Skip to main content
Kola/Legal/Privacy Policy
Official Document

Privacy Policy

Privacy at Kola

This Privacy Policy explains how Numero Technology Ltd handles personal data when organisations and their people use Kola through withkola.com, app.withkola.com, Slack, Microsoft Teams and related services.

Kola is a workplace culture and rewards platform. It can be used without a company wallet. Optional funded rewards, balances, contributions, payouts and cards involve additional personal and financial data only when the relevant feature is separately activated.

We do not sell personal data. We do not use private balances, private recognition or anonymous survey responses for advertising. We use personal data only for the purposes described here, on an appropriate legal basis and subject to the controls explained below.

1 Who we are and how to contact us

Kola is owned and operated by Numero Technology Ltd, incorporated in England and Wales.
111 New Union Street, Coventry, West Midlands CV1 2NT, United Kingdom.

For privacy questions, rights requests or complaints, contact [email protected]. For ordinary product support, contact [email protected].

2 Scope of this Policy

This Policy applies to personal data handled through the Kola public website, authenticated web application, Slack and Microsoft Teams applications, integrations, customer onboarding, support, events, marketing and optional rewards or financial features.

It applies to Organisation owners, administrators, employees, contractors, group members, website visitors, prospective customers, support contacts and other people whose information is submitted to Kola.

A Third Party Service, employer, reward issuer, payment provider, identity provider or linked merchant may have its own privacy notice. This Policy does not replace their notices or govern processing they carry out independently.

3 Our role and your employer's role

Data protection roles depend on the activity. This section is important because it determines who decides how personal data is used and who should answer a request.

Where the Organisation is controller

The Organisation is generally the controller when it decides to install Kola, imports or synchronises its workforce directory, configures workplace visibility, creates groups, runs recognition or engagement programmes, schedules celebrations, creates surveys, sets scoring rules, reviews company reports or instructs us to process Organisation Data. For these activities, we generally act as the Organisation's processor and follow its documented instructions, our agreement and applicable law.

The Organisation is responsible for having a lawful basis, giving employees appropriate workplace privacy information, using fair settings, responding to employment-related requests and not using Kola unlawfully for covert monitoring or unfair decisions.

Where Numero Technology Ltd is controller

We act as controller when we decide how and why personal data is used for account security, identity linking, service administration, abuse and fraud prevention, direct support relationships, legal compliance, product communications, marketing preferences, website operation and our own business records. We may also act as controller for optional financial or verification activities where we determine the relevant purposes or have our own legal obligations.

Independent and joint participants

Slack, Microsoft, Google, payment and identity providers, reward issuers, card or payout providers and merchants may act as independent controllers for their own services. If an arrangement makes us joint controllers with another party, we will provide any additional information required about our respective responsibilities.

4 Personal data we collect

CategoryExamples
Identity and contactName, work email, username, profile image, preferred name, phone number where provided, account identifiers and authentication status.
Workplace and membershipEmployer or Organisation, job title, department, group memberships, work location, role, manager relationship, workspace or tenant identifiers and account status.
Integration dataSlack or Teams user, workspace, tenant, team and channel identifiers; installation permissions; OAuth tokens; connection status; permitted directory fields; message and interaction metadata.
Profile and important datesTimezone, language, notification settings, birthday or anniversary information, visibility preferences, optional uploaded image and wishlist information.
Recognition and contentRecognition text, recipient, company value, audience, reactions, attachments, moderation status, reports and delivery history.
Engagement and participationRecognition Scores, badges, levels, leaderboard position, campaign activity, game participation, event invitations, RSVPs, gift-exchange participation and group activity.
Listening and feedbackPoll choices, survey or mood-check responses, optional free text, response status and privacy or anonymity settings.
Rewards and transactionsReward selection, eligibility, order and fulfilment status, Kola Balance reference, wallet or Pot activity, payment reference, amount, currency, fee, beneficiary and reconciliation status.
Verification and complianceBusiness or identity verification details, date of birth where required, address, government document reference, bank-account details, sanctions or fraud-screening result and provider customer reference. We minimise storage in Kola where a provider can collect this directly.
Technical and securityIP address, device and browser type, cookie or session identifiers, login activity, request and correlation IDs, audit events, error and diagnostic data, security alerts and approximate location inferred from IP where needed for security.
Support and communicationsSupport messages, files you send, call or meeting notes where applicable, complaint records, consent and preference history, and service or marketing communication activity.
Website and prospectPages viewed, referral source, form submissions, business contact information, event registrations and cookie choices.

