Controller
Cognita GRC, Douala, Cameroun. Data protection contact: guillaume@cognitagrc.io.
What we collect, and why
Self-assessment — if you ask to receive your report: email address, WhatsApp number (optional), organisation, sector, headcount, your twenty answers and the computed exposure. Purpose: to send you the report and follow up about it. Legal basis: your consent (art. 9). You can answer all twenty questions and see your result without providing anything.
Site scanner: the address you submit and the technical result of the scan. Purpose: to run the scan you asked for. Legal basis: your request. This data is kept for one hour and then deleted automatically.
Technical logging: your IP address is used to cap scans per hour and prevent abuse. Legal basis: legitimate interest in protecting the service. Retention: one hour.
Account and subscription — if you open an account: your name, email address, the name and nature of your organisation, your role in the team, and the date you last signed in. Purpose: to give you access to the service and to bill the subscription. Legal basis: performance of the contract. Sign-in uses a single-use link sent to your address; we store no password.
Payment — if you subscribe: the customer and subscription identifiers issued by our payment processor, the amount and the due date. Your card details are entered at the processor and never pass through our servers; we neither see nor store them.
DPO programme application — if you apply: name, email, WhatsApp number, city, profile, optionally a LinkedIn address, your free-text answers and how you found us. Purpose: to assess your application and tell you the outcome. Legal basis: your consent, timestamped (art. 9). We do not ask for a CV: an address is enough to qualify a profile (art. 5).
We collect no sensitive data within the meaning of article 48, and we use no advertising tracker and no third-party analytics.
Cookies
The site sets only strictly necessary cookies: NEXT_LOCALE, conformia_session. They remember the language you chose and, once you are signed in, keep your session — the latter is set at sign-in and never before. No advertising cookie, no third-party tracker: you can check it with our own scanner.
Retention
Report requests (prospects): three years from the last contact, then deletion.
Account and subscription: for the life of the contract, then ten years for the accounting and contractual records the law requires us to keep.
DPO programme applications: two years from the decision, then deletion; you may ask for erasure at any time.
Scan results and anti-abuse counters: one hour.
Database backups: thirty days at most.
Recipients and processors
Hosting: Railway Corporation (region europe-west4-drams3a (web, worker) / us-west2 (PostgreSQL, Redis)). Email delivery: Resend, when enabled. DNS and TLS: Cloudflare.
Payments: Stripe Payments Europe, Ltd. (Ireland, European Union), which collects the payment and alone holds the card data.
If you used a certified partner DPO’s link, your details and your answers are passed to them so they can provide the follow-up you asked for. The partner’s identity is shown on the page you answered from.
We neither sell nor rent any data.
Transfers outside Cameroon
As of today, the infrastructure is hosted in the Netherlands (EU) for the application; United States for the databases (region europe-west4-drams3a (web, worker) / us-west2 (PostgreSQL, Redis)), which matches the standard offer described in our documents. The data described above is therefore processed outside Cameroon.
We state this rather than leave it unsaid: article 32 subjects such transfers to authorization and contractual safeguards. That file is being assembled; its status is available on request at guillaume@cognitagrc.io. Residency in Cameroon or on-premise is offered to customers who require it.
Your rights
You have the rights of access, rectification, erasure, objection, restriction and portability set out in articles 37 to 47, and you may withdraw your consent at any time.
Write to guillaume@cognitagrc.io. We verify your identity before any disclosure, then answer within the applicable statutory period; that period is configured per jurisdiction because Cameroon’s implementing texts are unpublished.
The supervisory Authority provided for by article 53 has not yet been established, so no complaint route before it is open to date.
Security
End-to-end TLS, encryption at rest, restricted and logged access, encrypted backups. No personal data is written to application logs.
Contact us
For any question about these documents or your data: guillaume@cognitagrc.io.