Plain-language summary: KolApp uses personal information to provide and secure the platform, manage accounts and subscriptions, support customer-enabled integrations, respond to inquiries, schedule demos, communicate with users, and understand how our website and Services perform. We do not sell personal information for money, use Customer Data for independent advertising, or use Customer Data to train general-purpose AI models.
1. Scope and our privacy roles
This Privacy Policy (the “Policy”) applies to websites, applications, products, support, sales, demo-booking, and related services operated by KolApp LLC that link to this Policy (collectively, the “Services”). “KolApp,” “we,” “us,” and “our” mean KolApp LLC.
“Customer Data” means information, files, content, personal data, project records, schedules, comments, forms, budgets, rates, reports, automation rules, and other materials submitted to or generated within the Services by a customer or its authorized users.
When KolApp determines why and how personal information is processed—such as website analytics, inquiries, account administration, billing contacts, security operations, and direct communications—KolApp acts as a business or data controller.
When an organization uses KolApp to manage information about its employees, contractors, clients, guests, projects, or resources, that organization generally acts as the controller or business and KolApp generally acts as its processor or service provider. KolApp processes that Customer Data according to the customer's documented instructions, including the applicable Terms of Service, any executed Data Processing Addendum, and the customer's authorized configuration and use of the Services.
Workspace administrators determine what Customer Data is submitted, which integrations are connected, who receives access, and how information is used within the workspace. If you want to exercise rights concerning Customer Data in an organization-managed workspace, contact that organization or its workspace administrator first. KolApp will assist the customer as required by applicable law and our agreements.
The Services are designed for businesses and organizations. This Policy does not govern a third party's independent processing through a website, product, or service that KolApp does not control, even when it is linked to or integrated with the Services.
2. Information we collect
The information we collect depends on how you interact with KolApp, the features your organization enables, and the information you or your organization chooses to provide.
Account, organization, and profile information
Name, business email, organization, job role, profile details, profile photo, workspace membership, working hours, business days, time zone, user role, notification preferences, authentication identifiers, MFA status, and account settings.
Project and collaboration information
Projects, tasks, subtasks, milestones, statuses, comments, posts, files, custom fields and forms, dependencies, issues, risks, approvals, updates, documents, attachments, time and effort records, and other information submitted to a workspace.
Resource and scheduling information
Assignments, availability, work hours, time off, workload, utilization, skills, roles, departments, schedules, bookings, business calendars, capacity information, and authorized calendar availability.
Budget and financial project information
Project budgets, rates, cost forecasts, expenses, billable and non-billable time, vendors, materials, cost-to-date, portfolio financial rollups, and related reporting information.
Automation, reporting, and communication information
Automation rules, triggers, execution history, notifications, email templates, report settings, dashboard metrics, KPIs, report recipients, delivery records, subscription preferences, and unsubscribe elections.
Website, inquiry, demo, support, and feedback information
Company name, full name, company size, business email, phone number, message, preferred meeting time, time zone, invited guest emails, current project-management solution, primary use case, team size, purchasing timing, budget range, special requests, support tickets, chat messages, attachments, survey responses, and product feedback. If a call or meeting is recorded or transcribed, KolApp will provide notice and obtain consent where required.
Subscription and transaction information
Plan selection, seat count, subscription status, billing contact, billing address, invoices, transaction identifiers, payment status, payment failures, dunning status, and limited payment-method details returned by the payment processor, such as card brand and last four digits. KolApp does not store complete payment-card numbers, card security codes, or bank-account credentials on its own systems.
Security, audit, device, and usage information
IP address, approximate location derived from IP, browser and device type, operating system, session identifiers and timing, authentication state, login events, MFA status, administrative activity, permission and role changes, record-modification history, referring URLs, pages and features accessed, actions performed, timestamps, suspected security events, and cookie or similar identifiers.
Error, diagnostic, and automated-job information
Exception and error details, affected application component, browser characteristics, user and organization identifiers, session identifier, error reference identifier, timestamps, and scheduled-report or automation execution records such as run time, status, and error message.