Special category and sensitive data

Kola is not designed for users to submit unnecessary health, biometric, political, religious, trade-union, ethnicity, sexuality or other special category data in recognition messages, wishlists or ordinary workplace content. Survey responses and free text may nonetheless reveal sensitive information. Organisations must use such features carefully and establish an additional lawful condition where required.

Identity or financial providers may process sensitive verification information under their own notices. We do not use special category data to target marketing or determine workplace ranking.

5 Where personal data comes from

We receive personal data from the following sources:

Directly from you when you sign in, set preferences, recognise someone, respond, join an activity, redeem a reward, contact support or choose marketing settings.

From your Organisation when it installs Kola, invites users, synchronises a directory, configures roles and groups, enters important dates, issues rewards or provides support information.

From Slack, Microsoft Teams, Google, Microsoft identity services and other integrations according to the permissions shown and enabled.

From payment, reward, identity, fraud, card, payout and financial providers when an optional feature is activated and they return eligibility, status or transaction information.

Automatically from your browser, device, integrations and use of the Services through cookies, logs, audit records and security systems.

From public or business sources where appropriate for business-to-business contact, verification, fraud prevention or legal compliance.

6 How and why we use personal data

PurposeTypical dataLawful basis
Provide and administer KolaIdentity, workplace, integration, content, settings and activityContract; legitimate interests; and, where we act as processor, the Organisation's instructions.
Authenticate and link identitiesAccount identifiers, work email, authentication and integration dataContract and legitimate interests in secure, accurate access.
Deliver recognition celebrations and activitiesContent, dates, preferences, groups, recipients and delivery dataContract; legitimate interests; consent where a feature specifically requires it; Organisation instructions.
Operate scores games and insightsActivity, Recognition Scores, campaign and group dataLegitimate interests in providing configured engagement features; Organisation instructions.
Fulfil rewards and optional transactionsReward, wallet, payment, beneficiary and provider dataContract; legal obligation; legitimate interests in fulfilment, reconciliation and fraud prevention.
Verify identity and manage riskIdentity, device, transaction, screening and audit dataLegal obligation and legitimate interests in security, fraud prevention and protecting users.
Support and troubleshootAccount, technical, transaction and support communicationsContract and legitimate interests in resolving issues and improving service.
Secure and monitor the ServicesLogs, IP, device, access, audit and diagnostic dataLegal obligation and legitimate interests in security, resilience and abuse prevention.
Meet legal and regulatory dutiesIdentity, transaction, complaint, audit and retention recordsLegal obligation; public task where applicable; establishment or defence of legal claims.
Improve KolaUsage, feedback, failure and aggregated performance dataLegitimate interests in product improvement. We use aggregated or de-identified data where reasonably possible.
Communicate service informationContact, role, account and notification preferencesContract and legitimate interests in administering the relationship.
Market Kola and Numero ecosystem productsBusiness contact, usage context and marketing preferencesConsent where required; otherwise legitimate interests, subject to applicable direct-marketing rules and your right to object.

Legitimate interests

Where we rely on legitimate interests, we consider whether the use is necessary, what people reasonably expect and whether their rights override our interest. Our interests include providing and improving a useful workplace service, securing accounts, preventing abuse, communicating with business customers and understanding product performance. You may object to processing based on legitimate interests; see section 16.

Consent

Where we rely on consent, it must be specific and may be withdrawn at any time. Withdrawing consent does not make earlier processing unlawful. Some functionality may stop if it cannot operate without the information covered by the withdrawn consent.

7 Recognition celebrations and workplace visibility

Recognition can be posted to a public channel, restricted group, direct message or private destination depending on the sender's choice and Organisation policy. Kola provides a preview before publication where supported, but users must still confirm the intended recipient and audience.

