Last updated: 15 June 2026
How kn0w collects, uses, stores, and protects personal data. KN0W PTE. LTD. is the data controller. This Policy covers the website, our business contacts, and the engagement data we process for member companies during a kn0w Audit.
kn0w issues independent, peer-benchmarked Statements on AI accountability and maturity for FinTech and HealthTech companies.
Two entities operate kn0w:
KN0W PTE. LTD. (UEN 202615303G), incorporated in Singapore, registered office 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914, is the data controller for all personal data described in this Policy and the sole contracting party for every kn0w engagement.
kn0w LLC (Wyoming, USA, Registration ID 2026-001947286) is a technical sub-processor. It operates kn0w’s cloud infrastructure under the instruction of KN0W PTE. LTD. and under a written Sub-Processor Agreement. It makes no independent decisions about your data.
When this Policy says “kn0w”, “we”, “us”, or “our”, it means KN0W PTE. LTD. as controller.
This Policy covers two categories of personal data:
Website and business data. Personal data we collect when you visit kn0w.co, contact us, subscribe to updates, complete one of our free online self-assessment tools, or deal with us as a prospective or current client contact.
Engagement data. Personal data we collect from a member company’s personnel during a kn0w Audit, Quarterly Review, or Annual Statement — including structured intake responses and recorded interview sessions.
Engagement data is governed in detail by the Data Contribution Agreement (“DCA”) signed by each member company before any engagement data is collected. The DCA governs the substance of how engagement data is processed for that member; this Policy provides the privacy-law notice layer. Member companies also receive plain-English collection notices at the point each category of data is collected.
This Policy does not cover the anonymised Benchmark Dataset, which contains no personal data (see Section 7).
From website visitors and business contacts:
From member company personnel during engagements:
We collect engagement data only after the member company has executed the DCA. This is enforced as a system constraint, not a manual step.
| Purpose | Data | Legal basis |
|---|---|---|
| Responding to enquiries and providing the website | Website and business data | Legitimate interests |
| Delivering the kn0w Audit, Quarterly Reviews, and Annual Statements | Engagement data | Performance of contract (the DCA); legitimate interests |
| Producing each member’s scores, findings, and issued artefacts | Engagement data | Performance of contract |
| Building the anonymised Benchmark Dataset | Engagement data, anonymised before use (Section 7) | Legitimate interests; consent captured in the DCA |
| Billing and membership administration | Account and billing data | Performance of contract; legal obligation |
| Marketing communications you have opted into | Contact details | Consent |
| Security, audit logging, and legal compliance | All categories | Legal obligation; legitimate interests |
kn0w uses AI systems to conduct interview sessions and generate scoring narratives and findings. Three commitments apply:
kn0w’s scores are produced by a deterministic scoring engine applying fixed weightings to the responses gathered during an engagement. The output is a reading of a member company’s AI accountability posture, expressed as a band and per-dimension scores.
This output does not, by itself, produce a legal or similarly significant effect on any individual. It is a finding about a member company’s posture, not a decision about a person. Every issued Statement and Annual Statement passes through a mandatory human approval step before release: no artefact is issued to a member on a purely automated basis. A member company may ask us about the basis of any finding through the contacts in Section 18.
This Section describes the verified Benchmark Dataset built from member engagement data. kn0w also maintains a separate, indicative benchmark pool built from the free self-assessment responses described in Section 3. That indicative pool is global rather than jurisdictional, is built only from anonymised, aggregated self-reported answers that carry no identity, applies the same minimum-cohort floor of five companies (k=5) before any comparison is shown, and never feeds the verified percentiles described below. The two are firewalled from each other.
kn0w maintains a benchmark dataset that lets each member see its position against peers. It is built as follows:
kn0w may license the anonymised, aggregated Benchmark Dataset to institutional partners. Because this data carries no member identity and is not personal data, this licensing does not involve the disclosure of your personal data.
In this Policy, “member-identifiable data” means engagement data that identifies, or can reasonably be linked to, a member company or an individual within it, before it passes through the anonymisation process described in Section 7.
Member-identifiable data is stored in regional databases and never leaves its home region except through the single anonymising pathway described in Section 7.
kn0w currently operates in Australia. As kn0w expands to additional markets, member-identifiable data for each new market will be stored in-region, and this Policy will be updated with the applicable region and any additional transfer safeguards before members in that market are onboarded.
kn0w currently operates in Australia. Australian member-identifiable data is stored and processed in Australia (AWS Sydney) and does not leave Australia except through the anonymisation process in Section 7. Only anonymised, non-personal aggregate data — which is not personal data — is written to the United States benchmark store.
Any disclosure of personal information to overseas recipients (including the United States, where kn0w LLC operates infrastructure, and Singapore, where KN0W PTE. LTD. acts as controller) is limited to the arrangements described in Sections 7, 8, 10, and 11, and is addressed under the Australian Privacy Principles in Annex A.
When kn0w onboards members in other jurisdictions, this section will be updated with the transfer mechanisms applicable to those jurisdictions before any such member data is collected.
kn0w LLC, as the operator of kn0w’s cloud infrastructure, is a US entity and may be subject to the US CLOUD Act. We disclose this rather than claim it does not apply. This exposure cannot be eliminated as a matter of law; it is managed.
