Privacy Policy
Privacy at Kola
This Privacy Policy explains how Numero Technology Ltd handles personal data when organisations and their people use Kola through withkola.com, app.withkola.com, Slack, Microsoft Teams and related services.
Kola is a workplace culture and rewards platform. It can be used without a company wallet. Optional funded rewards, balances, contributions, payouts and cards involve additional personal and financial data only when the relevant feature is separately activated.
We do not sell personal data. We do not use private balances, private recognition or anonymous survey responses for advertising. We use personal data only for the purposes described here, on an appropriate legal basis and subject to the controls explained below.
1 Who we are and how to contact us
Kola is owned and operated by Numero Technology Ltd, incorporated in England and Wales.
111 New Union Street, Coventry, West Midlands CV1 2NT, United Kingdom.
For privacy questions, rights requests or complaints, contact [email protected]. For ordinary product support, contact [email protected].
2 Scope of this Policy
This Policy applies to personal data handled through the Kola public website, authenticated web application, Slack and Microsoft Teams applications, integrations, customer onboarding, support, events, marketing and optional rewards or financial features.
It applies to Organisation owners, administrators, employees, contractors, group members, website visitors, prospective customers, support contacts and other people whose information is submitted to Kola.
A Third Party Service, employer, reward issuer, payment provider, identity provider or linked merchant may have its own privacy notice. This Policy does not replace their notices or govern processing they carry out independently.
3 Our role and your employer's role
Data protection roles depend on the activity. This section is important because it determines who decides how personal data is used and who should answer a request.
Where the Organisation is controller
The Organisation is generally the controller when it decides to install Kola, imports or synchronises its workforce directory, configures workplace visibility, creates groups, runs recognition or engagement programmes, schedules celebrations, creates surveys, sets scoring rules, reviews company reports or instructs us to process Organisation Data. For these activities, we generally act as the Organisation's processor and follow its documented instructions, our agreement and applicable law.
The Organisation is responsible for having a lawful basis, giving employees appropriate workplace privacy information, using fair settings, responding to employment-related requests and not using Kola unlawfully for covert monitoring or unfair decisions.
Where Numero Technology Ltd is controller
We act as controller when we decide how and why personal data is used for account security, identity linking, service administration, abuse and fraud prevention, direct support relationships, legal compliance, product communications, marketing preferences, website operation and our own business records. We may also act as controller for optional financial or verification activities where we determine the relevant purposes or have our own legal obligations.
Independent and joint participants
Slack, Microsoft, Google, payment and identity providers, reward issuers, card or payout providers and merchants may act as independent controllers for their own services. If an arrangement makes us joint controllers with another party, we will provide any additional information required about our respective responsibilities.
4 Personal data we collect
| Category | Examples |
| Identity and contact | Name, work email, username, profile image, preferred name, phone number where provided, account identifiers and authentication status. |
| Workplace and membership | Employer or Organisation, job title, department, group memberships, work location, role, manager relationship, workspace or tenant identifiers and account status. |
| Integration data | Slack or Teams user, workspace, tenant, team and channel identifiers; installation permissions; OAuth tokens; connection status; permitted directory fields; message and interaction metadata. |
| Profile and important dates | Timezone, language, notification settings, birthday or anniversary information, visibility preferences, optional uploaded image and wishlist information. |
| Recognition and content | Recognition text, recipient, company value, audience, reactions, attachments, moderation status, reports and delivery history. |
| Engagement and participation | Recognition Scores, badges, levels, leaderboard position, campaign activity, game participation, event invitations, RSVPs, gift-exchange participation and group activity. |
| Listening and feedback | Poll choices, survey or mood-check responses, optional free text, response status and privacy or anonymity settings. |
| Rewards and transactions | Reward selection, eligibility, order and fulfilment status, Kola Balance reference, wallet or Pot activity, payment reference, amount, currency, fee, beneficiary and reconciliation status. |
| Verification and compliance | Business or identity verification details, date of birth where required, address, government document reference, bank-account details, sanctions or fraud-screening result and provider customer reference. We minimise storage in Kola where a provider can collect this directly. |
| Technical and security | IP address, device and browser type, cookie or session identifiers, login activity, request and correlation IDs, audit events, error and diagnostic data, security alerts and approximate location inferred from IP where needed for security. |
| Support and communications | Support messages, files you send, call or meeting notes where applicable, complaint records, consent and preference history, and service or marketing communication activity. |
| Website and prospect | Pages viewed, referral source, form submissions, business contact information, event registrations and cookie choices. |
Special category and sensitive data
Kola is not designed for users to submit unnecessary health, biometric, political, religious, trade-union, ethnicity, sexuality or other special category data in recognition messages, wishlists or ordinary workplace content. Survey responses and free text may nonetheless reveal sensitive information. Organisations must use such features carefully and establish an additional lawful condition where required.
