LEGAL

Privacy Policy

This Privacy Policy explains how Cognivox, a product designed and operated by Nathan Software Solutions Limited, collects, uses, stores and protects personal information when you use our website, services and AI-powered communications platform.

Last updated: 14 September 2026
01

Introduction

Cognivox is a product designed and operated by Nathan Software Solutions Limited ("Nathan Software"), a company registered in Scotland under company number SC750597.

Nathan Software respects your privacy and is committed to protecting personal information processed in connection with Cognivox.

This Privacy Policy explains how we collect, use, disclose, store and protect personal information when you visit the Cognivox website, contact us, create or use an account, connect an integration, or interact with services provided through the Cognivox platform.

References in this Privacy Policy to "Cognivox" refer to the Cognivox product and services. References to "we", "us" or "our" refer to Nathan Software as the operator of Cognivox, unless the context requires otherwise.

This Privacy Policy also explains the rights available to you under applicable data protection law.

02

Who we are

Cognivox is a product designed and operated by Nathan Software Solutions Limited ("Nathan Software"), a company registered in Scotland under company number SC750597.

Depending on how Cognivox is being used, Nathan Software may act as a data controller or as a data processor acting on behalf of a Cognivox customer.

Where Nathan Software determines the purposes and means of processing personal information in connection with Cognivox, Nathan Software acts as the data controller for that processing.

Where a business or organisation uses Cognivox to communicate with its own customers, callers, employees or other individuals, that organisation may be the data controller responsible for the personal information processed through those communications. In those circumstances, Nathan Software may process that information on the organisation's behalf through Cognivox.

03

Information we collect

The information we collect depends on how you interact with Cognivox and the services and integrations being used.

Information you provide to us

This may include:

  • Your name and contact details.
  • Your email address and telephone number.
  • Company or organisation information.
  • Account and profile information.
  • Information contained in enquiries, support requests or other correspondence.
  • Information you provide when configuring or using Cognivox services.
  • Appointment information, including appointment subject, description, location, requested date and time and associated contact information.

Information collected automatically

When you use our website or platform, certain technical information may be collected automatically, including:

  • IP address.
  • Browser and device information.
  • Operating system.
  • Login and authentication information.
  • Usage and activity information.
  • Diagnostic, security and error logs.

Information received from integrations

Where an authorised user connects a supported third-party integration, Cognivox may receive and process information from that service where necessary to provide the requested integration.

This may include calendar and scheduling information received through Google Calendar as described in Section 05 of this Privacy Policy.

04

AI communications and conversation transcripts

Cognivox provides AI-powered communication services, including AI receptionist functionality. When an individual makes a telephone call to a Cognivox-powered service, the audio of the conversation is processed in real time so that the AI receptionist can understand the caller, generate appropriate responses and perform authorised actions.

Telephone call audio

How telephone call audio is handled depends on the telephone service and configuration used by the relevant Cognivox customer.

For calls handled directly through supported Cognivox telecommunications services, including Twilio-based services, call audio is processed in real time to provide the AI receptionist service but Cognivox does not retain an audio recording of the call. A written transcript of the conversation may be retained as described below.

Where Cognivox is connected to a customer's SIP or PBX telephone system and call recording is enabled, Cognivox may create and retain an audio recording of the call in addition to the written transcript.

Information contained in conversations

Depending on the service and configuration being used, conversation information may include:

  • Written transcripts of telephone conversations.
  • Audio recordings of telephone calls where a SIP or PBX configuration has call recording enabled.
  • Chat messages and AI-generated responses.
  • Names, telephone numbers and email addresses voluntarily provided by callers.
  • The reason for contacting the relevant business or organisation.
  • Appointment and scheduling information.
  • Enquiries, messages and other information voluntarily provided during the conversation.
  • Technical and operational information associated with the communication.

Storage of telephone call transcripts

Cognivox may store a written transcript of telephone conversations handled by the Cognivox AI receptionist. For direct telecommunications services, including Twilio-based services, the transcript is retained without an audio recording of the call. Where SIP or PBX call recording is enabled, an audio recording may also be retained.

A transcript may contain personal information provided during the conversation, including names, contact details, appointment information, enquiries, messages and other information voluntarily provided by the caller.

Transcripts may be used to provide and administer the Cognivox service, maintain conversation history, allow authorised users of the relevant organisation to review customer communications, support requested business actions, investigate service or support issues, maintain security and meet applicable legal or contractual requirements.

Access to stored transcripts is restricted to authorised users and personnel where access is necessary for the provision, administration, security or support of the Cognivox service.

