Data handling
What we access, what we keep, and for how long
Written to be read by the person granting access and by whoever has to approve it. If your security or procurement team needs something more formal, ask and we’ll send it before you create anything.
Access
What we can see
For a Leak Check or a Revenue Leak Report, you create a read-only private app in your own HubSpot portal and share the token with us. We hold no write access at any point in any engagement.
- crm.objects.contacts.read Contact records
- crm.objects.companies.read Company records
- crm.objects.deals.read Deals and amounts
- crm.objects.owners.read Record ownership
- crm.objects.line_items.read Deal line items
- crm.schemas.* .read Property and pipeline definitions
- crm.lists.read List membership and logic
- Any write scope We cannot change a record
- Email content or call recordings Never accessed
- Workflow scope Grants write, so we decline it
- Settings, users or permissions No access
- Payment or billing data No access
You can revoke access yourself at any moment from Settings → Integrations → Private Apps, without telling us and without anything breaking on your side.
Storage
What we actually keep
We query your portal and retain aggregate findings — counts, calculated values, and the record identifiers needed to show you a specific example during a call. We do not retain exports of your contact or company database.
- Finding counts and calculations e.g. 61 deals, $118k banded
- Record IDs for cited examples So we can point at one on screen
- Portal-level metadata Hub tiers, pipeline structure, record volumes
- Contact names, emails or phone numbers Not extracted
- Full record exports Never created
- Email or call content Not accessible to us
- Your access token, after the engagement Deleted with the app
Retention
How long we hold it
- Access token. Deleted at the end of your Leak Check call, or at the close of a Report engagement. You’re welcome to watch us delete it, or delete it yourself.
- Findings data. Retained for the duration of our engagement and for 24 months afterwards, so we can reference your baseline if you return. Deleted on request at any time.
- The report document itself. Retained indefinitely as a record of work delivered, unless you ask us to remove it.
To request deletion, email us and we’ll confirm in writing within five business days.
Benchmarking
How your findings contribute, and how to opt out
Findings are stored in a consistent structure so we can build cross-portal benchmarks over time — the ability to tell a client how their leakage compares to other portals we’ve scanned. Benchmark data is aggregated and anonymised, and no client is identifiable in it.
If you’d rather your portal was excluded from benchmark data entirely, say so at any point and we’ll exclude it. It makes no difference to what you receive.
Practicalities
Security, location and sub-processors
- Token handling. Tokens are shared through a one-time secret link, never by email, and are stored in an encrypted password manager for the duration of the engagement.
- Where data sits. Findings data is held in Australia. If your organisation requires data residency confirmation in writing, ask before you begin.
- Who has access. CogniOps is a small team. Only people working directly on your engagement can access your findings. We do not use offshore contractors for delivery.
- Sub-processors. We’ll name every third-party service touching your data on request. We don’t put client data through third-party AI services.
- Breach notification. If we became aware of any unauthorised access to your data, we’d tell you within 24 hours, before we’d finished investigating it.
Your rights
Australian Privacy Principles
CogniOps Pty Ltd is an Australian company and handles personal information in line with the Australian Privacy Principles under the Privacy Act 1988. Where your organisation or its contacts are covered by the GDPR or UK GDPR, we’ll act as a processor under your instruction and sign a data processing agreement on request.
You can ask us at any time what we hold, ask for a copy of it, or ask us to delete it. Our full privacy policy sits here.
Questions about any of this before you grant access: michael@cogniops.com.
Comfortable? Here’s how to grant access
The access guide walks through every click, takes about four minutes, and shows you how to revoke it.