Privacy policy
Last drafted 10 July 2026. This explains what personal data Knownfor collects, why, and what happens to it — both for the people who run a workspace on Knownfor (account owners and their team) and for the people they in turn do business with (client customers).
Who this policy covers, and in what role
Knownfor is a business platform provided by The Thirty Co. Depending on whose data it is, we act in one of two different roles under UK GDPR:
- As controller— for an account owner's own business data: their name, email, login details, business profile, billing details, and how they use the platform. We decide why and how this data is processed, and this policy is our controller notice to you.
- As processor— for the personal data of an account owner's own clients and prospects ("client customers" in our terminology) — for example a name and email address submitted through a scorecard quiz, or held in a client portal. Here the account owner is the controller and decides why that data is collected; Knownfor only processes it on their documented instructions, under the terms set out in our Data Processing Agreement (DPA). If you are a client customer with a question about your own data, please contact the business you dealt with directly — they are the controller and the right first point of contact.
What we collect
Account owners and users
- Name, email address, and a hashed password (we never store passwords in plain text).
- Business name, vertical/industry, and workspace settings.
- Billing details, handled by our payment processor (Stripe) — we do not store card numbers ourselves.
- Usage data: pages visited, features used, and product analytics events.
- Support correspondence you send us.
Client customers (processed on the account owner's behalf)
- Answers submitted to a public scorecard/quiz, plus the name and email address given to receive a result.
- Contact and deal details an account owner adds about a lead or client.
- Activity on a client portal the account owner has shared with them, including an access code where the account owner has switched that on.
Lawful bases we rely on
- Performance of a contract — creating and running a workspace, processing payments, and delivering the core features an account has signed up for.
- Legitimate interests — keeping the platform secure, preventing abuse (e.g. rate limiting and bot protection on public forms), and improving the product from aggregate usage data.
- Consent — marketing emails to a client customer (opted in on the scorecard results screen, and revocable at any time via the unsubscribe link in every email); and community benchmarking, an account-owner-level, off-by-default setting that shares anonymised process shapes and outcome rates (never content, names, or client customer data) to improve the shared playbook library. Nothing is shared unless the account owner explicitly switches it on, and switching it off stops any further sharing immediately.
- Legal obligation — where we must keep or disclose records to comply with the law (for example tax and accounting records).
How long we keep data
Each workspace has a retention period (365 days by default) set in its account settings, which the account owner can adjust. Data belonging to a cancelled or deleted workspace is retained only for as long as that setting requires and then deleted, except where we must keep specific records for longer to meet a legal obligation (for example financial records for tax purposes).
Subprocessors
We use a small number of specialist providers to run Knownfor. Each is bound by a data processing agreement, and we only use processors who can meet UK GDPR requirements.
- Vercel — application hosting and infrastructure.
- Neon — managed Postgres database (EU region where available).
- Resend — transactional and marketing email delivery.
- Stripe — subscription billing and payment processing.
- Anthropic — AI features (e.g. turning a described process into a structured procedure), only where an account has AI switched on.
- PostHog — product analytics (EU region).
- Sentry — error monitoring and diagnostics.
We do not sell personal data, and we do not share client customer data with third parties for their own marketing purposes.
Your rights (UK GDPR)
Depending on your relationship to us, you have the right to:
- Ask what personal data we (or, if you are a client customer, the relevant account owner) hold about you.
- Ask for inaccurate data to be corrected.
- Ask for your data to be deleted, subject to any legal retention requirement.
- Ask us to restrict or object to certain processing.
- Ask for a portable copy of your data.
- Withdraw consent at any time, where processing relies on consent (e.g. marketing emails, community benchmarking).
- Complain to the UK Information Commissioner's Office (ico.org.uk) if you believe your data has been mishandled.
International transfers
Where a subprocessor operates or supports data outside the UK/EEA, we use providers who offer UK/EU regional hosting where it matters for this data (noted above), and rely on appropriate safeguards (such as the UK International Data Transfer Addendum or equivalent standard contractual clauses) for any transfer outside the UK.
Contact
Questions about this policy, or requests relating to your data, should go to ryan@thethirtyco.com.