DPA Change History

‍

This page records changes to the Cognyx Data Protection Addendum, including changes to the sub-processor list at Annex 2.

Under the Addendum, Cognyx gives notice of the addition or replacement of a sub-processor by updating Annex 2. This changelog is how you can see that an update has happened, what it was, and on what date — so that the 30-day objection window runs from a date both parties can identify.

Entries dated 17 September 2026 and later are recorded at the time of the change.

Entries before that date are reconstructed. The Addendum was maintained without a change record until 17 September 2026, and some changes made before then cannot be dated precisely. Those are grouped below and marked as undated rather than given a date we cannot support. We would rather publish an incomplete record honestly than a complete one we invented.

‍

Data Protection Addendum v1.4

September 25, 2026
Version: 1.4
Current

Published with Data Protection Addendum v1.4. This is a correction of the list, not a change to who processes your data. No new processing arrangement was entered into.

Added

  • Mailgun — email delivery, Europe. Mailgun has provided email delivery for the Services throughout. Its omission from this list was an error, now corrected.

Removed

  • Sendgrid — listed in error. Cognyx does not use Sendgrid; email delivery is provided by Mailgun.

‍

Read this version

Data Protection Addendum v1.3

September 24, 2026
Version: 1.3
Superseded

Published with Data Protection Addendum v1.3. No sub-processor was added, removed or changed. Annex 2 is unchanged.

Sub-processor notice is now given in advance, by email

Previously, Cognyx gave notice of a new or replacement sub-processor by updating the list at Annex 2, and the objection window ran from that update. A published update is not the same as telling you, and the period ran after the change rather than before it.

From this version, Cognyx gives at least 10 days' notice by email, before the sub-processor begins processing your data, to the contact you nominate for the purpose. Annex 2 and this changelog are still updated, as the public record. Your right to object on reasonable data-protection grounds, and the remedy if an objection cannot be resolved, are unchanged. The objection window now runs from the notice you receive, and before the change takes effect, rather than after it.

Where a sub-processor has to be engaged or replaced urgently — to keep the Services secure, available or running, or because a supplier stops providing its service — Cognyx may act on shorter notice and will tell you as soon as practicable. Your right to object applies from that notice in the same way.

This also corrects an inconsistency inside the Addendum. Section 5.1(a) elects Option 2 of Clause 9 of the Standard Contractual Clauses, which requires prior notice of sub-processor changes, and pointed to a clause that did not provide for any.

Annex 1 completed

Three fields in Annex 1 were blank or referred back to the Agreement without stating anything: the purpose of the data transfer and further processing, the retention period, and the subject matter, nature and duration of sub-processor transfers. Annex 1 is deemed to complete Annex I of the Standard Contractual Clauses, so those gaps were gaps in the Clauses themselves. All three are now stated in full. This records what Cognyx already does; it is not a change to the processing.

The restriction on AI model training has moved, and been strengthened

The commitment that Customer Personal Data is never used to train, fine-tune or improve any AI or machine-learning model previously sat in the Restricted Transfers section. It is a limit on the purpose of processing, not a transfer provision, and it now sits with the other processing terms. It is also now expressed to prevail over any other provision allowing Cognyx to enhance or improve the Services, so there is no room to read one against the other.

Audit clause restructured

Your audit rights are unchanged in substance, and the sequence is the same as before: documentary evidence first, inspection only if that evidence leaves the question open. The clause now opens with Cognyx's ISO/IEC 27001:2022 certificate and SOC 2 Type II report, named as the evidence provided in the first instance alongside assessment responses, so it is clear what you receive without having to ask. Both are also now named in the preamble, as the primary evidence of the measures the Addendum describes.

Four conditions are now stated explicitly: an auditor you mandate may not be a competitor of Cognyx and must be bound by confidentiality; the scope, timing, duration and reimbursement rate of an inspection are agreed between us before it begins; inspections take place during normal business hours without unnecessary disruption; and you reimburse Cognyx for time and expenses. The annual limit continues not to apply where a supervisory authority instructs an audit, or following a personal data breach affecting your data. That last exception previously turned on whether you believed a further audit was necessary, and is now tied to an actual breach.

