Knowlode

Legal · Last updated 6 October 2026

Data processing agreement (template)

A summary of the template we sign with every seller. The signed version governs. Download the PDF

§1

Parties and roles

The seller is the controller. Knowlode acts as processor for the processing of raw exports (GDPR Art. 28).

§2

Subject matter and duration

Anonymisation of the export described in the order form, from receipt until the raw data is deleted.

§3

Instructions

  • Knowlode processes raw data only on the seller’s documented instructions.
  • Processing is limited to redaction, entity replacement, re-identification testing, quality review and packaging.

§4

Data and data subjects

Employees, contractors, customers and suppliers of the seller who appear in the export. Special-category data is excluded by scope, and any that remains is deleted when detected.

§5

Location

Raw data is stored and processed in the EU only.

§6

Security measures

  • Encryption in transit and at rest.
  • Least-privilege access, logged and reviewed.
  • Confidentiality obligations for everyone with access.
  • Separation of each seller’s raw data.

§7

Sub-processors

Listed on the trust page. Sellers are notified 30 days before any change and may object.

§8

Assistance and breaches

Knowlode helps the seller answer data-subject requests and prepare DPIAs. Personal data breaches are reported without undue delay, and within 48 hours of discovery.

§9

Deletion

Raw data is deleted after the anonymised dataset passes review, and no later than 30 days after receipt. Deletion is confirmed in writing.

§10

Audit rights

Knowlode provides the information needed to show compliance, and allows audits on reasonable notice.

§11

Relation to the licence

Only the anonymised output is licensed to Knowlode, under the separate licence agreement.