The supplied document includes entries awaiting confirmation. Those entries are clearly highlighted below.
Introduction
Cognx is a DynamX company.
We respect your privacy and recognise the importance of protecting the information entrusted to us. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you visit our website, contact us, create an account, or use our AI platform and associated services.
Our services may include AI conversations, knowledge search, document analysis, connected-data queries, content generation, configurable assistants, agents, and automated workflows. The information processed depends on the services you use, your organisation’s settings, and the deployment arrangements agreed with you.
This Policy also explains your privacy rights and how to exercise them.
This Policy is a privacy notice, not a request for blanket consent. Where consent is required for a particular activity, we will request it separately.
1. Definitions
The following terms are used throughout this Policy.
Personal data: Information relating to an identified or identifiable individual, such as a name, email address, account identifier, or information that can identify someone when combined with other data.
Data subject: The individual whose personal data is being processed.
Processing: Any operation performed on personal data, including collecting, storing, organising, retrieving, analysing, disclosing, restricting, or deleting it.
Restriction of processing: Limiting how personal data may be used while retaining it where appropriate.
Profiling: Automated processing used to evaluate or predict aspects of an individual, such as their interests, behaviour, or work performance.
Pseudonymisation: Replacing identifying information with alternative identifiers while keeping the information needed to reconnect it to an individual separately. Pseudonymised information remains personal data where the individual can still be identified. Information Commissioner's Office
Controller: The person or organisation that determines why and how personal data is processed.
Processor: A person or organisation that processes personal data on behalf of a controller.
Recipient: A person or organisation to which personal data is disclosed.
Third party: An organisation or individual outside the relevant data subject, controller, processor, and persons authorised to process data under their direct authority.
Consent: A freely given, specific, informed, and unambiguous indication of an individual’s agreement to a particular use of their personal data.
Customer Content: Documents, prompts, conversations, files, datasets, connected records, instructions, and other information submitted to or made available through the platform.
Output: Responses, summaries, analyses, recommendations, generated documents, and other material produced through the platform.
2. Name and Address of the Controller
The legal entity responsible for operating Cognx is:
Registered operator: Dynamx Artificial Intelligence LLC
Registered address: M-03, Abdulraheem Ahmed Mohamed AlMahmoud Building Al Nahyan Area, Sector E19, Airport Road P.O. Box 46221 Abu Dhabi, United Arab Emirate
Privacy contact: Hello@dynamx.ai
References to “Cognx”, “we”, “us”, and “our” in this Policy mean that legal entity.
When we act as a controller
We act as a controller when we determine the purposes and means of processing information for our own business activities, such as handling enquiries, administering customer relationships, managing billing, and protecting our website and services.
When we act as a processor
Where an organisation uses Cognx to process its documents, prompts, business records, or other Customer Content, that organisation will generally determine the purposes of the processing. We process that information on its documented instructions under the applicable service agreement and Data Processing Agreement.
Where our customer is itself a processor, we may act as a subprocessor.
The applicable Data Processing Agreement sets out the processing instructions and responsibilities, including confidentiality, security, assistance with individual rights, subprocessors, and deletion or return of data. This Policy does not replace that agreement. Information Commissioner's Office
An organisation’s own privacy notices may also apply to information it makes available through Cognx.
3. Cookies and Similar Technologies
Our website and hosted platform may use cookies, local storage, and similar technologies to maintain sessions, support authentication, remember settings, and protect the Service.
Where optional analytics or other tracking technologies are used, we explain their purposes and provide the choices required by applicable law. Technologies requiring consent will not be activated until that consent has been obtained.
You can withdraw consent through the relevant privacy controls. Browser settings can also be used to block or delete cookies, although disabling essential technologies may prevent certain functions from working.
Continuing to browse the website is not treated as consent to activities that require an affirmative choice.
For details about the cookies and similar technologies used by Cognx, read the Cookies Statement.
View Cookies Policy4. Collection of General Data and Information
The personal data we process depends on how you interact with Cognx.
Website and technical information
When you access our website or hosted services, we may process your IP address, browser and device information, operating system, access times, requested pages, session identifiers, and technical error records.
We use this information to deliver the website, maintain sessions, investigate faults, prevent misuse, and protect the Service.
Technical information is treated as personal data where it identifies or can reasonably be linked to an individual.
Account and business information
We may process your name, work email address, organisation, job title, account role, authentication identifiers, subscription details, and billing contact information.
Customer Content and Output
When the platform is used, processing may include prompts, uploaded documents, connected business records, conversation history, generated responses, source references, and associated metadata.
This material may contain personal data about users or other individuals, including employees, customers, suppliers, or people mentioned in documents.
Usage and operational information
We may process information about features used, request volumes, token consumption, connector activity, workflow execution, errors, and audit events for service administration, billing, reliability, and security.
