- As a general retention standard, Cognidel may retain finance, tax, anti-fraud, and payment-reconciliation records for at least 7 years, or longer where law, litigation risk, safeguarding, or dispute handling requires a longer period.
- Where deletion is possible, Cognidel may instead anonymise, de-identify, archive, or restrict access to data depending on the legal and operational context.
- Cognidel may also preserve evidence relevant to disputes, suspected abuse, payment investigations, or legal holds even after an account has been closed.
Your rights and complaints
- Depending on the law that applies to you, you may have rights to access, correct, update, restrict, object to, port, or request deletion of certain personal data, as well as rights relating to consent withdrawal or complaint filing.
- Cognidel currently provides therapy operations and therapist onboarding in Kenya. Privacy complaints may be raised with the Office of the Data Protection Commissioner where applicable.
- Cognidel may ask for identity verification before acting on a privacy request and may refuse or narrow a request where the law allows, including to protect other users, preserve therapy integrity, or retain records required by law.
Security, incidents, and children
- Cognidel uses role controls, authentication, logging, moderation, review controls, and operational safeguards designed to reduce unauthorised access, abuse, and fraud.
- No internet service can guarantee absolute security. Cognidel therefore reserves the right to restrict access, require re-authentication, or pause services where security confidence is not high enough.
- If Cognidel becomes aware of a material incident affecting personal data, it may investigate and preserve evidence, and it will notify affected parties or regulators where required by applicable law, including within any mandatory legal timeframes.
- Cognidel is intended for adults unless a lawful parent, guardian, or dependent-care path is expressly supported for the relevant service. Where children or dependents are involved, lawful authority and any additional protections required by law must be satisfied.
- Where Cognidel reasonably suspects that a child or dependent was enrolled, monitored, or disclosed through the platform without proper authority, Cognidel may freeze the related service path and preserve records for review.
Country privacy frameworks considered by Cognidel
- Kenya: Cognidel expects privacy handling in or relating to this country to be assessed against Kenya Data Protection Act, 2019, with complaints or oversight potentially involving the Office of the Data Protection Commissioner.
High-risk privacy limits
- Cognidel does not promise medical-record secrecy beyond what can reasonably be delivered through the actual product architecture, user behaviour, and provider stack in use at the time.
- If a user chooses to share sensitive information in uploads, contact forms, or therapy workflows, Cognidel will apply platform controls to it, but the user remains responsible for deciding what to submit.
- Cognidel may refuse to process especially sensitive or legally high-risk requests through ordinary support channels and may require a safer or more formal process instead.