Privacy and data protection

Knot ERP Privacy Policy

How Knot ERP collects, uses, stores, protects, shares, and deletes personal data and Google user data.

Last updated: August 28, 2026 support@knot-sys.com
This policy applies to the Knot ERP website, public applications, dashboards, and online stores operated through the platform.

1. Who we are and our role

Knot ERP is a multi-tenant cloud ERP platform for sales, inventory, accounting, employees, CRM, online stores, and delivery. Knot acts as a controller for the core platform and account administration. When a subscribing business enters information about its employees or customers, that business normally acts as the controller and Knot acts as its service provider or processor under the applicable agreement.

2. Information we collect

The information depends on the feature used and the subscribing business settings. It may include:

  • Account and identity data: name, email, phone number, profile image, language, internal identifier, company, role, and permissions.
  • Operational content entered by users: customers, employees, products, invoices, orders, inventory, accounting records, files, and notes.
  • Payment and subscription data: plan and invoice status, transaction references, and limited payment-method metadata. Analytics never records full card numbers or security codes.
  • Device and security data: device, browser, operating system, login time, authentication attempts, audit logs, and session identifiers.
  • Consented usage data: pages, events, referral source, and approximate country or city. Analytics stores a masked IP and keyed HMAC for security and abuse prevention, not a full IP address.
  • Location data when a user requests a location-based feature such as maps, delivery, or attendance, and after device permission where required.

3. Google Sign-In data

When you choose Google Sign-In, Knot currently requests only the basic profile and email scopes. We receive your name, email address, profile image, verification status, a unique account identifier, and authentication tokens needed to complete sign-in or account linking.

We use this information to create or identify your account, prefill your profile, prevent fraud, and secure the sign-in session. Knot does not currently request permission to read Gmail, Google Drive, or Google Calendar through basic Google Sign-In, and does not read your messages, files, or calendar through that flow.

Knot's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalized or non-personalized AI or machine-learning models, for personalized advertising, or for sale.

4. How we use information

We use information only for disclosed purposes connected to the service, including:

  • Providing accounts, selected modules, and operations requested by users.
  • Authentication, permission enforcement, account security, fraud detection, and abuse prevention.
  • Processing subscriptions and payments and sending invoices, notifications, and service messages.
  • Support, troubleshooting, performance measurement, and usability improvements.
  • Producing aggregated analytics and operational insights. Names, emails, and IP addresses are not sent to the aggregate AI reporting feature.
  • Meeting legal obligations, enforcing terms, and protecting users and the platform.

5. Legal bases and consent

We process information as needed to perform a contract or deliver a requested feature, with consent where required, for proportionate security and legitimate interests, or to meet a legal obligation. You may reject or withdraw non-essential analytics consent without disabling storage that is strictly necessary for account operation and security.

6. Sharing and service providers

We do not sell personal data. We may process or disclose the minimum necessary information to providers of hosting, databases, authentication, email, notifications, payments, maps, support, and analytics according to the purpose and business configuration. We may also disclose information when legally required or necessary to protect the service and its users.

Each business is logically isolated and access is permission-based. A subscribing business may view information about its own employees and customers according to its permissions and legal relationship with them.

7. Retention and deletion

We retain information while needed to provide the service, meet accounting or legal obligations, resolve disputes, and secure the platform. The default retention is 395 days for analytics events and 730 days for consent records, and may be configured for applicable requirements. Limited backup copies may remain until the secure backup lifecycle expires.

You may request account and data deletion through our Data Deletion page. After verifying identity and authority, we delete or de-identify information unless a legal obligation or legitimate right requires retention of a specific subset.

8. Security and international processing

We use encrypted connections, password hashing, role-based permissions, tenant isolation, audit logs, rate limits, and operational access controls. No electronic method is completely secure, so controls are reviewed and updated according to risk.

Information may be processed in countries where infrastructure or providers operate. Where international-transfer requirements apply, we use the available contractual and technical basis and safeguards.

9. Your rights and contact

Depending on applicable law and the contractual relationship, you may request access, correction, export, restriction, objection, deletion, or withdrawal of consent. For information controlled by a subscribing business, we may refer the request to that business account administrator.

Privacy requests can be sent to support@knot-sys.com. Never include a password, verification code, or card details in your request.

10. Policy updates

We may update this policy when the service or legal requirements change. We will update the date above and provide notice or request renewed consent when a change introduces a materially new use that requires it.