Birthday and anniversary features use the visibility selected by the employee or permitted by the Organisation under applicable law. Kola should not expose a year of birth or calculate age by default. Employees may hide a date, restrict the audience or opt out of supported reminders.

Kola may use a Slack or Microsoft Teams profile image as the default where permissions allow. An employee may replace it with an uploaded image. A Kola-branded sharing card is created only for an eligible user action and is not posted externally without deliberate confirmation.

Organisation administrators can see workplace activity and reports permitted by their role. They cannot use ordinary administrator access to see another person's private Kola Balance, private wishlist settings or content expressly restricted from them. Financial and People permissions are separated.

8 Surveys polls and anonymous responses

A poll may be public, attributed, confidential or anonymous depending on its configuration. The interface should tell participants which model applies before they submit a response.

For a survey described as anonymous, Kola separates identity from response data where practicable, limits administrative access and reports results only after a suitable minimum response threshold. We do not provide an Organisation with identity-linked raw responses for a survey represented to users as anonymous.

No technical system can guarantee anonymity if a person voluntarily identifies themselves in free text, a group is extremely small or an Organisation combines results with information it already knows. Participants should avoid unnecessary identifying details, and Organisations must not attempt re-identification.

9 Optional rewards wallets and financial services

Installing Kola does not create a wallet or financial account. If an Organisation activates funded rewards or financial features, additional data may be required to quote, fund, verify, issue, redeem, pay out, reconcile, reverse or support the transaction.

A payment, banking, card, identity or payout provider may collect information directly through a secure flow. Where possible, Kola stores only a provider reference, verification outcome and information needed for user support, audit and reconciliation rather than a copy of the underlying document.

For cash withdrawals or future international payouts, we may process verified beneficiary details, country, currency, exchange-rate quote, fees, screening results, payment status and failure or refund information. For future virtual cards, the issuer may require identity and cardholder details and will provide its own terms and privacy notice.

Financial providers may use personal data for their own legal duties, including identity verification, sanctions screening, anti-money-laundering checks, transaction monitoring, fraud prevention, safeguarding, disputes and regulatory reporting. A user may be unable to use a financial feature if required information is not provided or checks are not completed.

10 Cookies analytics and similar technologies

We use cookies, local storage, session technologies and similar tools to operate the website and application. Strictly necessary technologies support authentication, security, load balancing, fraud prevention, preferences and core functionality.

Where required by law, we ask for consent before using non-essential analytics, advertising or similar technologies. You can accept, reject or change optional cookie choices through the available settings. Rejecting optional cookies does not prevent core Kola use, although some convenience or analytics features may be limited.

Our cookie banner or separate cookie notice will identify the technologies actually deployed, their providers, purposes and duration. Browser controls can also block or delete cookies, but blocking necessary technologies may prevent sign-in or secure functions.

11 Marketing across the Numero ecosystem

Numero Technology Ltd may use permitted business contact information to communicate about Kola and other current or future products, features and services offered within the Numero Technology Ltd ecosystem. We do not need to list every product in this Policy for that category to apply, but each marketing communication will identify the sender and will not disguise its commercial purpose.

We separate marketing from essential service communications. Accepting the Kola Terms does not automatically mean an individual has consented to every form of direct marketing.

Email marketing includes an unsubscribe link or another simple opt-out method.

SMS, WhatsApp, push notification or similar marketing is sent only where permitted and includes an appropriate way to stop or manage it.

We record consent, objections and suppression information so we can respect choices. We may keep a minimal suppression record after opt-out rather than delete it and risk contacting the person again.

We do not use private recognition, private balances or anonymous survey answers to target marketing.

We do not sell personal data or permit unrelated third parties to use Kola workplace data for their own advertising.

12 When we share personal data

We share personal data only where necessary for the purposes in this Policy, under appropriate obligations and access controls. Recipient categories may include:

The relevant Organisation and its authorised administrators, group leads and users, according to roles, settings and the chosen audience.

Slack, Microsoft Teams, Google and Microsoft identity services where you connect or use those services.

Cloud hosting, database, storage, security, logging, communications, support and analytics providers that process data for us.

Reward suppliers, gift-card issuers, airtime or data providers and fulfilment partners needed to deliver a selected reward.