Business contact and outreach information
For business-to-business sales and marketing, we may process professional contact information such as name, business email, employer, title, industry, company size, business location, professional profile information, campaign source, communication history, and marketing preferences. Where enabled, business emails may record delivery, opens, link clicks, replies, and unsubscribe activity.
Integration and AI-feature information
If you or your organization enables an integration, we may receive account identifiers, encrypted authorization tokens, availability information, and other information expressly authorized for that feature. If you elect to use an AI-enabled feature, we may process prompts, instructions, selected Customer Data, outputs, feedback, token counts, model information, timestamps, and technical metadata needed to provide and secure the feature.
Unless an applicable Service is expressly designed for the information and KolApp and the customer have completed all required agreements, do not submit protected health information regulated by HIPAA; complete payment-card data; Social Security, government-identification, or financial-account numbers or credentials; passwords, MFA codes, or authentication secrets; biometric or genetic identifiers; precise geolocation; personal information of individuals under 18; classified, controlled, or export-controlled information; or other information subject to heightened legal or contractual restrictions.
3. Sources of information
We collect personal information:
- Directly from you, including when you create an account, submit a form, book a demo, communicate with us, or enter information into the Services.
- From your organization and other users, such as when an administrator creates your account, assigns work, uploads a resource profile, invites a guest, or includes you in a project.
- From connected services that you or your organization authorizes, including calendar, identity, project-management, and productivity integrations.
- Automatically through cookies, analytics tools, logs, pixels, software development kits, and similar technologies.
- From service providers and business partners, such as payment, security, identity, support, communications, and marketing providers.
- From public and professional sources, such as company websites, professional-network profiles, business-contact databases, event registrations, referrals, and marketing partners, for permitted business outreach.
4. How we use personal information
We use personal information to:
- Provide, configure, maintain, secure, and improve KolApp's project-management, scheduling, budgeting, reporting, portfolio, automation, and collaboration features.
- Create and administer accounts, organizations, workspaces, roles, permissions, guest access, plans, seats, subscriptions, invoices, and account changes.
- Authenticate users, support MFA and SSO where enabled, manage sessions, monitor logins, prevent fraud, investigate abuse, and protect the Services.
- Process user instructions, calendar synchronization, integrations, automations, alerts, email summaries, reports, and notifications.
- Respond to support requests, contact inquiries, pricing questions, demonstrations, onboarding, training, and product feedback.
- Analyze website and product usage, diagnose errors, measure feature adoption, test features, and improve performance and usability.
- Conduct permitted business-to-business sales and marketing, personalize relevant outreach, attribute campaigns, measure engagement, and maintain suppression lists.
- Generate aggregated or de-identified statistics, analytics, benchmarks, security insights, and capacity-planning information that do not reasonably identify an individual or customer.
- Provide an AI-enabled feature that a customer elects to use, including generating requested outputs, preventing abuse, measuring consumption, and evaluating feature reliability.
- Comply with legal, tax, accounting, and regulatory obligations; respond to lawful requests; enforce agreements; and establish, exercise, or defend legal claims.
Except as needed to provide, secure, support, or maintain the Services, comply with law, or follow a customer's documented instructions, KolApp does not use Customer Data for independent advertising, sell it to data brokers, or use it to train general-purpose AI models.
5. Legal bases for processing
Where the laws of the European Economic Area, United Kingdom, or another jurisdiction require a legal basis and KolApp acts as controller, we rely on the following as appropriate:
| Legal basis | Typical purposes |
|---|---|
| Performance of a contract | Providing accounts, platform features, integrations, support, subscriptions, and requested demonstrations. |
| Legitimate interests | Securing and improving the Services, preventing misuse, administering business relationships, analyzing performance, conducting permitted business outreach, and defending legal claims. |
| Consent | Optional cookies, certain marketing communications, and integration permissions where consent is required. Consent may be withdrawn at any time without affecting prior lawful processing. |
| Legal obligations | Tax, accounting, regulatory, law-enforcement, and compliance requirements. |
| Vital interests and legal claims | Protecting rights and safety, responding to emergencies, and establishing, exercising, or defending claims. |
Where KolApp acts as processor or service provider, the customer is responsible for determining the legal basis for the Customer Data it submits and the instructions it gives KolApp.
