Privacy Policy
Cotnek Technologies · Last updated: 29 September 2026
This Privacy Policy explains how Cotnek collects, uses, stores, discloses and protects personal data when you use our Services.
1. Who We Are
Cotnek Technologies is a business licensed and registered in the United Arab Emirates and operates the Cotnek platform and the website at cotnek.com (together, the “Services”).
In this Privacy Policy, “Cotnek Technologies,” “Cotnek,” “we,” “us,” and “our” refer to the entity that owns and operates the Cotnek Services.
Our trade licence and company registration information can be provided where legally required or upon a legitimate request.
This Privacy Policy explains how we collect, use, store, disclose and protect personal data when you use our Services.
We process personal data in accordance with applicable data-protection laws, including the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL).
Where our processing falls within their territorial scope, the EU General Data Protection Regulation (GDPR) and/or UK GDPR may also apply.
2. Our Roles in Processing Personal Data
Depending on how Cotnek is used, we may act as either a Data Controller or a Data Processor.
When Cotnek acts as a Controller
We generally act as a controller for personal data relating to:
- visitors to the Cotnek website;
- Cotnek account holders;
- customers and subscribers;
- people who contact us;
- demo requests;
- partnership enquiries;
- training or waitlist registrations;
- billing and subscription information;
- security information; and
- usage information relating to our own Services.
In these situations, Cotnek determines why and how the relevant personal data is processed.
When Cotnek acts as a Processor
Our business customers may use Cotnek to collect, upload, manage or process personal data relating to their own customers, leads or contacts.
This may include:
- CRM leads and contacts;
- landing-page submissions;
- customer notes;
- sales records;
- marketing information;
- website chat conversations;
- campaign information;
- form submissions;
- customer communications; and
- data imported or connected by the customer.
For this information, the Cotnek customer generally acts as the Data Controller and Cotnek acts as the Data Processor on the customer’s instructions.
If you submitted information to a company that uses Cotnek, you should normally contact that company first regarding your personal data.
Cotnek will assist its customers with relevant data-protection obligations where required by applicable law and applicable contractual arrangements.
3. Information We Collect
Depending on how you use Cotnek, we may collect the following categories of information.
Account Information
- name;
- work email address;
- company name;
- job role;
- account preferences;
- time zone;
- login and authentication information; and
- account settings.
Passwords should be stored using secure cryptographic hashing rather than in readable form.
Business Profile Information
You may provide information about your business so that Cotnek can personalise and operate its features.
- business name;
- products and services;
- business description;
- target audience;
- business locations;
- brand information;
- website information; and
- other business preferences.
When you instruct Cotnek to analyse or read a publicly available website, we may process information available on that website for the requested purpose.
Billing and Subscription Information
We may process information such as:
- subscription plan;
- billing cycle;
- invoice information;
- transaction status;
- payment status; and
- subscription history.
Payment card information is processed by our third-party payment service providers.
Cotnek does not intend to store full payment-card numbers on its own systems where payments are processed by an authorised payment provider.
Customer Content
Information created, uploaded or processed through Cotnek may include:
- campaigns;
- CRM records;
- leads;
- notes;
- automations;
- landing pages;
- forms;
- content drafts;
- reports;
- customer communications;
- website chat conversations;
- messages submitted to AI features; and
- content generated by AI features.
Enquiries and Communications
If you contact Cotnek, we may collect:
- your name;
- email address;
- telephone number where provided;
- company;
- enquiry type;
- correspondence; and
- information contained in your message.
Technical and Usage Information
We may automatically collect certain technical information when you use the Services, including:
- IP address;
- device type;
- browser type;
- operating system;
- login activity;
- pages or features used;
- timestamps;
- error information;
- security events; and
- server and application logs.
We use this information primarily to operate, secure, maintain and improve the Services.
Please also see our Cookie Policy where applicable.
4. How and Why We Use Personal Data
Providing the Services
To:
- create and manage accounts;
- provide Cotnek features;
- operate CRM functionality;
- provide campaigns and automation tools;
- provide AI-powered functionality;
- maintain subscriptions;
- provide customer support; and
- fulfil our contractual obligations.
Payments and Billing
To:
- process subscription payments;
- issue invoices;
- manage billing;
- manage subscriptions;
- detect payment abuse or fraud; and
- comply with financial, accounting and legal requirements.
Customer Support and Enquiries
To:
- answer questions;
- respond to support requests;
- arrange demonstrations;
- manage partnership enquiries; and
- communicate with users about the Services.
