Legal
Privacy Policy
Version 1.0
Effective Date: June 27, 2026
Last Updated: June 27, 2026
We take your privacy seriously. This policy explains how KNAPTON collects, uses, and protects your information.
1. Our Privacy Commitment
KNAPTON Nexus Hub ("KNAPTON", "we", "our") is committed to handling personal information with care, honesty, and respect.
We do not sell personal information. We do not rent personal information. We do not use customer operational data to train AI or similar systems without explicit permission.
Protecting your privacy and the security of your information is a core part of how KNAPTON is designed.
This Privacy Policy explains what information KNAPTON collects, how we use it, how we protect it, and your rights. It applies to everyone who interacts with KNAPTON, including organization administrators, staff members, employees using the platform through their employer, and anyone who visits our public website.
We have written this policy in plain language because we believe you deserve a clear and honest explanation of how your information is handled.
2. Our Role With Your Information
How KNAPTON handles your information depends on the context.
When you contact KNAPTON directly, for example through our contact form, early access application, or platform support, KNAPTON is the organization responsible for your information. We decide why we collect it and how we use it.
When your employer or organization uses KNAPTON to manage their workforce, training, scheduling, or compliance, your organization is the party responsible for the personal information they enter about their staff. KNAPTON stores and processes that information on your organization's behalf. In this context, your organization decides what is entered, why it is collected, and how it is used. KNAPTON follows their direction.
In privacy law terms, KNAPTON acts as a data controller for information submitted directly to us, and as a data processor for personal information that customer organizations enter and manage within their workspaces.
If you are an employee or staff member and you have questions about personal information your employer has entered about you in the platform, we recommend contacting your employer first. Your employer controls that data. KNAPTON will cooperate with reasonable requests.
3. How KNAPTON Protects Privacy
KNAPTON is designed with privacy in mind. Features such as tenant isolation, permission-based access, separate business memberships, and audit history are built into the platform to help organizations protect information and maintain accountability.
Tenant Isolation
Each organization operates in a completely isolated workspace. One organization's data, including staff records, training history, schedules, certificates, and compliance information, is not accessible to any other organization on the platform. Tenant isolation is enforced at the data layer.
Permission-Based Access
Within a workspace, access is controlled by roles and permissions configured by the organization's administrators. Staff members can only access information appropriate to their assigned role. Administrators are responsible for configuring and maintaining appropriate access controls.
Identity Separation
One KNAPTON identity may belong to multiple separate organizational workspaces. Each membership is separate and private from the others. Your membership in one organization does not affect or expose your membership in another.
Business Contact Email Separation
A business contact email, which is an email address your employer may use to reach you for workplace communication, is stored separately from your login identity. It is not used for authentication and does not affect your KNAPTON account.
Support Mode
KNAPTON platform administrators may access a customer workspace to provide support. Support mode access does not create a business membership or grant ongoing access. All support mode sessions are logged and tracked for accountability.
Platform Administrative Access
Access to platform-level administrative functions is restricted to authorized KNAPTON personnel. Platform-level administrative actions are subject to audit logging.
Audit History
KNAPTON maintains audit records of significant actions within workspaces to support accountability, dispute resolution, and security.
4. Information We Collect
KNAPTON collects the following categories of information depending on how the platform is used:
Account and Identity Information
Your name and email address, your platform account role, and your account status. Login credentials are managed by our trusted authentication provider. We do not store or view plaintext passwords.
Business Contact Information
Contact email addresses, job titles, and phone numbers provided by organizations for their staff. A business contact email may be different from a login email. It is used for workplace communication purposes only.
Workspace Membership Information
Your role within an organization, your assigned work areas or locations, your employment status or type, and related configuration fields set by your organization's administrators.
Employment and Workforce Profile Information
Where enabled by your organization, payroll identifiers, employment classification codes, and related fields used for scheduling and payroll export purposes.
Training Records
Course enrollments, learning progress, completion status, quiz attempts and scores, assessment responses, and training completion history.
Certificates
Certificates issued through the platform, including the learner name, course title, completion date, expiry date, score where applicable, and certificate number.
Scheduling Records
Shift dates, times, work areas, and assignment status. Published and draft schedule information.
