Last updated: 15 June 2026

Privacy Policy.

How kn0w collects, uses, stores, and protects personal data. KN0W PTE. LTD. is the data controller. This Policy covers the website, our business contacts, and the engagement data we process for member companies during a kn0w Audit.

SECTION 01

Who we are

kn0w issues independent, peer-benchmarked Statements on AI accountability and maturity for FinTech and HealthTech companies.

Two entities operate kn0w:

KN0W PTE. LTD. (UEN 202615303G), incorporated in Singapore, registered office 160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914, is the data controller for all personal data described in this Policy and the sole contracting party for every kn0w engagement.

kn0w LLC (Wyoming, USA, Registration ID 2026-001947286) is a technical sub-processor. It operates kn0w’s cloud infrastructure under the instruction of KN0W PTE. LTD. and under a written Sub-Processor Agreement. It makes no independent decisions about your data.

When this Policy says “kn0w”, “we”, “us”, or “our”, it means KN0W PTE. LTD. as controller.

SECTION 02

What this Policy covers

This Policy covers two categories of personal data:

Website and business data. Personal data we collect when you visit kn0w.co, contact us, subscribe to updates, complete one of our free online self-assessment tools, or deal with us as a prospective or current client contact.

Engagement data. Personal data we collect from a member company’s personnel during a kn0w Audit, Quarterly Review, or Annual Statement — including structured intake responses and recorded interview sessions.

Engagement data is governed in detail by the Data Contribution Agreement (“DCA”) signed by each member company before any engagement data is collected. The DCA governs the substance of how engagement data is processed for that member; this Policy provides the privacy-law notice layer. Member companies also receive plain-English collection notices at the point each category of data is collected.

This Policy does not cover the anonymised Benchmark Dataset, which contains no personal data (see Section 7).

SECTION 03

Personal data we collect

From website visitors and business contacts:

  • Contact details you provide (name, work email, company, role) when you enquire, book a call, or subscribe.
  • Free self-assessment responses. If you complete one of our free, self-completed online self-assessment tools, we collect the work email you provide and the self-reported answers you give about your company (such as sector, country, approximate staff size, and your own assessment of your company’s AI practices). We use these to generate and email your results, to contact you about those results and kn0w’s services where you have agreed, and — in anonymised, aggregated form that carries no identity — to build indicative peer benchmarks. These responses are held in our customer-relationship and marketing systems and are kept separate from the audited member platform. Self-assessment results are indicative and self-reported; they are not a kn0w Statement.
  • Account and billing data if your company becomes a member, managed via our membership and billing provider.
  • Limited technical data. Our public website sets no cookies and runs no third-party analytics (see Section 15). Where our infrastructure provider processes server-level connection data (such as IP address) to deliver and secure the site, that processing is described in Section 15.

From member company personnel during engagements:

  • Intake responses submitted via structured forms (name, role, function, and responses about your company’s AI practices).
  • Voice session recordings and transcripts from structured interviews (a CEO pre-session and function-head sessions).

We collect engagement data only after the member company has executed the DCA. This is enforced as a system constraint, not a manual step.

SECTION 04

How we use personal data, and our legal bases

PurposeDataLegal basis
Responding to enquiries and providing the websiteWebsite and business dataLegitimate interests
Delivering the kn0w Audit, Quarterly Reviews, and Annual StatementsEngagement dataPerformance of contract (the DCA); legitimate interests
Producing each member’s scores, findings, and issued artefactsEngagement dataPerformance of contract
Building the anonymised Benchmark DatasetEngagement data, anonymised before use (Section 7)Legitimate interests; consent captured in the DCA
Billing and membership administrationAccount and billing dataPerformance of contract; legal obligation
Marketing communications you have opted intoContact detailsConsent
Security, audit logging, and legal complianceAll categoriesLegal obligation; legitimate interests
SECTION 05

AI processing

kn0w uses AI systems to conduct interview sessions and generate scoring narratives and findings. Three commitments apply:

  • Member data is never used to train AI models. Engagement data is processed by AI models solely to deliver the engagement.
  • Member-identifiable data is reasoned over only within its home region. AI processing of identifiable engagement data is performed on in-region infrastructure (AWS Sydney for Australian members). No member-identifiable data is sent to a model endpoint outside the member’s home region.
  • AI generates narrative; it does not issue the artefact. AI models produce the scoring narratives and draft findings. The scoring itself is performed by a separate deterministic scoring engine — the same inputs always produce the same outputs — and the issued Statement document is rendered deterministically, not generated by a model. Every issued artefact passes through a mandatory human approval step (Section 6).
SECTION 06

Automated processing and how decisions are made

kn0w’s scores are produced by a deterministic scoring engine applying fixed weightings to the responses gathered during an engagement. The output is a reading of a member company’s AI accountability posture, expressed as a band and per-dimension scores.

