C
Docs

Privacy Settings

Data retention, privacy settings, and data sharing preferences

Updated 2026-04-1321 min read

Privacy Settings

Control how Cothon collects, stores, and uses your data. Configure data retention policies, manage privacy preferences, and control what information you share.

Privacy Overview

Cothon is committed to protecting your privacy and giving you control over your data. These settings let you manage:

  • What data Cothon collects about your usage
  • How long data is retained
  • Who can see your activity and information
  • What data is shared with third parties
  • Your rights under privacy regulations

Note

Cothon is compliant with Canadian privacy laws (PIPEDA), GDPR, and other international privacy regulations.

Data Collection Settings

Usage Analytics

Control what usage data Cothon collects to improve the product.

Analytics Categories

CategoryWhat's CollectedUsed ForDefault
Product AnalyticsPage views, feature usage, clicksImprove featuresOn
PerformanceLoad times, errors, latencyOptimize speedOn
User BehaviorWorkflows, task completionBetter UXOn
Search AnalyticsSearch terms, filters usedImprove searchOn

What We Do NOT Collect

Cothon never collects:

  • Document content: Your RFPs, proposals, and analyses
  • Proprietary data: Company secrets, capabilities, pricing
  • Personal communications: Messages, comments, emails
  • Authentication credentials: Passwords, API keys
  • Financial details: Payment card numbers, banking info

How Analytics Data is Used

Analytics help us:

  1. Identify issues: Detect bugs and performance problems
  2. Improve features: Understand which features are valuable
  3. Optimize UX: Make the interface more intuitive
  4. Prioritize development: Build features users actually need
  5. Measure success: Track if improvements work

All analytics data is:

  • Anonymized: Not tied to your identity
  • Aggregated: Combined with other users' data
  • Encrypted: Protected in transit and at rest
  • Private: Never sold to third parties

Tip

We recommend leaving analytics enabled. It helps us improve Cothon for everyone while protecting your privacy.

Error Reporting

Configure automatic error and crash reporting.

Error Report Contents

When an error occurs, reports may include:

  • Error message: What went wrong
  • Stack trace: Technical debugging info
  • Browser info: Browser version, OS
  • User context: What you were doing (anonymized)
  • Session ID: For correlating related errors

Error reports do NOT include:

  • Document content or user data
  • Personal information
  • Proprietary business information

Error Reporting Options

OptionDescriptionRecommended For
AutomaticSend all errors automaticallyMost users
Ask FirstPrompt before sendingPrivacy-conscious users
ManualOnly send if you click "Report"Maximum privacy
DisabledNever send error reportsRestricted environments

Set in Settings > Privacy > Error Reporting.

Note

Error reports are critical for fixing bugs. We recommend "Automatic" for the best experience.

Diagnostic Data

Detailed diagnostic data for troubleshooting.

What's Included

  • System information (OS, browser, memory)
  • Cothon version and configuration
  • Performance metrics
  • Network connectivity data
  • Recent actions (anonymized)

When It's Collected

Diagnostic data is only collected:

  • When you explicitly request support
  • When you click "Send Diagnostics"
  • When a critical error occurs (if enabled)

Enable automatic diagnostic collection in Settings > Privacy > Diagnostics > Auto-collect.

Control whether your documents are sent to external AI providers (OpenAI, Google Gemini) for analysis. This is a PIPEDA individual consent control that applies regardless of your organization's AI settings.

User-Level Default

Navigate to Settings > Privacy > AI Processing Consent.

SettingDescription
AI Processing Enabled (default)Uploaded documents may be sent to AI providers for automated requirement extraction, compliance analysis, and proposal generation.
AI Processing DisabledYour documents are stored but NOT sent to any external AI provider. You can still view documents and add requirements manually.

When AI Processing is disabled at the user level, all new document uploads will default to skipping AI processing. You can override this on a per-upload basis.

Per-Upload Override

When uploading a document for bid analysis, you can toggle "Skip AI Processing" to prevent that specific document from being sent to AI providers, even if your default setting is enabled.

This creates a stub analysis record where you can manually add requirements, but no document text is transmitted to OpenAI or Google Gemini.

Note

Organization vs. Individual consent: Your organization administrator may enable or disable AI features for the entire team. However, PIPEDA requires individual consent — even if AI is enabled at the organization level, you always retain the right to opt out for your own uploads. When you opt out, an ai_processing.opted_out event is recorded in the audit log for compliance tracking.

Data Retention Settings

Control how long Cothon retains different types of data.

