Privacy Policy

www.knowndesign.ai
Version 3.0  |  Effective: June 2026 |  Last Updated: June 2026
UK GDPR  ·  Data Protection Act 2018  ·  Data (Use and Access) Act 2025  ·  PECR 2003

Governing Law: This Privacy Notice and all matters arising from it are governed by, and shall be construed in accordance with, the laws of England and Wales. Known Design AI Ltd is a company registered in England and Wales. All users, wherever located, contract with us on the basis of English law.

1. About Us

Known Design AI Ltd (“we”, “us”, “our”) is a company registered in England and Wales. Registered Office: 71 – 75 Shelton Street, Covent Garden, London WC2H 9JQ. Company Registration Number: 16965307. We operate www.knowndesign.ai and provide an AI-powered website builder and managed hosting service (the “Service”). We are the Data Controller for the purposes of the UK GDPR and the DPA 2018. ICO Registration Number: ZC082723. The service is delivered using the white-label platform of TenWeb, Inc. (trading as “10Web”), who acts as our data processor. Known Design AI Ltd remains your sole contractual counterparty and Data Controller at all times.

2. The Legal Framework

This Privacy Notice is issued pursuant to the following UK legislation:

LegislationRelevance to Known Design AI Ltd
UK General Data Protection Regulation (UK GDPR)The principal UK data protection law. Sets out the conditions under which personal data may be processed and the rights of data subjects.
Data Protection Act 2018 (DPA 2018)Supplements the UK GDPR. Provides additional conditions, exemptions, and enforcement provisions applicable in the UK.
Data (Use and Access) Act 2025 (DUAA 2025)Amends the UK GDPR and DPA 2018. Introduces Recognised Legitimate Interest basis, updated cookie consent rules (in force 5 February 2026), and requires a formal data protection complaints process by 19 June 2026.
Privacy and Electronic Communications Regulations 2003 (PECR)Governs cookies, similar technologies, and electronic marketing alongside the UK GDPR.
Consumer Rights Act 2015Statutory rights for individual consumers that are not excluded by this Notice or our Terms and Conditions.

We are not subject to EU GDPR (Regulation 2016/679). EU GDPR is not part of UK law following the UK’s departure from the European Union. This Notice is compliant with UK law only. Users located outside the UK contract with us on the basis of English law and this UK-law Privacy Notice.

3. What Personal Data We Collect

3.1 Data You Provide to Us

CategoryExamplesWhen Collected
Identity dataFull name, business nameAccount registration
Contact dataEmail address, correspondence addressAccount registration and support
Account credentialsPassword (stored as a one-way cryptographic hash – we cannot read it)Account registration
Billing dataPayment details processed by Stripe Inc. We receive only last four digits, billing country, and transaction reference. We do not store full card numbers.Subscription purchase
Profile dataWebsite URL, VAT number (optional), account preferencesAccount setup
Content dataAll text, images, and designs you create using the AI Website BuilderDuring use of the Service
Support dataContent of any support request or complaint you submitWhen you contact us
Marketing preferencesYour opt-in status for marketing communicationsAt registration or when updated by you

3.2 Data Collected Automatically

CategoryExamplesLawful Basis
Profile dataWebsite URL, VAT number (optional), account preferencesAccount setup
Content dataAll text, images, and designs you create using the AI Website BuilderDuring use of the Service
Support dataContent of any support request or complaint you submitWhen you contact us
Marketing preferencesYour opt-in status for marketing communicationsAt registration or when updated by you
Technical dataIP address, browser type, device type, operating systemLegitimate interests – platform security and fraud prevention
Usage dataPages visited, features used, time on page, clickstreamConsent (where non-essential cookies are accepted via our Cookie Preference Centre)
Log dataServer access logs, error reportsLegitimate interests – security monitoring
Cookie dataAs described in our Cookie Policy at www.knowndesign.co/cookie-policyStrictly necessary: no consent required. Non-essential: consent required under PECR 2003

3.3 Data from Third Parties

If you use a third-party login provider (such as Google), we receive only the data permitted by your settings on that platform, typically your name and email address. We receive payment confirmation data from Stripe Inc. (last four digits, country, transaction reference — never full card details).

4. How and Why We Use Your Personal Data

We process your personal data only where we have a lawful basis under Article 6 of the UK GDPR.

