Privacy Policy

Knowlio.cloud SaaS platform

Effective July 2, 2026
Version: 1.0
Legal Basis: Regulation (EU) 2016/679 (GDPR); Act CXII of 2011 (Infotv.).

1. The Data Controller

  • Data Controller: APPON LINE Kft.
  • Headquarters: Hungary, 2120 Dunakeszi, Római utca 1/1
  • Contact / Privacy Policy: info@knowlio.cloud

2. Dual Role: Data Controller and Data Processor

Due to the nature of the Service, the Service Provider operates in two different capacities:

  • As the data controller, with respect to the Subscriber’s (account holder’s) personal data: registration, billing, and operation of the Service.
  • As a data processor, with respect to the personal data that the Subscriber uploads to the knowledge base, as well as data generated during chatbot conversations (widget visitors, domain-chat users). In this regard, the Subscriber is the data controller, and the Service Provider acts on the Subscriber’s instructions pursuant to a data processing agreement (DPA, Article 28 of the GDPR).

This policy primarily describes the activities carried out in the capacity of Data Controller; details regarding data processing activities are set forth in the DPA.

3. Processed Data, Purposes, and Legal Bases (As Data Controller)

Data Set Cél Legal Basis (Article 6 of the GDPR)
Registration data (name, email, password hash) Account, Identification (1) b) contract
Billing Information Billing, Bookkeeping (1) c) legal obligation
Subscriber API Key (OpenAI/Anthropic) Operating the chatbot on behalf of the Subscriber (1) b) contract
Usage/log data (IP, device, events, token metrics) Security, Fraud Prevention, and Billing Basis (1) f) legitimate interest
Advocacy Communication Customer Service (1) b) / f)
Marketing Email / Newsletter Inquiry (1) a) consent
Cookies are not required Analytics, Marketing (1) a) consent (see Cookie Policy)

4. The knowledge base and chat data uploaded by the Subscriber (as a Data Processor)

  • Subscribers can upload documents (PDF, DOCX, XLSX, TXT, MD), which the system splits into segments and vectorizes (embeds) for RAG search. This data, as well as chat conversations (messages from widget visitors and domain-chat users), may contain personal data.
  • In this context, the data controller is the Subscriber: the Subscriber is responsible for establishing the legal basis, informing the data subjects, and ensuring that only lawfully processed data is uploaded.
  • The Subscriber may not upload special categories of data (Article 9 of the GDPR, e.g., health data) without an appropriate independent legal basis and safeguards.
  • In this regard, the Service Provider acts solely on the Subscriber’s instructions and in accordance with the DPA; it does not use the data to train AI models.

5. API Key Management and Security

  • The Service Provider stores the model API key provided by the Subscriber in an encrypted format (not in plaintext) and uses it solely for the operation of the chatbot.
  • The Subscriber may rotate or revoke their key at any time.
  • LLM calls initiated with a key are forwarded to the model provider (OpenAI/Anthropic); data processing there is governed by the legal relationship between that provider and the Subscriber.

6. Multi-tenant isolation

All Subscriber data (bots, knowledge base, embeddings, chat history) is stored in logically separate environments (multi-tenant isolation) to prevent other Subscribers from accessing it.

7. Data Processors and Recipients

Data Processor Function Transfers outside the EU
Rackforest ZRt.
1132 Budapest, Victor Hugo u. 11., 5. em.
Infrastructure, file storage (S3/local) None
Stripe Payments Europe, Ltd.
1 Grand Canal Street Lower Grand Canal Dock Dublin 2 D02 H210 Ireland
Payroll Processing USA - SCC / EU-US DPF
KBOSS.hu Kft 
1031 Budapest, Záhony utca 7.
Billing None
Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy L-1855 Luxembourg Luxembourg
Transactional/Marketing Email USA - SCC / EU-US DPF
OpenAI / Anthropic LLM Response Generation United States — see item 8

8. Data Transfers to Third Countries

Certain data processors (in particular, LLM providers, payment providers, and email service providers) may also process data in the United States. Safeguards for data transfers (GDPR Articles 44–49): EU-US Data Privacy Framework certification and Standard Contractual Clauses (SCCs) approved by the European Commission. The content transferred from the knowledge base and chat to the LLM should be minimized.

9. Data Retention Periods

Data Set Retention period
Account Information for the duration of the account's existence, until it is deleted
Billing Information 8 years, according to Act C of 2000
API key until the key is revoked / the account is deleted
Log/Security Data up to 12 months
Knowledge Base, Chat History as specified by the Subscriber; no later than 30 days after the termination of the contract

10. Rights of the Data Subject (Articles 15–22 of the GDPR)

Access, rectification, erasure, restriction, data portability, objection, withdrawal of consent.

Request: info@knowlio.cloud

The Service Provider will process the request within 1 month (plus 2 months in justified cases).

Requests from data subjects regarding personal data stored in the knowledge base or chat must primarily be submitted to the relevant Subscriber (as the data controller).

11. Data Breach

In the event of an incident, the Service Provider will document it and, if there is a risk, report it to the NAIH within 72 hours (Article 33 of the GDPR); in the event of a high risk, the Service Provider will also notify the data subjects.

12. Children's Information

The Service is not intended for individuals under the age of 16; parental consent is required for those under 16 (GDPR Article 8).

13. Data Security Measures

Encryption in transit and at rest (including API keys), multi-tenant isolation, access management, logging, rate limiting, regular backups, and vulnerability management in accordance with Article 32 of the GDPR.

14. Supervisory Authority

NAIH
Nemzeti Adatvédelmi és Információszabadság Hatóság
1055 Budapest, Falk Miksa utca 9-11.
https://www.naih.hu

15. Amendment

The Service Provider may amend these Terms and Conditions; the current version is available on the website, and the Service Provider will notify you of any significant changes via email.