Content Retention

Content TypeDefault RetentionAdjustable RangeNotes
Active AnalysesIndefiniteN/AUntil you delete
Active ProposalsIndefiniteN/AUntil you delete
Draft Documents90 days30-365 daysAuto-deleted if inactive
Deleted Items30 days0-90 daysRecoverable from trash
Archived ProjectsIndefiniteN/AUntil you delete

Warning

Content deleted after retention period expires is permanent and cannot be recovered.

Activity Data Retention

Control how long activity logs and history are kept.

Activity TypeDefaultRangePurpose
Activity Feed90 days30-365 daysRecent activity
Search History30 days7-90 daysSearch suggestions
View History90 days30-180 daysRecently viewed
Edit HistoryIndefinite90 days-indefiniteDocument versions
CollaborationIndefinite90 days-indefiniteComments, changes

Immediate Deletion Options

Delete activity data immediately:

  1. Clear Search History: Remove all saved searches
  2. Clear View History: Remove recently viewed items
  3. Clear Activity Feed: Remove activity log
  4. Clear All: Wipe all activity data

Access in Settings > Privacy > Data Retention > Clear Now.

Deleted Items

Configure trash/recycle bin behavior.

Trash Retention Period

SettingBehaviorUse Case
ImmediatePermanent deletion, no trashMaximum privacy
7 daysShort recovery windowQuick cleanup
30 days (default)Balanced recovery timeMost users
90 daysExtended recoverySafety-conscious

Auto-Empty Trash

  • Enabled: Automatically empty trash after retention period
  • Disabled: Items stay in trash until manually deleted
  • Schedule: Choose when auto-empty runs (daily, weekly)

Tip

Use 30-day retention with auto-empty enabled. This gives you time to recover accidentally deleted items without manual cleanup.

Audit Logs

For compliance and security, configure audit log retention.

Log TypeDefaultRequired ForAdjustable
Security Events1 yearComplianceNo
Access Logs90 daysAuditing90-365 days
Change Logs1 yearVersion control90 days-indefinite
Admin Actions2 yearsGovernance1-7 years

Note

Some audit logs have minimum retention periods for compliance. These cannot be reduced below the required duration.

Visibility & Sharing Settings

Control who can see your information and activity.

Profile Visibility

Configure what other users see about you.

Visibility Options

SettingWho Can SeeWhat They See
PublicEveryone in orgFull profile
TeamTeam members onlyFull profile
LimitedEveryone in orgName and photo only
PrivateOnly adminsName only

Set in Settings > Privacy > Profile Visibility.

Profile Components

Toggle visibility for each component:

  • Profile photo: Show or use generic avatar
  • Job title: Display or hide
  • Department: Show or hide
  • Phone number: Display or hide
  • Bio: Show or hide
  • Location: Display or hide

Activity Visibility

Control who sees your activity in activity feeds.

Activity TypeVisibility OptionsDefault
Content CreationPublic, Team, PrivateTeam
CommentsPublic, Team, PrivatePublic
EditsPublic, Team, PrivateTeam
SharesPublic, Team, PrivateTeam
ReactionsPublic, Team, PrivatePublic

Public: Everyone in organization Team: Only your team members Private: Only you (and content owner)

Presence & Status

Control online presence visibility.

Presence Indicators

SettingEffectWho Sees
OnlineGreen dot, "Active now"Everyone
AwayYellow dot, "Away"Everyone
Do Not DisturbRed dot, "DND"Everyone
InvisibleAppear offlineNo one

Status Settings

Configure automatic status:

  • Auto-away: Mark as away after N minutes of inactivity
  • Auto-offline: Mark as offline after N minutes
  • Show last seen: Display "Last active X ago"
  • Hide typing: Don't show "typing..." indicator

Tip

Use "Do Not Disturb" when working on urgent bids. Team members will see you're online but focused, reducing interruptions.

Work Hours

Set your working hours to manage expectations.

Team members see:

  • "Available" during work hours
  • "Outside work hours" when you're off
  • Your next availability time

Data Sharing & Third Parties

Control what data is shared with external services.

Integration Data Sharing

When you connect integrations (Slack, Teams, etc.), control what data they can access.

Integration Permissions

IntegrationData SharedCan Be Limited
SlackNotifications, summariesYes
TeamsNotifications, summariesYes
Google WorkspaceCalendar, emailYes
Microsoft 365Calendar, emailYes
Analytics ToolsUsage dataYes

Review and adjust permissions:

  1. Go to Settings > Privacy > Integrations
  2. Select an integration
  3. Review requested permissions
  4. Toggle off any you don't want to grant
  5. Save changes

Warning

Limiting permissions may reduce integration functionality. For example, disabling calendar access means Cothon can't check your availability.

AI Model Providers

Cothon uses AI models from Google (Gemini) and OpenAI (GPT).

