Privacy Policy

Last updated: March 31, 2026

This Privacy Policy explains how KOLO.io LTD (“KOLO”, “we”, “us”) collects, uses and protects your personal data when you use the KOLO application and related services (“Service”). We comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA) and other applicable data-protection laws.

1. Data Controller

KOLO.io LTD
124 City Road
London, EC1V 2NX
United Kingdom
Contact: contact@trykolo.io

2. Data we collect

  • Account data: name, email, password (hashed), optional phone number, preferred language.
  • Prospect data: names, phone numbers, notes and project details that you voluntarily add about your own real-estate prospects. You are the Data Controller for this data.
  • Usage data: screens visited, features used, approximate country derived from IP address, device type and operating system.
  • Payment data: processed directly by Stripe (web) or Apple (iOS StoreKit). We never receive or store full card numbers or banking details.

3. Contacts permission (iOS / Android)

When you add a new prospect, you may choose to import a single contact from your device's address book using the native iOS/Android Contact Picker. Your address book is never read in bulk, never uploaded to our servers, and never shared with third parties. Only the contact you explicitly select is read locally into the prospect form (name, phone number), where you can review and edit it before saving.

4. How we use your data

  • Provide, operate and improve the Service.
  • Generate AI suggestions to help you manage your prospects (prompts are sent to our AI providers — see section 7).
  • Process subscriptions and prevent fraud.
  • Communicate service-related notices (sign-up confirmation, password reset, receipt, weekly digest if enabled).
  • Comply with legal obligations (tax, anti-fraud).

5. Legal bases (GDPR / UK GDPR)

Contract performance (providing the Service), legitimate interest (security, service improvement), consent (optional marketing) and legal obligation (accounting, tax).

6. Hosting & Data retention

All data is hosted on secure servers located in France, on a sovereign, encrypted cloud environment. Data is encrypted in transit (TLS 1.2+) and at rest. Passwords are hashed using bcrypt.

Account and prospect data are retained as long as your account is active. Upon account deletion (Settings → Delete my account), your personal data and prospect data are permanently erased within 30 days, except where retention is required by law (invoices: 10 years).

7. Subprocessors

We rely on the following vetted subprocessors:

  • MongoDB Atlas — database hosting (EU region)
  • Stripe — web payment processing
  • Apple Inc. — iOS In-App Purchases
  • Anthropic, OpenAI — AI suggestions (data is processed transiently, not used for model training)
  • Resend / Brevo — transactional emails

All subprocessors are bound by Data Processing Agreements and, where applicable, EU Standard Contractual Clauses or UK International Data Transfer Agreement.

8. Your rights

Under GDPR, UK GDPR and CCPA you have the right to access, rectify, erase, export and object to the processing of your data, and to withdraw consent at any time. Exercise these rights by contacting contact@trykolo.io. You also have the right to lodge a complaint with your local supervisory authority (ICO in the UK, CNIL in France, or your local EU authority).

9. Data we never sell or share

KOLO does not sell your data, does not exploit it for commercial purposes, and does not share it with third parties for marketing or resale.

10. Children

KOLO is not directed to children under 16. We do not knowingly collect personal data from children. If you believe we have, contact us at contact@trykolo.io.

11. Changes

We may update this Policy. Material changes will be communicated in-app or by email at least 14 days before taking effect.

12. Contact

Email: contact@trykolo.io

© 2026 KOLO.io LTD. All rights reserved.