Cogent NetworksCogent Networks Cogent NetworksDriving Innovation, Powering Success. Cogent OS
HOME/ABOUT/PRIVACY POLICY

Privacy Policy

This policy explains how Cogent Networks Ltd collects, uses, stores and protects personal data - on this website, and on Cogent OS, the platform through which we deliver our services and operate our customer, vendor, worker and candidate portals. One thing before anything else: we do not sell personal data, we do not rent or trade it, and we do not use it for marketing or advertising - ever.

Version 1.0Effective date 4 September 2026Controller Cogent Networks LtdICO registration ZC205464Contact dpo@cogentnetworks.com
Binding commitments, not statements of intention
  • We do not sell, rent, licence or trade personal data to anyone, for any price.
  • We do not use personal data for marketing or advertising, and we do not allow anyone else to.
  • We do not profile individuals, and we make no decisions by automated means alone.
  • We do not use personal data to train, fine tune or provide input to any artificial intelligence or machine learning system.
  • We do not disclose to clients any personal data beyond the strict minimum in section 6 - never home addresses, dates of birth, identity document details, bank details, rates, vetting detail or references.
01Who we are

Cogent Networks Ltd is a company registered in England and Wales under company number 12215764, with its registered office at 167 - 169 Great Portland Street, Fifth Floor, London, England, W1W 5PF, United Kingdom. We provide IT managed services, field services, staffing, background verification and logistics services to business customers, founded in Europe and operating through group entities across EMEA, APAC and the Americas.

Cogent Networks Ltd is the controller of the personal data described in this policy and is registered with the UK Information Commissioner's Office under registration ZC205464. Where a Cogent Networks group company in the United Kingdom or the European Union processes personal data for its own purposes, that company is also a controller. Group companies outside the UK and the EU do not access the personal data described here.

For all data protection matters, contact our Data Protection Officer at dpo@cogentnetworks.com.

02What this policy covers

This policy applies to:

  • Visitors to cogentnetworks.com - people browsing this website or contacting us through it.
  • Users of Cogent OS - our operations platform at app.cogentnetworks.com, including customer portal users, vendor companies and their personnel, independent field service engineers and contracted workers, job applicants and candidates, individuals undergoing background verification, and our own internal staff.
  • Business contacts - people we deal with at customer, supplier and partner organisations.

Some audiences also receive a dedicated, more detailed privacy notice - for example our Privacy Notice for Contractors and Applicants, and the notices provided within background verification. Those notices supplement this policy for their audiences; where they give more detail, they take precedence.

03The data we collect

Website visitors: details you send us when you make an enquiry - name, business email address, telephone number, company, and the content of your message - plus the technical data needed to serve the site securely: IP address, browser type, and basic request logs.

Customer portal users: name, business contact details, employer and role, login credentials, and the records generated by using the portal - service requests, tickets, orders, approvals, signatures and correspondence.

Vendor companies and their personnel: company registration, tax and bank details, authorised contacts, rate and compliance information, and for vendor personnel proposed for engagements: name, contact details, skills and qualifications.

Field engineers, contractors and applicants: identity and contact details, right to work documentation, professional background and qualifications, engagement and payment records, service delivery records, and signed agreements. Full detail is in our Privacy Notice for Contractors and Applicants, provided during onboarding.

Background verification subjects: where we perform background verification, we process the information needed for the checks ordered - identity, address history, employment and education history, references, and where lawful and necessary, criminal record and sanctions information. Every check is performed only with the subject's own signed authorisation, and subjects receive their own notice within the process. See section 5.

Internal staff: employment records for our own employees, covered in detail by internal notices.

