Privacy Policy
How Cockpit Agents handles your data, including data from the business systems you connect.
Effective 1 September 2026
Who we are
Cockpit Agents is provided to organisations under a written agreement. You use Cockpit as a member of your organisation's workspace, not as a private individual. It is not a consumer service.
This policy describes how Cockpit Agents collects, uses, shares and protects your personal data. In this policy, "Cockpit" means the Cockpit Agents service, and "we" and "us" mean Ventures at Work B.V., the company established in the Netherlands that owns and operates it. We act as controller when we handle enquiries and administer our customer relationships. When we process personal data in your organisation’s workspace on its instructions, we act as processor.
This policy sits alongside our Terms of Service, our Cookie Statement, and our page on the Use of Google API Services.
Cockpit does not track you
Cockpit works for you, not advertisers. We use your data only to provide, secure and improve the features you choose. We do not follow you across websites, build advertising profiles, sell personal data or use customer data for advertising.
We do not use anything we collect to train AI models, and our providers are not permitted to either.
We share data only with the service providers needed to operate Cockpit and with members of your workspace according to its permissions. Those providers may process data only to deliver their services to us, not for their own advertising or profiling.
What we collect
We collect as little as we can. About a person we hold a name, an email address, and a link to the profile picture your sign-in provider hosts. We do not store the picture ourselves.
- Account information. We collect the identity you sign in with and the workspace you belong to.
- Session information. We record sign-in events, session timestamps and technical request information. We use these to protect the service.
- Content from connected services. We receive documents, messages, calendar entries and business data from the systems you choose to connect.
- Operational records. We keep technical logs and product telemetry. These can include interaction content, depending on your workspace settings. We use them only to secure, operate and improve Cockpit, never for advertising.
- Access requests. If you fill in the Request Access form on this website, we collect the email address and message you submit, and technical information about the request. This is the only thing we collect from people who are not yet using Cockpit.
Why we collect it
We collect your data for the reasons below, and for nothing else. Data protection law requires us to have a lawful reason for each one, so we name it alongside the purpose.
- To reply when you ask for access. If you fill in the Request Access form on this website, we use your email address and message to reply to you and to take the steps you have asked us to take before any agreement. We keep the technical details of that request separately, because we have a legitimate interest in preventing abuse of the form.
- To run the service for your organisation. We need this to perform the agreement your organisation has with us.
- To connect the providers you choose. You authorise each connector yourself, such as Gmail or Dropbox, and we act only on that instruction. This is different from the service providers Cockpit itself runs on, such as hosting and AI processing, which are part of the product rather than something you connect. Those are in Who we share data with.
- To keep the service and your data secure. We have a legitimate interest in preventing abuse, detecting incidents and protecting the people who use Cockpit.
- To keep Cockpit working and make it better. We look at how the product behaves so we can find faults and fix them. We use technical records for this wherever they are enough, and we do not read your business content for this purpose.
- To meet our legal obligations. Some records we are simply required by law to keep, such as accounting records.
Google user data
When you connect a Google service, Cockpit asks for the minimum scope that capability needs. We have no interest in holding access we do not use, and we do not request scopes we have no feature for. Cockpit reads the data you authorise, and where your organisation has enabled changes it also makes them, such as sending a message, amending a calendar event, or updating advertising and product data. We never use it for advertising or profiling, and we never use it to train AI models.
Cockpit Agents' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke access at any time in your Google Account permissions, or by disconnecting the service inside Cockpit. Our Use of Google API Services page sets out each Google service we connect to and exactly what we do with it.
How we protect data
We use technical and organisational measures appropriate to the risk. Content is encrypted at rest and connections are encrypted in transit. Access credentials are held in a dedicated secret store, separate from application data. Access to production systems is restricted to the people who need it and is logged. We review these measures as the service changes.
Data we treat as privacy sensitive is masked in the interface. We take care that it is not shown in full where it does not need to be.
No service can be guaranteed to be completely secure. If a personal data breach affects you, we will notify the relevant supervisory authority and, where the law requires it, the people affected.
Where data is processed
Some service providers process personal data outside the European Economic Area. We use the European Commission’s standard contractual clauses to protect these transfers. Contact us for information about these safeguards.
The Cockpit application
The application runs on Microsoft Azure. By default it runs in the European Union, in the Netherlands and Ireland, and that is where your data is stored. Your organisation can agree a different region with us, and can choose which AI models we use. Where your organisation has agreed something different, its agreement with us states the arrangement and overrides the default described here.
The AI models are operated by Microsoft, which may run them outside the European Union wherever it has capacity. Your data remains stored in the regions above. The models may not train on your content. Microsoft keeps prompts and responses for up to 30 days to detect misuse of the service, and a Microsoft reviewer may see content the system flags. Your organisation can ask us to apply for Microsoft's modified abuse monitoring, which removes this.
This website
This website is separate from the application. It is published on Cloudflare's content delivery network. Cloudflare is a United States company with a worldwide network, so these pages are served to you from whichever Cloudflare location is nearest to you, which may be outside the European Economic Area.
The Request Access form at the bottom of our home page is the only place on this website where you give us personal data. When you submit it, your email address and message go to Cloudflare rather than to the Cockpit application, and are stored in a Cloudflare database in the European Union. We also store technical information about the request, including your IP address and your browser, and we keep that only to stop automated abuse of the form. We use your address and message to reply to you. Nothing from this form is used for analytics, profiling or marketing. We keep an access request for up to 12 months, and you can ask us to delete it at any time.
The services you connect
These are operated by their own providers, under your organisation's agreement with them, and they may process data outside the European Economic Area. That processing is governed by your relationship with that provider, not by this policy. You choose which services to connect, and you can disconnect them at any time.
How long we keep data
- Account and workspace information is kept while your organisation uses Cockpit, and is removed after the agreement ends.
- Content from a connected service, and anything derived from it, is kept while the connection is active. How long it is kept beyond that is set in your organisation's agreement with us, because organisations differ in the regulatory requirements they have to meet. Disconnecting a service removes the stored credential and stops further access.
- Operational records, meaning technical logs and product telemetry, are kept according to the observability level your organisation chooses. That ranges from keeping nothing at all to 90 days. Your organisation can agree a different period with us. When the period ends, the records are deleted or aggregated.
- Access requests made through this website are kept for up to 12 months. Ask us and we will delete yours sooner.
- Records we must keep by law, such as accounting records, are kept for the period the law requires.
You may ask us to delete derived content at any time. We will do so unless we are required to keep it.
Your rights
You have the right to access your personal data, to have it corrected or deleted, to restrict or object to how we process it, and to receive it in a portable form. Where we rely on your consent, you may withdraw it at any time without affecting processing that already took place.
If the data you are asking about sits in an organisation's workspace, that organisation decides what happens to it, and you should contact them directly. We will help them respond. For the data we hold in our own right, such as your sign-in identity, contact us using the details below. We answer within one month and will say if we need longer.
You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or with the supervisory authority where you live or work.
Changes to this policy
We may update this policy as Cockpit changes. When we do, we update the date at the top of this page. If a change materially affects how we handle your personal data, we will tell you before it takes effect, by email or inside the product. Earlier versions are available on request.
Contact
For questions about this policy or to make a data subject request, email support@cockpitagents.com.
Cockpit Agents is a registered trade name of Ventures at Work B.V., established in the Netherlands. Our full company details are on the contact page.