Cognativ ← Back to site
Legal

GDPR Compliance

Last updated: 1 July 2026
Template notice. This is a starting template for Cognativ, provided for drafting purposes only. It is not legal advice. Have it reviewed and adapted by a qualified solicitor for your jurisdiction (UK GDPR / Data Protection Act 2018 and, where relevant, EU GDPR) before you publish it. It should be read alongside our Privacy Policy, which explains what data we collect and why.

This page sets out how Performance Capability ("we", "us", "our") complies with the UK General Data Protection Regulation and, where applicable, the EU General Data Protection Regulation when processing personal data through Cognativ (the "Service").

1. Data controller

Performance Capability is the data controller for personal data processed through Cognativ. See our Contact page to reach us about any data protection matter.

2. Lawful basis for processing

3. Automated processing

Diagnose, Predict and Prescribe are generated by an AI reasoning engine based on the content you submit. This output is decision-support for you, the user, to interpret and act on; it does not make any automated decision about you or any third party with legal or similarly significant effect, and no automated decision is made about a data subject without human involvement. You remain responsible for how you use and act on a diagnostic result.

4. Your rights

Subject to applicable law, you have the right to:

To exercise any of these rights, contact us. We aim to respond within one month, as required by GDPR.

5. Data we process and why

Account details, billing information, and the content you submit to run a diagnostic. Full detail is in our Privacy Policy.

6. Sub-processors

We use a small number of service providers to operate Cognativ, each under contractual data-protection terms: a hosting provider, a payment processor for subscriptions, and a third-party AI provider that powers the diagnostic engine. We do not sell personal data, and content you submit is not used to train foundation models.

7. International transfers

Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards, such as the UK's International Data Transfer Agreement or the EU Standard Contractual Clauses, or transfers to jurisdictions covered by an adequacy decision.

8. Data retention

We keep personal data for as long as your account is active and as needed to provide the Service, then for any period required to meet legal, accounting or reporting obligations, after which it is deleted or anonymised.

9. Security measures

We use appropriate technical and organisational measures, including encryption in transit, access controls, and restricting who can see the content you submit, to protect personal data against unauthorised access, loss or misuse.

10. Data breach notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals, in line with GDPR timeframes.

11. Contact

Performance Capability · Contact us · www.performancecapability.com