Data Processing Agreement
Last updated June 12, 2026.
This page summarizes CogniMemo's standard Data Processing Agreement ("DPA") for customers who act as data controllers under GDPR, UK GDPR, or similar laws. The full DPA is available on request and is incorporated into Business and Enterprise agreements.
1. Roles and scope
You are the controller of personal data you submit or connect to CogniMemo. Enortic Inc acts as processor on your behalf, processing personal data only according to your documented instructions, these Terms, and the DPA.
This DPA applies to personal data processed in connection with the CogniMemo service. It does not apply to data we process as a controller, such as billing contact details for your organization.
2. Processing instructions
We will process personal data only to provide the service, maintain security, comply with law, or as otherwise documented in your account configuration, integration settings, and written instructions. If we are required by law to process data beyond your instructions, we will inform you unless prohibited by law.
3. Categories of data and subjects
- Data subjects: your employees, contractors, and other individuals whose data you connect to the service.
- Categories: account identifiers, workspace content, communication metadata, usage logs, and audit records as configured by you.
- Special categories: we do not require special category data. If you choose to process it, you are responsible for establishing a lawful basis and any required safeguards.
4. Sub-processors
We use vetted sub-processors for infrastructure hosting, monitoring, email delivery, payment processing, and support tooling. A current list is available on request at hello@cognimemo.com.
We will notify customers of material sub-processor changes and provide an opportunity to object on reasonable grounds relating to data protection. If we cannot accommodate a valid objection, you may terminate the affected service.
5. Security measures
We implement technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls, logging, vulnerability management, and employee training. Details are described in our security documentation and SOC 2 report, available on request for eligible customers.
6. Data subject requests
We will assist you in responding to data subject requests to access, rectify, delete, restrict, or port personal data, using available product features or reasonable manual assistance. You are responsible for validating requests and determining the appropriate response.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and will provide information reasonably required for you to meet your regulatory obligations, subject to security and legal constraints.
8. Data residency and transfers
You may select a primary processing region (for example US or EU) on eligible plans. Where personal data is transferred outside the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses or other approved transfer mechanisms.
9. Deletion and return
Upon termination of the service, we will delete or return personal data according to your plan settings and written instructions, unless retention is required by law. Backup copies may persist for a limited period before being overwritten in the ordinary course of operations.
10. Audits and compliance
We make available SOC 2 reports and security summaries to eligible customers under confidentiality. You may request additional audit information no more than once per year, subject to reasonable scope and scheduling, or accept third-party audit reports in lieu of on-site inspection where permitted.
11. Liability and order of precedence
Each party's liability under the DPA is subject to the limitations in our Terms or your signed enterprise agreement. In the event of conflict between the DPA and Terms regarding processing of personal data, the DPA controls.
12. How to execute the DPA
Business and Enterprise customers may request the current DPA and sub-processor list by emailing hello@cognimemo.com. Signing is completed via order form, click-through acceptance in the admin console, or countersigned PDF.