Legal

Privacy policy

Privacy is at the heart of everything we do at Knowen. For any questions, simply email hello+privacy@knowen.ai.

What data does the application read and why?

You maintain full control over the data the app can access. In all instances, the app acts as an observer of the enterprise knowledge vaults and data communication sources you explicitly grant access to, ensuring privacy and control over your corporate data ecosystem.

How is the data stored?

The corporate communication and system data you provide access to is securely processed and stored in a secured vector database in the form of mathematical representations known as embeddings. These embeddings are crucial for the platform to provide context-aware text generation and intelligent search. When an enterprise request is handled, the platform uses these private embeddings to extract relevant context and shares no specific user data snippets with external parties to generate the secure response.

Is this GDPR compliant?

Yes. We strictly adhere to GDPR guidelines, collecting and processing enterprise and personal data only when necessary to perform our services, and never transferring or selling user data to third parties.

How can I request access, transfer, or deletion of my data?

You can request full access, transfer, or deletion of your associated enterprise data with Knowen by emailing us at hello+privacy@knowen.ai. We will permanently purge all associated data structures within 30 days of receiving a verified request.

How long is the data retained?

Data is securely retained throughout your subscription period and for an additional 30 days following subscription termination. After this transitional window, all historical data structures and embeddings are permanently and securely deleted from our hosting environments.

What security measures have been implemented?

Security is our top corporate priority. We have implemented technical and organizational best practices to ensure strict data protection:

1

Secure Data Storage: We use a hardened, multi-tenant vector database architecture, ensuring that client data vaults are completely isolated from one another.

2

Encryption and Network Security: We employ Transport Layer Security (TLS) to encrypt all traffic in transit, backed by rigorous network security configurations and enterprise firewalls.

3

Access Controls and Data Handling: Strict access control is enforced via robust Identity and Access Management (IAM) mechanisms. Multi-Factor Authentication (MFA/2FA) is mandatory on all sensitive tools, and client API credentials, secrets, or bot tokens are carefully compartmentalized.

4

Least Privilege Principle: We request only the minimum required application scopes. For example, workspace messaging access is restricted to corporate communication channels (such as Slack channels) to which the platform bot is explicitly added.

5

Role-Based Access Control (RBAC): System configuration defaults exclusively to the installing administrative account, with granular RBAC mechanisms available to delegate specific source management access to authorized team members.

6

Security Audits and Penetration Testing: We conduct recurring internal and external security audits and structural penetration testing to mitigate vulnerabilities. Detailed penetration report summaries are available to enterprise customers upon request.

What subprocessors do you use?

1

Scaleway: Our standard cloud infrastructure provider, based in France, offering energy-efficient, local green hosting architecture to minimize ecological impact. Complete enterprise self-hosting configurations are also available.

2

Sentry (Optional): European-hosted instances may be deployed for performance evaluation and application error monitoring. Sentry is headquartered in the United States, and users will be explicitly informed prior to activation.

3

Let's Encrypt (Optional): A non-profit entity based in the United States used to manage automated cryptographic HTTP traffic encryption across platform subdomains.

Questions about this document?

Email hello+privacy@knowen.ai and a person from our team will reply.