Knocknoc Privacy Policy
This policy explains how Knocknoc Pty Ltd (ACN 656 951 549) and KnocKnoc, Inc (Knocknoc, we, us, our) collect, hold, use and disclose personal information.
Knocknoc complies with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). Where Knocknoc processes personal information of individuals in the European Economic Area or the United Kingdom, it also complies with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK GDPR as applicable. Where Knocknoc processes personal information of California residents, it complies with the California Consumer Privacy Act 2018 as amended by the California Privacy Rights Act 2020 (CCPA).
By using our website, licensing portal, platform or other services, you acknowledge and agree to this policy.
If you do not agree with this privacy policy, do not access or use our services or interact with any other aspect of our business.
Who We Are
Knocknoc is the data controller for personal information collected through its website and licensing portal. For personal information processed through the Knocknoc platform on behalf of a business customer, Knocknoc acts as a data processor. In that case, the business customer is the data controller and the terms of its agreement with Knocknoc govern that processing.
Our Privacy and Security Culture
Knocknoc is a cybersecurity product company built for high-security, high-trust environments where customers retain full control.
Our products are intentionally designed so that Knocknoc and third parties cannot observe, access, or interfere with a customer’s secure use of the product. We do not track or monitor user activity, interface usage, or actions performed by users within customer deployments.
We collect limited, anonymised licence utilisation data. This process does not involve third-party services, and no user-identifiable information is transmitted outside the customer deployment.
This principle guides our product architecture and technology decisions. We collect as little data as possible, maintain deliberate separation between Knocknoc and customer environments, avoid third-party telemetry and analytics, and do not create remote access channels into customer deployments.
We also treat software supply chain risk as a core security consideration. We take deliberate steps to reduce the risk of Knocknoc becoming a pathway through which customers could be compromised. Our objective is not only to secure the product itself, but to ensure that Knocknoc does not introduce avoidable trust, access, or supply chain risk into customer environments.
Our public website and related properties naturally collect more information than product deployments and instances, as outlined below.
Personal Information We Collect
Information you give us
When you register on our licensing portal or contact us, we may collect:
- name
- email address
- company name
- phone number
- billing and payment information (processed by our payment providers, AirWallex, Stripe)
If you are participating in an event we are managing or delivering, we may take images or audio- visual recordings which identify you.
Information we collect automatically
When you visit our website or use our hosted platform, we may collect:
- IP address and approximate geographic location
- browser type and device information
- pages visited and time spent on our website
- summarised data relating to your use of the Knocknoc platform (see our Telemetry page)
- Information from third parties
We may collect information from:
- third parties that provide us with marketing, market research, and web analytics services;
- social media platforms;
- other service providers and business partners (who assist us to operate our business, including running promotions in connection with the supply of our products and services).
Where we collect personal information about you from a third party rather than directly from you, we collect it because we reasonably believe the third party has your consent or another lawful basis to share it with us, and we use it for the purposes set out in this policy. If you would like more information about the source of information we hold about you, contact us using the details in clause 14.
Sensitive information
We do not intentionally collect sensitive information (such as health information or financial account credentials). If you voluntarily provide sensitive information, we will handle it in accordance with this policy and will seek your consent where required by law.
How and Why We Use Your Information
We use personal information for the following purposes:
- to provide, operate and improve our platform and services
- to manage your account and process payments
- to communicate with you about your account, orders and support requests
- to send marketing communications (where you have consented or where we have a legitimate interest to do so. You may opt out at any time)
- contacting you when a reseller or other third party makes a referral to us and we reasonably believe that they have your consent or another lawful basis for providing your personal information to us
- to comply with our legal obligations
- to protect the security and integrity of our systems
Where we rely on GDPR, the lawful bases for our processing are:
- contract performance — to provide the services you have purchased
- legitimate interests — to improve our platform, prevent fraud and communicate relevant updates
- legal obligation — to comply with applicable laws
- consent — for marketing communications and any other processing where indicated
We may use de-identified, aggregated data about how our website, platform and software are used in order to troubleshoot issues, identify trends, and develop new products and features. This data does not identify you or any individual.
Disclosure of Personal Information
We do not sell personal information. We may disclose personal information to:
- our employees, contractors and related entities who need access to perform their roles
- our third-party service providers who assist us in operating our business (see clause 7)
- resellers, distributors and channel partners, where you purchase or use our services through one of these parties
- marketing partners, where you have consented to receive information from them
- government agencies or regulators where required by law
- a successor entity in connection with a merger, acquisition or sale of assets, subject to confidentiality obligations
We require all third parties who handle personal information on our behalf to do so in accordance with applicable privacy laws and contractual obligations consistent with this policy.
