Effective date: March 19, 2025
Introduction
Cortico AI (“Cortico,” “we”, “us” or “our”) provides services and tools (including enterprise software, our mobile app, and platform for organizations of many kinds) to host, record, and transcribe constructive small-group conversations – and to identify and share highlights, insights, and other interesting outputs and learnings from them (the “Services”). We offer the Services to organizations of many kinds (“Cortico Partners”). In connection with our provision of the Services, we may process certain Personal Data—meaning, information that identifies or relates to a particular individual or that is otherwise defined as “personal data”, “personally identifiable information” or “personal information” under data privacy laws, rules or regulations applicable to us—about Cortico Partners as well as their end users and other constituents (“End Users”).
While this Privacy Policy is designed to address our processing of Personal Data regarding both Cortico Partners and End Users, Cortico acts as a processor of End User data on behalf of Cortico Partners, and Cortico’s agreements with such Cortico Partners ultimately govern Cortico’s use of End User data. To the extent of any conflict between this Privacy Policy and our agreements with Cortico Partners, our agreements with Cortico Partners control. If you are an End User and have questions or concerns about the processing of your Personal Data, please refer them to the relevant Cortico Partner. For emphasis, this Privacy Policy covers Cortico’s processing of Personal Data; it does not cover the practices of companies we do not own or control or people we do not manage (such as our Cortico Partners). You may print a copy of this Privacy Policy by clicking here. If you have a challenge or special request regarding accessibility of this document, you may access this Privacy Policy in an alternative format by contacting help@cortico.ai.
Please see the Notice to European Users section below for additional information for individuals located in the European Economic Area or United Kingdom.
The Cortico Process
Within any given Cortico Partner project, the Cortico Services can vary, depending on the policies and procedures of the relevant Cortico Partner. You should refer to the policies and procedures of the relevant Cortico Partner for information concerning how your particular use of the Services will operate. However, typically, the Cortico Services entail the following:
Categories of Personal Data We Collect
Personal Data we may collect through the Services includes:
Sources of Personal Data
We collect Personal Data about you from the following categories of sources. We may combine Personal Data we receive about you from different sources:
Tracking & Other Technologies
The Services may use cookies and similar technologies such as pixel tags, web beacons, local storage technologies, clear GIFs and JavaScript (collectively, “Automatic Collection Technologies”) to enable our servers to recognize your web browser and tell us how and when you visit and use our Services, to analyze trends, learn about our user base and operate and improve our Services:
For more information concerning your choices with respect to the use of Automatic Collection Technologies, see the “Your Choices” section, below.
How We Use Your Personal Data
We use Personal Data for the following purposes:
We will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated, or incompatible purposes without providing you notice.
How We Share Your Personal Data
Categories of Third Parties with Whom We Share Personal Data
We disclose your Personal Data to the following categories of third parties:
Data Security and Retention
We employ measures designed to protect your Personal Data from unauthorized access, use and disclosure based on the type of Personal Data and how we are processing that data. You should also help protect your data by appropriately selecting and protecting your password and/or other sign-on mechanism; limiting access to your computer or device and browser; and signing off after you have finished accessing your account. Although we take measures designed to protect the security of your account and other data that we hold about you, please be aware that no method of transmitting data over the Internet or storing data is completely secure. We cannot guarantee the security of any data you share with us, and except as expressly required by law, we are not responsible for the theft, destruction, loss or inadvertent disclosure of your information or content.
We retain Personal Data about you for as long as you have an open account with us or as otherwise necessary to provide the Services. In some cases we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation. We may further retain information in an anonymous or aggregated form where that information would not identify you personally.
Personal Data of Children
We do not knowingly collect or solicit Personal Data about children under 13 years of age; if you are a child under the age of 13, please do not attempt to register for or otherwise use the Services or send us any Personal Data.
If we learn we have collected Personal Data from a child under 13 years of age, we will delete that information as quickly as possible. If you believe that a child under 13 years of age may have provided Personal Data to us, please contact us at help@cortico.ai.