Processing PurposeLawful Basis (UK GDPR Art. 6)Legal Provision
Creating and managing your accountPerformance of a contract – Art. 6(1)(b)Necessary to provide the Service you have signed up for
Delivering the AI Website Builder and hosting servicesPerformance of a contract – Art. 6(1)(b)Core delivery of the contracted Service
Processing subscription payments via StripePerformance of a contract – Art. 6(1)(b)Necessary to fulfil our billing obligations
Sending transactional emails (welcome, billing, password reset, security alerts)Performance of a contract – Art. 6(1)(b)Necessary communications in connection with the Service
Fraud prevention and platform security monitoringLegitimate interests – Art. 6(1)(f)We have a legitimate interest in preventing fraud and maintaining platform integrity
Improving and developing the Service (anonymised or aggregated data)Legitimate interests – Art. 6(1)(f) / Recognised Legitimate Interest – DUAA 2025We have a legitimate interest in improving the Service for all users
Responding to support and complaintsPerformance of a contract – Art. 6(1)(b) / Legitimate interests – Art. 6(1)(f)Necessary to perform our contract and address your queries
Complying with legal obligations (e.g. HMRC record-keeping, ICO requests)Legal obligation – Art. 6(1)(c)UK tax and regulatory law
Sending marketing communicationsConsent – Art. 6(1)(a)You must opt in. You may withdraw consent at any time.
Setting non-essential cookiesConsent – Art. 6(1)(a)Required under PECR 2003 Regulation 6, as amended by DUAA 2025
Statistical analytics (aggregate, non-identifiable)Recognised Legitimate Interest – DUAA 2025 / Legitimate interests – Art. 6(1)(f)ICO April 2026 guidance: aggregate analytics may not require consent where data is not linked to individuals

AI Co-pilot Sessions: If you use the AI co-pilot feature, your session may be recorded (video of website changes only) by Microsoft Clarity via 10Web, for troubleshooting only. Recordings are deleted after one month and are NOT used to train AI models. Lawful basis: Legitimate interests — Art. 6(1)(f).

5. Who We Share Your Personal Data With

We do not sell your personal data. We share it only in the following circumstances:

RecipientData SharedPurposeSafeguard
TenWeb, Inc. (10Web) – Data ProcessorAccount data, website content, usage data, co-pilot recordingsPlatform infrastructure: AI Builder, managed WordPress hosting, dashboard, backupsData Processing Agreement (UK GDPR Art. 28). International transfers: UK IDTA or UK Addendum to EU SCCs.
Stripe, Inc.Payment data sent directly browser-to-Stripe. We do not receive or store card numbers.Secure payment processing (PCI DSS Level 1)Data Processing Agreement. International transfers: UK IDTA.
Google LLC (Analytics via 10Web)Anonymised analytics data. IP addresses anonymised by default in GA4.Website usage analyticsData Processing Agreement. UK Extension to EU-US DPF / UK IDTA.
Microsoft Corporation (Clarity via 10Web)IP (anonymised), browser info, co-pilot session recordingsTroubleshooting of AI co-pilot feature. Deleted after one month.Data Processing Agreement. UK IDTA.
Cloudflare, Inc.IP addresses, HTTP request dataCDN, DDoS protection, and bot managementData Processing Agreement. UK IDTA.
Xneelo (Pty) LtdName, email addressSending transactional and marketing emailsXneelo Data Processing Agreement. https://xneelo.co.za/help-centre/products-and-services/dpa-requirement/
CookieYesCookie consent recordsCookie consent management under PECR 2003N/A (UK-registered company; no international transfer)
Professional advisersLimited data as requiredLegal, accounting, audit, and insuranceProfessional confidentiality obligations
HM Revenue & Customs, ICO, courts, law enforcementData required by lawCompliance with UK legal obligationsOnly where required or permitted by UK law
A purchaser of our businessAccount and service dataBusiness sale, merger, or restructureYou will be notified. The new controller will be bound by equivalent obligations.

6. International Data Transfers

Some of our processors, including TenWeb, Inc. (10Web), Stripe, Google, Microsoft, and Cloudflare, are based in or transfer data to the United States. All such transfers comply with Chapter V of the UK GDPR using one or more of the following ICO-approved mechanisms:

  • UK International Data Transfer Agreement (IDTA) – issued by the ICO under section 119A of the DPA 2018
  • UK Addendum to EU Standard Contractual Clauses – the ICO-approved addendum applying UK law to EU SCCs
  • UK adequacy regulations – transfers to countries designated adequate by the UK Secretary of State under Art. 45 UK GDPR
  • UK Extension to the EU-US Data Privacy Framework – where applicable (e.g. Google LLC)

You may request details of the transfer mechanism for any processor by contacting us at complain@knowndesign.ai.

7. How Long We Keep Your Personal Data

CategoryRetention PeriodLegal / Business Reason
Account and profile dataDuration of account + 7 years after closureUK tax and accounting law (HMRC); Limitation Act 1980
Payment and billing records7 years from the date of transactionCompanies Act 2006; UK tax law
Website content you createDuration of account + 60 days post-closureAllows export before deletion. 60-day window set by 10Web.
AI co-pilot session recordings1 month from recording, then automatically deletedSet by 10Web's processing terms with Microsoft Clarity
Support correspondence3 years from date of last contactLegitimate interests – enabling response to recurring issues and defending legal claims
Marketing consent and suppression recordsUntil withdrawn + 3 yearsLegal obligation under PECR 2003; ICO guidance on suppression lists
Cookie consent recordsMinimum 12 monthsICO and EDPB guidance on demonstrating lawful consent under PECR 2003
Security and access logsMaximum 12 monthsLegitimate interests – security monitoring and incident investigation

8. Your Rights Under UK Data Protection Law

Under the UK GDPR and DPA 2018, you have the following rights. We will respond to all valid requests within one calendar month of receipt.