04Why we use it, and our lawful basis
PurposeLawful basis (UK / EU GDPR)
Responding to enquiries and managing business relationshipsArticle 6(1)(f) - legitimate interests in operating our business
Providing services under contract, operating Cogent OS and its portals, assigning and delivering engagements, invoicing and paymentArticle 6(1)(b) - performance of a contract, or steps taken at your request before a contract
Assessing applicants and matching workers to engagementsArticle 6(1)(b) and 6(1)(f)
Vetting, background verification and sanctions screeningArticle 6(1)(f), Article 6(1)(c) where a legal obligation applies, and for criminal record data Article 10 - see section 5
Site security, incident investigation, establishing or defending legal claimsArticle 6(1)(f)
Tax, accounting, audit and statutory record keepingArticle 6(1)(c) - legal obligation
Keeping a candidate's details on file for future opportunitiesArticle 6(1)(a) - consent, always optional and withdrawable

Where we rely on legitimate interests we balance them against your rights, and you can object at any time - see section 11.

05Vetting and criminal record data

Our personnel and, where ordered, background verification subjects may be given unescorted access to client premises, systems and data. We therefore process criminal offence data only where necessary to assess suitability for that access, and only to the extent permitted by Article 10 of the UK and EU GDPR. In the United Kingdom we rely on Schedule 1 of the Data Protection Act 2018 and maintain an Appropriate Policy Document, available on request. In other territories we rely on the equivalent authorisation under the law applicable to the individual.

  • We never ask anyone to disclose spent, filtered, expired, protected or cancelled convictions.
  • Background checks are performed only with the subject's own signed, informed authorisation, given per screening.
  • Sealed results such as criminal record and medical content are readable only by specifically authorised roles inside Cogent Networks, on a strict need to know basis, and are never included in any report beyond the permitted conclusion.
  • Where a client requires confirmation of vetting, the client receives only a confirmation of the outcome - never the underlying detail.
  • Where a criminal record certificate is obtained, we record the outcome and securely destroy the certificate within 28 days of the vetting decision.
06Who we share data with
RecipientWhat and why
Our clients and their end clientsFor personnel placed on engagements: name and contact telephone number, plus a redacted CV where required to approve a placement, and a pass or fail vetting confirmation where contractually mandated. Nothing more.
Cogent Networks group companies (UK and EU only)Only what each company needs for its role in resourcing, delivery, payment and compliance, on a need to know basis.
Service providers acting as our processorsHosting, database and authentication, email delivery, accounting and payment processing, and professional advisers - each under a written data processing agreement and acting only on our instructions. Our principal processors are Supabase (database and authentication, hosted in the EU), Hetzner (server hosting, Germany) and Microsoft (business email and productivity).
Authorities and advisersTax authorities, regulators, law enforcement, insurers and legal advisers, where required by law or necessary to establish, exercise or defend legal claims.
A successor businessAs necessary in the event of a reorganisation, merger or sale, under confidentiality.
07What we never do

These are binding commitments, not statements of intention. If we ever needed to use personal data for a purpose outside this policy, we would tell you first and, where the law requires it, ask for your consent.

  • We do not sell, rent, licence or trade personal data to anyone, for any price.
  • We do not use personal data for marketing or advertising, and we do not allow anyone else to.
  • We do not profile individuals, and we make no decisions by automated means alone.
  • We do not use personal data to train, fine tune or provide input to any artificial intelligence or machine learning system.
  • We do not disclose to clients any personal data beyond the strict minimum in section 6 - never home addresses, dates of birth, identity document details, bank details, rates, vetting detail or references.
08Where data is stored and international transfers

Personal data processed on Cogent OS is stored on servers located within the European Union - our database and authentication infrastructure is hosted in Ireland and our application servers in Germany. It is not transferred outside the United Kingdom and the European Economic Area.

Cogent Networks Ltd is established in the United Kingdom, and our UK personnel access this EU hosted data to operate the business. That access is lawful under the European Commission's adequacy decision for the United Kingdom, renewed on 19 December 2025 and valid until 27 December 2031, which permits data to flow freely between the EEA and the UK without additional safeguards. If that decision were ever withdrawn, we would put Standard Contractual Clauses and the UK International Data Transfer Addendum in place before continuing.

Cogent Networks group entities outside the UK and the EU do not access this data. Where an engagement is performed at a client site outside the UK and the EEA, the only personal data reaching that client is the minimum described in section 6, under an appropriate safeguard.

