This Privacy Policy explains how personal data is collected, used, stored, and shared when you use Epicurus Pro (“Epicurus”, “the Service”) — an AI digital colleague that works in Microsoft Teams, Slack, WhatsApp, Telegram, email, and voice calls.
1. Who we are — the two companies behind Epicurus Pro
Epicurus Pro is provided by two companies working together:
- Cognivo (Dubai, United Arab Emirates) — owns the product, the brand, and the technology, and develops and operates the Epicurus Pro platform.
- Leonova Technologies Ltd (United Kingdom) — the distribution company: your contract, billing, and payment processing run through Leonova.
Roles under data protection law:
- For website, account, and billing data (your registration details, subscription, invoices): Leonova Technologies Ltd is the data controller.
- For customer content processed through Epicurus on behalf of your organisation (your chats, emails, documents, calls): your organisation is the data controller, and Leonova Technologies Ltd acts as a data processor on your organisation’s instructions, with Cognivo processing data as the platform operator under the same instructions.
Data Protection Officer: our designated DPO can be reached at dpo@cognivo.ae.
Privacy contact: privacy@cognivo.ae · Legal contact: legal@cognivo.ae
2. What data we collect
Depending on how your organisation uses Epicurus, we process the following categories of data:
Account & organisation data
- Names, work email addresses, and organisation identifiers
- Billing contact details and subscription information
- Administrator settings, roles, and integration configuration
- The Terms version you accepted and when (our consent record)
Chat & conversation data
- Messages you send to Epicurus in Teams, Slack, WhatsApp, Telegram, or other connected surfaces
- Thread context, mentions, reactions, and attachments you choose to share
- Conversation memory the Service maintains to work across sessions: conversation history, thread summaries, remembered facts you ask it to keep, working notes, and a daily activity journal for your organisation’s colleague
People & identity across surfaces
- Platform-specific user IDs (for example Teams or Slack member IDs) linked so one person is recognised across surfaces
- Display names, preferred names, and profile information needed to route messages and attribute usage
- Optional per-person preferences your team sets: how the colleague addresses you, communication style, voice choice, timezone, and location
- Contacts your team explicitly shares with the colleague (for example a phone book entry to call or message someone)
Voice calls & telephony
- Live voice conversations are processed in real time to let the colleague listen and speak; call transcripts are stored as text so your team can search and recall them
- If your organisation activates a phone line: call and SMS records for that number (numbers, timestamps, duration, message content), metered for billing
- Emails sent to your organisation’s colleague addresses (each engaged teammate can have an agent address under your organisation’s subdomain), including body text and attachments
- A log of emails the colleague has sent and received, so it can reference past correspondence
Files, documents & media
- Files and images you share with the colleague, and documents, spreadsheets, presentations, dashboards, and images it generates for you
- Descriptive labels generated for shared media so it can be found again later
Microsoft 365 & connected applications (with your consent)
If your organisation connects Microsoft 365, Epicurus may access data via the Microsoft Graph API, limited to the scopes you approve — this may include email content, calendar events, and directory information for people resolution. If you connect other business applications, access is limited to what you authorise. Actions that change your connected systems are approval-gated as described in §5. Credentials and API keys for connected applications are stored encrypted (AES-256-GCM).
Usage & billing metrics
- Token consumption (input/output) per user and per organisation
- Credit balances, top-up and metering events, and feature usage statistics
- Payment records processed through Stripe (we do not store full card numbers)
Support & feedback
- Support tickets you raise (including via the colleague itself) and their resolution history
- Feedback and beta-program reports you choose to send
Technical logs
- Operational logs: timestamps, request identifiers, error reports, and performance data used to keep the Service healthy
3. Why we use your data
We process personal data to:
- provide, operate, and maintain the Service;
- authenticate users and enforce per-organisation isolation;
- enable AI-assisted workflows, including conversation memory and recall;
- propose and (after human approval) perform actions in Microsoft 365 and connected platforms;
- meter usage, manage credits, and bill your organisation;
- provide customer support and service communications;
- monitor security, prevent abuse, and debug issues; and
- comply with legal obligations.
Legal bases (UK GDPR): For business customers, processing is typically based on contract performance and legitimate interests (operating a secure SaaS platform). Where consent is the basis — for example certain Microsoft 365 permissions, or beta conversation review (§10) — we rely on consent recorded through your organisation’s setup or your own explicit agreement, and you may withdraw it, though some features may then no longer work.
4. How AI processing works
Epicurus uses large language models — including a thinking model that plans and reasons before responding — to understand requests and generate outputs. Relevant portions of your conversation and connected data are sent to our AI model providers strictly to fulfil your request. The specific providers we use are listed in the sub-processor section (§7).
We configure providers not to use your data to train their public models where such controls are available. AI outputs should be reviewed by a human before relying on them for important decisions.
5. Where data is stored & how it is protected
Epicurus runs on managed cloud infrastructure (see §7). Data is encrypted in transit (TLS). At rest, protection is layered:
- Connected-application credentials and API keys: encrypted at the application level with AES-256-GCM.