Security and Fraud Prevention
To:
- protect accounts;
- prevent unauthorised access;
- investigate abuse;
- detect security threats;
- prevent fraud; and
- maintain the reliability and integrity of the Services.
Improving Cotnek
We may use appropriate usage and technical information to understand how the Services perform and to improve functionality, reliability and user experience.
Where possible and appropriate, we may use aggregated or de-identified information for analytics and product improvement.
Marketing Communications
We may send marketing communications where permitted by applicable law.
Where consent is required, we will request it before sending marketing communications.
Users can unsubscribe or opt out from marketing communications using the unsubscribe method included in the relevant message or by contacting us.
Legal Compliance
We may process or disclose information where reasonably necessary to:
- comply with applicable law;
- respond to lawful requests;
- comply with court orders;
- protect our legal rights;
- prevent fraud or misuse; or
- cooperate with competent regulatory or law-enforcement authorities.
Under UAE law, we process personal data in accordance with the PDPL, including based on consent or another lawful ground permitted by applicable law.
Where the EU GDPR or UK GDPR applies, lawful bases may include:
- performance of a contract;
- compliance with a legal obligation;
- legitimate interests;
- consent; or
- another lawful basis permitted by applicable law.
Cotnek does not sell personal data.
We do not use customer CRM content for third-party advertising.
5. Artificial Intelligence Features
Cotnek includes or may include artificial-intelligence-powered features such as:
- AI assistants;
- AI copywriting;
- content generation;
- business research;
- campaign assistance;
- automation assistance;
- website analysis;
- website chat;
- lead assistance; and
- other AI-powered tools.
When you use an AI feature, information needed to generate the requested response may be sent to one or more AI service providers.
Depending on the feature, this information may include:
- your prompt;
- relevant account information;
- business profile information;
- information you specifically select;
- relevant CRM records;
- website content;
- conversation context; or
- other information required to fulfil your request.
We seek to use AI service providers subject to appropriate contractual and data-protection safeguards.
Where applicable, we configure or select services so that API data is handled in accordance with the provider’s applicable enterprise or API data terms.
Cotnek does not guarantee that AI-generated content is accurate, complete or suitable for every purpose.
Users should review AI-generated information before relying on it, publishing it, sending it to customers or using it to make important business decisions.
Unless specifically disclosed and permitted by applicable law, Cotnek does not intend to use solely automated processing to make decisions about individuals that produce legal effects or similarly significant effects.
6. How We Share Personal Data
We do not sell personal data.
We may share personal data with trusted third-party service providers where necessary to operate Cotnek.
These providers may include:
- cloud hosting providers;
- database and infrastructure providers;
- cybersecurity and monitoring providers;
- AI model and AI infrastructure providers;
- payment processors;
- subscription-management providers;
- transactional email providers;
- communications providers;
- analytics and performance providers;
- customer-support providers; and
- professional advisers such as lawyers, accountants and auditors.
These providers are expected to process personal data only for authorised purposes and subject to appropriate confidentiality, security and data-protection obligations.
Legal Disclosures
We may disclose information where required by:
- applicable law;
- a court order;
- a competent authority;
- lawful law-enforcement requests; or
- the protection of Cotnek’s legal rights, users or systems.
Business Transfers
If Cotnek is involved in a:
- merger;
- acquisition;
- restructuring;
- financing;
- sale of assets; or
- transfer of ownership,
personal data may be transferred as part of that transaction, subject to applicable law and appropriate protections.
Information about relevant service providers or subprocessors may be made available where required by law or applicable contractual arrangements.
7. International Data Transfers
Cotnek operates from the United Arab Emirates, but some service providers may process or store personal data in other countries.
When personal data is transferred outside the UAE, we will seek to use safeguards required or permitted by applicable UAE data-protection law.
Depending on the circumstances, these safeguards may include:
- transfers to jurisdictions providing an appropriate level of protection;
- contractual data-protection obligations;
- approved contractual mechanisms;
- technical and organisational safeguards; or
- another transfer mechanism permitted by applicable law.
Where the EU GDPR or UK GDPR applies, Cotnek will use an applicable transfer mechanism where required, such as:
- an adequacy decision;
- Standard Contractual Clauses;
- the UK International Data Transfer Agreement or applicable UK Addendum; or
- another lawful transfer safeguard.
8. How Long We Keep Personal Data
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, contractual, accounting, security and operational requirements.
Retention periods may vary depending on the type of data.
Account and Customer Content
We generally retain account information and customer content while the relevant account remains active.