Data Sent to AI Providers

When using AI features, we send:

  • Document text (for analysis)
  • User prompts and questions
  • Context from your capabilities

We do NOT send:

  • Your personal information
  • Other users' data
  • Unrelated documents
  • Authentication credentials

AI Data Retention

ProviderRetentionUsed For TrainingOpt-Out
Google0 daysNoN/A
OpenAI30 daysNo (opted out)N/A

Note

Cothon has opted out of AI training for both Google and OpenAI. Your data is never used to train their models.

AI Privacy Settings

Configure AI-specific privacy:

  • Disable AI features: Opt out of AI entirely
  • Use only Google: Avoid OpenAI
  • Use only OpenAI: Avoid Google
  • Local processing: Use on-device AI when available (beta)

Set in Settings > Privacy > AI Privacy.

Analytics & Tracking

Control third-party analytics and tracking.

What We Use

  • Sentry: Error tracking and performance monitoring
  • PostHog: Product analytics and feature usage
  • Stripe: Payment processing (if subscribed)

Opt-Out Options

ServiceCan Opt OutImpact
Product AnalyticsYesWe can't improve features
Error TrackingYesHarder to fix bugs
Performance MonitoringYesSlower support
Payment AnalyticsNoRequired for billing

Opt out in Settings > Privacy > Third-Party Services.

Marketing Communications

Control marketing emails and communications.

CommunicationDescriptionFrequencyOpt-Out
Product UpdatesNew features, improvementsMonthlyYes
Best PracticesTips and guidesBi-weeklyYes
WebinarsTraining eventsMonthlyYes
NewslettersIndustry newsWeeklyYes
SurveysFeedback requestsQuarterlyYes
TransactionalAccount, billing, securityAs neededNo

Note

Transactional emails (password resets, security alerts, billing notices) cannot be opted out as they're essential for account management.

Privacy Rights & Requests

Exercise your privacy rights under GDPR, PIPEDA, and other regulations.

Your Privacy Rights

Under privacy laws, you have the right to:

  1. Access: Request a copy of your data
  2. Rectification: Correct inaccurate data
  3. Erasure: Delete your data ("right to be forgotten")
  4. Portability: Export your data in machine-readable format
  5. Restriction: Limit how your data is processed
  6. Objection: Object to certain processing activities
  7. Withdraw Consent: Revoke previously given consent

Data Access Request

Request a copy of all data Cothon holds about you.

Note

Data access requests are fulfilled within 30 days as required by GDPR. Most requests are completed within 7 days.

Data Correction Request

Correct inaccurate or incomplete personal data.

For most data, you can self-correct in Settings. For data you cannot edit:

  1. Go to Settings > Privacy > Privacy Rights > Request Correction
  2. Describe what data is incorrect
  3. Provide correct information
  4. Submit request

We'll review and update within 7 days.

Data Deletion Request

Request deletion of your personal data.

What Can Be Deleted

  • Your account and profile
  • Your analyses and proposals
  • Your activity history
  • Your preferences and settings

What Cannot Be Deleted

  • Legal records (required for compliance)
  • Financial records (required for accounting)
  • Audit logs (required for security)
  • Data in backups (deleted on next backup cycle)

Warning

Deletion is permanent after the grace period. Export your data before requesting deletion.

Data Portability Request

Export your data in machine-readable formats for transfer to another service.

Supported export formats:

  • JSON: Complete data with metadata
  • CSV: Tabular data for spreadsheets
  • XML: Structured data for integration
  • ZIP: Combined archive of all formats

Request in Settings > Privacy > Privacy Rights > Request Portability.

Objection to Processing

Object to specific processing activities:

  1. Go to Settings > Privacy > Privacy Rights > Object to Processing
  2. Select processing activities you object to:
    • Marketing communications
    • Usage analytics
    • AI processing
    • Third-party sharing
  3. Provide reason for objection
  4. Submit objection

We'll review and respond within 7 days.

Children's Privacy

Cothon is not intended for users under 16 years of age.

Age Verification

  • Users must be 16+ to create accounts
  • Age is verified during signup
  • Accounts created by users under 16 are terminated

COPPA Compliance

For US users under 13:

  • Cothon does not knowingly collect data from children under 13
  • If we learn of data from a child under 13, we delete it immediately
  • Parents can request deletion of child's data

Report underage accounts to privacy@cothon.ca.

Manage cookies and tracking technologies.

CategoryPurposeRequiredCan Opt Out
EssentialCore functionalityYesNo
FunctionalEnhanced featuresNoYes
AnalyticsUsage trackingNoYes
MarketingPersonalizationNoYes

Configure cookie preferences:

Do Not Track

Cothon respects Do Not Track (DNT) browser headers.

