Privacy
Privacy Policy
Last updated: August 11, 2026 · Cognitive Technology Consulting Inc.
This Privacy Policy describes how Cognitive Technology Consulting Inc. (“Cognitive Technology”, “CT”, “we”, “us”) handles information in connection with cognitivetech.net and related operator tools, including the Google OAuth client named agent-access. We work with clients in Canada and the United States, including Florida and Georgia.
Website visitors and contact forms
Our public marketing website may collect standard technical information such as IP address, browser type, and pages viewed through hosting and security providers (for example Cloudflare). We use this information to operate, secure, and improve the website. We do not sell website visitor data.
If you use a contact form, we collect the details you submit — typically your name, email address, and message. We also receive basic technical information needed to run and protect the site (for example, security checks via Cloudflare Turnstile, and standard server logs). Form messages may be delivered through email and hosting providers we use to operate the site (including Cloudflare and Resend). Those providers process data only to provide their services to us.
We use contact information to reply to your inquiry and decide whether we are a fit. We do not use contact-form submissions for bulk marketing unless you separately ask to stay in touch.
Canada and the United States
Because we work across Canada and the U.S., information you submit may be processed or stored in either country. If you have questions about your information, contact us and we will help where we reasonably can — including access or correction requests under applicable Canadian privacy rules.
How long we keep website inquiries
We keep inquiry information only as long as needed to respond and manage a possible engagement, unless a longer period is required for legal or security reasons.
Google user data — agent-access
agent-access is CT’s operator-facing Google OAuth client used by Cian’s AI assistant systems (Cleo / Agent Vault) to access Google APIs for Google accounts that an authorized operator explicitly connects. It is not a public consumer Gmail product.
What Google data we access
- Gmail (
gmail.readonly,gmail.modify): search, read, and label messages for business workflows (for example invoice and purchase-order processing). - Google Calendar (
calendar.readonly): read availability and scheduling context. - Google Drive (
drive.readonly): read documents when an operator points the agent at them.
Why we access it
To automate business operations for Cognitive Technology and Cian’s fractional-CTO client work — for example turning invoice emails into accounting workflows, using calendar context for scheduling, and reading documents needed for a specific task. Requests are made by CT’s agent infrastructure under authorized operator control.
How data is stored and retained
- OAuth refresh and access tokens are stored encrypted in Infisical Agent Vault on CT-controlled infrastructure, not in public client apps.
- Email, calendar, and Drive content may be processed in memory to complete a task. We may log operational details needed for the workflow (for example subjects, message IDs, or short summaries).
- We minimize retention of Google user content and do not keep wholesale copies of mailboxes for unrelated purposes.
Sharing
- We do not sell Google user data.
- We do not use Google user data for advertising.
- We do not transfer Google user data to unrelated third parties for their own use.
- Limited sharing may occur only as needed to operate CT business tools under our control — for example creating derived records in accounting or CRM systems (such as Xero) from invoice emails. That is not a raw wholesale dump of a mailbox to the public.
Google Limited Use
Cognitive Technology’s use of data obtained via Google APIs complies with Google’s Limited Use requirements: data is used only to provide or improve user-facing features that are evident in the purpose of agent-access; not for selling data; not for serving ads; and not for transfer except as necessary to provide or improve those features, as required by law, or with the user’s permission.
Security
Tokens are kept in an encrypted vault. Access is limited to authorized operators. Connections use HTTPS. You can revoke access at any time in your Google Account permissions.
Your choices
- Disconnect: Google Account → Security → Third-party access → remove agent-access (myaccount.google.com/permissions).
- Questions or requests: cian@cognitivetech.net.
Contact
Cognitive Technology Consulting Inc.
Email: cian@cognitivetech.net
Website: www.cognitivetech.net
Related: About agent-access · Terms of Service
Client engagements may also be covered by a separate written agreement.