LEGAL

Data Privacy Compliance - Your Rights Under Applicable Data Protection Law

Last updated: 4 June 2026KnowDesk, Lda · Amadora, Portugal
At a glance: KnowDesk Inc. is a US-incorporated Delaware company. We take privacy seriously and extend strong data rights to all users regardless of location. EU/EEA users are acknowledged under GDPR as a matter of good practice. You can request your data, correct it, or have it deleted at any time by emailing hello@knowdesk.io.

1. Our Role Under Applicable Privacy Law

1.1 Data Controller

KnowDesk Inc., a Delaware corporation, acts as a data controller for personal data collected from visitors to knowdesk.io and from registered account holders. As controller, we determine the purposes and means of processing your personal data. While KnowDesk Inc. is a US company and primarily governed by US privacy law, we acknowledge the rights of EU/EEA users under GDPR as a matter of good practice.

1.2 Data Processor

KnowDesk also acts as a data processor on behalf of our customers (companies using the KnowDesk platform). When end-users interact with a KnowDesk-powered widget on a customer's website, the customer is the data controller and KnowDesk processes that data according to their instructions.

2. Legal Bases for Processing

We process personal data only where we have a valid legal basis. For EU/EEA users, we reference the equivalent Article 6 GDPR bases below. For all users, our processing is grounded in the following lawful purposes:

LEGAL BASISWHEN WE USE ITEXAMPLES
Contract (Art. 6(1)(b) GDPR)Processing necessary to perform our contract with youAccount management, service delivery, billing
Legitimate Interest (Art. 6(1)(f) GDPR)Processing necessary for our legitimate business interestsSecurity monitoring, fraud prevention, product improvement
Consent (Art. 6(1)(a) GDPR)Where you have given clear, specific consentMarketing emails, optional analytics cookies
Legal Obligation (Art. 6(1)(c) GDPR)Where processing is required by applicable lawTax records, responding to lawful authorities

3. Your Privacy Rights

We extend the following rights to all users of our platform regardless of location. EU/EEA users may also exercise these as formal GDPR rights under Articles 15–22. To exercise any of these rights, contact us at hello@knowdesk.io. We will respond within 45 days as permitted under US law, with a possible 45-day extension where reasonably necessary.

RIGHTARTICLEWHAT IT MEANS
AccessArt. 15Receive a copy of all personal data we hold about you, and information about how we process it
RectificationArt. 16Have inaccurate or incomplete personal data corrected
ErasureArt. 17Have your personal data deleted ('right to be forgotten'), subject to legal retention obligations
RestrictionArt. 18Ask us to pause processing while a dispute is resolved
PortabilityArt. 20Receive your data in a structured, machine-readable format (JSON or CSV)
ObjectionArt. 21Object to processing based on legitimate interest, including for direct marketing
Withdraw ConsentArt. 7(3)Withdraw any previously given consent at any time, without affecting past processing
Automated DecisionsArt. 22Not be subject to solely automated decisions that significantly affect you

4. How to Submit a Data Request

To submit any privacy or data request:

  • Email: hello@knowdesk.io with the subject line 'Privacy Request — [Your Name]'
  • Call / Message: +1 (307) 316-8676
  • Post: KnowDesk Inc. · 1908 Thomes Avenue, Cheyenne, WY 82001, United States

We may ask you to verify your identity before processing sensitive requests such as data deletion or export. We will not charge a fee for requests unless they are manifestly unfounded or excessive.

5. Data Retention Periods

DATA TYPERETENTION PERIODREASON
Account & profile dataDuration of account + 30 days after deletionService delivery
Conversation logs12 months from creationAnalytics and dispute resolution
Knowledge source contentDeleted immediately on source removalUser control
Billing and invoice records7 yearsUS federal and state tax law requirements
Technical and security logs90 daysSecurity monitoring
Cookie consent records3 yearsGDPR accountability

6. Sub-Processors and International Transfers

KnowDesk Inc. is a US-based company. Data is primarily stored and processed in the United States. We use the following sub-processors, each subject to a Data Processing Agreement (DPA) and appropriate data protection standards:

SUB-PROCESSORCOUNTRYTRANSFER MECHANISMPURPOSE
SupabaseGermany (EU - Central)Data stored in EUDatabase, auth, storage
StripeUSAStandard Contractual Clauses (for EU users)Payment processing
CloudflareGlobalStandard Contractual Clauses (for EU users)CDN, security, edge computing
Cloud ServerGlobalStandard Contractual Clauses (for EU users)Application hosting

For EU/EEA users, where data is transferred outside the EU, we rely on the Standard Contractual Clauses approved by the European Commission in Decision 2021/914 where applicable.

7. Data Breach Notification

In the event of a personal data breach, we will assess the breach promptly and notify affected users directly without undue delay where the breach is likely to result in a high risk to their rights and freedoms. For EU/EEA users, we will use reasonable efforts to notify the relevant supervisory authority within 72 hours of becoming aware of the breach where required. We will also notify affected users directly where there is a high risk to their rights and freedoms.

8. Privacy Contact

As a US-incorporated company, KnowDesk Inc. is not required to appoint a formal Data Protection Officer under GDPR. However, we take privacy seriously and have a designated privacy contact for all data-related queries:

  • Email: hello@knowdesk.io
  • Post: KnowDesk Inc. · 1908 Thomes Avenue, Cheyenne, WY 82001, United States

9. Supervisory Authority

As a US-incorporated company, KnowDesk Inc. does not have a lead EU supervisory authority. However, if you are an EU/EEA resident and believe we have not handled your data appropriately, you have the right to lodge a complaint with the supervisory authority in your EU member state. You may also contact the US Federal Trade Commission (FTC) at ftc.gov regarding US privacy concerns.

10. Data Processing Agreement (DPA)

If you use KnowDesk to process personal data of your own customers or employees (for example, through conversation logs), you may need a Data Processing Agreement with us under Article 28 GDPR. To request a DPA, contact hello@knowdesk.io. We will provide a standard DPA within 5 business days.

© 2026 KnowDesk. All rights reserved.
Privacy PolicyTerms of ServiceCookie PolicyGDPR