Legal

Privacy Policy

How Kolo, a product of LimTC, collects, uses, shares and protects personal data across the Kolo website and platform, and your rights under GDPR and Ukrainian data protection law.

Last updated: 14 July 2026

This Privacy Policy explains how personal data is collected, used, shared and protected in connection with the Kolo website at kolohr.com and the Kolo platform at app.kolohr.com (together, the “Service”). Kolo is operated by LimTC, a company registered in Ukraine [full legal entity name, EDRPOU registration number and registered address to be completed] (“LimTC”, “we”, “us”). Please read it alongside our Terms of Service.

1. Our role: controller and processor

Our responsibilities depend on how you use Kolo:

  • As a data controller. When you visit our website, request a demo, or create and administer an account, we determine how your account, contact and billing data are used, and we act as the controller of that data.
  • As a data processor. When a customer organisation uses Kolo to manage its own people (for example employee profiles, absence, wellbeing check-ins, expenses, assets and recruitment records), that organisation is the controller of that personal data and we act as a processor, handling it only on the customer’s documented instructions under a Data Processing Agreement (DPA).

If your employer uses Kolo and you have questions about how your personal data is handled, please contact your employer in the first instance, as they control that data.

2. Information we collect

Information you provide

  • Account and contact data: name, work email, company, job role, and password.
  • Customer content: information customers enter about their people, such as profiles, roles, documents, time off, wellbeing and mood check-ins, assets, budgets and expenses, recruitment records, and messages. We process this on the customer’s behalf as a processor.
  • Communications: details you send us through demo or quote requests, the contact form, or support.

Information collected automatically

  • Usage and device data: IP address, browser type, device information, pages viewed, and timestamps.
  • Cookies and similar technologies (see section 3).

Payment information

Payments are processed by our payment provider, LiqPay (operated by JSC CB PrivatBank). We do not collect or store full card numbers; we receive only limited transaction confirmation data needed to manage subscriptions.

3. Cookies and analytics

We use essential cookies to operate the Service and analytics cookies to understand how the website is used. Website analytics are provided by Google Analytics (GA4). You can control or block cookies through your browser settings and, where presented, through our cookie preferences. Blocking some cookies may affect how the website works.

4. How we use information and our legal bases

Where we act as controller, we rely on the following legal bases under the EU General Data Protection Regulation (GDPR) and applicable Ukrainian law:

  • To provide and operate the Service — performance of a contract.
  • To respond to enquiries and demos — pre-contractual steps and our legitimate interests.
  • To secure the Service, prevent fraud and improve our products — our legitimate interests.
  • To send marketing communications — your consent, which you may withdraw at any time.
  • To meet legal, tax and accounting obligations — compliance with a legal obligation.

Where we act as processor, the legal basis for processing customer content is determined by the customer as controller, and we process it only on their instructions.

5. How we share information and our subprocessors

We do not sell personal data. We share it only as needed to run Kolo, comply with law, or protect our rights. We use the following trusted subprocessors:

  • Supabase — database, authentication and file storage for platform data.
  • Netlify — website and application hosting and content delivery.
  • Google (Google Analytics) — website analytics.
  • LiqPay / PrivatBank — payment processing.
  • Email and communications providers — transactional and account emails.

We may also disclose data to comply with legal obligations, enforce our agreements, or as part of a merger, acquisition or sale of assets, in each case with appropriate safeguards. A current list of subprocessors is available on request.

6. International data transfers

Some of our subprocessors may process data outside Ukraine or the European Economic Area. Where they do, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and equivalent legal mechanisms, to protect your data.

7. Data retention

We retain account and customer data while an account is active. Following cancellation or termination, data is kept for a limited grace period during which the customer may export it, after which it is permanently deleted, unless a longer period is required to meet legal, tax or regulatory obligations. Website and analytics data are retained in line with our analytics configuration.

8. Security

We apply technical and organisational measures designed to protect personal data, including encryption in transit, access controls, logical isolation of each customer’s data, least-privilege access for our team, and secure hosting infrastructure. No method of transmission or storage is completely secure, but we work to protect data and will notify affected parties and authorities of a personal data breach where required by law.

9. Your rights

Subject to applicable law, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority — in Ukraine, the Ukrainian Parliament Commissioner for Human Rights (the Ombudsman), and in the EU, your local Data Protection Authority.

To exercise rights over data we hold as controller, contact us at hello@limtc.com. If your employer is the controller of your data, please direct your request to your employer.

10. Sensitive and special-category data

Kolo’s wellbeing and mood check-ins, and certain HR records, may involve sensitive information. Where a customer enables and uses these features, the customer, as controller, is responsible for establishing a lawful basis and obtaining any consents required. We process such data only as instructed by the customer.

11. Children

Kolo is a workplace product and is not directed to children. We do not knowingly collect personal data from anyone under 16, except where such data is provided by a customer about an employee and its processing is lawful.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, take reasonable steps to notify you.

13. Contact us

LimTC, [registered address], Ukraine. For any questions about this policy or your personal data, email hello@limtc.com.