- Audit-vault records (where an organisation enables the encrypted conversation audit vault): sealed with AES-256-GCM under a client-held key.
- Other stored content (including conversation history): protected by our infrastructure provider’s storage-level protections and strict access controls. We are extending application-level encryption to further data categories as part of our ongoing compliance programme.
Each organisation’s data is logically isolated by tenant. We do not commingle one customer’s conversation memory, configuration, or usage records with another’s. Sessions use signed, HTTP-only, secure cookies; each user can invalidate all outstanding sessions for their own account (“sign out everywhere”), and organisation administrators can remove members, which revokes their access.
Actions that change your systems ride a deterministic permission engine: the AI model declares intent, and a separate rules engine decides whether human approval is required, according to your organisation’s configuration — high-risk actions (deletions, payments) always require explicit approval. Approvals are recorded in an audit trail.
6. Data retention
We keep data only as long as needed for the purposes above. Our current retention behaviour:
- Active subscription: conversation memory, transcripts, summaries, and configuration are retained for the life of the subscription so your colleague keeps its context.
- After termination: we delete your organisation’s data on written request, using our organisation-level purge process, subject to legal retention requirements. Contact privacy@cognivo.ae.
- Billing records: retained as required for accounting and tax compliance.
- Operational logs: rotated on size and count limits and kept short-term for debugging and security monitoring.
- Consent records (Terms acceptance, beta review consent): retained as the durable record of the agreement.
7. Sub-processors & service providers
We use trusted third parties to run Epicurus. They process data only to provide their function to us and under contractual safeguards:
- Railway — application hosting and infrastructure
- OpenAI — AI language models
- Anthropic — AI language models
- xAI — voice AI models and live search
- Anysphere (Cursor) — AI task-execution models (the “thinking model”)
- Microsoft — Microsoft 365, Teams, and Graph API integrations (where your organisation connects them)
- Stripe — payment processing and subscription management (engaged by Leonova Technologies Ltd)
- Amazon Web Services (SES) and Resend — transactional email delivery
- Pipedream and Composio — connector platforms for the business applications you choose to connect
- Browserbase — cloud browser sessions for web tasks you ask the colleague to perform
- Telnyx — telephony carrier (where your organisation activates a phone line)
- Cloudflare — DNS and network services
The chat platforms your organisation already uses (Microsoft Teams, Slack, WhatsApp, Telegram) receive and deliver messages under your organisation’s own agreements with those platforms.
We may update this list as our stack evolves. Enterprise customers may request advance notice of material sub-processor changes.
8. International transfers
Some of the providers above process data outside the UK/EEA (for example AI model providers in the United States), and Cognivo, as the platform owner, is established in the United Arab Emirates. Where personal data leaves the UK/EEA, we rely on appropriate safeguards in our agreements with each provider, such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses, where applicable.
9. Your rights (UK & EU GDPR)
If you are in the UK or EEA, you may have the right to:
- access a copy of your personal data;
- rectify inaccurate data;
- erase data in certain circumstances;
- restrict or object to processing;
- data portability (where processing is automated and based on consent or contract); and
- withdraw consent where processing is consent-based.
How to exercise them: for data your employer controls through Epicurus, contact your organisation first — they are usually the data controller, and we will assist them in responding. To exercise your rights with us directly, email privacy@cognivo.ae or our DPO at dpo@cognivo.ae. We respond within one month, subject to extensions permitted by law.
What we can do today: organisation administrators can manage and remove people from their organisation in the dashboard; on request we can correct person records, and we operate a hard-delete purge process for organisation offboarding and erasure requests. Access and portability requests are fulfilled through our support process.
You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk, or your local supervisory authority.
10. Beta program & conversation review
Where your organisation joined during a beta window, the signup page said so, and the following applies: only if you expressly agreed at signup, our team may review your conversations with your colleague to diagnose and fix issues during the beta. That consent is recorded per user with a timestamp and version, first consent wins, and it is never assumed. If you did not opt in, we do not claim this review right.
11. Compliance posture
Honest status: we do not currently hold ISO 27001, SOC 2, or similar certifications. We are preparing for independent certification — ISO 27001 is our first target — and we align our controls with recognised frameworks as we build. Our engineering controls (deterministic permission gating, human-in-the-loop approvals, audit trails, tenant isolation, encryption of credentials) are documented for customer security reviews: ask us at legal@cognivo.ae.
12. Children
Epicurus is a business service and is not directed at children under 16. We do not knowingly collect children’s personal data.
13. Changes to this policy
We may update this Privacy Policy from time to time. Each revision carries a version stamp (shown at the top of this page). Material changes will be communicated to account administrators — for example a dashboard notice asking you to review the updated policy.
14. Contact
Privacy: privacy@cognivo.ae
Data Protection Officer: dpo@cognivo.ae
Legal: legal@cognivo.ae
Support: support@cognivo.ae
Website: epicurus.pro