This does not authorise us to reuse confidential Customer Content for unrelated purposes.
Sources of information
We receive information directly from you, from your organisation or its administrators, from systems that you or your organisation authorise us to connect, and from providers involved in authentication, payments, or service delivery.
5. Registration on Our Platform
When an account is created, we use the registration information to establish access, authenticate users, assign permissions, administer the subscription, and communicate about the Service.
Where you register using an organisation’s identity provider, we receive the information made available through that authentication arrangement, such as your name, work email address, and organisational identifier.
Your organisation’s administrators may manage your access and, depending on the deployment and permissions, access workspace records, conversations, or activity logs.
You may update account information through available settings or by contacting us. Where an account is controlled by your organisation, some changes must be requested through its administrator.
Deleting or disabling an account does not necessarily delete information that must be retained under the organisation’s instructions or applicable law.
6. Contact via the Website
When you contact us through email, a contact form, or another communication channel, we process the information you provide to respond, arrange demonstrations, investigate issues, or manage our relationship with you.
This may include your name, contact details, organisation, message content, and any supporting attachments.
Relevant information may be handled through the communication and support providers described in Section 9. We do not treat sending an enquiry as permission for unrelated marketing.
Please avoid including passwords, access tokens, or unnecessary sensitive information in ordinary correspondence. Where additional information is required for support, we will explain an appropriate method for providing it.
7. Processing Documents, Prompts and Connected Data
Where enabled, Cognx processes Customer Content to carry out the tasks requested by authorised users.
This can include extracting text, organising documents, building search indexes, retrieving relevant passages, querying connected systems, and generating responses or analyses.
Search indexes and numerical representations used for retrieval, sometimes called embeddings, are subject to the same relevant privacy restrictions where they contain or relate to identifiable individuals.
Connected systems
A connector may access information within the permissions granted to it. Depending on its configuration, it may import records into the platform, retrieve information when requested, or execute queries against a connected system.
Access through a shared or administrative credential may be broader than the permissions of an individual user. Customers must consider that scope when authorising connections.
Agents and workflows
Where configured, agents may process information across several steps, call external tools, create files, update records, or send information to another system.
The processing is governed by the workflow’s purpose, authorised permissions, applicable agreement, and any required approvals.
Connecting a system or enabling a workflow does not itself establish a lawful basis for processing every individual’s personal data contained within it.
8. AI Models, Training and Service Improvement
Processing to provide AI responses
To produce a response or carry out a requested task, the Service may supply a selected model with prompts, relevant conversation history, retrieved passages, and other necessary context.
The model may operate within a customer-controlled environment or through an external provider, depending on the agreed deployment.
Model training
We do not use Customer Content or Output to train or fine-tune models for our own general use, other customers, or third parties without separate, explicit written authorisation.
A customer-specific training engagement requires a separate agreement identifying its purpose, the information used, permitted processing, and retention arrangements.
Any processing of personal data for training must also have an appropriate lawful basis. Customer authorisation does not replace individual consent where that consent is legally required. AI development and ordinary deployment should be assessed as distinct processing purposes rather than assumed to share the same justification. Information Commissioner's Office
For model providers we appoint, we require contractual restrictions consistent with our commitments. Providers independently selected and contracted by a customer are also governed by that customer’s arrangements with them.
A restriction on model training does not necessarily mean that a provider retains no information. Any operational or security retention must be disclosed in the applicable provider and deployment information.
Service improvement
We may use appropriately limited operational information to diagnose errors, assess performance, and improve reliability. This does not create a separate right to use confidential prompts, documents, or Output for general model training.
9. Sharing Personal Data
We disclose personal data only for identified purposes and subject to applicable legal and contractual requirements.
Service providers: We may use providers for hosting, infrastructure, authentication, AI processing, payments, communications, support, and security. Providers acting on our behalf are subject to appropriate processing and confidentiality obligations.
Your organisation: Information may be available to your organisation’s administrators and authorised users according to workspace permissions and the features enabled.
Connected services and recipients: Information may be transmitted to systems or recipients selected through an authorised integration, export, sharing action, or workflow.
Professional advisers and authorities: We may disclose information where reasonably necessary for legal advice, compliance with a binding obligation, protection of legal rights, or investigation of unlawful activity.
Corporate transactions: Personal data may be disclosed where necessary in connection with a proposed or completed merger, acquisition, or business transfer, subject to appropriate confidentiality and privacy safeguards.
We do not sell personal data or use Customer Content to target advertising.
Provider information: [Insert a link to the current subprocessor and model-provider notice, including relevant processing purposes and locations.]
10. Hosting and International Data Transfers
The location of processing depends on the hosting arrangement, selected models, connected services, and authorised support access.