Transfers of Personal Data
The Services are hosted and operated in the United States (“U.S.”) through Cortico and its service providers, and if you do not reside in the U.S., laws in the U.S. may differ from the laws where you reside. By using the Services, you acknowledge that any Personal Data about you, regardless of whether provided by you or obtained from a third party, is being provided to Cortico in the U.S. and will be hosted on U.S. servers, and you authorize Cortico to transfer, store and process your information to and in the U.S., and possibly other countries where privacy laws may not be as protective as those in your state, province or country.
Your Choices
Cortico values the privacy of all of its users. When you use our Services, no matter where you reside, we still strive to provide you with the following rights. If you have any questions about this section or whether any of the following rights apply to you, please contact us at help@cortico.ai.
To exercise any right you may have to access, delete or correct your Personal Data, you must send us a request that provides sufficient information to allow us to verify your identity and locate your Personal Data. Such request can be submitted by calling us at 617-404-9812 or emailing help@cortico.ai.
Access
You may request a) confirmation of whether or not we are processing your Personal Data and b) to access your Personal Data. You can also access certain of your Personal Data by logging into your account.
Correction
You may correct inaccuracies in your Personal Data, to the extent such correction is appropriate in consideration of the nature of such data and our purposes of processing your Personal Data.
You can also correct certain of your Personal Data by logging into your account.
Deletion
You may delete certain Personal Data you have provided to us or we have obtained about you or close your Cortico account. You can also delete certain of your Personal Data by logging into your account.
Opt-out of communications
You may opt-out of marketing-related emails by following the opt-out or unsubscribe instructions at the bottom of the email, or by contacting us. Please note that if you choose to opt-out of marketing-related emails, you may continue to receive service-related and other non-marketing emails.
Cookies and other technologies
Most browsers let you remove or reject cookies. To do this, follow the instructions in your browser settings. Many browsers accept cookies by default until you change your settings. Please note that if you set your browser to disable cookies, the Services may not work properly. For more information about cookies, including how to see what cookies have been set on your browser and how to manage and delete them, visit www.allaboutcookies.org. You can also configure your device to prevent images from loading to prevent web beacons from functioning.
Blocking images/clear gifs
Most browsers and devices allow you to configure your device to prevent images from loading. To do this, follow the instructions in your particular browser or device settings.
Mobile location data
You can disable our access to your device’s precise geolocation in your mobile device settings.
You will need to apply these opt-out settings on each device and browser from which you wish to limit the use of your information for interest-based advertising purposes.
We cannot offer any assurances as to whether the companies we work with participate in the opt-out programs described above.
Do Not Track
Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. We currently do not respond to “Do Not Track” signals. To find out more about “Do Not Track,” please visit http://www.allaboutdnt.com.
Declining to provide information
We need to collect personal information to provide certain services. If you do not provide the information we identify as required or mandatory, we may not be able to provide those services.
Nevada Resident Rights
If you are a resident of Nevada, you have the right to opt-out of the sale of certain Personal Data for monetary consideration. While we do not currently engage in such sales, if you are a Nevada resident and would like to make a request to opt out of any potential future sales, please email help@cortico.ai. Please include in the subject line “Nevada Do Not Sell Request” and provide us with your name and the email address associated with your account.
Other Sites and Services
The Services may contain links to websites, mobile applications, and other online services operated by third parties. In addition, our content may be integrated into web pages or other online services that are not associated with us. These links and integrations are not an endorsement of, or representation that we are affiliated with, any third party. We do not control websites, mobile applications or online services operated by third parties, and we are not responsible for their actions. We encourage you to read the privacy policies of the other websites, mobile applications and online services you use.
Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make material changes to this Privacy Policy, we will notify you by updating the date of this Privacy Policy and posting it on the Service or other appropriate means. Any modifications to this Privacy Policy will be effective upon our posting the modified version (or as otherwise indicated at the time of posting). In all cases, your use of the Service after the effective date of any modified Privacy Policy indicates your acknowledging that the modified Privacy Policy applies to your interactions with the Service and our business.
Contact Us
If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data or your choices and rights regarding such collection and use, please do not hesitate to contact us at:
617-404-9812
Cortico.ai
help@cortico.ai
68 Harrison Ave Ste 605 #83158 Boston, MA 02111
Notice to European Users
EU and UK Residents
If you are a resident of the European Economic Area (“EEA”) or United Kingdom (“UK”) you may have additional rights under the EU or UK General Data Protection Regulation (the “GDPR”) with respect to your Personal Data, as outlined below.
