Knowledgeable
Legal

Privacy Policy

This notice explains what personal data Knowledgeable collects, how we use it, and the rights you have over it. It applies to our website and to the Knowledgeable platform.

Last updated: June 2026Draft. Pending legal review

1. Who we are

Knowledgeable ("we", "us", "our") provides an AI-enhanced operating system for market access, health economics and evidence generation teams. We are the data controller for personal data processed via our website, and a data processor for customer data processed on behalf of organisations that subscribe to our platform under a separate Data Processing Agreement (DPA).

Questions about this notice or our data practices can be sent to privacy@knowledgeable.ai.

2. Data we collect

2.1 Account & identity data

  • Name, work email address, job title, organisation.
  • Authentication identifiers (e.g. SSO subject IDs, hashed passwords).

2.2 Usage data

  • Pages visited, features used, search queries within the platform.
  • Device, browser, IP address, approximate location, timestamps.

2.3 Content data

  • Documents, datasets, notes, prompts and other material you upload or generate inside the platform.
  • Outputs produced by AI features acting on your content (summaries, evidence extractions, syntheses).

2.4 Communications

  • Messages you send us via contact forms, email or support channels.

3. Lawful bases

We rely on the following lawful bases under UK GDPR and EU GDPR:

  • Contract, to provide the platform and fulfil agreements with you or your organisation.
  • Legitimate interests, to secure, improve and analyse our service, prevent abuse, and run our business.
  • Consent, for non-essential cookies, marketing communications and optional analytics.
  • Legal obligation, where we must retain or disclose data to comply with law.

4. How we use your data

  • Provide, secure and operate the Knowledgeable platform.
  • Authenticate users and manage organisation-level access controls.
  • Provide customer support and respond to enquiries.
  • Detect, investigate and prevent fraud, abuse and security incidents.
  • Improve features, performance and reliability using aggregated, de-identified usage signals.
  • Send service announcements; with consent, send product news and event invitations.

We do not use customer content (documents, prompts, outputs) to train shared or third-party foundation models. Customer content is processed only to deliver the service to that customer.

5. Sharing & sub-processors

We share personal data with vetted sub-processors who help us operate the service, for example cloud hosting, observability, email delivery, and authentication providers. All sub-processors are bound by written contracts requiring appropriate technical and organisational measures. A current list is available on request from privacy@knowledgeable.ai.

6. International transfers

Where personal data leaves the UK or EEA, we rely on adequacy decisions, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses (SCCs) with appropriate supplementary measures.

7. Retention

  • Account data: for the life of the account, plus up to 12 months after closure.
  • Customer content: per the customer's contract; deleted or returned on termination.
  • Logs and security telemetry: typically 30–365 days, depending on type.
  • Marketing data: until you withdraw consent or after 24 months of inactivity.

8. Your rights

Subject to applicable law, you have the right to access, rectify, erase, restrict, port and object to processing of your personal data, and to withdraw consent at any time. To exercise any of these rights, email privacy@knowledgeable.ai. If your data is held by us on behalf of an organisation, we will direct requests to that organisation as the controller.

You also have the right to lodge a complaint with a supervisory authority, in the UK, the Information Commissioner's Office (ico.org.uk).

9. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, least-privilege access controls, audit logging and a secure development lifecycle. See our Security page for details.

10. Cookies

Our use of cookies and similar technologies is described in our Cookie Policy.

11. Changes to this notice

We may update this notice to reflect changes in our practices or the law. Material changes will be notified via the platform or by email where appropriate. The "Last updated" date at the top of this page shows the latest revision.

12. Contact

Knowledgeable, privacy@knowledgeable.ai