6. Customer Data and workspace controls
Customers decide what Customer Data to submit and are responsible for providing required notices and obtaining required rights, permissions, and consents from employees, contractors, clients, guests, and other individuals whose information is added to the Services.
Workspace administrators may access, export, correct, restrict, or delete Customer Data; manage roles and permissions; review audit activity; manage integrations; designate report recipients; and suspend or delete accounts. An organization's own policies and instructions may also govern its users' access.
KolApp processes Customer Data to perform its agreement with the customer, follow authorized instructions, maintain security and reliability, provide support with appropriate authorization, prevent abuse, comply with law, and perform other processing described in the applicable agreement.
KolApp may generate and use aggregated or de-identified information for analytics, security, capacity planning, service improvement, and business insights, provided it does not reasonably identify the customer or an individual. KolApp will maintain de-identified information in de-identified form and will not attempt to re-identify it except to test whether de-identification controls remain effective or as permitted by law.
Where applicable law requires written processor terms, KolApp and the customer will enter KolApp's then-current Data Processing Addendum upon request. An executed Data Processing Addendum, Order Form, or enterprise agreement controls if it provides stronger or more specific commitments concerning Customer Data.
7. How we disclose information
KolApp may disclose personal information to:
- Your organization, administrators, and authorized users. Workspace information is visible according to configured roles, permissions, sharing settings, and report-recipient designations.
- Service providers and subprocessors. Providers support cloud hosting, data storage, authentication, security, communications, customer support, analytics, payments, scheduling, and other business operations. They may process information only for contracted purposes and subject to applicable safeguards.
- Customer-enabled integrations. When you or your organization enables an integration, KolApp exchanges information as needed to perform the requested connection. The provider's own terms and privacy policy also apply to its independent processing.
- Professional advisers. Lawyers, auditors, accountants, insurers, and other advisers subject to appropriate confidentiality duties.
- Authorities and legal recipients. Where reasonably necessary to comply with law or lawful process, enforce agreements, investigate fraud or security issues, or protect rights and safety. Where legally permitted, KolApp will make reasonable efforts to notify the affected customer before disclosing Customer Data in response to legal process.
- Business-transaction participants. In connection with an actual or proposed merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and legal protections.
- Other parties at your direction or with your consent.
Core infrastructure and application providers
| Provider | Function | Information involved | Typical processing location |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure, application hosting, compute, databases, storage, backups, queuing, secrets management, authentication, logging, and outbound email delivery, as applicable. | Customer Data, uploaded files, account and authentication information, encrypted integration tokens, technical logs, and backups. | United States and applicable AWS regions. |
| Cloudflare, Inc. | DNS, content delivery, TLS termination, DDoS protection, and web-application security, where enabled. | Connection metadata and request content transmitted through the service. | Global edge network. |
| WP Engine, Inc. | Hosting and operation of KolApp's WordPress marketing website, where applicable. | Website request information, device and browser information, logs, and information submitted through hosted pages. | United States and locations used by its service providers. |
Payments, website services, and customer-enabled integrations
| Provider | Function | Information involved |
|---|---|---|
| Stripe, Inc. | Payment processing, subscription billing, invoicing, payment retries, and transaction administration. | Billing contacts, payment method information held by Stripe, transaction information, invoice information, and subscription status. |
| Google LLC | Google Calendar integration when enabled; website analytics, tag management, and maps where used. | For calendar synchronization, account identifiers, encrypted tokens, and free/busy availability. Website services may process browser, device, IP, cookie, page-activity, and location-search information. |
| Microsoft Corporation | Outlook/Microsoft 365 calendar integration when enabled; Microsoft Bookings and Microsoft Clarity where used. | For calendar synchronization, account identifiers, encrypted tokens, and availability. Website services may process booking details, browser, device, IP, cookie, and interaction information. |
KolApp may update its providers as the Services evolve. Information about current subprocessors is available by contacting KolApp through the method in Section 21. Where an executed DPA requires notice of new subprocessors, KolApp will provide notice and an opportunity to object as stated in that DPA.
