← Back to HomeCognition7
LEGAL

We take your privacy seriously. Especially your voice.

Your recordings, your business intelligence, and your voice clone are yours. This policy explains exactly what we collect, why we collect it, how we protect it, and how you can delete it — any time, instantly. We comply with privacy law in South Africa, the European Union, and the United States.

Last updated: May 2025

Plain English summary: We collect what we need to run the platform. We never sell your data. Your voice is encrypted and used only to narrate your content. You can delete everything — including your voice clone — at any time from Settings. We comply with South Africa's POPIA, the EU's GDPR, and the US CCPA (California).

1. Who We Are

Cognition7 AI operates the platform at businessai7.com. We are an AI execution intelligence platform that processes voice recordings and meeting transcripts to generate business content and automate workflows. References to "we", "us", and "our" refer to Cognition7 AI. References to "you" refer to any person using our platform.

For privacy enquiries: privacy@businessai7.com

2. Jurisdiction and Applicable Law

We serve clients globally. Depending on where you are located, different privacy laws apply. We comply with all three frameworks — whichever gives you the strongest protection applies to you:

  • South Africa — Protection of Personal Information Act (POPIA), Act 4 of 2013
  • European Union / EEA — General Data Protection Regulation (GDPR), EU 2016/679
  • United States (California) — California Consumer Privacy Act (CCPA) and CPRA
  • United Kingdom — UK GDPR and the Data Protection Act 2018
  • All other jurisdictions — We apply GDPR-equivalent standards as a baseline

We do not operate separate systems for different regions. Every user gets the same protections regardless of location.

3. What We Collect and Why

Account information

  • Email address and name — to create and manage your account
  • Profile information (job title, industry, skills) — to personalise your content outputs
  • Billing information — processed by PayPal or Paystack; we never see or store card details

Voice and audio data

  • Audio recordings you upload or record — transcribed by our private AI transcription engine
  • Voice samples provided during onboarding — used to generate your personalised voice model
  • Your cloned voice ID — stored encrypted and used only to narrate your generated content

⚠ Voice cloning requires your explicit consent (opt-in). Your consent is recorded with a timestamp. You can revoke consent and delete your voice clone at any time in Settings. Under GDPR and POPIA, voice biometric data is a special category requiring explicit consent — we treat it accordingly.

Content and intelligence data

  • Transcripts of your recordings — stored in our encrypted database
  • Strategic themes, decisions, and actions extracted by Claude — stored as memory nodes
  • Generated content (posts, scripts, emails) — stored and linked to your account
  • Business memory nodes — persistent intelligence extracted across your sessions

Technical data

  • API usage logs — call type, token counts, cost (used for billing and abuse prevention)
  • Authentication session tokens — managed by Supabase, never stored in plain text
  • IP addresses — used for rate limiting and fraud prevention, not for tracking
  • Error logs — to identify and fix platform issues, purged after 30 days

4. Legal Basis for Processing (GDPR / UK GDPR)

For users in the EU, EEA, and UK, we process your data under the following legal bases:

  • Contract performance — processing your recordings and generating content is necessary to provide the service you signed up for
  • Legitimate interests — usage analytics and abuse prevention to maintain platform integrity
  • Explicit consent — voice cloning and any optional features involving biometric data
  • Legal obligation — retaining billing records as required by law

5. How We Use Your Data

  • To transcribe your recordings and extract business intelligence
  • To generate platform-specific content in your voice and style
  • To publish content to your connected social accounts on your instruction
  • To build and maintain your business memory layer
  • To send transactional emails (session ready, usage warnings, billing receipts)
  • To enforce plan limits and prevent abuse
  • To improve the platform using aggregate, anonymised data only

We never use your recordings or business intelligence to train AI models.Your data is processed to serve you — not to improve systems for other users.

We never sell, rent, or share your personal data with third parties for marketing or advertising purposes. Ever. Under any circumstances.

