www.knowndesign.ai
Version 3.0 | Effective: June 2026 | Last Updated: June 2026
UK GDPR · Data Protection Act 2018 · Data (Use and Access) Act 2025 · PECR 2003
Governing Law: This Privacy Notice and all matters arising from it are governed by, and shall be construed in accordance with, the laws of England and Wales. Known Design AI Ltd is a company registered in England and Wales. All users, wherever located, contract with us on the basis of English law.
Known Design AI Ltd (“we”, “us”, “our”) is a company registered in England and Wales. Registered Office: 71 – 75 Shelton Street, Covent Garden, London WC2H 9JQ. Company Registration Number: 16965307. We operate www.knowndesign.ai and provide an AI-powered website builder and managed hosting service (the “Service”). We are the Data Controller for the purposes of the UK GDPR and the DPA 2018. ICO Registration Number: ZC082723. The service is delivered using the white-label platform of TenWeb, Inc. (trading as “10Web”), who acts as our data processor. Known Design AI Ltd remains your sole contractual counterparty and Data Controller at all times.
This Privacy Notice is issued pursuant to the following UK legislation:
| Legislation | Relevance to Known Design AI Ltd |
|---|---|
| UK General Data Protection Regulation (UK GDPR) | The principal UK data protection law. Sets out the conditions under which personal data may be processed and the rights of data subjects. |
| Data Protection Act 2018 (DPA 2018) | Supplements the UK GDPR. Provides additional conditions, exemptions, and enforcement provisions applicable in the UK. |
| Data (Use and Access) Act 2025 (DUAA 2025) | Amends the UK GDPR and DPA 2018. Introduces Recognised Legitimate Interest basis, updated cookie consent rules (in force 5 February 2026), and requires a formal data protection complaints process by 19 June 2026. |
| Privacy and Electronic Communications Regulations 2003 (PECR) | Governs cookies, similar technologies, and electronic marketing alongside the UK GDPR. |
| Consumer Rights Act 2015 | Statutory rights for individual consumers that are not excluded by this Notice or our Terms and Conditions. |
We are not subject to EU GDPR (Regulation 2016/679). EU GDPR is not part of UK law following the UK’s departure from the European Union. This Notice is compliant with UK law only. Users located outside the UK contract with us on the basis of English law and this UK-law Privacy Notice.
| Category | Examples | When Collected |
|---|---|---|
| Identity data | Full name, business name | Account registration |
| Contact data | Email address, correspondence address | Account registration and support |
| Account credentials | Password (stored as a one-way cryptographic hash – we cannot read it) | Account registration |
| Billing data | Payment details processed by Stripe Inc. We receive only last four digits, billing country, and transaction reference. We do not store full card numbers. | Subscription purchase |
| Profile data | Website URL, VAT number (optional), account preferences | Account setup |
| Content data | All text, images, and designs you create using the AI Website Builder | During use of the Service |
| Support data | Content of any support request or complaint you submit | When you contact us |
| Marketing preferences | Your opt-in status for marketing communications | At registration or when updated by you |
| Category | Examples | Lawful Basis |
|---|---|---|
| Profile data | Website URL, VAT number (optional), account preferences | Account setup |
| Content data | All text, images, and designs you create using the AI Website Builder | During use of the Service |
| Support data | Content of any support request or complaint you submit | When you contact us |
| Marketing preferences | Your opt-in status for marketing communications | At registration or when updated by you |
| Technical data | IP address, browser type, device type, operating system | Legitimate interests – platform security and fraud prevention |
| Usage data | Pages visited, features used, time on page, clickstream | Consent (where non-essential cookies are accepted via our Cookie Preference Centre) |
| Log data | Server access logs, error reports | Legitimate interests – security monitoring |
| Cookie data | As described in our Cookie Policy at www.knowndesign.co/cookie-policy | Strictly necessary: no consent required. Non-essential: consent required under PECR 2003 |
If you use a third-party login provider (such as Google), we receive only the data permitted by your settings on that platform, typically your name and email address. We receive payment confirmation data from Stripe Inc. (last four digits, country, transaction reference — never full card details).