KolApp does not sell personal information for monetary consideration and does not currently share personal information for cross-context behavioral advertising. If these practices change, KolApp will provide the notice and opt-out mechanisms required by applicable law before the change takes effect.
8. Calendar integrations
When an authorized user connects Google Calendar, Microsoft Outlook, or Microsoft 365, KolApp accesses calendar information only to provide the availability synchronization selected by the user or customer.
KolApp is designed to retrieve, process, and store only availability status and applicable busy-time ranges. KolApp does not use or store event titles, descriptions, attendees, locations, attachments, meeting notes, or other event contents for availability synchronization, even where a provider's required permission may technically permit broader access.
Google Calendar
Where supported by the enabled configuration, KolApp uses Google's narrowly focused free/busy permission, such as https://www.googleapis.com/auth/calendar.freebusy, together with basic authentication permissions needed to identify and maintain the connected account. KolApp's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Microsoft Outlook and Microsoft 365
Microsoft may require a calendar-read permission to provide availability through its scheduling interface. Regardless of the permission label or information technically available from Microsoft, KolApp limits its collection, use, display, and storage for this functionality to availability status, working hours where used, and busy-time ranges.
Tokens, background synchronization, and revocation
KolApp stores access and refresh tokens in encrypted form as needed to maintain an authorized connection and perform background synchronization. Tokens are not shared except with contracted infrastructure providers where necessary to host, secure, or maintain the integration, or as required by law.
An authorized user or workspace administrator may disconnect an integration through available KolApp settings and may also revoke access through the connected provider. After revocation, KolApp stops new retrieval and deletes or deactivates stored tokens, subject to security records and normal backup deletion. Availability information already synchronized into a workspace remains Customer Data and is handled according to customer instructions and Section 11.
KolApp does not use calendar data for advertising, independent profiling, creditworthiness, or general-purpose AI model training. Human access is limited to support requested or authorized by the customer, security or abuse investigations, legal requirements, or permitted processing of aggregated and de-identified information.
9. AI-enabled features
Certain optional features may use third-party AI models to create summaries, suggestions, drafts, analyses, or other requested outputs. When a user invokes such a feature, the relevant prompt, instruction, selected Customer Data, and supporting context may be sent to KolApp's contracted AI provider, and the output is returned to the Services.
Where KolApp uses a contracted AI provider, KolApp does not permit that provider to use Customer Data submitted through the Services to train general-purpose models. Provider retention for security, abuse monitoring, or service administration is governed by KolApp's applicable provider agreement.
KolApp records technical metering information such as the model used, token counts, timestamps, organization identifier, and request status to enforce allowances, administer billing where applicable, monitor reliability, and control costs.
AI output may be inaccurate, incomplete, or unsuitable for a particular purpose. It must be reviewed by an appropriate person before reliance and must not be used as the sole basis for employment, legal, financial, medical, or similarly significant decisions about an individual.
10. Cookies, analytics, and embedded services
KolApp and its providers use cookies, pixels, local storage, logs, and similar technologies to operate the website and Services, remember preferences, secure sessions, understand usage, measure communications, and improve performance.
| Category | Purpose | Choice |
|---|---|---|
| Strictly necessary | Authentication, session management, security, load balancing, fraud prevention, and essential functions. | These cannot generally be disabled without affecting the Services. |
| Functional | Remembering preferences such as time zone, layout, and display choices. | May be disabled with reduced functionality. |
| Analytics | Understanding website and feature usage, diagnosing performance, and improving experience. | Controlled through available cookie settings where required. |
| Marketing and attribution | Campaign attribution, email delivery, opens, link clicks, and permitted business-marketing measurement. | Controlled through available cookie and email preferences. |
Technologies currently used on the KolApp website
- Google Analytics and Google Tag Manager to measure website traffic, page interactions, and campaign performance.
- Microsoft Clarity to understand website usage and improve page experience, which may include session-interaction data.
- Microsoft Bookings to display demonstration availability and process booking information.
- Google Maps to display location information where embedded.
These providers may receive device, browser, IP address, cookie identifier, page activity, and information submitted directly to an embedded service. Where required, non-essential technologies will not activate until consent is provided. Choices may be associated with a particular browser or device and may need to be repeated after clearing cookies.