Following account closure, information may be deleted, de-identified or retained for a limited period where reasonably necessary for:
- account recovery;
- fraud prevention;
- legal compliance;
- dispute resolution;
- security; or
- backup restoration.
Our normal objective is to remove or anonymise active account content within 90 days after account closure, except where longer retention is required or permitted by law.
Billing and Financial Records
Billing, transaction and invoice records may be retained for the period required under applicable UAE tax, accounting and commercial laws.
Enquiries
General enquiry and waitlist information may normally be retained for up to 24 months, unless:
- the enquiry develops into an ongoing business relationship;
- a longer period is required by law; or
- you validly request deletion earlier.
Backups and Security Logs
Backup copies may remain temporarily after information has been removed from active systems and will be deleted or overwritten according to our backup-retention procedures.
Security and server logs may be retained for as long as reasonably necessary for security, fraud prevention, troubleshooting and legal compliance.
9. Security
We use reasonable technical and organisational measures designed to protect personal data against:
- unauthorised access;
- accidental loss;
- misuse;
- alteration;
- disclosure; and
- destruction.
Depending on the relevant system and feature, these safeguards may include:
- HTTPS encryption for data in transit;
- password hashing;
- access controls;
- role-based permissions;
- workspace separation;
- secure password-reset procedures;
- infrastructure access controls;
- system monitoring;
- security logging; and
- backups.
No online platform or information system can guarantee absolute security.
If we become aware of a personal-data breach, we will investigate it and take appropriate action.
Where required by applicable law, we will notify the relevant regulatory authority and/or affected individuals.
10. Your Privacy Rights
Depending on where you are located and the law applicable to the processing of your information, you may have rights relating to your personal data.
These may include the right to:
- request information about the personal data we process;
- access your personal data;
- request correction of inaccurate or incomplete information;
- request deletion of personal data;
- request restriction of certain processing;
- object to certain processing where applicable;
- receive your personal data in a portable format where applicable;
- withdraw consent where processing is based on consent;
- object to certain direct-marketing activities; and
- exercise applicable rights relating to decisions based solely on automated processing, including profiling.
Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Some rights are subject to legal limitations and exceptions.
Customer-Controlled Data
If Cotnek processes your information on behalf of one of our business customers, that customer is normally responsible for handling your privacy request.
If you contact us about information controlled by a Cotnek customer, we may direct your request to that customer or assist the customer where required.
Making a Request
To exercise a privacy right relating directly to Cotnek, contact:
Where possible, contact us using the email address associated with your Cotnek account.
We may request reasonable information to verify your identity before fulfilling a request.
We will respond within the timeframe required by applicable law.
Where the EU GDPR or UK GDPR applies, requests will generally be addressed within the applicable statutory timeframe.
You may also have the right to submit a complaint to the competent UAE data-protection authority or, where applicable, the competent data-protection authority in your country.
11. Children’s Privacy
Cotnek is designed for businesses and professional users.
The Services are not directed to children under the age of 18.
We do not knowingly intend to collect personal data directly from children through the Services.
If we become aware that personal information has been collected from a child in circumstances where it should not have been collected, we will take reasonable steps to address the situation in accordance with applicable law.
12. Cookies and Similar Technologies
Cotnek may use cookies and similar technologies to:
- keep users signed in;
- maintain essential website functionality;
- remember preferences;
- improve security;
- analyse service performance; and
- understand how users interact with the Services.
Where required by applicable law, we will request consent before using non-essential cookies.
Users may also be able to manage certain cookies through their browser settings.
Further information may be provided in our Cookie Policy.
13. Third-Party Services and Integrations
Cotnek may allow users to connect third-party services, platforms or accounts.
These may include, depending on the features available:
- social-media platforms;
- advertising platforms;
- payment providers;
- email services;
- messaging services;
- CRM or business applications; and
- other external integrations.
When you choose to connect a third-party service, information may be exchanged between Cotnek and that third party as necessary to provide the requested integration.
Third-party services have their own privacy policies and terms.
Cotnek is not responsible for the independent privacy practices of third-party services.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to Cotnek;
- new features;
- new service providers;
- changes in law;
- security improvements; or
- changes in our data-processing practices.
When we update this policy, we will update the “Last updated” date.
For material changes, we may provide additional notice through:
- the Cotnek platform;
- email;
- the website; or
- another appropriate communication method.
15. Contact Us
For privacy questions, requests or concerns, please contact:
Cotnek Technologies
Dubai, United Arab Emirates
Email: support@cotnek.com
Website: cotnek.com
If required by applicable law, additional legal entity, licence, registration or contact information may be provided through the Cotnek website or directly upon request.
