Privacy Policy
Knowlio.cloud SaaS platform
Effective July 2, 2026
Version: 1.0
Legal Basis: Regulation (EU) 2016/679 (GDPR); Act CXII of 2011 (Infotv.).
1. The Data Controller
- Data Controller: APPON LINE Kft.
- Headquarters: Hungary, 2120 Dunakeszi, Római utca 1/1
- Contact / Privacy Policy: info@knowlio.cloud
2. Dual Role: Data Controller and Data Processor
Due to the nature of the Service, the Service Provider operates in two different capacities:
- As the data controller, with respect to the Subscriber’s (account holder’s) personal data: registration, billing, and operation of the Service.
- As a data processor, with respect to the personal data that the Subscriber uploads to the knowledge base, as well as data generated during chatbot conversations (widget visitors, domain-chat users). In this regard, the Subscriber is the data controller, and the Service Provider acts on the Subscriber’s instructions pursuant to a data processing agreement (DPA, Article 28 of the GDPR).
This policy primarily describes the activities carried out in the capacity of Data Controller; details regarding data processing activities are set forth in the DPA.
3. Processed Data, Purposes, and Legal Bases (As Data Controller)
| Data Set | Cél | Legal Basis (Article 6 of the GDPR) |
|---|---|---|
| Registration data (name, email, password hash) | Account, Identification | (1) b) contract |
| Billing Information | Billing, Bookkeeping | (1) c) legal obligation |
| Subscriber API Key (OpenAI/Anthropic) | Operating the chatbot on behalf of the Subscriber | (1) b) contract |
| Usage/log data (IP, device, events, token metrics) | Security, Fraud Prevention, and Billing Basis | (1) f) legitimate interest |
| Advocacy Communication | Customer Service | (1) b) / f) |
| Marketing Email / Newsletter | Inquiry | (1) a) consent |
| Cookies are not required | Analytics, Marketing | (1) a) consent (see Cookie Policy) |
4. The knowledge base and chat data uploaded by the Subscriber (as a Data Processor)
- Subscribers can upload documents (PDF, DOCX, XLSX, TXT, MD), which the system splits into segments and vectorizes (embeds) for RAG search. This data, as well as chat conversations (messages from widget visitors and domain-chat users), may contain personal data.
- In this context, the data controller is the Subscriber: the Subscriber is responsible for establishing the legal basis, informing the data subjects, and ensuring that only lawfully processed data is uploaded.
- The Subscriber may not upload special categories of data (Article 9 of the GDPR, e.g., health data) without an appropriate independent legal basis and safeguards.
- In this regard, the Service Provider acts solely on the Subscriber’s instructions and in accordance with the DPA; it does not use the data to train AI models.
5. API Key Management and Security
- The Service Provider stores the model API key provided by the Subscriber in an encrypted format (not in plaintext) and uses it solely for the operation of the chatbot.
- The Subscriber may rotate or revoke their key at any time.
- LLM calls initiated with a key are forwarded to the model provider (OpenAI/Anthropic); data processing there is governed by the legal relationship between that provider and the Subscriber.
6. Multi-tenant isolation
All Subscriber data (bots, knowledge base, embeddings, chat history) is stored in logically separate environments (multi-tenant isolation) to prevent other Subscribers from accessing it.
7. Data Processors and Recipients
| Data Processor | Function | Transfers outside the EU |
|---|---|---|
| Rackforest ZRt. 1132 Budapest, Victor Hugo u. 11., 5. em. |
Infrastructure, file storage (S3/local) | None |
| Stripe Payments Europe, Ltd. 1 Grand Canal Street Lower Grand Canal Dock Dublin 2 D02 H210 Ireland |
Payroll Processing | USA - SCC / EU-US DPF |
| KBOSS.hu Kft 1031 Budapest, Záhony utca 7. |
Billing | None |
| Amazon Web Services EMEA SARL 38 Avenue John F. Kennedy L-1855 Luxembourg Luxembourg |
Transactional/Marketing Email | USA - SCC / EU-US DPF |
| OpenAI / Anthropic | LLM Response Generation | United States — see item 8 |
8. Data Transfers to Third Countries
Certain data processors (in particular, LLM providers, payment providers, and email service providers) may also process data in the United States. Safeguards for data transfers (GDPR Articles 44–49): EU-US Data Privacy Framework certification and Standard Contractual Clauses (SCCs) approved by the European Commission. The content transferred from the knowledge base and chat to the LLM should be minimized.
9. Data Retention Periods
| Data Set | Retention period |
|---|---|
| Account Information | for the duration of the account's existence, until it is deleted |
| Billing Information | 8 years, according to Act C of 2000 |
| API key | until the key is revoked / the account is deleted |
| Log/Security Data | up to 12 months |
| Knowledge Base, Chat History | as specified by the Subscriber; no later than 30 days after the termination of the contract |
10. Rights of the Data Subject (Articles 15–22 of the GDPR)
Access, rectification, erasure, restriction, data portability, objection, withdrawal of consent.
Request: info@knowlio.cloud
The Service Provider will process the request within 1 month (plus 2 months in justified cases).
Requests from data subjects regarding personal data stored in the knowledge base or chat must primarily be submitted to the relevant Subscriber (as the data controller).
11. Data Breach
In the event of an incident, the Service Provider will document it and, if there is a risk, report it to the NAIH within 72 hours (Article 33 of the GDPR); in the event of a high risk, the Service Provider will also notify the data subjects.
12. Children's Information
The Service is not intended for individuals under the age of 16; parental consent is required for those under 16 (GDPR Article 8).
13. Data Security Measures
Encryption in transit and at rest (including API keys), multi-tenant isolation, access management, logging, rate limiting, regular backups, and vulnerability management in accordance with Article 32 of the GDPR.
14. Supervisory Authority
NAIH
Nemzeti Adatvédelmi és Információszabadság Hatóság
1055 Budapest, Falk Miksa utca 9-11.
https://www.naih.hu
15. Amendment
The Service Provider may amend these Terms and Conditions; the current version is available on the website, and the Service Provider will notify you of any significant changes via email.