Most browsers allow users to refuse or delete cookies. Some browsers transmit “Do Not Track” or opt-out preference signals. Because no uniform standard applies to all Do Not Track signals, KolApp's response may vary. Where required by applicable law and technically applicable, KolApp recognizes legally valid opt-out preference signals such as Global Privacy Control for the browser or device sending the signal.
11. Data retention
KolApp retains personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain security and audit records, comply with legal obligations, resolve disputes, enforce agreements, and support legitimate business operations.
KolApp retains Customer Data for the duration of the applicable subscription and for up to ninety (90) days following expiration or termination. No later than the end of that 90-day period, Customer Data will be permanently deleted from active systems and backups and will no longer be recoverable. Backup deletion may occur through KolApp's normal backup-rotation process but will be completed within the same 90-day period.
| Information | Retention approach |
|---|---|
| Customer Data | While the subscription is active and for no more than 90 days following expiration or termination, subject to the limited exceptions below. |
| Account and profile information | While the account or customer relationship remains active and for a limited period afterward for closure, security, dispute resolution, and legal compliance. |
| Billing, transaction, and tax information | For the period required by applicable tax, accounting, fraud-prevention, audit, and legal obligations. |
| Security, audit, administrative, error, and diagnostic records | For a period appropriate to detect and investigate incidents, maintain reliability and governance records, and support active investigations or legal holds. |
| Inquiry, demonstration, support, and sales information | While responding to the matter and for reasonable follow-up, relationship management, recordkeeping, and legal compliance. |
| Marketing and business-prospect information | While relevant to a permitted business relationship or outreach activity, unless the recipient opts out or objects. |
| Opt-out and suppression information | For as long as reasonably necessary to document and continue honoring the opt-out. |
| Integration tokens | While the integration remains connected. Tokens are deleted or deactivated following disconnection, subject to limited security records and the 90-day backup-deletion period. |
| Aggregated or de-identified information | May be retained where it cannot reasonably identify an individual or customer and is maintained in de-identified form. |
KolApp may retain limited information longer where required by law or reasonably necessary for billing, fraud prevention, security investigations, dispute resolution, enforcement, or a legal hold. Information retained for these purposes remains protected and is not used to restore or continue a terminated account.
12. Data security
KolApp maintains administrative, technical, physical, and organizational safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, loss, or destruction. Depending on the Service, plan, and configuration, these safeguards may include:
- Encryption in transit and at rest;
- Logical separation of customer workspaces and tenant-aware access controls;
- Role-based permissions enforced for authorized actions;
- Managed authentication, MFA, SSO where enabled, session controls, and restricted administrative access;
- Encrypted integration tokens and managed storage of infrastructure secrets;
- Input validation, parameterized database access, anti-CSRF controls, and web-application protections;
- Audit, error, job-execution, and security logging;
- Monitoring, backups, incident-response procedures, and access review.
Authentication credentials are handled through KolApp's managed identity infrastructure. KolApp does not store user passwords in plaintext.
KolApp maintains procedures designed to identify, investigate, contain, and remediate security incidents. KolApp will notify affected customers without undue delay after becoming aware of a confirmed security incident involving unauthorized access to or disclosure of Customer Data in KolApp's custody, as required by applicable law or an executed DPA. Where KolApp acts as processor, the customer remains responsible for determining whether it must notify individuals or regulators, and KolApp will provide reasonably available assistance as required.
No system is completely secure. KolApp cannot guarantee that unauthorized access, loss, misuse, or alteration will never occur and cannot protect against compromise of a user's own device, credentials, network, identity provider, or email account.
13. International data transfers
The KolApp application is primarily hosted in the United States. KolApp and its providers may also process personal information in the United States and other countries where they operate. Those countries may have data-protection laws that differ from the laws in an individual's location.
Where required, KolApp uses appropriate safeguards for international transfers, which may include the European Commission's Standard Contractual Clauses, the United Kingdom's International Data Transfer Addendum or Agreement, contractual protections, transfer-impact assessments, adequacy decisions, encryption and access controls, and other lawful mechanisms. Business customers may contact KolApp to request information about the transfer mechanism applicable to their Customer Data.