This output does not, by itself, produce a legal or similarly significant effect on any individual. It is a finding about a member company’s posture, not a decision about a person. Every issued Statement and Annual Statement passes through a mandatory human approval step before release: no artefact is issued to a member on a purely automated basis. A member company may ask us about the basis of any finding through the contacts in Section 18.

SECTION 07

The anonymised Benchmark Dataset

This Section describes the verified Benchmark Dataset built from member engagement data. kn0w also maintains a separate, indicative benchmark pool built from the free self-assessment responses described in Section 3. That indicative pool is global rather than jurisdictional, is built only from anonymised, aggregated self-reported answers that carry no identity, applies the same minimum-cohort floor of five companies (k=5) before any comparison is shown, and never feeds the verified percentiles described below. The two are firewalled from each other.

kn0w maintains a benchmark dataset that lets each member see its position against peers. It is built as follows:

  • A single, dedicated anonymisation pipeline is the only permitted pathway between regional member data and the benchmark store. Nothing else crosses that boundary.
  • Data entering the Benchmark Dataset is anonymised and aggregated. Every aggregate is stripped of member identity and assigned a fresh identifier at the moment it is written, so an anonymised record cannot be traced back to the member it came from. The dataset contains no names, no company identifiers, and no combination of fields that permits re-identification.
  • Peer comparisons are only ever rendered against cohorts of at least five companies (k=5), enforced from the first Audit. If fewer than five companies match a cohort, no comparison is returned. This threshold is enforced structurally in the platform, not by policy alone.
  • The Benchmark Dataset is hosted in the United States (AWS us-east-1). Because it is anonymised before transfer and carries no member identity, it is not personal data.
  • Anonymised aggregate data is retained indefinitely.

kn0w may license the anonymised, aggregated Benchmark Dataset to institutional partners. Because this data carries no member identity and is not personal data, this licensing does not involve the disclosure of your personal data.

SECTION 08

Where your data lives — regional residency

In this Policy, “member-identifiable data” means engagement data that identifies, or can reasonably be linked to, a member company or an individual within it, before it passes through the anonymisation process described in Section 7.

Member-identifiable data is stored in regional databases and never leaves its home region except through the single anonymising pathway described in Section 7.

  • Australian member data is stored and processed in AWS Sydney (ap-southeast-2).
  • Website and business data is processed by the service providers listed in Section 11.

kn0w currently operates in Australia. As kn0w expands to additional markets, member-identifiable data for each new market will be stored in-region, and this Policy will be updated with the applicable region and any additional transfer safeguards before members in that market are onboarded.

SECTION 09

International transfers

kn0w currently operates in Australia. Australian member-identifiable data is stored and processed in Australia (AWS Sydney) and does not leave Australia except through the anonymisation process in Section 7. Only anonymised, non-personal aggregate data — which is not personal data — is written to the United States benchmark store.

Any disclosure of personal information to overseas recipients (including the United States, where kn0w LLC operates infrastructure, and Singapore, where KN0W PTE. LTD. acts as controller) is limited to the arrangements described in Sections 7, 8, 10, and 11, and is addressed under the Australian Privacy Principles in Annex A.

When kn0w onboards members in other jurisdictions, this section will be updated with the transfer mechanisms applicable to those jurisdictions before any such member data is collected.

SECTION 10

US legal process — CLOUD Act disclosure

kn0w LLC, as the operator of kn0w’s cloud infrastructure, is a US entity and may be subject to the US CLOUD Act. We disclose this rather than claim it does not apply. This exposure cannot be eliminated as a matter of law; it is managed.

Under the Sub-Processor Agreement, kn0w LLC is contractually required to: (a) notify KN0W PTE. LTD. upon receiving any legal demand for member data; (b) challenge or seek to narrow any such request where the law allows; and (c) not disclose member data without the direction of KN0W PTE. LTD. except where legally compelled.

Because member-identifiable data never leaves its home region (Sydney), any demand made to the US entity reaches only the anonymised Benchmark Dataset — data that carries no member identity.

SECTION 11

Who we share personal data with

We do not sell personal data. We share it only with:

  • kn0w LLC — technical sub-processor operating our AWS infrastructure (see Sections 1 and 10).
  • Service providers acting on our instructions. These currently include:
ProviderFunctionPersonal data involved
Amazon Web Services (AWS) — operated by kn0w LLCCloud infrastructure, including in-region AI processing via Amazon Bedrock and the voice pipeline (Amazon Transcribe and Amazon Polly)Engagement data, including voice recordings and transcripts
OutsetaMembership, authentication, and billingWebsite and business data; account data
TypeformStructured intake formsEngagement data; enquiry data
PandaDocContracts and consent (DCA, proposals)Business contact data
WebflowWebsite and member portal front-endWebsite and business data
VantaCompliance monitoringLimited operational data

The current, canonical list of service providers is published at kn0w.co/security and available on request.