Where Cognivox processes a transcript on behalf of a customer, the Cognivox customer may be the data controller responsible for determining the purposes for which the transcript is processed and the appropriate retention requirements. Nathan Software may act as a data processor for that processing.

Use of artificial intelligence services

Cognivox uses the OpenAI API to provide AI-powered functionality. Conversation information may be transmitted to and processed by OpenAI where necessary to understand a request, generate a response or determine an appropriate authorised action.

Cognivox uses OpenAI as an artificial intelligence service provider for inference and does not permit Google Workspace API data, including raw, aggregated or derived Google user data, to be used to train or improve generalised or non-personalised artificial intelligence or machine-learning models.

Cognivox's OpenAI API organisation is configured so that API inputs and outputs are not voluntarily shared with OpenAI for model training or model improvement. Feedback sharing and evaluation or fine-tuning data sharing are also disabled for this purpose.

OpenAI does not receive Cognivox users' Google OAuth credentials and does not independently access a user's Google Calendar through Cognivox. Google Calendar access is performed by Cognivox through its own Calendar integration and only within the permissions authorised by the connected user.

Information for callers

Businesses and organisations using Cognivox are responsible for ensuring that callers receive appropriate information about the processing of their personal information where required by applicable data protection law.

This includes ensuring that callers are appropriately informed where their telephone conversation will be processed by an AI receptionist and a written transcript of that conversation will be retained. Where SIP or PBX call recording is enabled, the relevant customer is also responsible for ensuring that callers receive any notice required by applicable law about the recording and for establishing an appropriate lawful basis for that processing.

Please do not provide unnecessary sensitive information.

Unless specifically required for an authorised service, individuals should avoid providing sensitive personal information during interactions with Cognivox-powered services.

05

Google API Services and Google user data

Cognivox allows authorised customers to connect supported Google services, including Google Calendar, to their Cognivox account. Google integrations are optional and are enabled only when an authorised user chooses to connect their Google Account and grants Cognivox the requested permissions through Google's authorisation process.

Cognivox accesses Google user data only after the user has authorised the relevant integration and only to provide the user-facing functionality associated with that integration.

Google data we access

When a user connects Google Calendar to Cognivox, Cognivox may access Google Calendar data necessary to provide calendar and appointment functionality. Depending on the permissions granted, this may include:

  • Calendar information.
  • Calendar events.
  • Event dates and times.
  • Appointment and calendar availability.
  • Event identifiers and other information required to associate a Cognivox appointment with a Google Calendar event.
  • Event information required to create, update or delete appointments and corresponding calendar events.
  • Other Google Calendar information necessary to provide functionality explicitly requested by the user.

Cognivox requests access only to Google user data that is necessary to provide features the user has chosen to enable.

How we use Google user data

Google user data accessed through Cognivox is used only to provide or support the user-facing functionality for which access was granted.

When a customer connects Google Calendar, authorised Google Calendar data may be used to:

  • Check calendar and appointment availability.
  • Determine whether an employee or other authorised calendar participant is available at a requested date and time.
  • Identify suitable dates and times for appointments.
  • Create calendar events and appointments when requested and authorised.
  • Update existing calendar events and appointments when requested and authorised.
  • Delete or cancel calendar events and appointments when requested and authorised.
  • Synchronise Cognivox appointment records with corresponding Google Calendar events where applicable.
  • Respond to appointment and scheduling requests made through Cognivox-powered communications.

Cognivox does not use Google user data for purposes unrelated to the functionality that the user has authorised.

Cognivox does not use Google user data for advertising, advertising personalisation or profiling for advertising purposes.

AI processing of Google-derived information

Cognivox's AI receptionist may use limited information obtained from or derived from Google Calendar where necessary to fulfil a scheduling request.

For example, if a caller or chat user asks to make an appointment at a particular date and time, Cognivox's Calendar integration may check the relevant Google Calendar. The AI receptionist may then use the resulting availability information to confirm the requested time or ask the individual to select another time.

Calendar operations are performed by Cognivox's Calendar integration. The AI service does not independently connect to or control the user's Google Calendar.

Limited Google-derived scheduling information may be included in an OpenAI API request where necessary for the AI receptionist to respond to the user's scheduling request. Cognivox does not provide Google OAuth access tokens or credentials to OpenAI.

Cognivox does not use or permit Google Workspace API data, including raw, aggregated or derived Google user data, to be used to develop, train or improve generalised or non-personalised artificial intelligence or machine-learning models.

Storage of appointments and Google Calendar data

Cognivox stores appointment records where necessary to provide its scheduling, appointment management and calendar integration functionality.