Payment, banking, virtual-account, card, identity-verification, fraud, foreign-exchange and payout providers for activated financial services.

Professional advisers, auditors, insurers and potential buyers or investors under confidentiality and only where appropriate.

Courts, regulators, law enforcement, tax authorities or other bodies where disclosure is required or lawfully necessary to protect rights, safety and the integrity of the Services.

A successor or acquiring organisation in a merger, reorganisation, financing or sale, subject to applicable law and continued protection of personal data.

Service providers and subprocessors

Processors and subprocessors may use personal data only to provide contracted services, protect those services and meet applicable legal duties. We assess providers according to the nature and risk of the processing and use data protection terms where required. Organisations may request current subprocessor information from [email protected] or use any published subprocessor page when available.

13 International transfers

Kola serves organisations and users in more than one country. Personal data may be accessed or processed in the United Kingdom, Nigeria, other African countries, the European Economic Area, the United States or another country where an approved provider operates.

Where UK data protection law treats a transfer as restricted, we use an available lawful mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another permitted safeguard. We also assess transfer risk and apply supplementary technical and organisational measures where appropriate.

Where Nigerian or other local law applies, we use the applicable transfer basis and safeguards required by that law. You may contact [email protected] for information about the relevant safeguard, subject to commercial confidentiality and security restrictions.

14 How long we keep personal data

We keep personal data only for as long as needed for the purpose, contractual commitments, dispute resolution, security, financial reconciliation and applicable legal obligations. The actual period depends on the data, Organisation settings, provider relationship and whether a legal hold applies.

Data classTypical retention approach
Active account and profileFor the active relationship. After deactivation or termination, normally deleted or anonymised from active systems within 90 days unless the Organisation requests an earlier permitted action or a legal reason requires retention.
Recognition celebration group and event contentFor the Organisation's active use and configured history period, then deleted or anonymised after termination and any agreed export window, normally within 90 days.
Survey and poll dataAccording to the stated survey purpose and Organisation settings. Identity linkage for anonymous surveys is minimised or separated and removed when no longer needed.
Security access and audit logsTypically 12 to 24 months, with longer retention for a live investigation, serious incident, legal claim or immutable financial audit requirement.
Support and complaint recordsTypically up to 3 years after closure, or longer where needed for a dispute, regulatory complaint or transaction record.
Financial transaction and compliance recordsUsually 5 to 7 years after the transaction or relationship, depending on accounting, tax, anti-money-laundering, provider and local legal requirements.
KYC or verification materialPreferably held by the verification provider. Any copy or reference held by Kola is retained only for the required compliance, dispute or audit period and then securely deleted.
Marketing recordsWhile the relationship or consent remains relevant. A minimal suppression record may be kept for as long as needed to honour an objection or unsubscribe.
Website analyticsAccording to the disclosed cookie or analytics duration, with aggregation or deletion when identifiable detail is no longer needed.
BackupsRemoved through protected backup rotation, typically within 90 days, unless isolated for incident recovery or legal preservation.
Aggregated or de-identified dataMay be retained for longer where it no longer identifies a person and reasonable controls prevent re-identification.

Deletion is not always immediate

Deletion from active systems may not remove information instantly from protected backups, audit records, completed transaction records or content already shared with an authorised audience. We restrict backup use and remove data through the normal rotation. We may retain limited information where necessary to establish, exercise or defend legal claims, comply with law, prevent fraud or honour an opt-out.

15 Security

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected according to risk and may include:

Tenant and group access controls, role-based permissions and separation of People and Wallet authority.

Encryption in transit and appropriate encryption or protected storage at rest.

Secure authentication, short-lived or rotated tokens and step-up verification for sensitive actions.

Request-signature validation, replay protection, rate limits and idempotency controls for integrations and transactions.

Audit trails for role changes, configuration, exports, support access and financial intents.

Restricted, logged and time-bound support access based on least privilege.

Monitoring, secure development, dependency review, backups, recovery testing and incident procedures.

Data minimisation, log filtering and separation of sensitive provider data from ordinary workplace activity.

Security incidents

If a personal data breach occurs, we assess risk, take containment and recovery steps and notify the relevant Organisation, regulator and affected people where required by law or contract. Users should report suspected compromise promptly to [email protected] and avoid sending passwords or full identity documents by ordinary email.