  • Professional advisers (legal, accounting, insurance) where necessary.
  • Authorities where disclosure is required by law, subject to Section 10 for member data.
  • A successor entity in the event of a merger, acquisition, or sale of assets, in which case this Policy continues to apply to your data until replaced with notice.
SECTION 12

How long we keep personal data

DataRetention
Raw member-identifiable engagement dataDuration of standing + 12 months, then automatically deleted
Voice session audioDeleted within 30 days of the session date
Anonymised aggregate benchmark dataRetained indefinitely (not personal data)
Issued Statements and Annual Statements (institutional record)The issued artefact is retained permanently as an institutional record; member-identifiable detail in the underlying working data is redacted at standing + 12 months
Website enquiry and marketing data24 months from last contact, unless you ask us to delete it sooner
Server-level connection data (e.g. IP address in infrastructure logs)Retained in our infrastructure provider’s logs only as long as needed to deliver and secure the site, then deleted
Billing recordsAs required by applicable tax and corporate law

Deletion and redaction of engagement data are automated and logged.

SECTION 13

How we protect personal data

Our security controls include: regional data isolation with hard boundaries, encryption at rest and in transit, least-privilege access controls, append-only audit logging of lifecycle events, automated deletion, and continuous infrastructure monitoring. The same controls run on every regional instance; they are part of the architecture, not configured per engagement.

kn0w is pursuing SOC 2 Type II and ISO 27001 certification through Vanta. Neither is yet certified, and we do not claim either until it is issued. Our current security posture is documented at kn0w.co/security.

SECTION 14

Data breaches

If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and affected individuals where, and within the timeframes, required by the applicable law in your jurisdiction. Our internal logging and monitoring are designed to support prompt detection and assessment.

SECTION 15

Cookies and tracking

Our public website (kn0w.co) sets no cookies. It does not use analytics cookies, advertising cookies, or third-party tracking pixels. You can browse the public site without any cookie being placed on your device and without being tracked. Our website infrastructure provider delivers page content, fonts, and scripts without setting cookies, and may process server-level connection data (such as IP address) only as needed to deliver and secure the site.

Our member application (app.kn0w.co) is accessible only after you sign in. Because it is a secure, authenticated application, it uses a small number of strictly necessary cookies to operate. These are not used for advertising or cross-site tracking.

Cookie typePurposeSet by
Session / authenticationKeeps you signed in during a session and links you to your member accountOur membership and authentication provider
Security (e.g. CSRF token)Protects against cross-site request forgery and similar attacksOur application

If we ever introduce non-essential cookies, we will update this section and, where required, ask for your consent first.

SECTION 16

Your rights

You have rights over your personal data. What they are and how to exercise them depends on where you are. The annexes below set out jurisdiction-specific detail. In all cases you can contact us at privacy@kn0w.co and we will respond within the timeframe required by your jurisdiction’s law.

If you are personnel of a member company, note that some rights (for example, deletion of engagement data mid-engagement) interact with the member company’s DCA; we will coordinate with the member company where the law permits.

Annex A — Australia

We handle personal information of Australian individuals in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). You may request access to, or correction of, your personal information by contacting us. We will respond within a reasonable period.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).

Australian member data is hosted in Australia (AWS Sydney). Consistent with APP 8, any disclosure of personal information to overseas recipients is limited to the arrangements described in Sections 7 to 11. Overseas recipients are located in: the United States (AWS infrastructure operated by kn0w LLC, holding anonymised, non-personal benchmark data only) and Singapore (KN0W PTE. LTD. as controller). Where service providers listed in Section 11 operate from other locations, those locations are identified on request.

Annex B — Singapore

KN0W PTE. LTD. complies with the Personal Data Protection Act 2012 (PDPA). You may request access to or correction of your personal data, or withdraw consent, by contacting us at privacy@kn0w.co. If you are not satisfied with our response, you may direct a complaint to the Personal Data Protection Commission (pdpc.gov.sg).

Annex C — Other jurisdictions

kn0w currently operates in Australia. If you are outside Australia, we apply the protections in this Policy as a baseline and honour rights of access, correction, and deletion to the extent provided by your local law. As kn0w expands into new markets — including the United Kingdom and EEA — jurisdiction-specific rights detail and transfer mechanisms will be added to this Policy before members in those markets are onboarded.

SECTION 17

Children

kn0w’s services are provided to companies and are not directed at children. We do not knowingly collect personal data from anyone under 18.

SECTION 18

Changes to this Policy and contact

We may update this Policy. Material changes will be notified to member companies directly and reflected by the “Last updated” date above; where a material change affects website visitors or business contacts, we will also post notice on this page. Prior versions are available on request.

KN0W PTE. LTD.
160 Robinson Road, #14-04, Singapore Business Federation Center, Singapore 068914
Privacy enquiries: privacy@kn0w.co
Security and data-handling review: audit@kn0w.co