Service Description and Privacy Details — KnowScapes
Annex A to the Privacy Notice for Services · Version 1.2 · Effective 2 October 2026
This annex sets out everything that applies to KnowScapes alone: what the service
does, which plans and processing modes exist, which data arises, where it is
processed and how long it is kept. It is at the same time the service description
under § 1(6) of our
General Terms and Conditions and the annex to
our Privacy Notice for Services
under its section 7. This annex is written in English, and the English version is
authoritative.
KnowScapes is offered exclusively to businesses.
Part 1 — Service description
1.1 What the service does
KnowScapes answers questions. You send a conversation to the API, an agent (an
“Expert”) generates a reply from it using the knowledge base configured for that
agent, and we return the reply.
Replies are generated by language models. They draw on your knowledge base and on
the general knowledge contained in the language model itself (“world
knowledge”). World knowledge comes from the model only: no question, message or
part of a conversation is sent to a search engine or any other external web
service to obtain it. See section 1.6.
| Endpoint | Purpose |
|---|---|
https://knowscapes.com/api/v1/chat/completions | generate a reply (OpenAI-compatible) |
https://knowscapes.com/api/v1/models | list the agents a key may use |
https://knowscapes.com | interface for configuring agents, knowledge bases and sources |
The API is OpenAI-compatible so that existing clients work without modification.
Each API key is bound to exactly one agent.
1.2 Plans
Which plans exist, what they include and what they cost is published in the plan
overview at knowscapes.org/pricing. The version
published when you order is the one that applies to your contract; see § 1(6) of
the General Terms and Conditions. In short:
Community (free). Accessed with a free key. One primary website and one
additional document as knowledge sources. Replies are generated on capacity we
fund, within the Community usage limits; you need no model provider of your own.
The plan is intended for a chat assistant answering visitor questions on a real
website. No contract within the meaning of the General Terms and Conditions
arises; the Terms of Use apply,
together with this annex.
Professional and Business (paid). Larger knowledge bases; Business adds
connected sources with scheduled updates (section 1.7). On these plans you
connect your own AI provider (section 1.5): both the processing of your
knowledge sources (ingestion) and the answering of requests run through that
provider, and its charges are billed to you by the provider.
Enterprise (paid). Everything in Business, with daily updates of connected
sources and a choice of processing mode (section 1.4), including processing
exclusively on our own servers in Germany.
Paid subscriptions are monthly or annual, as you choose at order time. Both
are terminable at any time; termination takes effect at the end of the current
billing period — the end of the month for a monthly subscription, the end of the
twelve-month term for an annual one, which then runs to that date. The General
Terms and Conditions apply.
All plans address the same endpoints.
1.3 Allowances
The allowances in force are published separately — for the Community plan at
knowscapes.org/free-key-limits, for
paid plans in the plan overview at
knowscapes.org/pricing. They are published
there rather than here so that they can be adjusted without changing this annex.
For free access we announce changes in accordance with section 2.2 of the Terms
of Use; for a running paid contract, § 1(6) of the General Terms and Conditions
applies, so a change to those pages does not alter what you already bought.
Document allowances count the distinct documents processed into a knowledge base,
cumulatively. Updating a document does not count again; deleting a source file or
a connection does not release capacity (see section 1.8).
When an allowance is exhausted the service stops answering until the next period.
Nothing is lost in the meantime: settings, agents and keys are untouched, and the
service resumes by itself once the allowance is available again.
The Community plan is meant for the visitors of one website. We may throttle or
suspend a free key whose use clearly goes beyond that — for example automated
bulk requests, use as a back end for other services, or resale of access — and
will tell you by e-mail.
1.4 Processing modes
Where your knowledge sources are processed (ingestion) and where requests are
answered depends on your plan and, on Enterprise, on the mode you select:
| Plan / mode | Answering requests | Ingestion of knowledge sources | Personal data in knowledge sources |
|---|---|---|---|
| Community, without your own provider | our own servers in the EU/EEA | external providers selected by us (Part 2) | not permitted |
| Professional, Business | your own AI provider (1.5) | your own AI provider (1.5) | not permitted |
| Enterprise — internal Germany | our own servers in Germany | our own servers in Germany | permitted (Part 2) |
| Enterprise — routed, EU | our own servers in the EU/EEA; on your selection, providers in the EU/EEA via our routing | providers in the EU/EEA via our routing | not permitted |
| Enterprise — routed, worldwide | our own servers in the EU/EEA; on your selection, providers worldwide via our routing | providers worldwide via our routing | not permitted |
| Any plan, with your own provider | your own AI provider (1.5) | your own AI provider (1.5) | not permitted |
In the internal Germany mode, ingestion and answering both run on our own
hardware in Germany, and no content, prompts, retrieved context or replies are
sent to any external AI provider. It is the only mode in which knowledge sources
may contain personal data. Using it is your choice; no Enterprise customer is
required to use it.
