Skip to content
Knotis
Knotis
Book a demo

Privacy policy

Last updated: September 21, 2026

Who we are

Knotis is an operations platform for aquaculture businesses. It is provided by [Company legal name], [registered address], Greece (“Knotis”, “we”, “us”). You can reach us about privacy at [email protected].

This policy explains how we handle personal data when you visit our website, request a demo, or use Knotis as a customer or as a member of a customer’s team.

Our two roles

As controller. We decide how personal data is used for our website, for demo and contact requests, for customer accounts and billing, and for our own security and support. This policy describes that processing in full.

As processor. When a fish farming company uses Knotis, it enters data about its own staff, contractors and site visitors. For that data the company is the controller and we process it only on its instructions, under a data processing agreement. If you work for or visited one of our customers, contact that company first about your data. We will help them respond.

Data we collect as controller

  • Website visitors: pages visited, device and browser information and approximate location derived from your IP address. Analytics data is collected only if you accept analytics cookies.
  • Demo and contact requests: name, email, phone number, company and your message.
  • Account holders: name, email address, profile photo if you add one, role, the Organization you belong to, sign-in times and security logs.
  • Billing contacts: company name, VAT number, billing address and invoices. Card details are handled by our payment provider and never stored by us.
  • Support: the content of emails and messages you send us.

Data we process for our customers

Depending on the features a customer enables, Knotis may hold:

  • Staff records: name, email, role, team, assigned sites and invitations.
  • Attendance: clock-in and clock-out times, the site, the method used (GPS, QR code, NFC or manual entry), the GPS location at the moment of the clock event, reasons given for manual entries, and a selfie when the customer requires one.
  • Rosters and time: shifts, shift requests, leave, timesheets, overtime and the pay rules applied to them.
  • Visitors: name, company, purpose of visit, sign-in and sign-out times and a selfie taken at the kiosk.
  • Operational activity: who created or changed nets, cages, in-water cycles and work orders, recorded in the audit log.

Location is captured only at the moment of a clock event. Knotis does not track staff location continuously. Selfies are stored as photos for review by the customer’s managers and are not used for biometric identification.

Purpose Legal basis (GDPR)
Replying to demo and contact requests Steps before a contract, Art. 6(1)(b), or our legitimate interest in responding, Art. 6(1)(f)
Providing the Service and managing accounts Performance of our contract, Art. 6(1)(b)
Invoicing and accounting Legal obligation, Art. 6(1)(c)
Keeping the Service secure, preventing abuse, audit logs Legitimate interest, Art. 6(1)(f)
Product updates and service announcements to customers Legitimate interest, Art. 6(1)(f); you can opt out at any time
Website analytics and advertising measurement Your consent, Art. 6(1)(a)

For the data we process on behalf of customers, the legal basis is determined by the customer as controller.

Cookies

Our website uses strictly necessary cookies to work, for example to remember your language and your cookie choice. Analytics and advertising cookies are enabled only if you accept them in the cookie banner. You can change your choice at any time from the link in the footer.

The Knotis web application uses only the cookies needed to keep you signed in and secure.

Who we share data with

We do not sell personal data. We share it only with:

  • service providers who host the platform, send email, process payments and provide support tools, under contracts that require them to protect it and use it only on our instructions;
  • professional advisers such as accountants and lawyers, where necessary;
  • authorities, when the law requires it.

A current list of our sub-processors is available to customers on request.

International transfers

We host Knotis in the European Union ([hosting region]). If a service provider processes data outside the European Economic Area, we make sure an adequate safeguard is in place, such as an adequacy decision or the European Commission’s Standard Contractual Clauses.

How long we keep data

  • Demo and contact requests: up to 24 months after our last exchange, unless you become a customer.
  • Account data: for as long as the account is active, and deleted within 30 days after the customer’s subscription ends and its export period closes.
  • Billing records: for as long as Greek tax law requires.
  • Security logs: up to 12 months.
  • Customer data: according to the customer’s settings and instructions. For example, visitor records and kiosk selfies are deleted automatically after the retention period the customer sets (90 days if none is chosen).

Security

We protect personal data with encryption in transit, role-based access with site-level permissions, hashed passwords, audit logging of changes and restricted access for our own staff. No system is perfectly secure; if a breach affects your data, we will notify you and the authorities as the law requires.

Your rights

Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format. Where we rely on your consent, you can withdraw it at any time without affecting earlier processing.

To exercise your rights, email [email protected]. We will reply within one month. If your data is held for one of our customers, we will pass your request to them.

You also have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr) or the authority in your country.

Children

Knotis is a business service and is not directed at children. We do not knowingly collect data from anyone under 16.

Changes to this policy

We may update this policy as the Service changes. We will notify customers of material changes by email or in the app. The date at the top of this page shows when it was last updated.

Contact

[Company legal name], [registered address], Greece. Email: [email protected].