Cordanis — Privacy policy

What we collect, and what we do with it.

Cordanis is an operating system for B2B sales teams. It works on data you bring to it and data you connect to it. This policy says plainly what that data is, how it is used, and how to take it back.

Effective September 20, 2026 · Applies to the Cordanis application at cordanis.com

01 What this covers

This policy applies to the Cordanis application and website at cordanis.com, operated by Cordanis. It covers the people who sign in to Cordanis (sellers, managers, and administrators at customer organizations) and the data those people bring into their workspace or connect through third-party sources.

Cordanis is used by organizations. If you use Cordanis through your employer, your employer is the customer and decides what data is connected, who can see it, and when it is deleted. This policy describes how Cordanis, as the provider, handles that data.

02 Information we process

  • Account data. Your name, work email address, and organization, collected when your account is created or you are invited. Authentication is handled by Amazon Cognito; Cordanis never stores your password.
  • Workspace data. Accounts, contacts, notes, research, documents, and messaging that you or your organization upload, write, or generate inside Cordanis.
  • Connected source data. Data read from services you choose to connect, such as Google Workspace (Gmail and Calendar), Salesforce, and Apollo. Sections 03 and 04 describe this in detail.
  • Usage and operational data. Request logs, run events, error reports, and timing. These carry identifiers, status, and timestamps only. Operational logs never contain message bodies, file contents, prompts, tokens, or credentials.

Cordanis does not use advertising trackers on the application and does not sell personal information.

03 Google user data

When you connect a Google account, Cordanis requests only the scopes it needs for the features you enable:

ScopeWhat Cordanis does with it
Read Gmail (gmail.readonly)Finds replies from your prospects and customers, detects threads that are waiting on you, and gives the Assistant the context of a conversation you ask about. Cordanis reads messages related to accounts and contacts in your workspace.
Compose and send Gmail (gmail.compose)Sends messages you have reviewed and approved in Cordanis, from your own address. Nothing is sent without an explicit approval from you on that message.
Read Calendar (calendar.readonly)Shows your upcoming meetings and prepares briefs for external meetings based on the attendees and the accounts they belong to.
  • Cordanis uses Google user data only to provide and improve the features you see in the product for your own use. It does not use Google user data for advertising, does not sell it, and does not transfer it to third parties except as needed to provide the service (for example, to the AWS infrastructure the service runs on), to comply with law, or with your explicit consent.
  • People at Cordanis do not read your Gmail or Calendar data. The exceptions are the ones Google permits: you ask us to for support, it is needed for security or to comply with law, or the data has been aggregated and anonymized for internal operations.
  • Google user data is not used to train generalized artificial intelligence or machine learning models. Model inference runs through Amazon Bedrock, which does not train on customer content.
  • Access and refresh tokens for your Google account are held in an encrypted credential vault inside our AWS environment (Amazon Bedrock AgentCore Identity), scoped to your user. They are never written to logs, never sent to the browser, and never exposed to the language model.
  • Cordanis may read on your behalf while you are away, for example to prepare your daily plan before you sign in. Those runs use the same grant you gave when you connected, act only as you, and are logged as runs you can inspect.
  • You can revoke access at any time from your Google Account security settings or by disconnecting Google in Cordanis. Revocation takes effect on the next read.

Cordanis' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

04 Other connected sources

  • Salesforce. Read with your own Salesforce login and permissions; writes to Salesforce happen only after you approve a specific change in Cordanis.
  • Apollo.Connected at the organization level by an administrator; used to find and enrich contacts and accounts. Actions that spend your organization's Apollo credits require an approval.
  • Web search. Public web results used for account research. No personal data from your workspace is sent as a query without your instruction.

Each connected source uses least-privilege scopes and can be disconnected in Cordanis or revoked at the provider at any time.

05 How AI processing works

  • The Cordanis Assistant runs on foundation models through Amazon Bedrock, inside our AWS environment. Amazon Bedrock does not use your content to train models, and Cordanis does not train models on your data.
  • The Assistant's general toolbelt is read-only. Sending email, changing CRM records, enrolling contacts in outreach, and other actions with outside effects are separate server operations that run only after a person confirms them.
  • Every tool call the Assistant makes produces a run event you can inspect: which tool, which target, and the result.

06 Storage, security, and subprocessors

  • Customer data is stored in private, tenant-scoped storage on Amazon Web Services in the United States, encrypted in transit and at rest.
  • Access to production systems is limited to Cordanis engineers who need it to operate the service, under individual credentials and audit logging.
  • Subprocessors: Amazon Web Services (hosting, storage, model inference, authentication, credential vault). The providers you connect (Google, Salesforce, Apollo) process your data under their own terms when Cordanis calls them on your behalf.
  • For the full description of our security controls, see Trust & controls.

07 Retention and deletion

  • Workspace data is kept for as long as your organization's account is active. When an organization closes its account, its data is deleted within 30 days, except where law requires a longer hold.
  • Data read from connected sources is kept only as long as it is useful to the feature that read it: message metadata and derived signals for the daily plan, meeting details for briefs. Full message bodies are not copied into long-term storage.
  • Disconnecting a source stops all further reads immediately. Revoking at the provider does the same. On request, Cordanis deletes data previously read from that source.
  • Operational logs are retained for 90 days.

08 Your choices

  • Disconnect any source from Settings in Cordanis.
  • Revoke Google access from your Google Account at myaccount.google.com/permissions.
  • Ask us to export or delete your personal data, or your organization's data, at the address below. We answer within 30 days.

09 Changes to this policy

When this policy changes, the effective date at the top changes with it and the previous version is available on request. Material changes to how connected source data is used are announced to organization administrators before they take effect.

10 Contact

Questions, requests, and complaints about privacy: support@cordanis.com.