Data isolation described accurately

The Addendum described Cognyx as storing data in a multi-tenant environment, with logical isolation between customers. That understated how the Services are actually built. Each client has its own Kubernetes namespaces, its own Cloud SQL database instances and its own service accounts, running on shared Google Cloud infrastructure. The description now says so. Nothing about the architecture has changed; the description was behind it.

Opening paragraph corrected

The Addendum described itself as forming part of Terms of Service published at the legal notices page. That page is a statutory notices page, not terms of service. The Addendum now refers to the agreement between Cognyx and the Customer that incorporates it.

Correction to a date in this changelog

The Algolia entry was previously dated 16 September 2026. The correct date is 18 September 2026, the date it was published with Addendum v1.2. The entry above has been moved and redated. We record the correction here rather than changing the date silently, because the date is what an objection period would run from.

‍

Read this version

Data Protection Addendum v1.2

September 18, 2026
Version: 1.2
Superseded

Added

  • Algolia — Object search indexing — Europe

‍

Read this version

Data Protection Addendum v1.1

September 17, 2026
Version: 1.1
Superseded

Added

  • Clerk — authentication, USA. Clerk has provided authentication for the Services throughout. Its omission from this list was an error, now corrected.

Removed

  • Google Firebase — listed in error. Cognyx does not use Firebase; authentication is provided by Clerk.
  • Figma and Qualitee — neither processes customer personal data. Qualitee is no longer a Cognyx supplier.
  • RBB Advisors and Memo Bank — these provide accounting, payroll and banking services to Cognyx. They process Cognyx's own company and staff data, for which Cognyx is the controller, and never customer personal data. They are recorded in Cognyx's Record of Processing Activities instead of on this list.

Corrected

  • Microsoft Azure — description corrected. Azure provides AI services (Azure OpenAI, and Mistral via Azure AI Foundry). It does not host the Services.
  • Google Cloud Platform — recorded as the sole hosting provider for the Services.
  • Sentry — location corrected from USA to Europe. Error data is processed in Sentry's Frankfurt region.
  • PostHog — location corrected from USA to Europe.

The description of infrastructure, resiliency, firewall controls and data storage in Annex 1 was updated to match, so that the Addendum describes Google Cloud Platform as the hosting provider throughout.

‍

Read this version

Earlier History

Between 22 April 2026 and 17 September 2026 — undated changes

The following changes were made during this period. The exact dates are not recoverable from our records.

Sub-processors added to Annex 2

Governing law and jurisdiction of the Standard Contractual Clauses

Sub-processor notice mechanism introduced

A clause was added setting out that Cognyx gives notice of sub-processor additions by updating Annex 2, that a customer may object on reasonable data-protection grounds within 30 days of the update, and that where an objection is not resolved in good faith the customer's sole remedy is to terminate the affected portion of the Services. No equivalent clause appeared in the version published on 22 April 2026.

Restriction on AI model training added

An express commitment was added that Customer Personal Data will not be used to train, fine-tune or improve any AI or machine-learning model, whether operated by Cognyx or by any sub-processor.

Infrastructure description updated

Annex 1 was updated from describing Azure as the sole data centre to describing Azure and Google Cloud Platform.

Description of processing rewritten (Annex 1)

Certifications

Privacy contact

Clause numbering

The numbering of clauses was lost from the published page during this period. Cross-references in the text (for example "Section 4.2(d)") therefore no longer resolve to a visible clause number. This is a presentation defect, not a change of terms, and is being corrected.

22 June 2026 — version history removed

The version history section was removed from the published page. Reinstating a customer-facing record of changes is the purpose of this changelog.

18 February 2026 — privacy contact named

The Data Protection Officer was named on the page.

Before 18 February 2026

No change record exists for the period before this date.

‍