In the routed modes, answering stays on our own servers in the EU/EEA by
default. You can switch an agent to answer through our routing as well; requests
of that agent, including your end users’ messages, are then processed by the
providers named in Part 2. Only switch this on after reading Part 2, section 2.1,
“Processing location”.
A mode applies per knowledge base and agent as configured in the interface.
1.5 Your own AI provider
In the KnowScapes interface you can assign an agent your own access to an
external AI provider — your own API key with Anthropic, OpenAI or OpenRouter,
for example. On Professional and Business this is how the service works; on
Community and Enterprise it is optional.
If you use this:
- ingestion and requests of that agent are forwarded to the provider you chose,
on your instruction and on the basis of your contract with them; - that provider is not our sub-processor but a recipient you chose;
- you settle that provider’s charges directly with them; our allowances for AI
processing do not apply to those requests, and we charge nothing for
forwarding them; - we have no influence over its availability, processing location, retention
periods or use of the data — including whether it uses inputs for training —
and can make no statement about them.
1.6 AI-generated replies, and what is not owed
Replies are generated automatically by language models from your knowledge base
and the model’s general knowledge. They can be incomplete or wrong, even where
your sources are correct.
- You are responsible for checking replies before relying on them, and for not
deploying the service for decisions with legal or similarly significant effect
on individuals. - Where third parties interact with an agent — visitors of your website, for
example — you are responsible for informing them that they are communicating
with an AI. The WordPress plugin “KnowScapes AI Client” shows such a notice by
default; you may adapt its wording but not remove it. If you use the API
directly, provide an equivalent notice yourself.
Not owed: the creation, maintenance or extension of knowledge sources; the
factual accuracy of individual replies; a particular availability (see section
3.2 of the Terms of Use); and a particular response time. § 11 of the General
Terms and Conditions and section 9 of the Terms of Use remain unaffected.
1.7 Connected sources
On plans that include them, you can connect external storage — for example a
cloud drive or an SFTP server — as a source for your knowledge base. The
connection types offered are shown in the interface and may change.
- You choose and set up each connection yourself, and you need your own account
with the storage provider under its own terms. That provider is not our
sub-processor; the storage location and terms of your files there stay as
they are. - We fetch the files you select at the interval of your plan and process only new
or changed content. - The access credentials you enter (for example access tokens, passwords or keys)
are stored encrypted, used only to fetch your selected files, and deleted when
you remove the connection. - Fetched files are treated like uploads: section 1.8 and Part 2 apply.
1.8 Knowledge bases, sources and deletion
A knowledge base is built from your sources — your primary website, uploaded
documents and connected sources. Ingestion turns their content into a knowledge
graph. Two consequences follow, and they matter:
- A knowledge base can only be deleted as a whole. The account holder can
delete a knowledge base at any time; we then delete the knowledge graph and
everything derived from it, and any retained original files, immediately. - A single source cannot be removed from a knowledge base. Once a document has
been processed, its contribution is part of the graph. Deleting the source file,
or removing a connection, stops future updates from it but does not remove what
was learned from it, and does not release document capacity. To remove a
document’s content, delete the knowledge base and rebuild it without that
document.
Original files. By default we delete an uploaded or fetched file as soon as
its ingestion is complete; only the knowledge graph is kept. You can choose to
retain original files — so that replies can refer to them — in the interface; they
are then stored with the knowledge base and deleted with it at the latest.
When your access ends, we delete all knowledge bases, retained files and derived
data. Deleted data is removed from our backups when they are overwritten in the
regular backup cycle.
Part 2 — Privacy details
This part supplements the Privacy Notice for Services. Its sections 1 to 7 apply;
only the details specific to KnowScapes are set out here.
2.1 As processor: content entered by your end users
What reaches us
With every request through the API:
- the text of the current message;
- the preceding messages of the same conversation (the WordPress plugin limits
these; in its current version, at most the last 20, each truncated to 4,000
characters); - the system prompt you configured;
- if you switched on the “page context” feature in the plugin: the title, address
and text of the published page the visitor is reading, limited to the
character count you set; - the agent identifier and the reply-length cap;
- your API key as authorisation.
What does not reach us
When the service is used through the WordPress plugin, your server makes the
request, not your visitor’s browser. We therefore do not receive: the visitor’s
IP address, their browser, their referrer, their user ID, their name, their
e-mail address, or any cookie. We set no cookies in your visitors’ browsers and
receive none.