16 Your rights and choices

Depending on your location, the context and applicable law, you may have rights to:

Be informed about how personal data is used.

Request access to personal data and information about its processing.

Ask for inaccurate or incomplete personal data to be corrected.

Ask for deletion where there is no continuing lawful reason to keep the data.

Ask us to restrict processing in specified circumstances.

Object to processing based on legitimate interests and object at any time to direct marketing.

Receive certain personal data in a structured, commonly used and machine-readable format and ask for transmission where applicable.

Withdraw consent where processing relies on consent.

Ask for safeguards relating to a restricted international transfer.

Challenge a decision based solely on automated processing that has legal or similarly significant effects, where applicable.

Complain to the relevant data protection authority and, where available, seek a legal remedy.

How to exercise a right

Email [email protected] with enough detail for us to identify the relevant account, Organisation and request. We may ask for proportionate verification and may need to consult the Organisation where it is the controller. We normally respond within the period required by applicable law. A request is generally free, but a lawful fee or refusal may apply to a manifestly unfounded or excessive request.

Your product choices

Kola also provides practical controls over supported birthday and anniversary visibility, recognition audience, wishlists, notifications, marketing, optional cookies and external sharing. Product settings do not replace a legal rights request, and a legal request may not override another person's rights or mandatory recordkeeping.

17 Organisation administrators and requests

If your request concerns data that your employer or Organisation controls - such as workforce directory information, an Organisation-created survey, a workplace role or a company retention instruction - contacting the Organisation first may be the fastest route. If you contact us, we may refer or transmit the request to the Organisation and assist it as processor.

We will not allow an administrator to use support access to bypass product privacy controls, reveal private balances or identify anonymous respondents. We may require verified authority, log the access and notify appropriate parties.

18 Children

Kola is a workplace service and is not directed to children under 16. Organisations should not submit a child's personal data or invite a user below the applicable minimum age without first establishing a lawful basis, providing suitable notices and agreeing necessary safeguards with us.

If you believe a child has used Kola or personal data has been submitted without appropriate authority, contact [email protected] so we can investigate with the relevant Organisation.

19 Automated decisions and profiling

Kola may automatically schedule reminders, detect repeated activity, apply scoring rules, flag suspected abuse, recommend troubleshooting steps or generate aggregate insights. Recognition Scores and leaderboards reflect configured participation rules and are not intended to determine employment rights or performance.

We do not intend to make solely automated decisions about a person that produce legal or similarly significant effects without appropriate notice, a lawful basis and required safeguards. Organisations must not use Kola scores or automated insights as the sole basis for hiring, dismissal, promotion, discipline, pay or comparable decisions.

20 Third party links and services

Kola may display links to merchant websites, social networks, Slack, Microsoft services or other third parties. Their privacy practices apply when you leave Kola or use their independent service. We do not control their content or information handling.

Wishlist links are user-provided. We may validate the URL and show the destination domain but do not scrape or republish merchant content as though it were ours. Check the destination before entering payment or personal information.

21 Changes to this Policy

We may update this Policy when Kola, our providers, the law or our processing changes. We will publish the updated Policy, change the effective date and provide additional notice where a change is material or consent is required.

Earlier versions may be retained for reference. A Policy update does not reduce rights that already apply under law or allow us to use personal data for a materially incompatible purpose without an appropriate basis and notice.

22 Complaints

Please contact [email protected] first if you are concerned about how we have handled personal data. We will acknowledge, investigate and communicate the outcome in accordance with applicable complaint-handling requirements.

In the United Kingdom, you may complain to the Information Commissioner's Office. Information is available at ico.org.uk. In Nigeria, you may complain to the Nigeria Data Protection Commission at ndpc.gov.ng. Users elsewhere may contact the competent data protection authority in their country. You may complain to a regulator without contacting us first, but we would appreciate the opportunity to resolve the issue.

23 Contact details

Numero Technology Ltd
111 New Union Street, Coventry, West Midlands CV1 2NT, United Kingdom

Privacy and rights requests [email protected]

Product support [email protected]

Website withkola.com