1. Who We Are
Kola CRM is a product of Chestnut Compute Corp ("Chestnut Compute", "we", "us", or "our"), a corporation registered in Ontario, Canada.
Registered address:
302-1 Brian Peck Crescent
Toronto, ON M4G 4J7
Canada
Privacy contact: privacy@kolacrm.com
This Privacy Policy governs information collected through kolacrm.com, the Kola CRM software application, and any related services (collectively, the "Service").
2. Legal Framework
We are subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, Ontario's privacy legislation. We also aim to meet the standards of the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) for customers in those jurisdictions.
By purchasing or using the Service you consent to the practices described in this Policy.
3. Information We Collect
3.1 Purchase & Account Information
When you buy a Kola CRM license we collect:
- Name and email address (required to deliver your license key and provide support)
- Payment information — processed entirely by our third-party payment processor; Chestnut Compute does not receive or store your full card number or banking details
- Purchase tier, transaction ID, and timestamp
3.2 License Validation Data (Phone-Home)
Kola CRM performs an automatic license check each time the application loads. This request is sent to our license validation service and logs the following data:
- Your license key (hashed — the raw key is never stored in plaintext on our servers)
- The hostname or domain where the application is running (Professional and Business tiers only — used for domain-lock enforcement)
- IP address of the requesting client
- Timestamp of the request
- License tier and validation result
Validation requests are processed via Cloudflare Workers infrastructure. Logs are retained for 12 months and then deleted.
3.3 Cloud Backup Data (Optional Add-On)
If you subscribe to the optional Chestnut Cloud Backup service ($49/year), your CRM data is encrypted on your device before transmission and stored as encrypted snapshots on our secure infrastructure. We cannot read the contents of your backups — encryption and decryption occur entirely on your end.
We store:
- Encrypted backup snapshots (contents are opaque to us)
- Backup metadata: snapshot timestamp, file size, version identifier, and your account identifier
Cloud Backup data is retained for the duration of your active subscription plus a 30-day grace period after cancellation, after which it is permanently deleted. You may request immediate deletion at any time.
3.4 Website Usage Data
When you visit kolacrm.com we may collect standard web server log data including your IP address, browser type, referring URL, pages visited, and timestamps. This data is used to maintain website security and improve the Service. We do not use invasive tracking technologies or sell this data.
4. What We Do Not Collect
Your CRM data is yours. Contacts, companies, deals, notes, activity logs, and all other data you enter into Kola CRM are stored exclusively on your own device (Starter tier) or your own self-hosted server (Professional and Business tiers). This data never passes through Chestnut Compute's systems unless you have subscribed to Cloud Backup.
Your AI API keys are yours. The "Ask Kola" AI feature requires you to supply your own API key (Anthropic or OpenAI). Your key is stored in your browser's local storage and is never transmitted to Chestnut Compute's servers.
5. How We Use Your Information
| Data Category | Purpose | Legal Basis (PIPEDA / GDPR) |
|---|---|---|
| Purchase & account information | License delivery, support, fraud prevention, legal obligations | Contract performance; legitimate interests |
| License validation logs | License enforcement, abuse detection, key revocation | Legitimate interests; contract performance |
| Cloud Backup data | Storing encrypted backups on your behalf | Contract performance (add-on subscription) |
| Website usage data | Security, analytics, service improvement | Legitimate interests |
We do not use your information for advertising, behavioural profiling, or sale to third parties.
6. Disclosure to Third Parties
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
6.1 Service Providers
- Cloudflare, Inc. — License validation infrastructure (Cloudflare Workers and KV). Cloudflare processes request metadata in accordance with their Data Processing Agreement.
- Payment Processor — Your purchase is processed by our payment provider (e.g., Stripe or similar). Payment data is governed by the payment provider's privacy policy. Chestnut Compute receives only a transaction confirmation and your email address.
- Transactional Email Provider — We use a third-party email service to send you your license key and support communications. Only your email address and name are shared for this purpose.
6.2 Legal Requirements
We may disclose information if required to do so by law, court order, or regulatory authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Chestnut Compute, our customers, or the public.
6.3 Business Transfer
If Chestnut Compute Corp is acquired, merged, or undergoes a material change of ownership, your information may be transferred to the successor entity, subject to the same privacy protections described herein. You will be notified of any such transfer.
7. Data Retention
- Purchase and account records: Retained for 7 years from date of purchase to meet Canadian tax and accounting obligations, then deleted.
- License validation logs: Retained for 12 months, then automatically deleted.
- Cloud Backup data: Retained for the duration of active subscription + 30-day grace period after cancellation.
- Website logs: Retained for up to 90 days.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal information from unauthorised access, disclosure, alteration, or destruction. These measures include:
- HTTPS encryption in transit for all communications with our services
- Hashing of license keys — raw keys are never stored in plaintext on our servers
- Client-side encryption for all Cloud Backup data before transmission
- Access controls limiting personnel access to personal data
- Regular review of our security practices
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we are committed to promptly notifying affected individuals of any breach that poses a risk of significant harm, in accordance with PIPEDA's mandatory breach notification requirements.
9. Your Privacy Rights
Under PIPEDA (and applicable provincial law), you have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Withdraw consent (where processing is consent-based) — note that withdrawing consent for necessary processing (e.g., license validation) may affect your ability to use the Service
- Request deletion of your personal information, subject to our legal retention obligations
- Complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) if you believe we have not handled your information appropriately
To exercise any of these rights, contact us at privacy@kolacrm.com. We will respond within 30 days.
GDPR Rights (EU/EEA Customers)
If you are located in the European Economic Area, you have additional rights including the right to data portability and the right to object to processing based on legitimate interests. Contact us to exercise these rights.
CCPA Rights (California Customers)
California residents have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell personal information. To submit a CCPA request, contact privacy@kolacrm.com.
10. Cookies and Tracking Technologies
Our website may use essential cookies necessary for site functionality (e.g., session management). We do not use advertising cookies or third-party tracking pixels. You may configure your browser to refuse cookies; this may limit certain website functionality.
The Kola CRM application itself uses browser localStorage — not cookies — to store your application settings and data on your own device. This data never leaves your device unless you use the Cloud Backup add-on.
11. Cross-Border Data Transfers
Our license validation infrastructure is operated by Cloudflare, which processes data in data centres globally. Purchase and billing data may be processed by our payment provider in jurisdictions outside Canada. We take steps to ensure that any cross-border transfers are subject to appropriate safeguards consistent with PIPEDA.
12. Children's Privacy
Kola CRM is a business-to-business product intended for use by adults in a commercial capacity. We do not knowingly collect personal information from individuals under the age of 18. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by posting the revised Policy at kolacrm.com/privacy-policy and, where we have your email address, notifying you by email at least 14 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.
We maintain an archive of prior versions of this Policy, available on request.
14. Contact Us
For privacy inquiries, access requests, or complaints:
Chestnut Compute Corp
Attn: Privacy Officer
302-1 Brian Peck Crescent
Toronto, ON M4G 4J7
Canada
privacy@kolacrm.com