14. Your privacy rights
Depending on location, the information involved, KolApp's role, and applicable exceptions, an individual may have the right to:
- Confirm whether KolApp processes personal information and request access to it;
- Correct inaccurate or incomplete personal information;
- Request deletion of personal information;
- Receive a portable copy of certain personal information;
- Restrict or object to certain processing;
- Withdraw consent where processing relies on consent;
- Opt out of marketing communications;
- Opt out of sale, sharing, targeted advertising, or certain profiling where applicable;
- Request information about specific third parties to which personal information was disclosed where applicable law provides that right;
- Appeal a decision concerning a privacy request where applicable; and
- Complain to an applicable privacy or data-protection authority.
To submit a request, use the contact information in Section 21. KolApp may need to verify identity, account association, and authority before completing a request. Authorized agents may submit requests where permitted by law, subject to proof of authorization and applicable identity verification.
If the information is part of a customer-managed workspace, contact the customer or workspace administrator first. KolApp will not ordinarily act on an individual's instructions concerning Customer Data without the controlling customer's authorization, but will assist the customer with verified requests as required by applicable law and agreement.
KolApp will not unlawfully discriminate or retaliate against an individual for exercising an applicable privacy right. KolApp does not ordinarily charge a fee, but may charge a reasonable fee or decline a request where permitted for requests that are manifestly unfounded, excessive, or repetitive.
EEA, United Kingdom, and Switzerland
Where KolApp acts as controller and applicable law provides, individuals may have rights of access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, withdrawal of consent, and objection to direct marketing. Individuals may also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects and may lodge a complaint with their local supervisory authority.
15. Additional U.S. state privacy notices
Residents of states with comprehensive privacy laws may have rights to know, access, correct, delete, or obtain a portable copy of personal information and to opt out of certain sales, sharing, targeted advertising, or profiling. These rights apply only when the relevant law covers KolApp and the particular processing activity.
Categories processed during the preceding 12 months
| Category | Examples | Purposes and recipients |
|---|---|---|
| Identifiers and professional information | Name, business email, company, title, phone, account ID, and professional profile information. | Accounts, demos, support, subscriptions, security, and business communications; disclosed to the customer, authorized users, and operational providers as needed. |
| Commercial and Customer Data | Projects, tasks, files, schedules, budgets, rates, plans, seats, invoices, and transaction status. | Providing the platform, collaboration, reporting, billing, support, and customer-directed integrations. |
| Internet, device, usage, and approximate location | IP address, device, browser, pages, referrals, timestamps, feature activity, diagnostics, and location inferred from IP. | Operating, securing, measuring, troubleshooting, and improving the Services; disclosed to hosting, security, analytics, and communications providers. |
| Account access and security information | Authentication identifiers, MFA status, sessions, login history, roles, permissions, and suspected threats. | Authentication, access control, fraud prevention, investigations, and security. |
| Communications and interactions | Forms, emails, tickets, demo details, meeting information, feedback, delivery, opens, clicks, replies, and opt-outs. | Support, demonstrations, onboarding, service notices, business outreach, and preference management. |
| Inferences | Likely product interests, account needs, feature preferences, and security-risk indicators. | Service improvement, relevant communications, account assistance, and security. |
| Sensitive personal information | Account credentials or security information and sensitive information a customer submits despite applicable restrictions or under an approved use. | Providing and securing the Services or following customer instructions. KolApp does not use sensitive personal information to infer characteristics or for purposes requiring a right to limit under California law. |
KolApp does not offer financial incentives or differences in price or service in exchange for personal information.
Virginia residents
Where the Virginia Consumer Data Protection Act applies, Virginia residents acting in an individual or household context may request access, correction, deletion, or portability and may opt out of targeted advertising, sale, or qualifying profiling. KolApp will respond without undue delay and generally within 45 days. Where reasonably necessary, KolApp may extend the period once by an additional 45 days and will explain the extension within the initial period.
If KolApp declines a request, the response will include the reason and instructions for appeal. An appeal may be submitted using the same contact method with the subject or message heading “Privacy Appeal.” KolApp will respond to a qualifying appeal in writing within 60 days. If the appeal is denied, KolApp will provide a method to contact the Virginia Attorney General.
