Privacy Policy
Last updated: August 2026
1. What we collect
Account information (name, email, role), the operational data your organization enters (projects, time entries, invoices, employee records relevant to your enabled modules), and standard technical data such as sign-in timestamps and IP address for security purposes.
2. How we use it
To provide and operate the service, enforce the roles and permissions your organization configures, secure accounts, and communicate service-related notices.
3. Data isolation
Data is scoped per tenant at the application layer. Users from one organization cannot access another organization's data through the product.
4. Third parties
Where you connect an integration (Microsoft 365, Google Workspace, or others as they become available), that provider processes data according to the permissions you grant during that connection's own OAuth consent screen — not silently in the background.
5. Retention
Data remains accessible for the duration of your subscription and for a limited period afterward to allow export, per your plan's terms.
6. Your rights
Depending on your jurisdiction, you may have rights to access, correct, or request deletion of personal data. Requests can be directed to hello@koraerp.com.
7. Changes
We'll update this policy as the product changes, and note material changes here.