A UK or UAE business address does not, by itself, mean that all platform information is stored or processed in that country.
Where personal data is transferred internationally, we use the mechanism required by the law applicable to that transfer. For restricted UK transfers, this may involve adequacy regulations or appropriate safeguards, such as an International Data Transfer Agreement or applicable Addendum, together with the required assessment. You may request information about relevant safeguards by contacting us. Information Commissioner's Office
Transfers subject to UAE or other applicable data-protection requirements must satisfy those requirements separately.
Customer-managed deployments
Where a customer operates Cognx within its own infrastructure, the customer controls the information stored there, subject to the agreed allocation of responsibilities.
We process information made available to us through support, administration, or other disclosed service functions. External models, connectors, and enabled telemetry must be considered separately; self-hosting alone is not a guarantee that no information leaves the customer’s environment.
11. Security of Personal Data
We maintain technical and organisational safeguards appropriate to the information we process and the services we undertake to provide.
Access to personal data by our personnel is limited to authorised purposes and personnel who need it for those purposes.
Specific measures and responsibilities are described in the applicable security documentation and customer agreement. Customers remain responsible for the security settings, credentials, and infrastructure allocated to them.
No information system or method of transmission can be guaranteed completely secure. This does not reduce our legal or contractual security obligations.
Where a personal-data breach occurs, we will notify affected customers, individuals, or authorities as required by applicable law and the relevant agreement.
12. Routine Erasure and Restriction of Personal Data
We retain personal data only for as long as necessary for its stated purpose, to follow lawful customer instructions, or to meet applicable legal requirements.
When retention is no longer justified, we delete the information, return it where required, or render it genuinely anonymous.
Where information must be retained for a legal obligation or active dispute, its use is restricted to the relevant purpose.
Deletion may involve several records, including source documents, search indexes, conversation history, and operational records. Disconnecting a source does not necessarily delete information previously imported from it.
Backup copies are removed according to the applicable retention cycle. Until removed, they remain protected and are not used for unrelated purposes.
Customer-managed installations and copies exported into other systems are subject to the controls and responsibilities applicable to those environments.
13. Rights of the Data Subject
Your rights depend on the applicable law, the purpose of processing, and our role. They are not all absolute, and lawful exceptions may apply.
a) Confirmation and access
You may request confirmation that your personal data is being processed, access to that information, and an explanation of relevant processing activities.
b) Rectification
You may request correction of inaccurate personal data or completion of incomplete information.
Where an AI-generated statement about you is inaccurate, please identify the statement and relevant context so the responsible controller can assess appropriate correction or other action.
c) Erasure
You may request deletion where the applicable legal conditions are met. Some information may need to be retained for legal obligations, legitimate claims, or other lawful exceptions.
d) Restriction of processing
You may request that use of your information be limited in qualifying circumstances, including while accuracy or lawfulness is being examined.
e) Data portability
Where applicable, you may request certain information in a structured, commonly used, machine-readable format and ask for it to be transferred to another controller where technically feasible.
f) Objection
You may object to certain processing based on the circumstances of your situation.
You may object to the use of your personal data for direct marketing at any time. We will stop that marketing use, including related profiling.
g) Automated decision-making
Where applicable, you may request information, human intervention, or review of decisions made solely through automated processing that significantly affect you.
The precise rights and restrictions depend on the governing data-protection regime and the circumstances described in Section 17.
h) Withdrawal of consent
Where processing relies on your consent, you may withdraw it at any time. Withdrawal does not make earlier lawful processing unlawful.
Exercising your rights
Contact Hello@dynamx.ai with your request. We may seek proportionate information to confirm your identity or clarify what you are requesting.
We respond within the period required by applicable law and explain any permitted extension, refusal, or limitation. Requests are normally free of charge unless the law permits otherwise.
Where we process the relevant information solely on an organisation’s behalf, we will help direct the request to that organisation and assist it as required. We will handle requests concerning information for which we are the controller ourselves.
14. Legal Basis for Processing
We identify the legal basis for each processing purpose rather than relying on acceptance of this Policy.
