Privacy Policy

Version: V1.0 Effective date: 2026-08-18 Last updated: 2026-08-12 Companion document: Terms of Service (see Terms-of-Service-2026-08-V1.0.md)


This Privacy Policy explains how Cosmaya Global LLC ("we," "us," "our," or the "Company") collects, uses, shares, retains, and protects your personal information when you use the CiviCordia platform and the reunion/alumni-networking service at the civicordia.ai domain and its subdomains, and related applications (the "Service").

By using the Service you agree to this Policy and to our Terms of Service. If you do not agree, do not use the Service.


1. The Short Version

The rest of this Policy gives the detail. The short version does not replace it.


2. Information We Collect

2.1 Information you provide directly

2.2 Information from third parties and organizers

2.3 Information collected automatically

2.4 Derived information


3. How We Use Your Information

We use personal information to:

We will not use your information for materially different purposes without providing notice and, where required, obtaining your consent.


4. AI Processing

4.1 The Service uses artificial intelligence, including third-party AI/model providers, to transcribe voice, extract and structure profile information, create embeddings for search, and generate summaries, matches, and draft text.

4.2 Your content is processed to provide the Service to you and to the members/communities you choose to share with. Our AI and infrastructure providers are contractually restricted from using your content to train their own models:

We do not use your content, or AI-derived assertions about you, to train or fine-tune any AI model.

4.3 AI output can be inaccurate, incomplete, misleading, or out of date, and may contain material inaccuracies even when it appears accurate. You can review, edit, or delete AI-derived content about you. Automated suggestions are not intended to, and in the Service as currently offered do not, produce legal or similarly significant effects about you.

4.4 EU AI Act. Where our processing engages Regulation (EU) 2024/1689 (the "EU AI Act"), we comply with the applicable transparency and information obligations. In particular, we make clear (both in the Service itself and in Section 4.1 of this Policy) that Cora is an AI-powered personal agent and that AI is used throughout the Service.


5. How We Share Information

We share personal information only as follows:

We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising (as those terms are defined under US state privacy laws).


6. Legal Bases for Processing (where GDPR / similar laws apply)

Depending on the activity, we rely on: performance of our contract with you (to provide the Service, including transcription of voice input you submit during onboarding or conversation); your consent (for example, certain optional imports or optional features — which you may withdraw as easily as you gave it); our legitimate interests (to secure the Service and prevent abuse, balanced against your rights); and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time without affecting prior processing.


7. International Data Transfers

The Service and its sub-processors store and process personal information in the United States and the European Union. These are the locations of our processing infrastructure and sub-processors, not descriptors of where our users reside — the CEG pilot is not offered to EU/EEA residents (see §10.4 EU paragraph). Specifically: GCP us-central1 (our compute, Vertex AI, Speech-to-Text); AWS us-east-1 (MongoDB Atlas, Pinecone, Amazon SES, and our Apify request proxy); and Apify's own platform, which processes data in the EU and the US per its Trust Center. These locations may be outside your country of residence and may have different data-protection laws. Where required, we implement appropriate safeguards for such transfers — including the European Commission's Standard Contractual Clauses (SCCs) with each sub-processor, and reliance on the EU-US Data Privacy Framework where the sub-processor is certified.


8. Data Retention

We retain personal information for as long as your account is active and as needed to provide the Service, and thereafter only as necessary to comply with legal obligations, resolve disputes, maintain security, and enforce our agreements. When you delete content or your account, we delete or de-identify the associated personal information within 30 days of your request, except:


9. Security

We use technical and organizational measures designed to protect personal information — including encryption in transit, hashed passwords, access controls, and per-member namespace isolation for vector search. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law.


10. Your Rights and Choices

10.1 Your rights (universal baseline)

Subject to your jurisdiction and applicable law, you have the right to:

10.2 How to exercise these rights

Use the in-product controls (Section 11) or contact us at raj@cosmaya.global. We will respond within the timeframes required by applicable law — within 45 days as a default, extendable by up to 45 additional days with notice to you, or shorter where a specific jurisdiction requires it (for example, within one month under GDPR / UK-GDPR; within 30 days for DPDPA grievance redressal). We may need to verify your identity before we can act. We will not discriminate against you for exercising your rights.

Appeal. If we deny your request, you may appeal by replying to our response or writing to raj@cosmaya.global with the subject line "Appeal". We will review the appeal and respond within 45 days. For US state residents whose law provides for appeal (including Connecticut, Virginia, New Jersey, Texas, and others), this mechanism satisfies the statutory appeal right.

10.3 Correction notifications to recipients

Where we hold a record of which members received a given AI-derived assertion about you, we will notify those members of your correction. Three structural limits apply, stated plainly: (i) some disclosure paths carry no per-assertion identity that we can trace to recipients (for example, summaries built from bare public strings) — on those paths we cannot notify recipients; (ii) assertions that existed before we rebuilt our extraction on 4 August 2026 may reference identifiers that no longer resolve — those recipients are reconstructible only from our purpose-limited legal-hold snapshot (see Section 8(c)); (iii) we can identify which factoms informed a description and when it was shown, but we cannot identify which specific factom produced which specific sentence within a synthesized description. We commit to notify where the record allows it; we do not promise complete recipient tracing across all past disclosures. This matches the Terms of Service §5.6 substance and is intended to be read as one honest commitment across both documents.