The plugin itself stores no conversations, creates no tables and writes no
visitor identifier; there, a conversation exists only in the visitor’s browser.
Processing location
Unless you select otherwise (section 1.4), requests and conversations in the
interface are processed on hardware we operate ourselves, entirely within the
EU/EEA:
- servers on our own premises in Germany;
- dedicated servers we rent at the data centre locations of Hetzner Online GmbH
in Nuremberg and Falkenstein (Germany) and Helsinki (Finland).
Finland is a member state of the European Union, so no transfer to a third
country takes place at any of these locations. In the internal Germany mode,
only the locations in Germany are used.
Requests leave this infrastructure only
- when the agent uses your own AI provider (section 1.5) — on Professional and
Business always; or - on Enterprise, when you switch an agent in a routed mode to answer through our
routing (section 1.4). Your end users’ messages are then processed by OpenRouter
and the providers listed under “Knowledge sources” below — in the EU/EEA in
the routed EU mode, worldwide in the routed worldwide mode. For this processing
they act as our sub-processors under the data processing agreement, which also
sets out the safeguards for any transfer to a third country. Inform your end
users accordingly in your own privacy notice before you switch this on.
Sub-processors
| Provider | Seat | Purpose | Processing location |
|---|---|---|---|
| Hetzner Online GmbH | Gunzenhausen, Germany | operation of dedicated servers | Nuremberg, Falkenstein (DE), Helsinki (FI) |
This is the complete list of sub-processors for content your end users enter and
for data we store for you, except where you switch on answering through our
routing (above). No analytics, advertising, content delivery or error-tracking
service is involved, and no external mail service: service e-mails, including the
one carrying a free key, are sent from our own mail server on the infrastructure
named above.
Servers on our own premises involve no further provider; physical access control
there is ours.
The processors named in our
general privacy notice relate
to visits to our websites and are not involved in this service.
Once a service e-mail has left our mail server it is delivered to the mail
provider of the address you gave us. Which provider that is, and how it handles
the message, is your choice and outside our control — worth knowing because the
install link in a key e-mail carries the key itself.
Training and further processing
We do not use content to train or improve models and do not process it further.
Where we route content to external providers ourselves — on Community and in the
Enterprise routed modes — we use only providers that do not use inputs to train
or improve models. For your own AI provider (section 1.5) this is governed by
your contract with that provider.
Retention of conversation content
Three cases, and they are different. Which one applies depends on how the service
is deployed, not on a setting we choose.
1. Requests through the API — not stored by us. Where KnowScapes answers
through the API, as it does for a website chat assistant, the content of the
request is processed in memory to generate the reply and then discarded. Message
text, conversation history and page context are not written to storage by
us, not kept for diagnostics and not retained in any form. This is the case that
applies to every deployment of the “KnowScapes AI Client” WordPress plugin. Where
a request is answered by an external provider (above), that provider’s retention
applies to it in addition.
2. Your own conversations in the KnowScapes interface — kept for you, with a
period you set. Conversations an account holder conducts in the interface are
kept searchable for that account holder. You set the period:
| Setting | Meaning |
|---|---|
| 30 days | shortest retention |
| 90 days | default |
| 365 days | longest automatic retention |
| “until I delete them” | no automatic deletion; deletion only by you, or when your access ends |
After the period you set has elapsed we delete the conversations automatically.
Independently of that you can delete individual conversations or the entire
history yourself at any time. When your access ends we delete the history in
full.
3. Internal deployments where you ask for retention. For internal use — a due
diligence data room, for instance — retaining conversations may be what you want.
We enable it on your documented instruction, and then:
- you decide which conversations are retained and for how long;
- you remain the controller. Informing the people who use your deployment, and
describing the retention in your own terms and privacy notice, is yours to
do — we cannot do it for you, because we do not know who your users are or what
you told them; - the instruction and the agreed period are recorded in the data processing
agreement, so that both sides can show what was agreed; - this is never switched on by default, and never for the API case in point 1.
In none of the three cases is content used to train or improve models, and in
none is it processed further by us. Retention in cases 2 and 3 serves only to let
the intended people find a conversation again.
Knowledge sources
Knowledge sources are the pages of the website you register, the documents you
upload and the files fetched from connected sources. The permitted file types and
sizes are shown in the interface and in the plan overview. The resulting
knowledge graph, and any original files you chose to retain, are stored on our
own infrastructure in the EU/EEA — in the internal Germany mode, in Germany.