Time Off and Availability Records
Leave requests, including leave type, dates, and approval status. Availability preferences and availability change requests.
Attendance and Payroll Export Records
Where enabled, clock-in and clock-out records, attendance corrections, payroll period data, and payroll export records.
Uploaded Files and Documents
Profile pictures, organization logos, training materials, proof documents uploaded for external training verification, and workforce documents required or tracked by your organization.
In-App Notifications
Operational messages generated by the platform based on activity in your workspace, such as shift assignments, approvals, reminders, and certificate expiry alerts.
Audit Logs
Records of significant actions taken within a workspace, including user management, role changes, course publishing, certificate issuance, schedule publishing, and support access. These support accountability and platform integrity.
Support and Administrative Records
Records related to platform administration, support mode access, platform security, and platform-level operations.
Public Contact Inquiries
Name, email, subject, and message submitted through our Contact page.
Early Access Submissions
Name, email, organization, job role, company size, areas of interest, and current needs submitted through our Early Access page.
Technical and Security Information
Session activity, login timestamps, and information generated by platform operations to support security, troubleshooting, and audit purposes. We do not systematically collect browser type, IP addresses, or device information at the application level.
5. Public Forms
Contact Form
Our Contact page allows anyone to send us a message. We collect your name, email address, an optional subject, and your message. This information is delivered to our team by email and retained only as long as reasonably necessary to respond to and manage your inquiry. Contact form submissions are not stored within the platform.
Early Access Form
Our Early Access page allows prospective customers to express interest in the platform. We collect your name, email, organization name, job role, company size, primary area of interest, and a description of your current needs. This information is stored securely within KNAPTON and is accessible only to KNAPTON platform administrators. It is used for the purpose of evaluating interest, following up with prospective customers, and managing our customer relationships. Early access submissions are retained until they are manually archived or deleted by a platform administrator, or until a future automated retention process is in place.
We will not expose your inquiry details to other users, and we will not share them with third parties for commercial purposes.
6. How We Use Information
KNAPTON uses personal information only for legitimate purposes related to operating and improving the platform:
• Provide and operate the platform and all of its features
• Authenticate users and authorize access to appropriate workspaces and records
• Manage workspace access, tenant isolation, and permission enforcement
• Deliver training management, scheduling, certificate issuance, compliance tracking, workforce tools, and in-app notifications
• Respond to contact inquiries and support requests
• Manage early access applications and prospective customer relationships
• Maintain audit history and platform accountability records
• Secure the platform, investigate incidents, and maintain platform integrity
• Comply with legal obligations where required
• Improve platform reliability, performance, and functionality
We do not use personal information for advertising, marketing to third parties, or building advertising profiles.
7. Authentication and Passwords
Login credentials are managed by our trusted platform authentication services. KNAPTON does not store or have access to plaintext passwords at any level of the application.
Your login identity (the email address you use to sign in) is separate from any business contact email your employer may store for you in their workspace. These serve different purposes and are not interchangeable.
Password reset tokens and invitation tokens are stored securely as cryptographic hashes. The plaintext token exists only in the link sent to you by email. Tokens have expiry windows, and once a token is used or expired it is no longer valid, though records of token activity may be retained for security and audit purposes.
If you lose access to your account, your organization's administrator can initiate a password reset. KNAPTON cannot retrieve your original password.
10. Data Location and Cross-Border Processing
KNAPTON is based in Canada.
At the time this policy was last updated, our platform infrastructure, including application data, uploaded files, authentication systems, backend processing, logs, and related operational services, may be stored or processed in the United States.
Some third-party service providers used by KNAPTON may store or process data in jurisdictions outside Canada, including the United States and other countries. Information processed outside Canada may be subject to the laws of those jurisdictions, including lawful access by government authorities.
KNAPTON takes reasonable steps to protect personal information regardless of where it is stored or processed. We work with service providers that maintain appropriate data protection practices.
11. File Uploads
Users and organizations may upload files to the platform, including profile pictures, organization logos, training materials, proof documents for external training verification, and workforce documents required by their organization.
Uploaded files are stored using managed platform file storage services.
Some uploaded files, such as profile pictures and organization logos, may be accessible to anyone who has the file URL. Other files, such as training proof documents, are handled as private files accessible only through appropriate access controls.
