Privacy Policy

Chestnut Compute Corp  ·  Last Updated: June 14, 2026  ·  Under legal review — effective date to be confirmed

Plain-language summary: Kola CRM is built on a data-ownership model. Your CRM data (contacts, deals, notes) stays on your own browser or server — we never see it. We collect only what is necessary to deliver and protect your license, process your purchase, and (if you subscribe) maintain your Cloud Backup.

1. Who We Are

Kola CRM is a product of Chestnut Compute Corp ("Chestnut Compute", "we", "us", or "our"), a corporation registered in Ontario, Canada.

Registered address:
302-1 Brian Peck Crescent
Toronto, ON M4G 4J7
Canada

Privacy contact: privacy@kolacrm.com

This Privacy Policy governs information collected through kolacrm.com, the Kola CRM software application, and any related services (collectively, the "Service").

2. Legal Framework

We are subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, Ontario's privacy legislation. We also aim to meet the standards of the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) for customers in those jurisdictions.

By purchasing or using the Service you consent to the practices described in this Policy.

3. Information We Collect

3.1 Purchase & Account Information

When you buy a Kola CRM license we collect:

3.2 License Validation Data (Phone-Home)

Kola CRM performs an automatic license check each time the application loads. This request is sent to our license validation service and logs the following data:

Purpose: License validation data is used exclusively to confirm your license is valid, detect misuse or key-sharing, enforce tier-appropriate domain restrictions, and revoke keys in the event of confirmed abuse. It is not used for marketing or profiling.

Validation requests are processed via Cloudflare Workers infrastructure. Logs are retained for 12 months and then deleted.

3.3 Cloud Backup Data (Optional Add-On)

If you subscribe to the optional Chestnut Cloud Backup service ($49/year), your CRM data is encrypted on your device before transmission and stored as encrypted snapshots on our secure infrastructure. We cannot read the contents of your backups — encryption and decryption occur entirely on your end.

We store:

Cloud Backup data is retained for the duration of your active subscription plus a 30-day grace period after cancellation, after which it is permanently deleted. You may request immediate deletion at any time.

3.4 Website Usage Data

When you visit kolacrm.com we may collect standard web server log data including your IP address, browser type, referring URL, pages visited, and timestamps. This data is used to maintain website security and improve the Service. We do not use invasive tracking technologies or sell this data.

4. What We Do Not Collect

Your CRM data is yours. Contacts, companies, deals, notes, activity logs, and all other data you enter into Kola CRM are stored exclusively on your own device (Starter tier) or your own self-hosted server (Professional and Business tiers). This data never passes through Chestnut Compute's systems unless you have subscribed to Cloud Backup.

Your AI API keys are yours. The "Ask Kola" AI feature requires you to supply your own API key (Anthropic or OpenAI). Your key is stored in your browser's local storage and is never transmitted to Chestnut Compute's servers.

5. How We Use Your Information

Data Category Purpose Legal Basis (PIPEDA / GDPR)
Purchase & account information License delivery, support, fraud prevention, legal obligations Contract performance; legitimate interests
License validation logs License enforcement, abuse detection, key revocation Legitimate interests; contract performance
Cloud Backup data Storing encrypted backups on your behalf Contract performance (add-on subscription)
Website usage data Security, analytics, service improvement Legitimate interests

We do not use your information for advertising, behavioural profiling, or sale to third parties.

6. Disclosure to Third Parties

We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:

6.1 Service Providers

6.2 Legal Requirements

We may disclose information if required to do so by law, court order, or regulatory authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Chestnut Compute, our customers, or the public.

6.3 Business Transfer

If Chestnut Compute Corp is acquired, merged, or undergoes a material change of ownership, your information may be transferred to the successor entity, subject to the same privacy protections described herein. You will be notified of any such transfer.

7. Data Retention

8. Data Security

We implement appropriate technical and organisational measures to protect your personal information from unauthorised access, disclosure, alteration, or destruction. These measures include:

No method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we are committed to promptly notifying affected individuals of any breach that poses a risk of significant harm, in accordance with PIPEDA's mandatory breach notification requirements.

9. Your Privacy Rights

Under PIPEDA (and applicable provincial law), you have the right to:

To exercise any of these rights, contact us at privacy@kolacrm.com. We will respond within 30 days.

GDPR Rights (EU/EEA Customers)

If you are located in the European Economic Area, you have additional rights including the right to data portability and the right to object to processing based on legitimate interests. Contact us to exercise these rights.

CCPA Rights (California Customers)

California residents have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell personal information. To submit a CCPA request, contact privacy@kolacrm.com.

10. Cookies and Tracking Technologies

Our website may use essential cookies necessary for site functionality (e.g., session management). We do not use advertising cookies or third-party tracking pixels. You may configure your browser to refuse cookies; this may limit certain website functionality.

The Kola CRM application itself uses browser localStorage — not cookies — to store your application settings and data on your own device. This data never leaves your device unless you use the Cloud Backup add-on.

11. Cross-Border Data Transfers

Our license validation infrastructure is operated by Cloudflare, which processes data in data centres globally. Purchase and billing data may be processed by our payment provider in jurisdictions outside Canada. We take steps to ensure that any cross-border transfers are subject to appropriate safeguards consistent with PIPEDA.

12. Children's Privacy

Kola CRM is a business-to-business product intended for use by adults in a commercial capacity. We do not knowingly collect personal information from individuals under the age of 18. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by posting the revised Policy at kolacrm.com/privacy-policy and, where we have your email address, notifying you by email at least 14 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.

We maintain an archive of prior versions of this Policy, available on request.

14. Contact Us

For privacy inquiries, access requests, or complaints:

Chestnut Compute Corp
Attn: Privacy Officer
302-1 Brian Peck Crescent
Toronto, ON M4G 4J7
Canada
privacy@kolacrm.com