Identity or financial providers may process sensitive verification information under their own notices. We do not use special category data to target marketing or determine workplace ranking.
5 Where personal data comes from
We receive personal data from the following sources:
Directly from you when you sign in, set preferences, recognise someone, respond, join an activity, redeem a reward, contact support or choose marketing settings.
From your Organisation when it installs Kola, invites users, synchronises a directory, configures roles and groups, enters important dates, issues rewards or provides support information.
From Slack, Microsoft Teams, Google, Microsoft identity services and other integrations according to the permissions shown and enabled.
From payment, reward, identity, fraud, card, payout and financial providers when an optional feature is activated and they return eligibility, status or transaction information.
Automatically from your browser, device, integrations and use of the Services through cookies, logs, audit records and security systems.
From public or business sources where appropriate for business-to-business contact, verification, fraud prevention or legal compliance.
6 How and why we use personal data
| Purpose | Typical data | Lawful basis |
| Provide and administer Kola | Identity, workplace, integration, content, settings and activity | Contract; legitimate interests; and, where we act as processor, the Organisation's instructions. |
| Authenticate and link identities | Account identifiers, work email, authentication and integration data | Contract and legitimate interests in secure, accurate access. |
| Deliver recognition celebrations and activities | Content, dates, preferences, groups, recipients and delivery data | Contract; legitimate interests; consent where a feature specifically requires it; Organisation instructions. |
| Operate scores games and insights | Activity, Recognition Scores, campaign and group data | Legitimate interests in providing configured engagement features; Organisation instructions. |
| Fulfil rewards and optional transactions | Reward, wallet, payment, beneficiary and provider data | Contract; legal obligation; legitimate interests in fulfilment, reconciliation and fraud prevention. |
| Verify identity and manage risk | Identity, device, transaction, screening and audit data | Legal obligation and legitimate interests in security, fraud prevention and protecting users. |
| Support and troubleshoot | Account, technical, transaction and support communications | Contract and legitimate interests in resolving issues and improving service. |
| Secure and monitor the Services | Logs, IP, device, access, audit and diagnostic data | Legal obligation and legitimate interests in security, resilience and abuse prevention. |
| Meet legal and regulatory duties | Identity, transaction, complaint, audit and retention records | Legal obligation; public task where applicable; establishment or defence of legal claims. |
| Improve Kola | Usage, feedback, failure and aggregated performance data | Legitimate interests in product improvement. We use aggregated or de-identified data where reasonably possible. |
| Communicate service information | Contact, role, account and notification preferences | Contract and legitimate interests in administering the relationship. |
| Market Kola and Numero ecosystem products | Business contact, usage context and marketing preferences | Consent where required; otherwise legitimate interests, subject to applicable direct-marketing rules and your right to object. |
Legitimate interests
Where we rely on legitimate interests, we consider whether the use is necessary, what people reasonably expect and whether their rights override our interest. Our interests include providing and improving a useful workplace service, securing accounts, preventing abuse, communicating with business customers and understanding product performance. You may object to processing based on legitimate interests; see section 16.
Consent
Where we rely on consent, it must be specific and may be withdrawn at any time. Withdrawing consent does not make earlier processing unlawful. Some functionality may stop if it cannot operate without the information covered by the withdrawn consent.
7 Recognition celebrations and workplace visibility
Recognition can be posted to a public channel, restricted group, direct message or private destination depending on the sender's choice and Organisation policy. Kola provides a preview before publication where supported, but users must still confirm the intended recipient and audience.
