This policy explains how Cogent Networks Ltd collects, uses, stores and protects personal data - on this website, and on Cogent OS, the platform through which we deliver our services and operate our customer, vendor, worker and candidate portals. One thing before anything else: we do not sell personal data, we do not rent or trade it, and we do not use it for marketing or advertising - ever.
Cogent Networks Ltd is a company registered in England and Wales under company number 12215764, with its registered office at 167 - 169 Great Portland Street, Fifth Floor, London, England, W1W 5PF, United Kingdom. We provide IT managed services, field services, staffing, background verification and logistics services to business customers, founded in Europe and operating through group entities across EMEA, APAC and the Americas.
Cogent Networks Ltd is the controller of the personal data described in this policy and is registered with the UK Information Commissioner's Office under registration ZC205464. Where a Cogent Networks group company in the United Kingdom or the European Union processes personal data for its own purposes, that company is also a controller. Group companies outside the UK and the EU do not access the personal data described here.
For all data protection matters, contact our Data Protection Officer at dpo@cogentnetworks.com.
This policy applies to:
Some audiences also receive a dedicated, more detailed privacy notice - for example our Privacy Notice for Contractors and Applicants, and the notices provided within background verification. Those notices supplement this policy for their audiences; where they give more detail, they take precedence.
Website visitors: details you send us when you make an enquiry - name, business email address, telephone number, company, and the content of your message - plus the technical data needed to serve the site securely: IP address, browser type, and basic request logs.
Customer portal users: name, business contact details, employer and role, login credentials, and the records generated by using the portal - service requests, tickets, orders, approvals, signatures and correspondence.
Vendor companies and their personnel: company registration, tax and bank details, authorised contacts, rate and compliance information, and for vendor personnel proposed for engagements: name, contact details, skills and qualifications.
Field engineers, contractors and applicants: identity and contact details, right to work documentation, professional background and qualifications, engagement and payment records, service delivery records, and signed agreements. Full detail is in our Privacy Notice for Contractors and Applicants, provided during onboarding.
Background verification subjects: where we perform background verification, we process the information needed for the checks ordered - identity, address history, employment and education history, references, and where lawful and necessary, criminal record and sanctions information. Every check is performed only with the subject's own signed authorisation, and subjects receive their own notice within the process. See section 5.
Internal staff: employment records for our own employees, covered in detail by internal notices.
| Purpose | Lawful basis (UK / EU GDPR) |
|---|---|
| Responding to enquiries and managing business relationships | Article 6(1)(f) - legitimate interests in operating our business |
| Providing services under contract, operating Cogent OS and its portals, assigning and delivering engagements, invoicing and payment | Article 6(1)(b) - performance of a contract, or steps taken at your request before a contract |
| Assessing applicants and matching workers to engagements | Article 6(1)(b) and 6(1)(f) |
| Vetting, background verification and sanctions screening | Article 6(1)(f), Article 6(1)(c) where a legal obligation applies, and for criminal record data Article 10 - see section 5 |
| Site security, incident investigation, establishing or defending legal claims | Article 6(1)(f) |
| Tax, accounting, audit and statutory record keeping | Article 6(1)(c) - legal obligation |
| Keeping a candidate's details on file for future opportunities | Article 6(1)(a) - consent, always optional and withdrawable |
Where we rely on legitimate interests we balance them against your rights, and you can object at any time - see section 11.
Our personnel and, where ordered, background verification subjects may be given unescorted access to client premises, systems and data. We therefore process criminal offence data only where necessary to assess suitability for that access, and only to the extent permitted by Article 10 of the UK and EU GDPR. In the United Kingdom we rely on Schedule 1 of the Data Protection Act 2018 and maintain an Appropriate Policy Document, available on request. In other territories we rely on the equivalent authorisation under the law applicable to the individual.
| Recipient | What and why |
|---|---|
| Our clients and their end clients | For personnel placed on engagements: name and contact telephone number, plus a redacted CV where required to approve a placement, and a pass or fail vetting confirmation where contractually mandated. Nothing more. |
| Cogent Networks group companies (UK and EU only) | Only what each company needs for its role in resourcing, delivery, payment and compliance, on a need to know basis. |
| Service providers acting as our processors | Hosting, database and authentication, email delivery, accounting and payment processing, and professional advisers - each under a written data processing agreement and acting only on our instructions. Our principal processors are Supabase (database and authentication, hosted in the EU), Hetzner (server hosting, Germany) and Microsoft (business email and productivity). |
| Authorities and advisers | Tax authorities, regulators, law enforcement, insurers and legal advisers, where required by law or necessary to establish, exercise or defend legal claims. |
| A successor business | As necessary in the event of a reorganisation, merger or sale, under confidentiality. |
These are binding commitments, not statements of intention. If we ever needed to use personal data for a purpose outside this policy, we would tell you first and, where the law requires it, ask for your consent.