We process your personal data only where we have a lawful basis under Article 6 of the UK GDPR.
| Processing Purpose | Lawful Basis (UK GDPR Art. 6) | Legal Provision |
|---|---|---|
| Creating and managing your account | Performance of a contract – Art. 6(1)(b) | Necessary to provide the Service you have signed up for |
| Delivering the AI Website Builder and hosting services | Performance of a contract – Art. 6(1)(b) | Core delivery of the contracted Service |
| Processing subscription payments via Stripe | Performance of a contract – Art. 6(1)(b) | Necessary to fulfil our billing obligations |
| Sending transactional emails (welcome, billing, password reset, security alerts) | Performance of a contract – Art. 6(1)(b) | Necessary communications in connection with the Service |
| Fraud prevention and platform security monitoring | Legitimate interests – Art. 6(1)(f) | We have a legitimate interest in preventing fraud and maintaining platform integrity |
| Improving and developing the Service (anonymised or aggregated data) | Legitimate interests – Art. 6(1)(f) / Recognised Legitimate Interest – DUAA 2025 | We have a legitimate interest in improving the Service for all users |
| Responding to support and complaints | Performance of a contract – Art. 6(1)(b) / Legitimate interests – Art. 6(1)(f) | Necessary to perform our contract and address your queries |
| Complying with legal obligations (e.g. HMRC record-keeping, ICO requests) | Legal obligation – Art. 6(1)(c) | UK tax and regulatory law |
| Sending marketing communications | Consent – Art. 6(1)(a) | You must opt in. You may withdraw consent at any time. |
| Setting non-essential cookies | Consent – Art. 6(1)(a) | Required under PECR 2003 Regulation 6, as amended by DUAA 2025 |
| Statistical analytics (aggregate, non-identifiable) | Recognised Legitimate Interest – DUAA 2025 / Legitimate interests – Art. 6(1)(f) | ICO April 2026 guidance: aggregate analytics may not require consent where data is not linked to individuals |
AI Co-pilot Sessions: If you use the AI co-pilot feature, your session may be recorded (video of website changes only) by Microsoft Clarity via 10Web, for troubleshooting only. Recordings are deleted after one month and are NOT used to train AI models. Lawful basis: Legitimate interests — Art. 6(1)(f).
We do not sell your personal data. We share it only in the following circumstances:
| Recipient | Data Shared | Purpose | Safeguard |
|---|---|---|---|
| TenWeb, Inc. (10Web) – Data Processor | Account data, website content, usage data, co-pilot recordings | Platform infrastructure: AI Builder, managed WordPress hosting, dashboard, backups | Data Processing Agreement (UK GDPR Art. 28). International transfers: UK IDTA or UK Addendum to EU SCCs. |
| Stripe, Inc. | Payment data sent directly browser-to-Stripe. We do not receive or store card numbers. | Secure payment processing (PCI DSS Level 1) | Data Processing Agreement. International transfers: UK IDTA. |
| Google LLC (Analytics via 10Web) | Anonymised analytics data. IP addresses anonymised by default in GA4. | Website usage analytics | Data Processing Agreement. UK Extension to EU-US DPF / UK IDTA. |
| Microsoft Corporation (Clarity via 10Web) | IP (anonymised), browser info, co-pilot session recordings | Troubleshooting of AI co-pilot feature. Deleted after one month. | Data Processing Agreement. UK IDTA. |
| Cloudflare, Inc. | IP addresses, HTTP request data | CDN, DDoS protection, and bot management | Data Processing Agreement. UK IDTA. |
| Xneelo (Pty) Ltd | Name, email address | Sending transactional and marketing emails | Xneelo Data Processing Agreement. https://xneelo.co.za/help-centre/products-and-services/dpa-requirement/ |
| CookieYes | Cookie consent records | Cookie consent management under PECR 2003 | N/A (UK-registered company; no international transfer) |
| Professional advisers | Limited data as required | Legal, accounting, audit, and insurance | Professional confidentiality obligations |
| HM Revenue & Customs, ICO, courts, law enforcement | Data required by law | Compliance with UK legal obligations | Only where required or permitted by UK law |
| A purchaser of our business | Account and service data | Business sale, merger, or restructure | You will be notified. The new controller will be bound by equivalent obligations. |
Some of our processors, including TenWeb, Inc. (10Web), Stripe, Google, Microsoft, and Cloudflare, are based in or transfer data to the United States. All such transfers comply with Chapter V of the UK GDPR using one or more of the following ICO-approved mechanisms:
You may request details of the transfer mechanism for any processor by contacting us at complain@knowndesign.ai.
| Category | Retention Period | Legal / Business Reason |
|---|---|---|
| Account and profile data | Duration of account + 7 years after closure | UK tax and accounting law (HMRC); Limitation Act 1980 |
| Payment and billing records | 7 years from the date of transaction | Companies Act 2006; UK tax law |
| Website content you create | Duration of account + 60 days post-closure | Allows export before deletion. 60-day window set by 10Web. |
| AI co-pilot session recordings | 1 month from recording, then automatically deleted | Set by 10Web's processing terms with Microsoft Clarity |
| Support correspondence | 3 years from date of last contact | Legitimate interests – enabling response to recurring issues and defending legal claims |
| Marketing consent and suppression records | Until withdrawn + 3 years | Legal obligation under PECR 2003; ICO guidance on suppression lists |
| Cookie consent records | Minimum 12 months | ICO and EDPB guidance on demonstrating lawful consent under PECR 2003 |
| Security and access logs | Maximum 12 months | Legitimate interests – security monitoring and incident investigation |
Under the UK GDPR and DPA 2018, you have the following rights. We will respond to all valid requests within one calendar month of receipt.