Birthday and anniversary features use the visibility selected by the employee or permitted by the Organisation under applicable law. Kola should not expose a year of birth or calculate age by default. Employees may hide a date, restrict the audience or opt out of supported reminders.
Kola may use a Slack or Microsoft Teams profile image as the default where permissions allow. An employee may replace it with an uploaded image. A Kola-branded sharing card is created only for an eligible user action and is not posted externally without deliberate confirmation.
Organisation administrators can see workplace activity and reports permitted by their role. They cannot use ordinary administrator access to see another person's private Kola Balance, private wishlist settings or content expressly restricted from them. Financial and People permissions are separated.
8 Surveys polls and anonymous responses
A poll may be public, attributed, confidential or anonymous depending on its configuration. The interface should tell participants which model applies before they submit a response.
For a survey described as anonymous, Kola separates identity from response data where practicable, limits administrative access and reports results only after a suitable minimum response threshold. We do not provide an Organisation with identity-linked raw responses for a survey represented to users as anonymous.
No technical system can guarantee anonymity if a person voluntarily identifies themselves in free text, a group is extremely small or an Organisation combines results with information it already knows. Participants should avoid unnecessary identifying details, and Organisations must not attempt re-identification.
9 Optional rewards wallets and financial services
Installing Kola does not create a wallet or financial account. If an Organisation activates funded rewards or financial features, additional data may be required to quote, fund, verify, issue, redeem, pay out, reconcile, reverse or support the transaction.
A payment, banking, card, identity or payout provider may collect information directly through a secure flow. Where possible, Kola stores only a provider reference, verification outcome and information needed for user support, audit and reconciliation rather than a copy of the underlying document.
For cash withdrawals or future international payouts, we may process verified beneficiary details, country, currency, exchange-rate quote, fees, screening results, payment status and failure or refund information. For future virtual cards, the issuer may require identity and cardholder details and will provide its own terms and privacy notice.
Financial providers may use personal data for their own legal duties, including identity verification, sanctions screening, anti-money-laundering checks, transaction monitoring, fraud prevention, safeguarding, disputes and regulatory reporting. A user may be unable to use a financial feature if required information is not provided or checks are not completed.
10 Cookies analytics and similar technologies
We use cookies, local storage, session technologies and similar tools to operate the website and application. Strictly necessary technologies support authentication, security, load balancing, fraud prevention, preferences and core functionality.
Where required by law, we ask for consent before using non-essential analytics, advertising or similar technologies. You can accept, reject or change optional cookie choices through the available settings. Rejecting optional cookies does not prevent core Kola use, although some convenience or analytics features may be limited.
Our cookie banner or separate cookie notice will identify the technologies actually deployed, their providers, purposes and duration. Browser controls can also block or delete cookies, but blocking necessary technologies may prevent sign-in or secure functions.
11 Marketing across the Numero ecosystem
Numero Technology Ltd may use permitted business contact information to communicate about Kola and other current or future products, features and services offered within the Numero Technology Ltd ecosystem. We do not need to list every product in this Policy for that category to apply, but each marketing communication will identify the sender and will not disguise its commercial purpose.
We separate marketing from essential service communications. Accepting the Kola Terms does not automatically mean an individual has consented to every form of direct marketing.
Email marketing includes an unsubscribe link or another simple opt-out method.
SMS, WhatsApp, push notification or similar marketing is sent only where permitted and includes an appropriate way to stop or manage it.
We record consent, objections and suppression information so we can respect choices. We may keep a minimal suppression record after opt-out rather than delete it and risk contacting the person again.
We do not use private recognition, private balances or anonymous survey answers to target marketing.
We do not sell personal data or permit unrelated third parties to use Kola workplace data for their own advertising.
12 When we share personal data
We share personal data only where necessary for the purposes in this Policy, under appropriate obligations and access controls. Recipient categories may include:
The relevant Organisation and its authorised administrators, group leads and users, according to roles, settings and the chosen audience.
Slack, Microsoft Teams, Google and Microsoft identity services where you connect or use those services.
Cloud hosting, database, storage, security, logging, communications, support and analytics providers that process data for us.
Reward suppliers, gift-card issuers, airtime or data providers and fulfilment partners needed to deliver a selected reward.