Depending on the appointment and configuration, stored information may include:

  • Appointment subject or title.
  • Appointment description.
  • Appointment location.
  • Start and end dates and times.
  • Appointment status.
  • Customer name and contact information.
  • The company and employee associated with the appointment.
  • Calendar provider information.
  • An external Google Calendar event identifier used to associate the Cognivox appointment with the corresponding Google Calendar event.
  • Creation and modification information necessary to administer the appointment.

Cognivox may also process and securely retain Google authorisation credentials, including OAuth tokens, where necessary to maintain a Google integration that the user has chosen to enable.

Cognivox does not store a user's Google Account password.

Protection of Google user data

Where Google user data, Google-derived information, appointment information or authorisation credentials are processed or retained, Cognivox applies appropriate technical and organisational safeguards designed to protect that information against unauthorised access, disclosure, alteration, loss or misuse.

Access to Google user data and associated appointment information is limited according to the functionality and permissions required to provide and administer the relevant Cognivox service.

Sharing and transfer of Google user data

Cognivox does not sell Google user data.

Cognivox does not share Google user data with third parties for advertising or advertising personalisation.

Google user data or limited information derived from it may be processed by service providers acting on our behalf only where necessary to provide, maintain or secure Cognivox's user-facing functionality.

Cognivox currently uses the OpenAI API as its third-party artificial intelligence service. Limited Google-derived information may be transmitted to OpenAI where necessary to process a scheduling request, such as determining how the AI receptionist should respond after Cognivox has checked appointment availability.

Cognivox's OpenAI API data-sharing controls are configured so that API inputs and outputs are not voluntarily shared for model training or model improvement. Cognivox does not permit Google user data transferred in connection with the service to be used to train or improve generalised or non-personalised AI or machine-learning models.

Other service providers may process information on our behalf where necessary to operate, host, secure or provide Cognivox. Where service providers process personal information on our behalf, their access is limited to what is necessary to perform the relevant service and is subject to appropriate contractual, confidentiality, security and data protection requirements.

We may also disclose information where required by applicable law or where necessary to protect the security, rights or integrity of Cognivox, Nathan Software, our users or others.

Google API Services User Data Policy

Cognivox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

These commitments apply to Google user data obtained through Google APIs and to information aggregated or derived from that data where applicable under Google's requirements.

Google user data is used only to provide or improve the user-facing functionality that the user has authorised and is not used for advertising, advertising personalisation or purposes unrelated to the authorised Google integration.

Retention of Google user data

Google user data, Google-derived information, appointment records and authorisation credentials are retained only for as long as reasonably necessary to provide the relevant integration and Cognivox functionality, maintain security, comply with applicable legal obligations, resolve disputes or otherwise fulfil the purposes described in this Privacy Policy.

Retention periods may also depend on the configuration and instructions of the Cognivox customer responsible for the relevant information.

Disconnecting Google services and revoking access

Users may disconnect a supported Google integration from Cognivox where that functionality is available within their account.

Users may also revoke Cognivox's access to their Google Account at any time through their Google Account security and permissions settings.

Revoking access prevents Cognivox from making further Google API requests using the revoked authorisation. Revocation does not necessarily delete appointment records or other information already stored by Cognivox where that information remains necessary for the purposes described in this Privacy Policy or is required or permitted to be retained by applicable law.

Deletion of Google user data

Users may request deletion of Google user data and associated Google-derived information processed by Cognivox, subject to applicable legal requirements and any circumstances in which information must or may lawfully be retained.

Where Cognivox processes Google user data on behalf of a Cognivox customer, a deletion request may need to be handled by or in cooperation with that customer as the relevant data controller.

To request deletion of Google user data, obtain assistance disconnecting a Google integration, or ask a question about how Cognivox handles Google user data, please contact enquiries@cognivox.io .

06

How we use personal information

We may use personal information for purposes including:

  • Providing and operating Cognivox services.
  • Processing and responding to telephone, chat and other communications.
  • Processing AI-powered conversations and generating responses.
  • Generating and maintaining written transcripts of telephone conversations handled by the Cognivox AI receptionist.
  • Creating, administering and securing accounts.
  • Providing customer support.
  • Providing appointment booking, scheduling and calendar integration functionality.
  • Creating, updating, managing and cancelling appointments where requested.
  • Maintaining conversation and appointment records where necessary to provide the service.
  • Maintaining the security and reliability of our systems.
  • Diagnosing technical problems and improving service performance.
  • Preventing fraud, misuse and unauthorised access.
  • Complying with legal and regulatory obligations.
08

Sharing personal information

We do not sell personal information.

