Privacy Policy

Last Updated: January 1, 2025

knXw ("we," "our," or "us") is committed to protecting your privacy and ensuring transparency in how we collect, use, and safeguard your data. This Privacy Policy explains our practices for the knXw psychographic analytics platform ("Service").

1. Data We Collect

Account Information

What we collect:

  • Email address (required for authentication)
  • Full name (optional, for personalization)
  • Company name (optional, for B2B features)
  • Billing information (processed securely via Stripe, never stored directly)

Lawful Basis: Contract performance (GDPR Art. 6(1)(b))

Behavioral & Psychographic Data

What we collect:

  • Event data: page views, clicks, scrolls, form interactions, time on page
  • Device information: user agent, screen resolution, viewport size
  • Session data: session ID, timestamp, referrer URL
  • Derived psychographic profiles: motivation, cognitive style, risk profile, emotional state (AI-generated)

Privacy-First Processing:

  • All user IDs are SHA-256 hashed before storage
  • No personally identifiable information (PII) is stored in raw form
  • IP addresses are anonymized (last octet removed)
  • Data minimization: only behavior necessary for analysis is captured

Lawful Basis: Legitimate interest (GDPR Art. 6(1)(f)) for platform functionality; Consent (GDPR Art. 6(1)(a)) for enhanced psychographic analysis

Technical & Usage Data

What we collect:

  • Log data: API requests, response times, error logs
  • Performance metrics: latency, throughput, system health
  • Usage analytics: feature adoption, dashboard views, integration usage

Lawful Basis: Legitimate interest for system security, performance optimization, and service improvement

2. How We Use Your Data

We use collected data for the following purposes:

Service Provision

  • Generate psychographic profiles for end-users of your applications
  • Provide real-time behavioral analytics and insights
  • Enable adaptive engagement and personalization features
  • Power AI-driven recommendations and content optimization

Platform Improvement

  • Train and refine AI models (only with aggregated, anonymized data)
  • Improve accuracy of psychographic inference
  • Optimize system performance and reliability
  • Develop new features based on usage patterns

Security & Compliance

  • Detect and prevent fraud, abuse, and policy violations
  • Maintain audit logs for compliance purposes
  • Respond to legal requests and regulatory obligations
  • Enforce our Terms of Service

Communication

  • Send essential service notifications (downtime, security alerts)
  • Provide customer support and respond to inquiries
  • Share product updates and feature announcements (opt-in)

Important: We NEVER sell your data to third parties. We NEVER use your data for advertising purposes unrelated to knXw services.

3. Data Sharing & Disclosure

We share data only in limited circumstances:

Service Providers (Processors)

We engage trusted third-party providers who process data on our behalf:

  • AWS: Cloud infrastructure & storage (DPA in place)
  • Stripe: Payment processing (PCI-DSS compliant)
  • OpenAI: LLM inference for psychographic analysis (no PII shared, prompts are anonymized)
  • Resend: Transactional email delivery

All processors are bound by Data Processing Agreements (DPAs) and cannot use your data for their own purposes.

Legal Obligations

We may disclose data when required by law:

  • In response to valid legal process (subpoenas, court orders)
  • To protect rights, property, or safety of knXw, users, or the public
  • To comply with regulatory requirements

Business Transfers

In the event of a merger, acquisition, or sale of assets, user data may be transferred to the acquiring entity. Users will be notified via email and given the option to delete their data before transfer.

With Your Consent

We will share data with third parties only when you explicitly consent (e.g., enabling CRM integrations like HubSpot).

4. Security Measures

Encryption
  • TLS 1.3 for data in transit
  • AES-256 encryption for data at rest
  • End-to-end encryption for sensitive API keys
Access Controls
  • Role-based access control (RBAC)
  • Multi-factor authentication (MFA) for admin accounts
  • Principle of least privilege
Monitoring & Auditing
  • Continuous security monitoring
  • Automated vulnerability scanning
  • Comprehensive audit logging
Compliance
  • GDPR compliant (EU representative available)
  • SOC 2 Type II in progress (Q2 2025)
  • Regular penetration testing

While we implement industry-standard security measures, no system is 100% secure. We encourage users to use strong passwords and enable MFA.

5. Your Rights Under GDPR

If you are an EU resident, you have the following rights:

✓ Right to Access (Art. 15)

Request a copy of all personal data we hold about you.

✓ Right to Rectification (Art. 16)

Correct inaccurate or incomplete data.

✓ Right to Erasure / "Right to be Forgotten" (Art. 17)

Request deletion of your data. We will comply within 30 days unless we have a legal obligation to retain it.

✓ Right to Restrict Processing (Art. 18)

Limit how we use your data while a complaint or correction request is being resolved.

✓ Right to Data Portability (Art. 20)

Receive your data in a structured, machine-readable format (JSON, CSV).

✓ Right to Object (Art. 21)

Object to processing based on legitimate interests or for direct marketing.

✓ Right to Withdraw Consent (Art. 7(3))

Withdraw consent for data processing at any time (does not affect the lawfulness of processing before withdrawal).

How to Exercise Your Rights

Email us at privacy@knxw.app with your request. We will respond within 30 days.

You also have the right to lodge a complaint with your local Data Protection Authority.

6. Data Retention

Data TypeRetention PeriodRationale
Account InformationDuration of account + 90 daysService provision, recovery period
Behavioral Event Data90 days (configurable up to 365 days)Real-time analytics, trend analysis
Psychographic ProfilesDuration of account + 30 daysService continuity, profile accuracy
Audit Logs7 yearsLegal/regulatory compliance
Billing Records7 yearsTax and accounting requirements

After the retention period, data is securely deleted (overwrite + cryptographic erasure). Anonymized, aggregated data used for research may be retained indefinitely.

7. Cookies & Tracking Technologies

We use cookies and similar technologies for:

Essential Cookies

Required for authentication, session management, and security. Cannot be disabled.

  • session_id - User session tracking
  • csrf_token - Security protection

Analytics Cookies

Used to understand platform usage and improve features. Requires consent.

  • knxw_analytics - Anonymous usage tracking

Preference Cookies

Remember your settings and preferences.

  • theme - UI theme preference
  • sidebar_collapsed - Layout preference

You can manage cookie preferences via your browser settings. Disabling essential cookies may impact functionality.

8. Contact Us

For privacy-related inquiries, data requests, or to exercise your rights:

Data Protection Officer (DPO)

Email: privacy@knxw.app

Mailing Address: knXw, Inc., 548 Market St, PMB 66133, San Francisco, CA 94104-5401

We aim to respond to all requests within 30 days. For urgent security or privacy concerns, please mark your email as "URGENT."

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

Material changes (e.g., changes in data sharing practices) will be communicated via:

  • Email notification to all users
  • Prominent notice on the knXw dashboard
  • 30-day notice period before changes take effect

Continued use of the Service after changes take effect constitutes acceptance of the updated policy. If you do not agree, you may delete your account before the effective date.

This Privacy Policy was last updated on January 1, 2025. Version 1.3. Previous versions available upon request.