Legal · Last updated 6 October 2026
Data processing agreement (template)
A summary of the template we sign with every seller. The signed version governs. Download the PDF
§1
Parties and roles
The seller is the controller. Knowlode acts as processor for the processing of raw exports (GDPR Art. 28).
§2
Subject matter and duration
Anonymisation of the export described in the order form, from receipt until the raw data is deleted.
§3
Instructions
- Knowlode processes raw data only on the seller’s documented instructions.
- Processing is limited to redaction, entity replacement, re-identification testing, quality review and packaging.
§4
Data and data subjects
Employees, contractors, customers and suppliers of the seller who appear in the export. Special-category data is excluded by scope, and any that remains is deleted when detected.
§5
Location
Raw data is stored and processed in the EU only.
§6
Security measures
- Encryption in transit and at rest.
- Least-privilege access, logged and reviewed.
- Confidentiality obligations for everyone with access.
- Separation of each seller’s raw data.
§7
Sub-processors
Listed on the trust page. Sellers are notified 30 days before any change and may object.
§8
Assistance and breaches
Knowlode helps the seller answer data-subject requests and prepare DPIAs. Personal data breaches are reported without undue delay, and within 48 hours of discovery.
§9
Deletion
Raw data is deleted after the anonymised dataset passes review, and no later than 30 days after receipt. Deletion is confirmed in writing.
§10
Audit rights
Knowlode provides the information needed to show compliance, and allows audits on reasonable notice.
§11
Relation to the licence
Only the anonymised output is licensed to Knowlode, under the separate licence agreement.