For this section, we use the terms “Personal Data” and “processing” as they are defined in the GDPR, but “Personal Data” generally means information that can be used to individually identify a person, and “processing” generally covers actions that can be performed in connection with data such as collection, use, storage and disclosure. Cortico is the controller of your Personal Data processed in connection with the Services.
If there are any conflicts between this section and any other provision of this Privacy Policy, the policy or portion that is more protective of Personal Data shall control to the extent of such conflict. If you have any questions about this section or whether any of the following applies to you, please contact us at help@cortico.ai.
EU/UK GDPR Representative
EU: DP-Dock GmbH, Attn: Cortico Corp., Ballindamm 39, 20095 Hamburg, Germany
UK: DP Data Protection Services UK Ltd., Attn: Cortico Corp., 16 Great Queen Street,
Covent Garden, London, WC2B 5AH, United Kingdom
www.dp-dock.com
cortico.ai@gdpr-rep.com
Personal Data Use and Processing Grounds
We will only process your Personal Data if we have a lawful basis for doing so. Those lawful bases are:
∙ Contractual Necessity: We process Personal Data as a matter of “contractual necessity”, meaning that we need to process the data to perform under our Terms of Use with you, which enables us to provide you with the Services. When we process Personal Data due to contractual necessity, failure to provide such Personal Data will result in your inability to use some or all portions of the Services that require such data.
∙ Legitimate Interests: We process Personal Data where it is necessary for our legitimate interests and your interests and fundamental rights do not override those interests.
∙ Consent: In many cases we process Personal Data based on the consent you expressly grant to us at the time we collect such data. When we process Personal Data based on your consent, it will be expressly indicated to you at the point and time of collection.
∙ Other Processing Grounds: From time to time we may also need to process Personal Data to comply with a legal obligation, if it is necessary to protect the vital interests of you or other data subjects, or if it is necessary for a task carried out in the public interest.
We have set out below the legal bases we rely on in respect of the relevant purposes for which we use your Personal Data.
Purpose | Categories of Personal Data involved | Legal basis |
To operate, understand and personalize our Services | Contact dataAccount detailsDemographic dataRecorded sessionsDevice dataGeolocation | Contractual Necessity.Legitimate Interests. have a legitimate interest in ensuring the ongoing security and proper operation of our Service, our business and associated IT services, systems and networks. |
To meet or fulfill the reason you provided the information to us | Contact dataCommunications dataTransactional dataCommunication interaction data | Contractual Necessity.Legitimate Interests. We have a legitimate interest in providing our users with a good service. |
To communicate with you about the Services, including Service announcements, updates or offers | Contact dataMarketing dataCommunications dataCommunication interaction data | Legitimate Interests. We have a legitimate interest in promoting our operations and goals as an organization and sending marketing communications for that purpose.Consent, in circumstances or in jurisdictions where consent is required under applicable data protection laws to the sending of any given marketing communications. |
To provide support and assistance for the Services | Contact dataRecorded sessionsCommunications dataDevice dataGeolocation data | Contractual Necessity. Legitimate Interests. We have a legitimate interest in providing our users with a good service. |
To create and manage your account or other user profiles | Contact dataAccount dataDemographic data | Contractual Necessity. Legitimate Interests. We have a legitimate interest in providing our users with a good service. |
To personalize website content and communications based on your preferences, to respond to user inquiries and fulfill user requests | Demographic dataDevice dataOnline activity data | Legitimate Interests. We have a legitimate interest in providing you with a good service via the Services, which is personalized to you and that remembers your selections and preferences.Consent, in respect of any optional processing relevant to personalization (including processing directly associated with any optional cookies used for this purpose). |
To improve and develop the Services and for analytics purposes, including testing, research, analysis and product development | Any and all data categories as relevant in the circumstances | Legitimate Interests. We may use your personal information for research and development purposes, including to analyze and improve the Service and our business.Consent, in respect of any optional processing relevant to personalization (including processing directly associated with any optional cookies used for this purpose). |
For marketing and advertising purposes, including direct marketing and interest-based advertising | Contact dataMarketing dataOnline activity data | Legitimate Interests. We have a legitimate interest in promoting our operations and goals as an organization and sending marketing communications for that purpose.Consent, in circumstances or in jurisdictions where consent is required under applicable data protection laws to the sending of any given marketing communications. |
