Knovara

Privacy notice

Last updated September 2026

Who we are

Knovara is a software product operated by FirmsNest Software Labs Pvt Ltd ("FirmsNest", "we", "us"), K-359 Sector K, Aashiyana, Near Emerald Mall, Lucknow 226012, India. This notice explains how personal data is handled by the Knovara product and by this website, knovara.app.

Knovara is deployed for each customer organisation as a dedicated installation used from Microsoft Teams. When an organisation uses Knovara, that organisation is the data fiduciary (controller) of its employees' and documents' personal data, and FirmsNest processes that data on the organisation's instructions as its processor. For this website, and for the contact details of people who write to us, FirmsNest is the data fiduciary.

Data we process — the Knovara product

  • Sign-in data. Your Microsoft 365 identity (name, user identifier, tenant identifier) as issued by your organisation's Microsoft Entra ID. Knovara stores no passwords and holds access tokens only for the request that uses them.
  • Questions and answers. The questions you ask and the answers Knovara gives, kept as conversation context for follow-up questions for a bounded period.
  • Document references. Identifiers of the SharePoint documents and list items used to answer a question (site, item identifier, version), so that access can be re-checked later. Document text itself is not stored in Knovara's database, logs or analytics.
  • Audit records. Who asked what, when, which sources were used, and what was changed, including its outcome. These records are kept free of document text and secrets.
  • Usage counts for the organisation's monthly ceiling.

Knovara reads documents only through the signed-in person's own Microsoft 365 permissions, at the moment of the request. It cannot access anything that person cannot already open, and it does not build a copy of your document library.

Data we process — this website

This website does not require an account and does not use advertising cookies. Our hosting provider records standard server logs (IP address, user agent, pages requested) for security and reliability. If you write to us at support@knovara.app, we keep your message and contact details to reply and to follow up about Knovara.

Where data lives

The Knovara product runs in a dedicated deployment in the customer organisation's own cloud account and chosen region. Product data (the sign-in data, conversation context, document references, audit records and usage counts above) is stored and processed there, under the organisation's control. FirmsNest operates the deployment on the organisation's behalf and has access only as needed to run and support it.

AI processing happens through the model service inside the customer's cloud account (for example Amazon Bedrock in the customer's AWS account, or Azure OpenAI in the customer's Azure subscription). Prompts and document content are sent to that in-account service to generate an answer; they are not sent to a model service that FirmsNest operates for multiple customers.

This website is hosted on Vercel. FirmsNest is an Indian company and handles personal data consistently with the Digital Personal Data Protection Act, 2023.

Service providers

We use a small number of providers strictly to deliver Knovara and this website, each bound to process data only on instructions:

  • Your cloud provider (Amazon Web Services or Microsoft Azure), under the customer organisation's own account, for hosting the Knovara deployment and the model service.
  • Microsoft — Microsoft 365, Teams, SharePoint and Entra ID, under the customer organisation's own Microsoft agreements. The Teams bot channel is delivered through Azure Bot Service.
  • Anthropic Claude models, accessed through the in-account model service above. Under the applicable provider terms, customer content is not used to train these models.
  • Vercel — hosting for this website.

How we protect it

  • One isolated deployment per customer: no shared database, no shared model endpoint between customers.
  • Delegated, per-person access to Microsoft 365; no standing service account with access to documents.
  • Encryption in transit and at rest; secrets kept in the cloud provider's secret manager and injected at runtime.
  • Every change to a document or list is previewed, confirmed by the person, re-authorised at the moment of the change, and recorded.
  • Content retrieved from documents is treated as data, never as instructions to the assistant.

Retention

Conversation context is kept for a bounded period to support follow-up questions, then discarded. Audit records and document references are retained for as long as the customer organisation's agreement requires, and are exported or deleted on the organisation's instruction at offboarding. Website server logs are kept for a short operational period. Messages sent to us are kept for as long as needed to respond and follow up.

Your rights

Under the Digital Personal Data Protection Act, 2023, you may request access to, correction of, or erasure of your personal data, and may nominate another person to exercise these rights. Because each customer organisation controls the personal data processed in its Knovara deployment, requests about product data are handled with and through that organisation. For this website, or if you are unsure whom to ask, write to our grievance contact at support@knovara.app; we will respond within the timelines the Act prescribes.

Changes to this notice

We may update this notice as the product and the law evolve. Material changes are reflected in the "last updated" date above, and significant changes are notified to customer organisations.

Contact

FirmsNest Software Labs Pvt Ltd
K-359 Sector K, Aashiyana, Near Emerald Mall, Lucknow 226012, India
support@knovara.app

See also the Terms of use and the security and deployment details.