Third-Party Service Providers
Knocknoc uses a small group of key third-party service providers that may process personal information. Details of those service providers are set out in our Trust Centre. Knocknoc’s website may contain links to other websites. We cannot control the privacy controls of third-party websites. Third party service providers may use their own cookies to collect data about your activities on our website. Use of third-party sites is subject to the terms and conditions found on those sites.
International Transfers
Knocknoc is headquartered in Australia. Our third-party service providers may process personal information in other countries, including the United States.
Where personal information of individuals in the EEA or UK is transferred to a country that does not have an adequacy decision, we rely on appropriate safeguards, including Standard Contractual Clauses approved by the European Commission, to protect that information.
Retention
We retain personal information only for as long as necessary to fulfil the purpose for which it was collected, after which we securely delete or de-identify it. In determining how long to retain information, we consider:
- the length of our relationship with you and your account status
- any legal, accounting or regulatory obligation requiring us to keep records (for example, tax and corporate record-keeping laws)
- whether retention is reasonably necessary to establish, exercise or defend legal claims
- your preferences, where you have asked us to delete your information.
- Security
Knocknoc takes reasonable technical and organisational measures to protect personal information from misuse, loss, unauthorised access, modification and disclosure. These measures include encryption in transit and at rest, access controls and regular security assessments.
Knocknoc holds SOC 2 Type II certification. Further information is available at trust.knocknoc.io.
No method of transmission over the internet is completely secure. We cannot guarantee absolute security, but we will notify you in accordance with applicable privacy laws if a breach affecting your personal information occurs and notification is required by law.
Your Rights
All individuals
You may request access to, or correction of, the personal information we hold about you by contacting us using the details in clause 14. We will respond within a reasonable time and, in any event, within the timeframes required by applicable law.
This applies whether we collected your information directly from you or from a third party, such as a reseller or referral partner. If we collected your information from a third party, you may still contact us to find out what information we hold, where it came from, and to request access or correction.
All unsubscribe or opt-out requests may be made by emailing us at [email protected] or by clicking the “unsubscribe” link at the bottom of the email. We will process your request within a reasonable time after receipt. However, we are not responsible for, and in some cases we are incapable of, removing your personal data from the lists of any third party who has previously been provided your information in accordance with this Privacy Policy or your consent. You should contact such third parties directly.
EEA and UK individuals (GDPR)
If the GDPR applies to the processing of your information, you also have the right to:
- erasure of your personal information in certain circumstances
- restriction of processing pending resolution of an objection or complaint
- receive your information in a structured, machine-readable format
- object to processing based on legitimate interests
- withdraw consent at any time (without affecting the lawfulness of prior processing)
- lodge a complaint with a supervisory authority in your country of residence
- California residents (CCPA)
If you are a California resident, you have the right to:
- know what personal information we collect, use, disclose or share
- request deletion of your personal information (subject to certain exceptions)
- opt out of the sale or sharing of your personal information (Knocknoc does not sell personal information)
- non-discrimination for exercising your privacy rights
To exercise any of these rights, contact us as set out in clause 14. We will verify your identity before processing your request.
Cookies and Tracking
Our website uses cookies and similar technologies to improve your experience and collect usage analytics. We use Google Tag Manager to manage tracking scripts.
You can control cookies through your browser settings. Disabling cookies may affect the functionality of our website.
Children
Our software and platform is not directed at children under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us and we will delete it.
Contact and Complaints
For privacy queries, requests to exercise your rights, or complaints about how we handle your personal information, contact us at: [email protected] or write to us at Knocknoc Pty Ltd (ACN 656 951 549) of 18 Lexington Drive, Bella Vista NSW 2153 Australia.
If you are not satisfied with our response, you may lodge a complaint with the relevant regulator:
- Australia: Office of the Australian Information Commissioner (OAIC) at oaic.gov.au
- EEA/UK: your local data protection supervisory authority
- California: California Privacy Protection Agency (CPPA) at cppa.ca.gov
- Changes to This Policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by posting a notice on our website before the changes take effect. The current version is always available at knocknoc.io/legal/privacy-policy.
Continued use of our platform and software after the effective date of any update constitutes acceptance of the updated policy.