Payment, banking, virtual-account, card, identity-verification, fraud, foreign-exchange and payout providers for activated financial services.
Professional advisers, auditors, insurers and potential buyers or investors under confidentiality and only where appropriate.
Courts, regulators, law enforcement, tax authorities or other bodies where disclosure is required or lawfully necessary to protect rights, safety and the integrity of the Services.
A successor or acquiring organisation in a merger, reorganisation, financing or sale, subject to applicable law and continued protection of personal data.
Service providers and subprocessors
Processors and subprocessors may use personal data only to provide contracted services, protect those services and meet applicable legal duties. We assess providers according to the nature and risk of the processing and use data protection terms where required. Organisations may request current subprocessor information from [email protected] or use any published subprocessor page when available.
13 International transfers
Kola serves organisations and users in more than one country. Personal data may be accessed or processed in the United Kingdom, Nigeria, other African countries, the European Economic Area, the United States or another country where an approved provider operates.
Where UK data protection law treats a transfer as restricted, we use an available lawful mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another permitted safeguard. We also assess transfer risk and apply supplementary technical and organisational measures where appropriate.
Where Nigerian or other local law applies, we use the applicable transfer basis and safeguards required by that law. You may contact [email protected] for information about the relevant safeguard, subject to commercial confidentiality and security restrictions.
14 How long we keep personal data
We keep personal data only for as long as needed for the purpose, contractual commitments, dispute resolution, security, financial reconciliation and applicable legal obligations. The actual period depends on the data, Organisation settings, provider relationship and whether a legal hold applies.
| Data class | Typical retention approach |
| Active account and profile | For the active relationship. After deactivation or termination, normally deleted or anonymised from active systems within 90 days unless the Organisation requests an earlier permitted action or a legal reason requires retention. |
| Recognition celebration group and event content | For the Organisation's active use and configured history period, then deleted or anonymised after termination and any agreed export window, normally within 90 days. |
| Survey and poll data | According to the stated survey purpose and Organisation settings. Identity linkage for anonymous surveys is minimised or separated and removed when no longer needed. |
| Security access and audit logs | Typically 12 to 24 months, with longer retention for a live investigation, serious incident, legal claim or immutable financial audit requirement. |
| Support and complaint records | Typically up to 3 years after closure, or longer where needed for a dispute, regulatory complaint or transaction record. |
| Financial transaction and compliance records | Usually 5 to 7 years after the transaction or relationship, depending on accounting, tax, anti-money-laundering, provider and local legal requirements. |
| KYC or verification material | Preferably held by the verification provider. Any copy or reference held by Kola is retained only for the required compliance, dispute or audit period and then securely deleted. |
| Marketing records | While the relationship or consent remains relevant. A minimal suppression record may be kept for as long as needed to honour an objection or unsubscribe. |
| Website analytics | According to the disclosed cookie or analytics duration, with aggregation or deletion when identifiable detail is no longer needed. |
| Backups | Removed through protected backup rotation, typically within 90 days, unless isolated for incident recovery or legal preservation. |
| Aggregated or de-identified data | May be retained for longer where it no longer identifies a person and reasonable controls prevent re-identification. |
Deletion is not always immediate
Deletion from active systems may not remove information instantly from protected backups, audit records, completed transaction records or content already shared with an authorised audience. We restrict backup use and remove data through the normal rotation. We may retain limited information where necessary to establish, exercise or defend legal claims, comply with law, prevent fraud or honour an opt-out.
15 Security
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected according to risk and may include:
Tenant and group access controls, role-based permissions and separation of People and Wallet authority.
Encryption in transit and appropriate encryption or protected storage at rest.
Secure authentication, short-lived or rotated tokens and step-up verification for sensitive actions.
Request-signature validation, replay protection, rate limits and idempotency controls for integrations and transactions.
Audit trails for role changes, configuration, exports, support access and financial intents.
Restricted, logged and time-bound support access based on least privilege.
Monitoring, secure development, dependency review, backups, recovery testing and incident procedures.
Data minimisation, log filtering and separation of sensitive provider data from ordinary workplace activity.
Security incidents
If a personal data breach occurs, we assess risk, take containment and recovery steps and notify the relevant Organisation, regulator and affected people where required by law or contract. Users should report suspected compromise promptly to [email protected] and avoid sending passwords or full identity documents by ordinary email.