Personal data. Knowledge sources may contain personal data only in the
Enterprise internal Germany mode. In every other mode — Community, Professional,
Business, the Enterprise routed modes, and any agent using your own AI provider —
knowledge sources must not contain personal data, for example no names,
contact details or other information about identifiable people. You are
responsible for complying with this, including for the content of connected
sources. For website pages this means: exclude pages that contain personal data
— team or staff pages, author profiles, your imprint — from the pages to be
indexed.
Community. Ingestion is carried out by external providers we select, in
particular via OpenRouter, Inc., currently restricted to a selection of providers
we consider trustworthy. Because the Community plan is free, we do not commit to
particular providers or processing locations; they may be outside the EU/EEA and
may change without notice. We do commit that only providers that do not use
inputs to train or improve models are used. Providers may retain inputs and
outputs temporarily under their own policies, typically for up to 30 days, for
example to detect abuse; do not use the Community plan for sources whose
confidentiality does not permit this.
Professional and Business. Ingestion runs through your own AI provider
(section 1.5); we do not involve any provider of our own.
Enterprise, internal Germany. Ingestion takes place exclusively on our own
servers in Germany. No external AI provider is involved. Knowledge sources may
contain personal data; you are the controller for them and we are your
processor; section 3 of the Privacy Notice for Services and the data processing
agreement apply. Because a single document cannot be removed from a knowledge
base (section 1.8), a request to erase one person’s data from a knowledge base is
met by deleting the knowledge base and rebuilding it; plan your sources with
this in mind.
Enterprise, routed. Ingestion is carried out via OpenRouter, Inc., routed only
to the providers listed below — in the routed EU mode only to those that process
in the EU/EEA. Only providers that do not use inputs to train or improve models
are used. Providers may retain inputs and outputs temporarily under their own
policies, typically for up to 30 days. We announce changes to this list to
Enterprise customers in advance, as set out in the data processing agreement.
| Provider | Seat | Processing location (as stated by the provider) |
|---|---|---|
| OpenRouter, Inc. (routing) | New York, USA | USA |
| DeepInfra, Inc. | Palo Alto, USA | USA |
| CoreWeave, Inc. | Livingston, New Jersey, USA | USA, Europe |
| Parasail, Inc. | San Mateo, USA | USA, EU and other countries |
| Crusoe Technologies LLC | USA | USA |
| Fireworks.ai, Inc. | USA | USA |
| Together Computer, Inc. | USA | North America |
| Nebius B.V. | Schiphol, Netherlands | various regions |
| DigitalOcean, LLC | Broomfield, Colorado, USA | USA and other regions |
| OpenAI Ireland Ltd / OpenAI OpCo, LLC | Dublin, Ireland / San Francisco, USA | USA |
| Anthropic Ireland, Limited / Anthropic PBC | Dublin, Ireland / San Francisco, USA | worldwide |
The same selection is currently used for the Community plan, for information
only and without commitment.
Deletion. See section 1.8: knowledge bases are deleted as a whole; original
files are deleted after ingestion unless you chose to retain them, and with the
knowledge base at the latest; everything is deleted when your access ends.
2.2 As controller: data about you
Requesting a free key (Community plan)
Transmitted and processed, through the WordPress plugin or our website:
| Data | Purpose |
|---|---|
| e-mail address | delivering the key, queries, notices about this key |
| URL of the website | attributing the key, spotting repeat requests |
| name of the website | salutation and attribution in the e-mail |
| address of the plugin settings page | so the e-mail can carry a button that installs the key on exactly that site |
Legal basis: Art. 6(1)(b) GDPR.
The request never happens automatically. In the plugin it requires an
administrator to tick a box naming precisely this transmission and to press a
button. The key itself is never part of the HTTP response; it arrives by e-mail.
Retention: for as long as the key is active. After twelve months without use we
delete the key and the associated e-mail address and website details.
Usage counters
Per key: the time of last use, the number of requests and the token consumption
in the current period, the number of failed or rejected requests, and a daily
history of these figures. We keep the daily history for 13 months. Legal basis:
Art. 6(1)(f) GDPR; our legitimate interest is enforcing allowances, defending
against abuse and capacity planning. Server logs with IP addresses are covered in
section 4.2 of the Privacy Notice for Services.
Agents, knowledge bases and connections
The agents, knowledge bases and connections you set up we store for as long as
your access exists, or until you delete them — that is the purpose of the
service.
Part 3 — What this annex does not cover
- Prices and plans — see the plan overview at
knowscapes.org/pricing. - The data processing agreement under Art. 28 GDPR — a separate document,
available on request at contact@xplicator.com. - The WordPress plugin “KnowScapes AI Client” is free software under the GPL
and is not the subject of this annex.