Compliance ledger
How we protect the data entrusted to us.
This page lists what we do, the rules we rely on, and the status of each commitment. Where something is still in preparation, we say so.
§1
Processing location
- EUIn preparation
Raw data never leaves the EU
Raw exports will be stored and processed only on EU infrastructure. We are selecting the provider and will name it and its region here before the first export.
- WebsiteOur commitment
Enquiries stored in the EU
Enquiries from this website are stored in a database restricted to the EU jurisdiction and deleted after 24 months.
§2
Anonymisation pipeline
Every dataset passes the same steps. A dataset that fails a step is fixed or not licensed.
- 01Scope and exclusionsSystems, periods and exclusions agreed in writing.
- 02Staff noticeEmployees informed, with a 30-day opt-out window.
- 03Standard exportYour administrator runs the export.
- 04EU redactionPersonal data detected and removed on EU infrastructure.
- 05Entity replacementNames and identifiers replaced consistently, keeping relationships.
- 06Re-identification testTested from the view of a well-resourced recipient.
- 07Quality reviewSampling and scoring by a person.
- 08Licensed; raw data deletedOnly the tested dataset is licensed. The raw export is deleted.
§3
Legal basis
GDPR Art. 28Our commitmentWe act as your processor
Raw data is processed on your documented instructions under a data processing agreement.
GDPR Art. 6(1)(f)Our commitmentLegitimate interest, assessed in writing
Each engagement includes a legitimate-interest assessment and a compatibility assessment under
GDPR Art. 6(4).GDPR Art. 9Our commitmentSpecial-category data excluded at source and deleted if found
HR, health, private and direct-message channels and private email are excluded at source. Redaction removes what remains, and any special-category data still found is deleted.
GDPR Art. 13(3)Our commitmentStaff informed before export
Employees receive a notice and a 30-day opt-out window before any export.
GDPR Art. 35On requestData protection impact assessment
Our DPIA for the processing pipeline is available to sellers and their DPOs on request.
GDPR Recital 26Our commitmentAnonymisation standard
We assess identifiability from the point of view of a well-resourced recipient, and document residual risk for each dataset.
§4
AI Act provenance
AI Act Art. 53Our commitmentProvenance pack for buyers
Provenance pack to support your Art. 53 training-content summary. It does not replace the buyer’s own obligations.
§5
Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Website hosting, security and enquiry database | Enquiry database restricted to the EU; website served from a global network |
| EU processing provider (being selected) | Processing of raw exports | EU, named here before the first export |
§6
Certifications
- ISO/IEC 27001In preparation
Information security management
Preparation is under way. We will publish the certificate when it is awarded.
- SOC 2Planned
Service organisation controls
Planned after ISO/IEC 27001.
§7
Data protection contact
Contact our data protection team at dpo@knowlode.com.
You can also complain to the data protection authority in the EU country where you live or work.
§8
Documents to download
- Sample anonymisation report (PDF)A synthetic example of the report every dataset receives.
- Data processing agreement template (PDF)The template we sign with every seller.