| Right | Legal Provision | What It Means | How to Exercise |
|---|---|---|---|
| Right of access | Art. 15 UK GDPR | Request a copy of all personal data we hold about you (a Subject Access Request). | Email privacy@knowndesign.ai – subject line 'Subject Access Request' |
| Right to rectification | Art. 16 UK GDPR | Request correction of inaccurate or incomplete personal data. | Update in dashboard or email support@knowndesign.ai |
| Right to erasure | Art. 17 UK GDPR | Request deletion of your data in certain circumstances. Note: Some data must be retained for legal compliance. | Email support@knowndesign.ai |
| Right to restriction | Art. 18 UK GDPR | Ask us to restrict processing of your data in specified circumstances. | Email privacy@knowndesign.ai |
| Right to data portability | Art. 20 UK GDPR | Receive your data in a structured, machine-readable format. | Email privacy@knowndesign.ai |
| Right to object | Art. 21 UK GDPR | Object to processing based on legitimate interests or for direct marketing. Marketing objections actioned immediately. | Email support@knowndesign.ai or unsubscribe link in any marketing email |
| Rights re automated decisions | Art. 22 UK GDPR | Not to be subject to solely automated decisions with significant effects. We do not currently make such decisions. | Email privacy@knowndesign.ai if you believe this applies |
| Right to withdraw consent | Art. 7(3) UK GDPR | Withdraw consent at any time where processing is consent-based. Withdrawal does not affect prior lawful processing. | Unsubscribe link in emails; Cookie Preference Centre; or email privacy@knowndesign.ai |
If you are dissatisfied with how we have handled a rights request, you may complain to the Information Commissioner’s Office (ICO): www.ico.org.uk | Tel: 0303 123 1113 | Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would, however, appreciate the opportunity to address your concerns directly first.
We implement appropriate technical and organisational measures under Article 32 UK GDPR to protect your personal data, including: TLS encryption in transit; encryption at rest on Google Cloud / AWS; access controls and least-privilege principles; MFA on all admin accounts; payment card data processed by Stripe (PCI DSS Level 1 – we never store card numbers); automated security scanning by 10Web; and Cloudflare DDoS protection. In the event of a personal data breach posing a risk to your rights, we will notify the ICO within 72 hours and, where required, notify you directly.
We use strictly necessary cookies (set without consent under PECR Regulation 6(4)), analytics cookies (consent required), functional cookies (consent required), and marketing cookies (explicit consent required). The DUAA 2025 (in force 5 February 2026) introduced an exemption from consent for purely aggregate analytics where no individual is identified. Full details are in our Cookie Policy at https://knowndesign.ai/cookie-policy/. Manage your preferences at any time via the Cookie Preference Centre in our website footer.
The Service is not directed at individuals under 18. We do not knowingly collect personal data from anyone under 18. If you believe we have done so, contact us immediately at privacy@knowndesign.ai and we will delete the data without undue delay.
Our Service may contain links to third-party websites. This Notice applies only to personal data processed by Known Design AI Ltd. We are not responsible for third-party privacy practices and encourage you to review their notices before sharing personal data.
We may update this Notice from time to time. Material changes will be communicated by posting an updated Notice on our website and emailing registered users at least 30 days before changes take effect. Your continued use of the Service after the effective date constitutes acceptance.
Known Design AI Ltd
Data Protection Enquiries: privacy@knowndesign.ai
Registered Office: 71 – 75 Shelton Street, Covent Garden, London WC2H 9JQ
ICO Registration Number: ZC082723
Website: www.knowndesign.ai
Data Protection Officer: Roger Raad
Formal Data Protection Complaints Process (required under DUAA 2025 by 19 June 2026): If you wish to raise a complaint about our handling of your personal data, please write to privacy@knowndesign.ai with the subject line ‘Data Protection Complaint’. We will acknowledge your complaint within 5 working days and aim to resolve it within 30 calendar days. If we cannot resolve it within 30 days, we will notify you and provide a revised timescale.
This Privacy Notice, and any dispute or claim arising out of or in connection with it, is governed by and construed in accordance with the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction, subject to your statutory rights to bring proceedings in the courts of Scotland or Northern Ireland if you are domiciled there.
Copyright © Known Design AI Ltd 2026. All Rights Reserved. Privacy Policy, Terms and Conditions, Cookie Policy, GDPR, DUAA2025, ICO Compliance #ZC082723.