16 Your rights and choices
Depending on your location, the context and applicable law, you may have rights to:
Be informed about how personal data is used.
Request access to personal data and information about its processing.
Ask for inaccurate or incomplete personal data to be corrected.
Ask for deletion where there is no continuing lawful reason to keep the data.
Ask us to restrict processing in specified circumstances.
Object to processing based on legitimate interests and object at any time to direct marketing.
Receive certain personal data in a structured, commonly used and machine-readable format and ask for transmission where applicable.
Withdraw consent where processing relies on consent.
Ask for safeguards relating to a restricted international transfer.
Challenge a decision based solely on automated processing that has legal or similarly significant effects, where applicable.
Complain to the relevant data protection authority and, where available, seek a legal remedy.
How to exercise a right
Email [email protected] with enough detail for us to identify the relevant account, Organisation and request. We may ask for proportionate verification and may need to consult the Organisation where it is the controller. We normally respond within the period required by applicable law. A request is generally free, but a lawful fee or refusal may apply to a manifestly unfounded or excessive request.
Your product choices
Kola also provides practical controls over supported birthday and anniversary visibility, recognition audience, wishlists, notifications, marketing, optional cookies and external sharing. Product settings do not replace a legal rights request, and a legal request may not override another person's rights or mandatory recordkeeping.
17 Organisation administrators and requests
If your request concerns data that your employer or Organisation controls - such as workforce directory information, an Organisation-created survey, a workplace role or a company retention instruction - contacting the Organisation first may be the fastest route. If you contact us, we may refer or transmit the request to the Organisation and assist it as processor.
We will not allow an administrator to use support access to bypass product privacy controls, reveal private balances or identify anonymous respondents. We may require verified authority, log the access and notify appropriate parties.
18 Children
Kola is a workplace service and is not directed to children under 16. Organisations should not submit a child's personal data or invite a user below the applicable minimum age without first establishing a lawful basis, providing suitable notices and agreeing necessary safeguards with us.
If you believe a child has used Kola or personal data has been submitted without appropriate authority, contact [email protected] so we can investigate with the relevant Organisation.
19 Automated decisions and profiling
Kola may automatically schedule reminders, detect repeated activity, apply scoring rules, flag suspected abuse, recommend troubleshooting steps or generate aggregate insights. Recognition Scores and leaderboards reflect configured participation rules and are not intended to determine employment rights or performance.
We do not intend to make solely automated decisions about a person that produce legal or similarly significant effects without appropriate notice, a lawful basis and required safeguards. Organisations must not use Kola scores or automated insights as the sole basis for hiring, dismissal, promotion, discipline, pay or comparable decisions.
20 Third party links and services
Kola may display links to merchant websites, social networks, Slack, Microsoft services or other third parties. Their privacy practices apply when you leave Kola or use their independent service. We do not control their content or information handling.
Wishlist links are user-provided. We may validate the URL and show the destination domain but do not scrape or republish merchant content as though it were ours. Check the destination before entering payment or personal information.
21 Changes to this Policy
We may update this Policy when Kola, our providers, the law or our processing changes. We will publish the updated Policy, change the effective date and provide additional notice where a change is material or consent is required.
Earlier versions may be retained for reference. A Policy update does not reduce rights that already apply under law or allow us to use personal data for a materially incompatible purpose without an appropriate basis and notice.
22 Complaints
Please contact [email protected] first if you are concerned about how we have handled personal data. We will acknowledge, investigate and communicate the outcome in accordance with applicable complaint-handling requirements.
In the United Kingdom, you may complain to the Information Commissioner's Office. Information is available at ico.org.uk. In Nigeria, you may complain to the Nigeria Data Protection Commission at ndpc.gov.ng. Users elsewhere may contact the competent data protection authority in their country. You may complain to a regulator without contacting us first, but we would appreciate the opportunity to resolve the issue.
23 Contact details
Numero Technology Ltd
111 New Union Street, Coventry, West Midlands CV1 2NT, United Kingdom
Privacy and rights requests [email protected]
Product support [email protected]
Website withkola.com
Inquiries: [email protected] · [email protected]