COGNIVAL
Lock InDay 1sAboutFAQContactPreorder · £39.99

Legal

Privacy Policy.

Last updated: 10 August 2026 · Version v91-2026-08-10

1. About this Privacy Policy

This Privacy Policy explains how Cognival LTD collects, uses, stores, shares and protects personal data when you visit our website, join our waitlist, contact us, interact with our communications, preorder Lock In, join Cognival Day 1s, confirm delivery or sizing details, or receive an order.

We process personal data in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations, and other applicable data protection laws.

2. Controller details

The data controller is Cognival LTD, a private limited company registered in England and Wales under company number 16782883.

  • Registered office: 1 De La Warr Way, Cambourne, Cambridge, England, CB23 6DX.
  • Email: business@cognival.co.uk.
  • Website: cognival.co.uk.

3. Personal data we collect

We collect personal data that you provide directly and data generated by your use of the website.

CategoryExamples
Identity and contact dataName, email address, telephone number, delivery details, customer communications.
Fulfilment dataDelivery address, post-payment T-shirt size selection, order status, carrier and tracking information where applicable.
Waitlist and launch dataEmail address, signup source, preferences, product interest, launch communications.
Order and transaction dataProducts ordered, Day 1s membership, billing and shipping details, payment status, delivery information, membership eligibility and customer support records.
Technical dataIP address, browser type, device information, operating system, pages viewed, timestamps, error logs and security logs.
Marketing dataEmail preferences, campaign interaction, consent status, unsubscribe records.
Enquiry-protection dataOne-time form challenge, Turnstile verification result, hashed IP and message fingerprints, spam risk signals and quarantine-review status.

4. How we collect personal data

  • When you submit a waitlist or contact form, complete Stripe Checkout, or use a secure fulfilment form where additional details are required.
  • When you contact us by email or through the website.
  • When you interact with launch communications, product updates, or customer service.
  • Automatically through essential website technologies, server logs, security tools, and analytics where enabled.
  • From service providers involved in hosting, payment processing, fulfilment, email delivery, analytics, fraud prevention, or customer support.

5. How we use personal data

PurposeLegal basis
To operate the website, forms, secure order links, and customer communications.Contract performance and legitimate interests.
To manage waitlist access, launch updates, and first-batch communications.Consent and legitimate interests.
To respond to inquiries and provide customer support.Legitimate interests and contract performance.
To process orders, payments, delivery, refunds, and customer records.Contract performance and legal obligations.
To send marketing communications where permitted.Consent or legitimate interests, depending on the communication and applicable law.
To protect the website, prevent fraud, and maintain security.Legitimate interests and legal obligations.
To distinguish genuine enquiries from automated abuse, hold suspected spam for review and protect people whose email addresses may be misused by senders.Legitimate interests in service security, fraud prevention and reliable customer support.
To comply with accounting, tax, regulatory, and legal obligations.Legal obligations.

6. Email and marketing communications

If you join the waitlist or opt in to updates, we may send launch news, first-batch access, product updates, and offers. You can unsubscribe from marketing emails at any time using the unsubscribe link in the email or by contacting us.

Transactional and service emails–including payment confirmation, production progress, secure delivery or size requests, delivery confirmation, carrier tracking, Day 1s membership access, safety, refund, or legal notices–may still be sent where necessary to perform a contract or operate the customer relationship. These are separate from optional general marketing.

7. Cookies, storage, and analytics

We use essential cookies, local storage, or session storage where needed for website operation, checkout recovery, form handling, security, and performance. We may also use analytics technologies to understand website performance and improve the customer experience.

Where legally required, non-essential cookies or similar technologies will be used only with appropriate consent.

8. Service providers and data sharing

We share personal data only where necessary for legitimate business and legal purposes. Current categories include Cloudflare for hosting, security, Turnstile verification and database services; Stripe for payment processing; Brevo for transactional and opted-in marketing email; Google Analytics after analytics consent; delivery carriers and fulfilment partners; professional advisers, regulators and legal authorities where required.

We do not sell personal data.

9. International transfers

Some service providers may process personal data outside the United Kingdom or European Economic Area. Where required, we rely on appropriate safeguards such as adequacy regulations, standard contractual clauses, transfer risk assessments, or equivalent lawful mechanisms.

10. Data retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy. Order, payment, refund and accounting records are normally retained for up to seven years where required for tax, accounting or legal purposes. Unused secure delivery tokens expire automatically. Operational logs and analytics are retained only for the configured service period and are periodically deleted or aggregated.

Marketing records are retained until you unsubscribe or ask us to remove them, unless a longer period is required to keep a suppression record or comply with law.

Expired contact-form challenges and short-window rate-limit records are deleted on a rolling basis. Suspected spam may be retained temporarily for security review, pattern detection and evidence of misuse, then deleted or anonymised when it is no longer needed. Accepted enquiries become customer-support records and are retained according to their context.

11. Enquiry screening and automated decisions

The contact form uses proportionate automated signals such as timing, repeated submissions, duplicate text, obvious keyboard patterns, links and Cloudflare Turnstile verification. Suspected automated or abusive submissions may be held in a quarantine queue rather than emailed immediately.

This screening does not make a legal or similarly significant decision about you. A Cognival administrator can review, approve, reject or delete quarantined submissions. Genuine customers can always contact business@cognival.co.uk directly if the form does not work as expected.

12. Security

We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, encrypted connections, secure hosting, restricted administrative access, logging, and data minimisation.

No website or online transmission is completely secure, but we take security seriously and maintain proportionate safeguards.

13. Your rights

Depending on your location and applicable law, you may have rights to access, correct, delete, restrict, object to processing, request portability, withdraw consent, or complain about how your personal data is handled.

To exercise your rights, contact business@cognival.co.uk. We may need to verify your identity before responding.

14. Complaints

If you are unhappy with how we handle personal data, please contact us first so we can address the issue. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk.

15. Children

Our website and products are not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The latest version will always be available on this page and will show the date it was last updated.

First-party analytics

With your consent, Cognival records privacy-conscious first-party analytics such as traffic source, pages viewed, and interactions with website buttons. We use an anonymous browser identifier and do not record passwords, payment-card details, or the contents of form fields. If you join the waiting list, your email may be associated with that anonymous journey so we can understand which campaigns lead to genuine signups. You can decline analytics in the consent banner.

COGNIVAL

Work hard. Play harder. Be fully there.

Lock InDay 1sAboutFAQContact
InstagramTikTokLinkedIn
Privacy PolicyTerms & Conditions