10.4 Jurisdiction-specific supplements

The rights in §10.1 are the universal baseline. Depending on where you live, additional or more specific rights and procedures may apply.

India (DPDP Act 2023). The DPDPA provides rights to access, correction, completion, updating, and erasure (s.12), and to grievance redressal. Contact our Grievance Officer at raj@cosmaya.global (see Section 15); we commit to a response period of not more than 30 days. You may nominate another individual to exercise your rights in the event of death or incapacity. The DPDPA does not include a portability right; we nonetheless offer portability on request (see Section 11).

European Union / European Economic Area (GDPR). The CEG pilot is not offered to residents of the European Union or European Economic Area at this time. We do not knowingly onboard EU/EEA residents to the Service during the pilot phase. If you are an EU/EEA resident and you believe you have been onboarded, contact us at raj@cosmaya.global; we will honour your GDPR rights (access, rectification, erasure, portability, restriction, objection, right to lodge a complaint with your national Supervisory Authority) and phase your account off the Service. We will re-evaluate EU/EEA availability — including appointment of an Article 27 representative and the associated compliance surface — as the Service scales beyond the current founder-only-LLC pilot.

United Kingdom (UK-GDPR). Rights in §10.1 apply. You may lodge a complaint with the Information Commissioner's Office (ICO), ico.org.uk.

California (CCPA / CPRA). In addition to §10.1, California residents have the right to know what personal information is collected, used, shared, or sold; the right to correct inaccurate information; and the right to opt out of "sale" or "sharing" for cross-context behavioral advertising. We do not sell personal information and do not "share" for cross-context behavioral advertising (§10.5). You have the right to be free from retaliation for exercising your rights.

Connecticut (CTDPA). In addition to §10.1, you have the rights of access, correction, deletion, portability, and opt-out of processing for purposes of targeted advertising, sale, or profiling in furtherance of decisions producing legal or similarly significant effects. You have an explicit right to appeal a denied request — the appeal mechanism is described in §10.2. Where we process sensitive data as defined by CTDPA § 42-515(29), we do so only with your opt-in consent (§ 42-518(b)(4)).

New Jersey (NJDPA). Same rights and structure as Connecticut. You have the rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and profiling in furtherance of decisions producing legal or similarly significant effects. The appeal mechanism in §10.2 applies. Sensitive-data processing requires your opt-in consent.

Texas (TDPSA). Same rights and structure as Connecticut and New Jersey. The appeal mechanism in §10.2 applies. Sensitive-data processing requires your opt-in consent.

Virginia (VCDPA). Same rights and structure as Connecticut, New Jersey, and Texas. Sensitive-data processing requires your opt-in consent; the appeal mechanism in §10.2 applies.

Washington (My Health My Data Act — MHMDA, RCW 19.373). MHMDA applies to "consumer health data" of Washington residents. The Service is designed for professional and community networking and does not ask you for health information. You control the visibility of every item in your context: any item can be marked private, edited, or deleted by you at any time, and an item marked private is withheld from other members' agents, from discovery, and from every cross-community disclosure surface. We do not knowingly disclose or share consumer health data or sensitive personal information across community boundaries. If you are a Washington resident and believe we have collected or processed consumer health data about you in a manner that requires MHMDA authorization, contact us at raj@cosmaya.global; we will delete such data promptly and, if applicable, obtain your written authorization before any future processing.

Illinois (BIPA). The Illinois Biometric Information Privacy Act (740 ILCS 14) applies to the collection or possession of biometric identifiers and biometric information. We do not collect or store biometric identifiers or biometric information. Voice data is processed transiently for transcription only and is not retained as biometric input (see Section 2.1).

Elsewhere. If you reside outside the jurisdictions listed above, the universal rights in §10.1 apply. Local law may provide additional rights; contact us at raj@cosmaya.global to exercise any of them.

10.5 What we do not do


11. Your Controls in the Service


12. Children

The Service is not directed to children and is intended for users 18 and older (or the age of majority in your jurisdiction). This threshold matches DPDPA s.2(f) (under-18 = child) and is compatible with GDPR Art. 8. We do not knowingly collect personal information from children, we do not track or behaviourally monitor children, and we do not deliver advertising to children. If you believe a child has provided us information, contact us at raj@cosmaya.global and we will delete it promptly.


13. Third-Party Services and Links

The Service may link to or integrate with third-party services (for example, an authorized profile import). Those services are governed by their own privacy policies, and we are not responsible for their practices. Review their policies before providing information.


14. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will provide reasonable notice (for example, by updating the "Last updated" date and, where appropriate, notifying you in the Service). Where a change materially affects processing that relies on your consent, we will ask you to accept the updated Policy before continuing. For other changes, your continued use after they take effect constitutes acceptance, except where additional consent is required by law.


15. Contact Us

Privacy questions / to exercise your rights: raj@cosmaya.global Cosmaya Global LLC, 37 Old Nourse Street, Westborough, MA 01581, USA

CiviCordia is operated by Cosmaya Global LLC. Questions about this document, or a request to access, correct, export or delete your information: raj@cosmaya.global.

Privacy Policy · Terms of Service