Knock2 identifies the companies and individuals visiting your website, so your privacy policy should disclose it. This article provides language you can add directly to your policy, along with answers to the questions we are asked most often. For most customers a single paragraph is sufficient. Additional detail is provided below for those who need it.
This article offers general guidance and does not constitute legal advice. Your legal counsel should make the final determination on what applies to your business.
1. Suggested privacy policy language
Two versions are provided below. The short version is appropriate if you need a single paragraph to add to an existing section. The expanded version provides a fuller disclosure, which is what an enterprise security review will typically look for.
Please replace the bracketed placeholders before publishing.
Short version
This can be added to your "Cookies and Tracking Technologies" or "Information We Collect" section.
We use Knock2, a website visitor identification service, to understand which businesses and, in some cases, which individuals visit our website. When you visit, Knock2 collects your IP address, the pages you view and the time you spend on them, your browser and device information, the website or campaign that referred you, and any campaign parameters in the URL. Knock2 stores a first-party identifier in your browser so that return visits can be recognized. Knock2 matches this information against its own and third-party business data sources to identify the organization associated with your visit and, where available, business contact information such as name, job title, business email address, and LinkedIn profile. We use this information for sales and marketing purposes, including to contact you about our products and services. Knock2 processes this information on our behalf under a written data processing agreement, and you can read Knock2's privacy policy at https://www.knock2.ai/privacy-policy. To ask us to stop, or to request access to or deletion of your information, contact us at [privacy@yourcompany.com]. |
Expanded version
These can be used as standalone subsections, or incorporated into the equivalent sections of your existing policy.
Website visitor identification
We use a website visitor identification service provided by Knock 2 AI LLC ("Knock2") to identify the organizations and, where available, the individuals who visit [www.yourcompany.com]. This helps us understand who is interested in our products, prioritize our sales outreach, and measure our marketing. |
Information collected automatically
When you visit our website, Knock2 collects on our behalf: your IP address; the pages you visit, the order in which you visit them, and the time you spend on each; your browser type, version, and device information; the referring website or source; and any campaign parameters contained in the URL you arrived through (for example utm_source and utm_medium). Knock2 also stores a randomly generated identifier in your browser's local storage so that repeat visits from the same browser can be associated with one another. Knock2's script also loads identification technology provided by its data partners, which may store or read information on your device. |
Information we obtain from third parties
We obtain information about visitors to our website from Knock2 and its data providers, including business contact information such as name, job title, employer, business email address, telephone number, professional social media profile, and general location. This information is derived from commercially available business data sources and is matched to your visit. We may combine it with information you provide directly to us and with information already held in our customer relationship management system. |
How we use this information
We use this information to identify prospective customers, to contact you about our products and services, to personalize our marketing, to route enquiries to the appropriate member of our team, and to analyze how our website performs. [If you use Knock2 to build advertising audiences, add: We may also use it to build audiences for advertising on third-party platforms.] |
Legal basis (include if you serve visitors in the EU, UK, or Switzerland)
Where the GDPR or UK GDPR applies, we rely on your consent, obtained through our cookie banner, to store and access information on your device and to carry out visitor identification. Where we process the resulting information for direct marketing to business contacts, we rely on our legitimate interest in promoting our products to relevant organizations, balanced against your rights and interests. You may withdraw consent or object to this processing at any time by contacting [privacy@yourcompany.com]. |
Who we share it with
We share this information with Knock2, which acts as our processor and service provider under a written data processing agreement, and with the customer relationship management, sales engagement, and communication tools we use to manage our sales process. A description of Knock2's own service providers is available at https://www.knock2.ai/subprocessors. |
How long we keep it
We retain visitor identification data for as long as we have a legitimate business need to do so, and then delete it or de-identify it. [Add your own retention period if your policy states specific periods elsewhere.] |
Your choices
You can ask us to stop identifying you and to delete the information we hold about you by contacting [privacy@yourcompany.com]. Knock2 honors the Global Privacy Control signal automatically, so if your browser sends it, you will not be identified as an individual. [If you run a consent banner, add: You can also change or withdraw your consent at any time through the cookie preferences link in the footer of our website.] You can prevent most of this collection by using your browser's private browsing mode, by clearing your browser's site data, or by using a tracking-blocking browser extension. |
For a cookie or tracking table
If your cookie policy is presented as a table, the following row can be added:
Name | Provider | Type | Purpose | Duration |
Knock2 visitor identifiers | Knock2 (knock2.ai) | First-party browser storage ( | Recognizes returning visitors and links page views into a single visit for visitor identification and analytics | Persistent until browser storage is cleared |
Within a consent management platform, Knock2 should be categorized as Analytics or Performance rather than Strictly Necessary, as it is not required to deliver your website.
2. What Knock2 collects
The table below sets out what the Knock2 script collects, should you need to verify the language above or respond to a question from your legal team.