09How long we keep data
DataRetention period
Website enquiriesAs long as needed to handle the enquiry and any follow up, then deleted
Unsuccessful applications, no pool consent given6 months from the decision, then deleted
Candidate pool details held with consentUp to 24 months from last contact, or until consent is withdrawn
Engagement, delivery and portal records, contracts and correspondenceDuration of the relationship, plus 6 years
Invoices, payment and tax records6 years from the end of the relevant tax year, or longer where local law requires
Criminal record declarationsDuration of the relationship, plus 12 months
Criminal record certificatesOutcome recorded; certificate destroyed within 28 days of the vetting decision
Background verification casesRetained per the notice provided in the verification process, then securely destroyed
10How we protect data

Cogent OS is built with security and data protection by design: role based access control so that every user sees only what their role requires, an immutable audit trail on every record, encryption in transit and at rest, sealed handling of the most sensitive categories, mandatory strong authentication, and EU data residency. Access to personal data inside Cogent Networks is restricted to the personnel who need it for the purposes in this policy, all of whom are bound by confidentiality obligations. Our suppliers are bound by written data processing agreements and security requirements, and we maintain breach response procedures - where a breach is likely to result in a risk to individuals, we will notify the ICO and, where required, the affected individuals without undue delay.

11Your rights

Subject to the conditions in applicable data protection law, you have the right to:

  • Access - obtain confirmation of whether we process your data, and a copy of it.
  • Rectification - have inaccurate data corrected and incomplete data completed.
  • Erasure - have your data deleted where we no longer need it, where you withdraw consent, or where you successfully object.
  • Restriction - have processing limited in certain circumstances.
  • Portability - receive the data you provided in a structured, commonly used, machine readable format.
  • Objection - object at any time to processing based on our legitimate interests.
  • Withdraw consent - at any time, where processing relies on consent, without affecting processing before withdrawal.

To exercise any right, email dpo@cogentnetworks.com. We respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies. There is no charge unless a request is manifestly unfounded or excessive.

12Cookies

This website uses cookies that are strictly necessary to operate - session, authentication and security features such as remembering a trusted browser where you choose it, and a local record of your cookie choice and your light or dark theme preference. These are set without consent because the site cannot function without them.

On your first visit you are asked whether you also consent to analytics cookies, which would help us understand how the site is used. You can choose Accept all or Essential only. Your choice is stored locally in your browser under the key cookie-consent and the banner does not appear again. You can change it at any time using the Cookie preferences link in the footer of any page.

No analytics cookies are set in this release. Analytics would load only where consent is recorded as all, and this policy will be updated to name the provider, the cookies set and their retention before any such cookie is used. We do not use advertising or cross-site tracking cookies, and we use no third-party consent-management service - the banner is part of this site.

13Children

Our services are for businesses and working professionals. We do not knowingly process the personal data of anyone under 18, and our systems are built to refuse records for anyone below that age.

14Changes to this policy

We may update this policy from time to time. Where changes are material we will notify affected individuals directly through the platform or by email. The current version, with its effective date, is always published on this page.

15Contact and complaints

For any question about this policy or our handling of personal data, contact our Data Protection Officer at dpo@cogentnetworks.com, or write to Cogent Networks Ltd, 167 - 169 Great Portland Street, Fifth Floor, London, England, W1W 5PF, United Kingdom.

If you are unhappy with our response, you have the right to lodge a complaint with a supervisory authority: in the United Kingdom, the Information Commissioner's Office at ico.org.uk; in the European Union, the supervisory authority of your country of residence, place of work, or the place of the alleged infringement.

Document control: Version 1.0, effective 4 September 2026. Approved by the Data Protection Officer, Cogent Networks Ltd. Reviewed at least annually.

Questions about how we handle data?

Contact our Data Protection Officer at dpo@cogentnetworks.com, or write to our registered office in London.

Get a Quote Talk to an expert
+44 20 3936 1085 · INFO@COGENTNETWORKS.COM