We may share or provide access to information where necessary to operate and provide Cognivox, including with service providers that support our infrastructure and services.

These may include providers of:

  • Cloud hosting and infrastructure.
  • Artificial intelligence services.
  • Telecommunications services.
  • Calendar and integration services.
  • Email and communications services.
  • Authentication and security services.
  • Analytics and technical monitoring.
  • Payment processing, where applicable.

Cognivox uses the OpenAI API to provide AI-powered functionality. Information may be transmitted to OpenAI where necessary to process an AI interaction and provide the requested service.

Cognivox does not permit Google Workspace API data transferred to an artificial intelligence provider in connection with Cognivox to be used to train or improve generalised or non-personalised AI or machine-learning models.

Where service providers process personal information on our behalf, we require appropriate contractual, confidentiality, security and data protection safeguards consistent with the nature of the processing and applicable law.

We may also disclose information where required by law, court order or regulatory authority, or where reasonably necessary to protect the rights, security or integrity of Nathan Software, Cognivox, our users or the public.

09

International data transfers

Some technology and infrastructure providers used in delivering Cognivox may process personal information outside the United Kingdom.

Where personal information is transferred internationally, we take appropriate steps to ensure that the transfer is made in accordance with applicable data protection law and that appropriate safeguards are in place where required.

10

Data retention

For calls handled directly through supported Cognivox telecommunications services, including Twilio-based services, Cognivox does not retain an audio recording of the telephone call. Where Cognivox is connected to a customer's SIP or PBX telephone system and call recording is enabled, an audio recording may be retained in addition to the written transcript.

Cognivox may retain written transcripts of telephone conversations together with other information required to provide its services. This may include messages, appointment records, customer contact information, account information and information associated with connected integrations.

Personal information, including conversation transcripts, is retained only for as long as reasonably necessary for the purposes for which it was collected, including providing the Cognivox service, maintaining appropriate conversation and appointment history, meeting contractual requirements, maintaining security and satisfying applicable legal, accounting or reporting obligations.

Retention periods may vary depending on the type of information, the service being provided, whether Nathan Software acts as controller or processor, and the configuration or instructions of the relevant Cognivox customer.

Where information is processed on behalf of a Cognivox customer, retention may also be determined by that customer's instructions and applicable legal requirements.

When information is no longer required, it will be deleted, anonymised or otherwise handled in accordance with applicable retention procedures and legal obligations.

11

Information security

We use appropriate technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, loss or destruction.

These measures are applied to information processed and stored by Cognivox, including conversation transcripts, appointment information, integration data and authorisation credentials where applicable.

No internet-based service or method of electronic storage can be guaranteed to be completely secure. We therefore review security measures as our services and the technologies we use evolve.

12

Your data protection rights

Depending on the circumstances and applicable law, you may have rights in relation to your personal information, including the right to:

  • Request access to your personal information.
  • Request correction of inaccurate or incomplete information.
  • Request deletion of your personal information in certain circumstances.
  • Request restriction of processing in certain circumstances.
  • Object to certain processing based on legitimate interests.
  • Request transfer of certain information where the right to data portability applies.
  • Withdraw consent where processing is based on consent.

Some rights are subject to legal exceptions and may not apply in every circumstance.

To exercise a right relating to personal information for which Nathan Software is the data controller, please contact us using the details below.

If your information was collected by another organisation using Cognivox, you may need to contact that organisation directly because it may be the data controller responsible for your information. Where appropriate, requests received by us relating to customer-controlled information may be referred to or handled in cooperation with the relevant customer.

13

Cookies

Our website may use cookies and similar technologies to provide essential functionality, maintain security, remember preferences and, where applicable and permitted, understand how our website is used.

Further information about the cookies we use and the choices available to you can be found in our Cookie Policy.

Read our Cookie Policy
14

Children's privacy

Cognivox is intended primarily for business and organisational use and is not designed as a service directed at children.

Organisations using Cognivox are responsible for ensuring that their use of the service is appropriate for their users and complies with applicable law.

15

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to Cognivox, our technology, integrations, business practices or legal requirements.

When we make changes, the updated policy will be published on this page and the "Last updated" date will be revised.

16

Contact us

If you have a question about this Privacy Policy, how personal information is handled in connection with Cognivox, how Google user data is handled, or you wish to exercise a data protection right for which Nathan Software is the relevant controller, please contact us.

You may also have the right to make a complaint to the Information Commissioner's Office (ICO), the UK's independent supervisory authority for data protection.

An unhandled error has occurred. Reload 🗙