Personal data processed on Cogent OS is stored on servers located within the European Union - our database and authentication infrastructure is hosted in Ireland and our application servers in Germany. It is not transferred outside the United Kingdom and the European Economic Area.
Cogent Networks Ltd is established in the United Kingdom, and our UK personnel access this EU hosted data to operate the business. That access is lawful under the European Commission's adequacy decision for the United Kingdom, renewed on 19 December 2025 and valid until 27 December 2031, which permits data to flow freely between the EEA and the UK without additional safeguards. If that decision were ever withdrawn, we would put Standard Contractual Clauses and the UK International Data Transfer Addendum in place before continuing.
Cogent Networks group entities outside the UK and the EU do not access this data. Where an engagement is performed at a client site outside the UK and the EEA, the only personal data reaching that client is the minimum described in section 6, under an appropriate safeguard.
| Data | Retention period |
|---|---|
| Website enquiries | As long as needed to handle the enquiry and any follow up, then deleted |
| Unsuccessful applications, no pool consent given | 6 months from the decision, then deleted |
| Candidate pool details held with consent | Up to 24 months from last contact, or until consent is withdrawn |
| Engagement, delivery and portal records, contracts and correspondence | Duration of the relationship, plus 6 years |
| Invoices, payment and tax records | 6 years from the end of the relevant tax year, or longer where local law requires |
| Criminal record declarations | Duration of the relationship, plus 12 months |
| Criminal record certificates | Outcome recorded; certificate destroyed within 28 days of the vetting decision |
| Background verification cases | Retained per the notice provided in the verification process, then securely destroyed |
Cogent OS is built with security and data protection by design: role based access control so that every user sees only what their role requires, an immutable audit trail on every record, encryption in transit and at rest, sealed handling of the most sensitive categories, mandatory strong authentication, and EU data residency. Access to personal data inside Cogent Networks is restricted to the personnel who need it for the purposes in this policy, all of whom are bound by confidentiality obligations. Our suppliers are bound by written data processing agreements and security requirements, and we maintain breach response procedures - where a breach is likely to result in a risk to individuals, we will notify the ICO and, where required, the affected individuals without undue delay.
Subject to the conditions in applicable data protection law, you have the right to:
To exercise any right, email dpo@cogentnetworks.com. We respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies. There is no charge unless a request is manifestly unfounded or excessive.
This website uses cookies that are strictly necessary to operate - session, authentication and security features such as remembering a trusted browser where you choose it, and a local record of your cookie choice and your light or dark theme preference. These are set without consent because the site cannot function without them.
On your first visit you are asked whether you also consent to analytics cookies, which would help us understand how the site is used. You can choose Accept all or Essential only. Your choice is stored locally in your browser under the key cookie-consent and the banner does not appear again. You can change it at any time using the Cookie preferences link in the footer of any page.
No analytics cookies are set in this release. Analytics would load only where consent is recorded as all, and this policy will be updated to name the provider, the cookies set and their retention before any such cookie is used. We do not use advertising or cross-site tracking cookies, and we use no third-party consent-management service - the banner is part of this site.
Our services are for businesses and working professionals. We do not knowingly process the personal data of anyone under 18, and our systems are built to refuse records for anyone below that age.
We may update this policy from time to time. Where changes are material we will notify affected individuals directly through the platform or by email. The current version, with its effective date, is always published on this page.
For any question about this policy or our handling of personal data, contact our Data Protection Officer at dpo@cogentnetworks.com, or write to Cogent Networks Ltd, 167 - 169 Great Portland Street, Fifth Floor, London, England, W1W 5PF, United Kingdom.
If you are unhappy with our response, you have the right to lodge a complaint with a supervisory authority: in the United Kingdom, the Information Commissioner's Office at ico.org.uk; in the European Union, the supervisory authority of your country of residence, place of work, or the place of the alleged infringement.
Document control: Version 1.0, effective 4 September 2026. Approved by the Data Protection Officer, Cogent Networks Ltd. Reviewed at least annually.
Contact our Data Protection Officer at dpo@cogentnetworks.com, or write to our registered office in London.