What | Details |
IP address | Captured server-side and used to identify the company the visit came from |
Page URLs and navigation | Which pages were viewed, in what order, and how long was spent on each |
Browser and device information | User agent string |
Referrer | The page or source that sent the visitor to you |
UTM parameters | Campaign attribution values in the URL (utm_source, utm_medium, utm_campaign, and so on) |
Browser storage identifiers | Knock2 writes first-party identifiers to |
Two details are worth noting when drafting your disclosure:
Knock2 uses browser
localStoragerather than a traditional cookie. If your cookie policy is presented as a cookie table, Knock2 should still be listed there and described as browser storage. EU and UK rules cover the storing or reading of any information on a visitor's device, not cookies alone.The script also loads identification technology provided by our data partners, which may store or read information on the device. Knock2 should therefore be described as involving third-party technology rather than as purely first-party. If you operate a strict content security policy, or a consent platform that blocks unrecognized scripts, please contact support@knock2.ai and we will provide the domains to allowlist.
Knock2 then returns the company associated with the visit (name, domain, industry, size, location, and technology stack) and, where available, business contact details for an individual (name, job title, business email address, phone number, and LinkedIn profile). The second category is worth reflecting in your policy: you are not only collecting data from your visitors, you are also obtaining data about them from third-party providers.
3. What Knock2 handles automatically
The following requires no configuration on your part:
Global Privacy Control
Certain browsers and privacy extensions send a GPC signal, which is a standing request not to have personal information sold or shared. Knock2 honors this signal automatically. For a visitor sending GPC, we do not identify the individual, and no contact is created or delivered to you. Company-level identification continues to run, so you will still see that an organization visited.
What Knock2 does not do
The following is often useful when completing security questionnaires:
Knock2 does not capture keystrokes, search terms, or the contents of form fields.
Knock2 does not record sessions or replay screens.
Your visitor data is not forwarded to third-party advertising or analytics platforms. It is sent to Knock2 and to the destinations you configure.
Knock2 is a business identification product. It does not identify consumers at home addresses for consumer marketing.
Your account and contact data is isolated. Other Knock2 customers cannot see your visitors, page view history, lead scores, or any other data specific to your workspace.
4. Responding to a removal request
If a visitor contacts you asking to be removed or to stop being tracked, there are two steps:
Address your own systems first. Remove or suppress the individual in your CRM and sales engagement tools. Knock2 cannot reach into your CRM to remove records that have already been synced there.
Contact support@knock2.ai with their email address, along with their name and company if available. We will suppress the individual so that they are not identified or delivered to you again. Suppression applies across all of Knock2 and does not expire.
When responding to the visitor, the accurate statement is that their information has been suppressed and will no longer be collected or shared. If you require something more specific for your records, such as a formal response to a request under the GDPR or CCPA, please let us know and we will confirm the status in writing.
5. International traffic and consent banners
For most US-focused websites, a clear privacy policy disclosure is what is expected, and no consent banner is required. If a meaningful share of your traffic originates in the EU, UK, or Switzerland, those frameworks do require opt-in consent before a tool such as Knock2 loads. The most straightforward approach is to deploy Knock2 through your consent management platform so that it fires only after a visitor accepts. Our CMP deployment guide covers OneTrust, Cookiebot, Osano, and Google Tag Manager. Setup typically takes about fifteen minutes.
FAQ
Do I need to name Knock2 in my privacy policy, or can I describe it generically?
A generic description ("a website visitor identification service") is acceptable, and some companies prefer this. We recommend naming Knock2 directly. It is more transparent, and it gives the reader a source to consult for further detail.
Does Knock2 honor Global Privacy Control signals?
Yes, automatically, and no configuration is required on your part. A visitor sending GPC is not identified as an individual, although company-level identification continues to run.
Does Knock2 honor Do Not Track?
No. The Do Not Track standard was abandoned before it was finalized, no law requires that it be honored, and the major browsers have discontinued support for it. Global Privacy Control is the signal that carries legal weight, and Knock2 honors it.
We push Knock2 data into an advertising platform. Does that change anything?
It can. Using visitor data for your own sales outreach is treated differently from sharing it with an advertising platform to build audiences, which carries its own disclosure requirements under California law. We recommend confirming the specifics with your legal counsel.
Do I need to list Knock2 as a subprocessor?
If you process personal data on behalf of your customers and Knock2 touches that data, then yes. For most Knock2 deployments this is not the case, as the visitor data is yours as a controller. If your own contracts require you to list every vendor that processes personal data, Knock2 should be included.
Can I get your DPA?
Yes. Please contact support@knock2.ai and we will provide it.
We have received a security questionnaire that asks about Knock2. Who should we send it to?
Please send it to support@knock2.ai and we will complete the sections relating to Knock2.
Reference links
Questions?
Please contact support@knock2.ai and we will help you arrive at the right wording for your situation.
This article provides general guidance and does not constitute legal advice. Privacy law varies by jurisdiction and changes frequently. Please have your legal counsel review your privacy policy before publishing.