To protect against or deter fraudulent, illegal or harmful actions and maintain the safety, security and integrity of our Services | Any and all data categories as relevant in the circumstances | Compliance with Law.Legitimate Interests. Where Compliance with Law is not applicable, we have a legitimate interest in participating in, supporting, and following legal process and requests, including through co-operation with authorities. We may also have a legitimate interest in ensuring the protection, maintenance, and enforcement of our rights, property, and/or safety. |
To comply with our legal or contractual obligations, resolve disputes, and enforce our Terms of Use | Any and all data categories as relevant in the circumstances | Compliance with Law.Legitimate Interests. Where Compliance with Law is not applicable, we have a legitimate interest in participating in, supporting, and following legal process and requests, including through co-operation with authorities. We may also have a legitimate interest in ensuring the protection, maintenance, and enforcement of our rights, property, and/or safety. |
To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations | Any and all data categories as relevant in the circumstances | Compliance with LawLegitimate Interests. Where Compliance with Law is not applicable, we have a legitimate interest in participating in, supporting, and following legal process and requests, including through co-operation with authorities. We may also have a legitimate interest in ensuring the protection, maintenance, and enforcement of our rights, property, and/or safety. |
To audit our internal processes for compliance with legal and contractual requirements or our internal policies | Any and all data categories as relevant in the circumstances | Legitimate Interests. We have a legitimate interest in ensuring that our internal processes are efficient and comply with regulatory and legal standards. |
To create aggregated, de-identified and/or anonymized data from your Personal Data and other individuals whose personal information we collect | Any and all data categories as relevant in the circumstances | Legitimate Interests. We have legitimate interest in taking steps to preserve our users’ privacy as we research how they use our Service. |
EU, UK and Swiss Data Subject Rights
You have certain rights with respect to your Personal Data, including those set forth below. For more information about these rights, or to submit a request, please email us at help@cortico.ai. Please note that in some circumstances, we may not be able to fully comply with your request, but in those circumstances, we will still respond to notify you of such a decision and why we have made that decision. In some cases, we may also need you to provide us with
additional information, which may include Personal Data, if necessary to verify your identity and the nature of your request.
∙ Access: You can request more information about the Personal Data we hold about you and request a copy of such Personal Data. You can also access certain of your Personal Data by logging on to your account.
∙ Rectification: If you believe that any Personal Data we are holding about you is incorrect or incomplete, you can request that we correct or supplement such data. You can also correct some of this information directly by logging on to your account.
∙ Erasure: You can request that we erase some or all of your Personal Data from our systems.
∙ Withdrawal of Consent: If we are processing your Personal Data based on your consent (as indicated at the time of collection of such data), you have the right to withdraw your consent at any time. Please note, however, that if you exercise this right, you may have to then provide express consent on a case-by-case basis for the use or disclosure of certain of your Personal Data, if such use or disclosure is necessary to enable you to utilize some or all of our Services.
∙ Portability: You can ask for a copy of your Personal Data in a machine-readable format. You can also request that we transmit the data to another controller where technically feasible.
∙ Objection: You can contact us to let us know that you object to the further use or disclosure of your Personal Data for certain purposes, such as for direct marketing purposes.
∙ Restriction of Processing: You can ask us to restrict further processing of your Personal Data.
∙ Right to File Complaint: You have the right to lodge a complaint about Cortico’s practices with respect to your Personal Data with the supervisory authority of your country or EU Member State. If you are in the EEA, a list of Supervisory Authorities is available here: https://edpb.europa.eu/about-edpb/board/members_en. If you are in the UK, the contact information for the UK data protection regulator can be found here: https://ico.org.uk/make-a-complaint/.
Data Processing outside the EEA/UK
We are a U.S.-based company and many of our service providers, advisers, partners or other recipients of data are also based in the U.S. This means that, if you use the Services, your personal information will necessarily be accessed and processed in the U.S. It may also be provided to recipients in other countries outside the EEA/UK.
Where we share your personal information with third parties who are based outside the EEA/UK, we try to ensure a similar degree of protection is afforded to it by making sure one of the following mechanisms is implemented:
You may contact us if you want further information on the specific mechanism used by us when transferring your personal information out of Europe.