kKNOWNFOR
DRAFT — for review by The Thirty Co before reliance; not yet legal advice.

Data Processing Agreement

Last drafted 10 July 2026. This is a processor-terms template that applies between an account owner (the controller, "you") and The Thirty Co, trading as Knownfor (the processor, "we"/"us"), covering the personal data of your own clients and prospects ("client customer" data) that we process on your behalf and on your instructions when you use the platform. It supplements our Terms of service.

1. Scope and roles

You are the controller for personal data you collect from your own clients, prospects, and leads through Knownfor — for example scorecard/quiz responses, client portal activity, and contact details held against a lead or deal. We process that data solely as your processor, strictly to provide the platform to you.

This DPA does not cover our own processing of account owner and user data (your own name, login, billing, and usage data), where we act as controller — that's covered by our Privacy policy.

2. Our instructions

We process client customer personal data only on your documented instructions — which are, principally, your use of the platform's features and settings (for example, which modules are switched on, your automation modes, your retention period, and your community benchmarking consent setting). We will tell you if we reasonably believe an instruction breaches data protection law.

3. Security measures

We maintain the following technical and organisational measures:

  • Encryption in transit — all traffic to and from the platform is served over HTTPS/TLS.
  • Encryption at rest — the underlying database (Neon/Postgres) encrypts data at rest.
  • Tenant isolation — every workspace ("account") is scoped by a tenant identifier enforced at the data-access layer, so one workspace cannot read or write another's data.
  • Access control — role-based permissions within a workspace (owner/admin/member), hashed passwords, and session-based authentication.
  • Audit logging — administrative and destructive actions are logged with actor, action, target, and before/after values.
  • Rate limiting and abuse protection on public-facing endpoints (e.g. scorecard submissions).

We keep these measures under review and improve them as the platform matures, but we make no claim to a specific external security certification unless and until we hold one.

4. Subprocessors

We use the following subprocessors in delivering Knownfor, each bound by its own data processing terms with us:

  • Vercel — application hosting
  • Neon — database (EU region where available)
  • Resend — email delivery
  • Stripe — payment processing
  • Anthropic — AI features (only where switched on for your workspace)
  • PostHog — product analytics (EU region)
  • Sentry — error monitoring

We'll give you reasonable notice before adding or replacing a subprocessor that will handle client customer data, and you may object on reasonable data-protection grounds.

5. Sub-processing by you

Community benchmarking is off by default. If you switch it on in account settings, anonymised process shapes and outcome rates from your automations (never content, names, or client customer data) may contribute to the shared playbook library available to other Knownfor accounts. You can switch this off at any time, which stops any further sharing immediately.

Personnel

Access to client customer data by our personnel is limited to what's needed to operate and support the platform, and personnel are bound by confidentiality obligations.

6. Breach notification

If we become aware of a personal data breach affecting your client customer data, we will notify you without undue delay, and in any event in time to allow you to meet your own regulatory notification obligations (for example, the UK GDPR's 72-hour requirement to the ICO), with the information available to us at the time and further detail as our investigation progresses.

7. Assistance

We will provide you with reasonable assistance to meet your own obligations under UK GDPR in respect of client customer data — including responding to data subject requests, data protection impact assessments, and consultations with the ICO — taking into account the nature of the processing and the information available to us.

8. Retention and deletion on termination

Client customer data is retained for the period set in your account's retention setting (365 days by default, adjustable in account settings). On termination or cancellation of your workspace, we retain data only for as long as that setting requires and then delete it, except where we are required by law to retain specific records for longer. You may request earlier deletion, subject to any legal retention requirement.

9. International transfers

Where a subprocessor operates or supports data outside the UK/EEA, we rely on appropriate safeguards (such as the UK International Data Transfer Addendum or equivalent standard contractual clauses) for any such transfer.

10. Audit

On reasonable written request, and no more than once per year unless required by a regulator or following a security incident, we will provide you with information reasonably necessary to demonstrate compliance with this DPA.

Contact

Questions about this DPA, or to request a countersigned copy for your own records, should go to ryan@thethirtyco.com.