If DNT is enabled in your browser:

  • Analytics cookies disabled
  • Third-party tracking disabled
  • Behavioral tracking disabled
  • Essential cookies still used (required for functionality)

Enable DNT in your browser settings. Cothon will automatically detect and respect it.

Tip

Most modern browsers support DNT. Search "[Your Browser] enable do not track" for instructions.

Tracking Prevention

Use Cothon's built-in tracking prevention:

  • Block third-party trackers: Prevent external tracking
  • Block cross-site cookies: Limit cross-site tracking
  • Fingerprinting protection: Prevent browser fingerprinting
  • Referrer masking: Hide where you came from

Enable in Settings > Privacy > Tracking Prevention.

Data Security & Encryption

How Cothon protects your privacy through security.

Encryption

Data StateEncryptionStandard
In TransitTLS 1.3AES-256
At RestAES-256FIPS 140-2
BackupsAES-256FIPS 140-2
ExportsOptionalUser's choice

Data Location

Data TypeLocationRegionCompliance
PrimaryCanadaMulti-regionPIPEDA
BackupsCanadaMulti-regionPIPEDA
CDN CacheGlobalEdge locationsGDPR

Note

All primary data is stored in Canadian data centers. Content may be cached globally via CDN for performance, but only metadata, not sensitive content.

Data Access Controls

Who can access your data:

RoleAccessPurposeLogged
YouFullYour dataYes
Your TeamShared onlyCollaborationYes
SupportWith permissionTroubleshootingYes
AdminsOrganization dataAdministrationYes
EngineersAnonymizedDevelopmentYes

All data access is logged and auditable.

Privacy Compliance

Cothon's compliance with privacy regulations.

Regulations We Comply With

  • PIPEDA: Canada's privacy law
  • GDPR: European General Data Protection Regulation
  • CCPA: California Consumer Privacy Act
  • SOC 2 Type II: Security and privacy controls
  • ISO 27001: Information security management

Privacy Certifications

  • ✓ SOC 2 Type II certified
  • ✓ ISO 27001 certified
  • ✓ Privacy Shield (EU-US)
  • ✓ PIPEDA compliant
  • ✓ GDPR compliant

Data Processing Agreements

For enterprise customers:

  • Data Processing Agreement (DPA) available
  • Business Associate Agreement (BAA) for HIPAA (if applicable)
  • Custom privacy terms negotiable

Contact legal@cothon.ca for enterprise privacy agreements.

Privacy by Design

Cothon follows Privacy by Design principles:

  1. Proactive: Privacy built in, not bolted on
  2. Default: Privacy is the default setting
  3. Embedded: Privacy integrated into design
  4. Positive-sum: Not zero-sum (privacy AND functionality)
  5. End-to-end: Lifecycle protection
  6. Visible: Transparency in operations
  7. User-centric: Your privacy, your control

Incident Response

In case of a data breach:

Our Response

  1. Immediate: Contain the breach
  2. 24 hours: Assess impact
  3. 72 hours: Notify affected users
  4. 7 days: Notify regulators (if required)
  5. 30 days: Publish incident report

Your Actions

If we notify you of a breach:

  1. Review the incident report
  2. Change your password
  3. Review account activity
  4. Enable 2FA if not already enabled
  5. Monitor your account

Breach Notifications

You'll be notified if:

  • Your personal data was accessed
  • Risk of harm to you
  • Required by law

Notification methods:

  • Email to primary address
  • In-app alert
  • SMS (if phone number on file)

Privacy Resources

Learning More

  • Privacy Policy: Full legal document
  • Cookie Policy: Detailed cookie information
  • Data Processing Agreement: For enterprise
  • Privacy FAQs: Common questions
  • Privacy Blog: Updates and best practices

Access in Settings > Privacy > Resources.

Privacy Support

Contact our privacy team:

  • Email: privacy@cothon.ca
  • Phone: 1-800-COTHON (privacy extension)
  • Live Chat: Available during business hours
  • Privacy Portal: Submit requests online

Data Protection Officer

Reach our DPO:

Email: dpo@cothon.ca Address: Cothon Inc., Attn: Data Protection Officer, [Address]

Privacy Checklist

Recommended privacy settings for procurement professionals:

  • Review and adjust data collection settings
  • Set appropriate data retention periods
  • Configure profile visibility (recommend "Team")
  • Set activity visibility to "Team" or "Private"
  • Configure work hours to manage availability
  • Review integration permissions
  • Verify AI privacy settings
  • Opt out of marketing emails (if desired)
  • Enable Do Not Track (in browser)
  • Review cookie settings
  • Set up 2FA (in Security settings)
  • Review active sessions regularly

FAQ

Next Steps

Related Articles

Was this page helpful?

Privacy Settings | Cothon Docs | Cothon