6. Third-Party Services

We work with the following sub-processors, each bound by data processing agreements:

  • Supabase (USA/EU) — database and authentication; SOC 2 Type II certified
  • Anthropic / Claude (USA) — AI processing; your transcripts are sent to Claude API. Anthropic's enterprise terms prohibit training on API data.
  • Voice synthesis partner (USA) — voice generation and TTS (only if you opt in)
  • Upload-Post — social media publishing on your explicit instruction
  • PayPal (USA) — payment processing; PCI DSS Level 1 compliant
  • Paystack (Nigeria/SA) — payment processing; PCI DSS compliant
  • Resend (USA) — transactional email delivery
  • Vercel (USA/EU) — frontend hosting; data processed in the region nearest to you

For EU/EEA users: where sub-processors are based outside the EEA, we rely on Standard Contractual Clauses (SCCs) as the transfer mechanism. A full list of SCCs is available on request at privacy@businessai7.com.

7. Your Rights

All users (global):

  • Access your data — request a copy of everything we hold about you
  • Correct inaccurate data — update your profile via Settings at any time
  • Delete your account — permanently purged within 30 days
  • Delete your voice clone — immediate, via Settings → Voice Clone

EU / EEA / UK users (GDPR / UK GDPR):

  • Right to data portability — receive your data in machine-readable format (JSON/CSV)
  • Right to object — object to processing based on legitimate interests
  • Right to restrict processing — limit how we use your data while a dispute is resolved
  • Right to withdraw consent — withdraw voice cloning consent at any time without penalty
  • Right to lodge a complaint — with your national supervisory authority (e.g. ICO in the UK, your EU DPA)

California users (CCPA / CPRA):

  • Right to know — what personal information we collect and how we use it
  • Right to delete — request deletion of your personal information
  • Right to opt-out of sale — we do not sell personal information; this right is satisfied by default
  • Right to non-discrimination — exercising your rights will not affect your service
  • Right to correct inaccurate personal information

South African users (POPIA):

  • Right to access and correct your personal information
  • Right to object to processing on reasonable grounds
  • Right to complain to the Information Regulator of South Africa
  • Right to be notified of data breaches that materially affect you

To exercise any right: email privacy@businessai7.com or use self-service options in Settings. We respond within 30 days (POPIA), 30 days (CCPA), or one month (GDPR), whichever is shortest — in practice we aim to respond within 7 business days.

8. Data Retention

  • Active account data — retained while your account is active
  • Deleted account — permanently purged within 30 days of deletion request
  • Voice models — deleted from our voice synthesis service immediately on removal from Settings
  • Billing records — retained for 7 years (SA and US tax law requirement)
  • API usage logs — retained for 12 months then anonymised
  • Error logs — purged after 30 days
  • Rate limit logs — purged after 24 hours

9. Data Security

  • Encryption at rest — all databases encrypted; AES-256-GCM for API keys and sensitive fields
  • Encryption in transit — TLS 1.2+ enforced on all connections
  • Row-level security — users can only access their own data; enforced at the database layer
  • Access controls — minimal privilege; only necessary team members can access production data
  • Breach notification — we will notify affected users and relevant authorities within 72 hours of discovering a material breach (GDPR requirement applied globally)

10. Cookies

We use essential cookies only — authentication session tokens required for the platform to work. No tracking cookies. No advertising cookies. No third-party analytics without your consent. We do not use cookies to build profiles or track you across other websites.

11. Children

Cognition7 is not intended for anyone under 18 (or 16 in some EU jurisdictions). We do not knowingly collect data from minors. Contact privacy@businessai7.com immediately if you believe a minor has created an account.

12. Changes to This Policy

We will notify you by email at least 14 days before making material changes. For changes required by law, we will notify you as soon as practicable. Continued use constitutes acceptance. You can always find the current version at businessai7.com/privacy.

13. Contact and Complaints

Privacy enquiries: privacy@businessai7.com
General support: order@businessai7.com
Platform: businessai7.com

Supervisory authorities for complaints:

  • South Africa — Information Regulator: inforeg.org.za
  • EU — Your national Data Protection Authority (list at edpb.europa.eu)
  • UK — Information Commissioner's Office: ico.org.uk
  • California / USA — California Attorney General: oag.ca.gov

Your data gives you power — not us. Every piece of intelligence we extract belongs to your business. We are the engine. You are the driver. Questions? Email privacy@businessai7.com — real humans respond within 7 business days.

Privacy PolicyTerms of ServiceRefund PolicyBilling & Plans
© 2026 Synova Capital · Cognition7