KNAPTON does not currently perform optical character recognition (OCR), content analysis, or automated processing of uploaded files. The platform includes an optional image cropping and resizing tool that users may use before uploading a profile picture. Only the final cropped image is uploaded and stored.
Users should not upload files containing malicious or inappropriate content.
12. Certificates and Public Verification
Some organizations using KNAPTON may choose to issue publicly verifiable certificates to their staff or learners.
Where an organization has enabled public certificate verification, a certificate verification page may display limited information needed to confirm a certificate's validity. This may include the learner's name, the course or training title, the completion date, the expiry date where applicable, and the certificate number.
Public verification exists to support the legitimate purpose of allowing third parties to confirm that a certificate is genuine. The decision to issue publicly verifiable certificates is controlled by the organization using the feature.
13. Sensitive Information
Some information entered into KNAPTON by customer organizations may be sensitive in nature. This can include leave reasons, proof documents related to health or personal circumstances, compliance records related to regulated work, or workforce documents.
Customers are responsible for using KNAPTON appropriately and avoiding the entry of sensitive or unnecessary personal information in fields that are not designed for it. For example, free-text notes fields or identifier fields should not be used to store detailed personal, health, or protected information beyond what is operationally necessary.
KNAPTON is a workforce training and scheduling management platform. It is not designed or intended to be a clinical health record system, a system of record for personal health information, or a regulated health information platform. Customers with obligations under health privacy legislation should review their obligations and ensure their use of KNAPTON is appropriate.
14. Data Retention
We retain personal information only for as long as reasonably necessary to provide our services, maintain business records, and meet legal, regulatory, contractual, operational, audit, tax, or dispute-resolution requirements, enforce our agreements, and protect the integrity and security of the platform. When information is no longer required, it may be securely deleted, anonymized, or archived in accordance with our retention practices.
Customer operational data (staff records, training records, schedules, certificates, and related information) is currently retained while the customer's workspace is active. Data is not automatically deleted when a staff member leaves an organization or when individual records are updated, unless an administrator manually removes or archives those records.
Contact form submissions are not stored within the platform. They are retained only as long as reasonably necessary to respond to and manage the inquiry.
Early access submissions are stored securely within KNAPTON until they are manually archived or deleted by a platform administrator, or until a future automated retention process is implemented.
Audit logs and security records may be retained for longer periods to support accountability, platform integrity, security investigations, and legal obligations.
A formal data retention and tenant archiving system is planned but has not yet been implemented. We will update this policy when it is.
If you have questions about retention of a specific record, please contact us.
15. Your Privacy Rights
Depending on applicable law, you may have the right to:
• Access the personal information we hold about you
• Request correction of inaccurate or incomplete records
• Request deletion of your personal information, subject to legal, contractual, audit, security, or operational obligations
• Withdraw consent where processing is based on consent
• Receive information about how your personal information is handled
Canadian residents may have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
If you are an employee or staff member and your request relates to information in your employer's workspace, you should contact your employer first. Your employer controls that data. KNAPTON processes it on their behalf.
For privacy questions or requests relating to information KNAPTON controls directly, please contact us through our Contact page. Some requests may be limited by legal, contractual, audit, security, or operational requirements. We will always explain any limitation that applies.
16. Breach Notification
KNAPTON will notify affected customers and, where required by applicable law, affected individuals and the relevant privacy regulator if a security or privacy incident creates a legal notification obligation.
Customers who become aware of a potential security incident involving their workspace should notify KNAPTON promptly through our Contact page.
18. Future Features and Integrations
KNAPTON may introduce new features, integrations, or services in the future. Examples may include connections to payroll systems, calendar tools, intelligent or AI-assisted features, or other tools designed to improve platform functionality.
Where new features involve material changes to how personal information is collected, used, or shared, KNAPTON will update this Privacy Policy and, where required, provide additional notice before implementing those changes.
We will not use customer operational data to train AI or similar systems without explicit permission.
19. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page. For material changes, we will make reasonable efforts to notify active customers in advance.
Continued use of the platform after an updated Privacy Policy takes effect constitutes acceptance of the updated policy.
20. Contact
For privacy questions, requests, or concerns, please contact us through our Contact page. We will do our best to respond promptly and transparently.
Privacy questions? Contact us.