RightLegal ProvisionWhat It MeansHow to Exercise
Right of accessArt. 15 UK GDPRRequest a copy of all personal data we hold about you (a Subject Access Request).Email privacy@knowndesign.ai – subject line 'Subject Access Request'
Right to rectificationArt. 16 UK GDPRRequest correction of inaccurate or incomplete personal data.Update in dashboard or email support@knowndesign.ai
Right to erasureArt. 17 UK GDPRRequest deletion of your data in certain circumstances. Note: Some data must be retained for legal compliance.Email support@knowndesign.ai
Right to restrictionArt. 18 UK GDPRAsk us to restrict processing of your data in specified circumstances.Email privacy@knowndesign.ai
Right to data portabilityArt. 20 UK GDPRReceive your data in a structured, machine-readable format.Email privacy@knowndesign.ai
Right to objectArt. 21 UK GDPRObject to processing based on legitimate interests or for direct marketing. Marketing objections actioned immediately.Email support@knowndesign.ai or unsubscribe link in any marketing email
Rights re automated decisionsArt. 22 UK GDPRNot to be subject to solely automated decisions with significant effects. We do not currently make such decisions.Email privacy@knowndesign.ai if you believe this applies
Right to withdraw consentArt. 7(3) UK GDPRWithdraw consent at any time where processing is consent-based. Withdrawal does not affect prior lawful processing.Unsubscribe link in emails; Cookie Preference Centre; or email privacy@knowndesign.ai

If you are dissatisfied with how we have handled a rights request, you may complain to the Information Commissioner’s Office (ICO): www.ico.org.uk | Tel: 0303 123 1113 | Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would, however, appreciate the opportunity to address your concerns directly first.

9. Data Security

We implement appropriate technical and organisational measures under Article 32 UK GDPR to protect your personal data, including: TLS encryption in transit; encryption at rest on Google Cloud / AWS; access controls and least-privilege principles; MFA on all admin accounts; payment card data processed by Stripe (PCI DSS Level 1 – we never store card numbers); automated security scanning by 10Web; and Cloudflare DDoS protection. In the event of a personal data breach posing a risk to your rights, we will notify the ICO within 72 hours and, where required, notify you directly.

10. Cookies

We use strictly necessary cookies (set without consent under PECR Regulation 6(4)), analytics cookies (consent required), functional cookies (consent required), and marketing cookies (explicit consent required). The DUAA 2025 (in force 5 February 2026) introduced an exemption from consent for purely aggregate analytics where no individual is identified. Full details are in our Cookie Policy at https://knowndesign.ai/cookie-policy/. Manage your preferences at any time via the Cookie Preference Centre in our website footer.

11. Children

The Service is not directed at individuals under 18. We do not knowingly collect personal data from anyone under 18. If you believe we have done so, contact us immediately at privacy@knowndesign.ai and we will delete the data without undue delay.

12. Third-Party Websites

Our Service may contain links to third-party websites. This Notice applies only to personal data processed by Known Design AI Ltd. We are not responsible for third-party privacy practices and encourage you to review their notices before sharing personal data.

13. Changes to This Privacy Notice

We may update this Notice from time to time. Material changes will be communicated by posting an updated Notice on our website and emailing registered users at least 30 days before changes take effect. Your continued use of the Service after the effective date constitutes acceptance.

14. Contact Us and Data Protection Complaints

Known Design AI Ltd

Data Protection Enquiries: privacy@knowndesign.ai
Registered Office: 71 – 75 Shelton Street, Covent Garden, London WC2H 9JQ
ICO Registration Number: ZC082723
Website: www.knowndesign.ai
Data Protection Officer: Roger Raad

Formal Data Protection Complaints Process (required under DUAA 2025 by 19 June 2026): If you wish to raise a complaint about our handling of your personal data, please write to privacy@knowndesign.ai with the subject line ‘Data Protection Complaint’. We will acknowledge your complaint within 5 working days and aim to resolve it within 30 calendar days. If we cannot resolve it within 30 days, we will notify you and provide a revised timescale.

15. Governing Law and Jurisdiction

This Privacy Notice, and any dispute or claim arising out of or in connection with it, is governed by and construed in accordance with the laws of England and Wales. The courts of England and Wales shall have exclusive jurisdiction, subject to your statutory rights to bring proceedings in the courts of Scotland or Northern Ireland if you are domiciled there.