California residents
Where the California Consumer Privacy Act applies, California residents may request information concerning categories and specific pieces of personal information, sources, purposes, and disclosures; request correction or deletion; obtain a portable copy; and opt out of sale or sharing. KolApp does not sell personal information for money, does not currently share personal information for cross-context behavioral advertising, and does not use or disclose sensitive personal information for purposes requiring a right to limit. KolApp does not knowingly sell or share personal information of individuals under 18.
Residents of other U.S. states
Residents of other states with applicable comprehensive privacy laws may exercise the rights provided by their state, including rights concerning access, correction, deletion, portability, targeted advertising, sale, profiling, appeals, authorized agents, or a list of specific third parties. KolApp will evaluate each request under the law applicable to the requester and relevant processing. Nevada residents may submit a verified request to opt out of a covered sale, although KolApp does not currently engage in such sales.
16. Marketing and communications
Transactional and administrative communications may include account, authentication, security, billing, legal, service, and maintenance notices. These messages may be necessary to administer an active account and generally cannot be disabled while the account remains active.
Marketing communications may include product news, educational information, offers, and permitted business outreach. A recipient may opt out through the unsubscribe link in the message or by contacting KolApp. KolApp may use secure per-recipient tokens to process unsubscribe requests without requiring sign-in and may record the date, time, request source, and associated IP address as a compliance and audit record.
Customer-directed reports, digests, and notifications are governed by workspace configuration and available user preferences. KolApp maintains limited suppression information for as long as reasonably necessary to honor applicable marketing opt-outs. Opting out of marketing does not prevent transactional, security, billing, or other service-related messages.
17. Automated decision-making
KolApp does not use Customer Data on its own behalf to make automated decisions that produce legal or similarly significant effects about individuals. The Services may generate project health indicators, budget and schedule variance calculations, resource-planning information, automated rules, and AI-generated summaries. These features describe projects or operational conditions, depend on customer-provided data and configuration, and are intended for appropriate human review.
Customers are responsible for determining whether their configuration and use of the Services complies with employment, privacy, anti-discrimination, and other applicable laws and for ensuring that outputs are not used as the sole basis for decisions that produce legal or similarly significant effects about an individual.
18. Children's privacy
The Services are designed for organizations and professional users and are intended only for individuals who are at least 18 years old. Individuals under 18 may not create an account, access, or use the Services. KolApp does not knowingly collect personal information directly from individuals under 18 through its website or Services.
Customers must not submit personal information of individuals under 18 unless KolApp has expressly authorized that use in writing and all required notices, consents, authorizations, and agreements are in place. If you believe an individual under 18 has provided personal information or is using the Services without authorization, contact KolApp so we can investigate and, where applicable, work with the controlling customer to remove the information and terminate the unauthorized access.
19. Third-party websites and services
The Services may link to or embed third-party websites and services, including calendar providers, identity providers, scheduling tools, maps, project-management integrations, payment processors, and support or communications providers. KolApp does not control how those parties process information for their own purposes. Review their privacy policies before providing information or authorizing a connection.
Disconnecting an integration stops new access through that connection but may not automatically remove information already synchronized into Customer Data. Stored integration information and tokens are deleted or deactivated according to customer instructions, KolApp's retention practices, legal requirements, provider requirements, and normal backup deletion.
20. Changes to this Policy
KolApp may update this Policy to reflect changes to the Services, technologies, providers, laws, security requirements, or privacy practices. KolApp will post the updated Policy and revise the “Last updated” date. Where required by applicable law, KolApp will provide additional notice or obtain consent before a material change takes effect.
21. Contact us
Contact KolApp with privacy questions, requests, appeals, subprocessor questions, or concerns through our contact form or by mail:
KolApp LLC
Attn: Privacy
11710 Plaza America Drive, Suite 2000
Reston, Virginia 20190
United States
For a privacy request, include “Privacy Request” in your message. For an appeal, include “Privacy Appeal.” Identify the email address associated with your account or inquiry, but do not include passwords, MFA codes, payment-card numbers, or other sensitive credentials.
Contact KolApp