United Kingdom and, where applicable, European data-protection law
For processing for which we act as controller, the relevant bases may include:
| Purpose | Applicable basis |
|---|---|
| Providing a service directly contracted with an individual, or taking requested steps before that contract | Contractual necessity |
| Managing business contacts and supporting users whose organisation is our customer | Legitimate interests in administering and delivering the business service, subject to the required assessment |
| Protecting accounts, investigating misuse, and maintaining service reliability | Legitimate interests in security and reliable operation, subject to the required assessment |
| Maintaining legally required financial records or responding to binding legal obligations | Compliance with a legal obligation |
| Optional activities requiring permission, including certain marketing or tracking activities | Consent |
Any reliance on legitimate interests requires consideration of the individual’s rights and reasonable expectations. Processing sensitive or otherwise specially protected information may require additional legal conditions. Information Commissioner's Office
United Arab Emirates
Where applicable, processing must comply with the UAE Federal Decree-Law No. 45 of 2021 concerning personal-data protection and relevant implementing requirements. Separate free-zone or sector-specific regimes may apply to particular activities. The relevant regime must be determined for the actual operator and processing—not simply from the customer’s country. Global Practice Guides
We rely on consent or an applicable ground permitting processing without consent under the relevant UAE regime. A basis available under UK law is not automatically treated as sufficient for UAE processing.
Customer-controlled processing
Where we act as processor, the customer determines the lawful basis for its processing and provides the necessary instructions. We do not rely on our own business interests to authorise unrelated use of customer-controlled personal data.
15. Period for Which Data Will Be Stored
Retention is determined by the purpose, sensitivity, contractual requirements, and applicable legal obligations.
| Information category | Retention approach |
|---|---|
| Account and subscription information | Retained while needed to administer the relationship, followed by any necessary legal or dispute-related period |
| Customer Content, conversations, and Output | Retained under the customer’s instructions, agreed settings, and applicable service and data-processing agreements |
| Billing and accounting records | Retained for the period required by applicable financial and tax obligations |
| Enquiries and support records | Retained while needed to resolve the matter and maintain a necessary support history |
| Security and audit records | Retained for a defined period appropriate to detection, investigation, and relevant obligations |
| Marketing preferences | Retained as necessary to respect the individual’s choices, including minimal suppression records after an objection |
Any post-termination export period is governed by the applicable Terms of Service, Order, and Data Processing Agreement.
Retention details: [Insert the approved retention periods or link to the applicable retention schedule, including backup deletion.]
16. Provision of Personal Data
Some information is necessary to create an account, authenticate a user, provide a requested service, issue an invoice, or comply with a legal requirement.
Where required information is not provided, we may be unable to perform the corresponding activity. We identify required fields or explain the requirement when collecting the information.
Optional information is identified as such. Refusing optional marketing consent does not, by itself, prevent access to an unrelated paid service.
Please provide only information relevant to the task. Sensitive personal data, children’s information, or information subject to special restrictions should be submitted only where the intended processing and safeguards have been agreed.
17. Automated Decision-Making and Profiling
Cognx uses automated processing to perform functions such as retrieval, summarisation, analysis, and workflow execution. These activities should not be confused with a blanket statement that the platform performs no automated processing.
Whether a particular workflow involves profiling or a solely automated decision with legal or similarly significant effects depends on its purpose, configuration, and consequences.
Where a customer configures such a workflow, that customer is responsible for establishing its lawful use, providing the required notices, and arranging appropriate oversight. We support the obligations assigned to us under the applicable agreement.
Any such use by Cognx for its own purposes must be described in a specific notice explaining the information used, the decision process, likely effects, and available safeguards.
The applicable safeguards may include an explanation of the decision, an opportunity to make representations, human intervention, and a means to challenge the outcome. Information Commissioner's Office
Before publication: [Confirm whether account screening, fraud controls, or other Cognx-operated functions make decisions of this kind, and add the required specific disclosure.]
18. Children’s Privacy
Cognx is intended for business and organisational use by adults. It is not offered as a service for children to register and use independently.
Where a customer needs to process information about children, the customer must establish the relevant lawful basis and required safeguards, and the processing must fall within the agreed service scope.
Contact us if you believe a child has created an account or supplied information without appropriate authorisation.
19. Changes to This Policy
We may update this Policy to reflect changes in our services, processing arrangements, or legal requirements.
The updated Policy will show its effective date. We will provide additional notice where required for material changes.
Where a new activity requires consent, we will obtain that consent before beginning the activity. Publishing an updated Policy does not, by itself, authorise a new use of Customer Content or override existing contractual restrictions.
20. Contact and Privacy Complaints
For privacy questions, rights requests, or complaints, contact:
Cognx
Email: Hello@dynamx.ai
Postal address: [Insert registered address]
Please describe your concern and provide enough information for us to identify the relevant interaction, account, or processing activity.
We will acknowledge privacy complaints promptly, investigate appropriately, keep you informed, and communicate the outcome without undue delay. Where UK requirements apply, we will acknowledge receipt within 30 days. Information Commissioner's Office
You may also complain to the relevant data-protection authority. This includes the Information Commissioner’s Office in the United Kingdom, where applicable, or the competent authority under the relevant UAE or other data-protection regime.
Nothing in this Policy restricts your statutory privacy rights or makes them dependent on accepting the governing-law provisions in our Terms of Service.
Back to top ↑