Under the Sub-Processor Agreement, kn0w LLC is contractually required to: (a) notify KN0W PTE. LTD. upon receiving any legal demand for member data; (b) challenge or seek to narrow any such request where the law allows; and (c) not disclose member data without the direction of KN0W PTE. LTD. except where legally compelled.
Because member-identifiable data never leaves its home region (Sydney), any demand made to the US entity reaches only the anonymised Benchmark Dataset — data that carries no member identity.
We do not sell personal data. We share it only with:
| Provider | Function | Personal data involved |
|---|---|---|
| Amazon Web Services (AWS) — operated by kn0w LLC | Cloud infrastructure, including in-region AI processing via Amazon Bedrock and the voice pipeline (Amazon Transcribe and Amazon Polly) | Engagement data, including voice recordings and transcripts |
| Outseta | Membership, authentication, and billing | Website and business data; account data |
| Typeform | Structured intake forms | Engagement data; enquiry data |
| PandaDoc | Contracts and consent (DCA, proposals) | Business contact data |
| Webflow | Website and member portal front-end | Website and business data |
| Vanta | Compliance monitoring | Limited operational data |
The current, canonical list of service providers is published at kn0w.co/security and available on request.
| Data | Retention |
|---|---|
| Raw member-identifiable engagement data | Duration of standing + 12 months, then automatically deleted |
| Voice session audio | Deleted within 30 days of the session date |
| Anonymised aggregate benchmark data | Retained indefinitely (not personal data) |
| Issued Statements and Annual Statements (institutional record) | The issued artefact is retained permanently as an institutional record; member-identifiable detail in the underlying working data is redacted at standing + 12 months |
| Website enquiry and marketing data | 24 months from last contact, unless you ask us to delete it sooner |
| Server-level connection data (e.g. IP address in infrastructure logs) | Retained in our infrastructure provider’s logs only as long as needed to deliver and secure the site, then deleted |
| Billing records | As required by applicable tax and corporate law |
Deletion and redaction of engagement data are automated and logged.
Our security controls include: regional data isolation with hard boundaries, encryption at rest and in transit, least-privilege access controls, append-only audit logging of lifecycle events, automated deletion, and continuous infrastructure monitoring. The same controls run on every regional instance; they are part of the architecture, not configured per engagement.
kn0w is pursuing SOC 2 Type II and ISO 27001 certification through Vanta. Neither is yet certified, and we do not claim either until it is issued. Our current security posture is documented at kn0w.co/security.
If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and affected individuals where, and within the timeframes, required by the applicable law in your jurisdiction. Our internal logging and monitoring are designed to support prompt detection and assessment.
Our public website (kn0w.co) sets no cookies. It does not use analytics cookies, advertising cookies, or third-party tracking pixels. You can browse the public site without any cookie being placed on your device and without being tracked. Our website infrastructure provider delivers page content, fonts, and scripts without setting cookies, and may process server-level connection data (such as IP address) only as needed to deliver and secure the site.
Our member application (app.kn0w.co) is accessible only after you sign in. Because it is a secure, authenticated application, it uses a small number of strictly necessary cookies to operate. These are not used for advertising or cross-site tracking.
| Cookie type | Purpose | Set by |
|---|---|---|
| Session / authentication | Keeps you signed in during a session and links you to your member account | Our membership and authentication provider |
| Security (e.g. CSRF token) | Protects against cross-site request forgery and similar attacks | Our application |
If we ever introduce non-essential cookies, we will update this section and, where required, ask for your consent first.
You have rights over your personal data. What they are and how to exercise them depends on where you are. The annexes below set out jurisdiction-specific detail. In all cases you can contact us at privacy@kn0w.co and we will respond within the timeframe required by your jurisdiction’s law.
If you are personnel of a member company, note that some rights (for example, deletion of engagement data mid-engagement) interact with the member company’s DCA; we will coordinate with the member company where the law permits.
We handle personal information of Australian individuals in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). You may request access to, or correction of, your personal information by contacting us. We will respond within a reasonable period.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).
Australian member data is hosted in Australia (AWS Sydney). Consistent with APP 8, any disclosure of personal information to overseas recipients is limited to the arrangements described in Sections 7 to 11. Overseas recipients are located in: the United States (AWS infrastructure operated by kn0w LLC, holding anonymised, non-personal benchmark data only) and Singapore (KN0W PTE. LTD. as controller). Where service providers listed in Section 11 operate from other locations, those locations are identified on request.
KN0W PTE. LTD. complies with the Personal Data Protection Act 2012 (PDPA). You may request access to or correction of your personal data, or withdraw consent, by contacting us at privacy@kn0w.co. If you are not satisfied with our response, you may direct a complaint to the Personal Data Protection Commission (pdpc.gov.sg).
kn0w currently operates in Australia. If you are outside Australia, we apply the protections in this Policy as a baseline and honour rights of access, correction, and deletion to the extent provided by your local law. As kn0w expands into new markets — including the United Kingdom and EEA — jurisdiction-specific rights detail and transfer mechanisms will be added to this Policy before members in those markets are onboarded.
kn0w’s services are provided to companies and are not directed at children. We do not knowingly collect personal data from anyone under 18.
We may update this Policy. Material changes will be notified to member companies directly and reflected by the “Last updated” date above; where a material change affects website visitors or business contacts, we will also post notice on this page. Prior versions are available on request.