Privacy Policy

Last updated: June 2026

Disclaimer: This Privacy Policy is a template provided for informational purposes. It has not been reviewed by legal counsel and does not constitute legal advice. You should consult a qualified attorney to ensure compliance with applicable data protection laws in your jurisdiction, including the GDPR.

1. Introduction

Kognite (“the Service”), operated by Global Software Development EU (“we,” “us,” or “our”), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Portable Agent Memory SaaS platform.

This policy is designed to comply with the European Union’s General Data Protection Regulation (GDPR) and other applicable data protection laws. By using the Service, you consent to the data practices described in this policy.

2. Data Controller

For the purposes of the GDPR, the data controller is:

Global Software Development EU

Bucharest, Romania

Email: [email protected]

3. Data We Collect

3.1 Information You Provide

  • Account Information: When you register, we collect your name, email address, and authentication provider identifiers (e.g., GitHub user ID, Google account ID).
  • User Content: Any data, memories, knowledge graph entries, MCP configurations, skills, and other content you upload to or generate through the Service.
  • Billing Information: If you subscribe to a paid plan, our payment processor (Stripe) collects your payment card details and billing address. We do not store full payment card numbers on our servers.
  • Communications: When you contact us for support, we collect the content of your messages and any attachments.

3.2 Information Collected Automatically

  • Usage Data: We collect information about how you interact with the Service, including API calls made, pages visited, features used, and timestamps.
  • Device and Connection Data: IP address, browser type, operating system, referring URLs, and device identifiers.
  • Cookies and Similar Technologies: We use essential cookies for authentication and session management. Our analytics are first-party and cookieless: page views are counted using an anonymous identifier that rotates daily and cannot be linked back to you across days; no raw IP address is stored.

4. How We Use Your Data

We process your personal data based on the following lawful bases under GDPR:

PurposeLawful Basis
Provide and maintain the ServicePerformance of a contract
Process payments and manage subscriptionsPerformance of a contract
Send service-related communicationsLegitimate interests
Improve and optimize the ServiceLegitimate interests
Ensure security and prevent fraudLegitimate interests
Comply with legal obligationsLegal obligation
Marketing communications (with consent)Consent

5. Data Storage and Retention

Your data is stored on servers located in the European Union (Germany), hosted on Hetzner infrastructure. We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption at rest (AES-256) and in transit (TLS 1.3);
  • Regular security audits and vulnerability assessments;
  • Access controls and authentication requirements;
  • Automated backup with encrypted storage.

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, or as required by law. Specifically:

  • Account data: Retained while your account is active and for 90 days after account deletion;
  • User Content: Retained while your account is active. Upon deletion request, content is permanently removed within 30 days;
  • Billing records: Retained for the period required by applicable tax and accounting laws (typically 7 years);
  • Usage logs: Retained for 90 days, then automatically purged.

For more details, refer to our Data Retention Policy (available in your dashboard under Settings > Compliance).

6. Third-Party Sharing and Subprocessors

We do not sell your personal data. We share data with third parties only as necessary to provide the Service, comply with legal obligations, or with your explicit consent.

6.1 Subprocessors

The following third-party services process data on our behalf. Each has a Data Processing Agreement (DPA) in place:

SubprocessorPurposeLocation
HetznerCloud hosting and infrastructureGermany (EU)
StripePayment processingUnited States (SCCs)
GitHub (OAuth)Authentication providerUnited States (SCCs)
Google (OAuth)Authentication providerUnited States (SCCs)
ResendTransactional email deliveryUnited States (SCCs)
SentryError monitoringUnited States (SCCs)
Kognite (first-party)Cookieless, anonymized analytics — processed on our own infrastructure, never sharedGermany (EU)

SCCs = Standard Contractual Clauses (EU-approved data transfer mechanism).

6.2 Legal Disclosures

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency). We will notify you of such disclosure unless prohibited by law.

7. Your GDPR Rights

If you are located in the European Economic Area (EEA), you have the following rights under the GDPR:

  • Right of Access (Art. 15): You may request a copy of the personal data we hold about you in a machine-readable format.
  • Right to Rectification (Art. 16): You may request that we correct any inaccurate or incomplete personal data.
  • Right to Erasure (Art. 17): You may request that we delete your personal data (“right to be forgotten”). We will comply within 30 days, subject to legal retention obligations.
  • Right to Restriction (Art. 18): You may request that we restrict the processing of your personal data while a complaint is reviewed.
  • Right to Data Portability (Art. 20): You may request your data in a structured, commonly used, and machine-readable format (JSON/CSV).
  • Right to Object (Art. 21): You may object to processing based on legitimate interests, including for direct marketing purposes.
  • Rights Related to Automated Decision-Making (Art. 22): You have the right not to be subject to decisions based solely on automated processing that produce legal effects. You may request human review of any such decision.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection supervisory authority.

8. Data Processing Agreement (DPA)

For business and enterprise customers who require a Data Processing Agreement under GDPR Article 28, we provide a standard DPA upon request. The DPA covers:

  • Subject matter, nature, and duration of processing;
  • Categories of personal data and data subjects;
  • Our obligations as a data processor (confidentiality, security, subprocessor management, breach notification, data subject rights assistance);
  • Technical and organizational measures (TOMs) implemented.

To request a DPA, contact us at [email protected].

9. International Data Transfers

Your data is primarily stored and processed within the European Union. When we transfer data to subprocessors located outside the EEA (such as Stripe or GitHub in the United States), we ensure appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs) with each subprocessor;
  • Transfer impact assessments (TIAs) to verify the subprocessor can provide adequate protection;
  • Supplementary technical measures where necessary (e.g., encryption key management retained within the EU).

10. Data Breach Notification

In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay, as required by GDPR Article 34.

11. Children’s Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will take steps to delete such information. If you believe a child has provided us with personal data, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email (to the address associated with your account) or through a prominent notice on the Service prior to the change becoming effective. The “Last updated” date at the top of this page indicates when this policy was last revised.

Your continued use of the Service after any changes constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: [email protected]

Data Protection Officer: [email protected]

Address: Global Software Development EU, Bucharest, Romania

You have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) or your local data protection authority.