Trust

Privacy policy

This covers data about you, our customer. How we handle data about your contacts is a separate question, answered on the GDPR page.

Who is responsible

Kohi Solutions Ltd, str. Filip Simidov 1, entr. B, floor 3, apt. 11, Veliko Tarnovo 5000, Bulgaria, EU VAT 206220247, is the controller for the personal data described here. Reach us at [email protected].

For the personal data of your contacts, which you upload or send to us through the product, you are the controller and we are your processor. See the GDPR and data residency page.

What we collect and why

When you join the waitlist

Your email address, and optionally what tool you currently use. We use it to contact you about beta access and nothing else. The legal basis is our legitimate interest in responding to someone who asked to be contacted. Ask us to remove you and we will.

When you hold an account

  • Account data: your name, email, password hash, and workspace settings. Needed to perform the contract.
  • Billing data: handled by our payment processor. We store the subscription state and invoices, not your card number.
  • Usage and diagnostic data: logs, error reports, and aggregate usage, used to keep the service working and to investigate faults. Legitimate interest.

When you visit this website

We use Google Analytics to understand which pages get read. It sets cookies and processes usage data. If you would rather not be counted, browser-level blocking or a tracking-protection extension is enough, and nothing on the site breaks without it.

How long we keep it

  • Waitlist entries: until the beta closes or you ask us to delete you, whichever comes first.
  • Account data: for as long as your account exists. When you close it, we delete your workspace data. Backups age out on their own retention cycle.
  • Invoices and tax records: for as long as EU and Bulgarian accounting law requires, which is longer than we would otherwise keep them.

Who else sees it

Only the sub-processors we use to run the service, each of which is listed on the GDPR page along with what it does. We do not sell personal data, and we do not share it for anyone else's advertising.

We disclose data to authorities only where we are legally obliged to, and we will tell you when we are permitted to tell you.

Your rights

Under the GDPR you can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable format. Email [email protected] and we will answer within one month.

If you think we have handled your data badly, you can complain to the Bulgarian Commission for Personal Data Protection, or to the supervisory authority where you live. We would rather you told us first so we can fix it.

Security

Data is encrypted in transit. Access to production systems is limited to the people who need it. API keys are scoped, so a key you issue for one job cannot quietly do another. No system is perfectly secure, and anyone who tells you otherwise is selling something.

Changes to this policy

If we change this materially, we will say so on this page and, for account holders, by email. We will not make a quiet change and rely on you re-reading it.