Privacy Policy

Last updated: August 2026

This is a starting template, not a finished legal document — it needs review by qualified legal counsel before it governs a real customer relationship.

1. What we collect

Account information (name, email, role), the operational data your organization enters (projects, time entries, invoices, employee records relevant to your enabled modules), and standard technical data such as sign-in timestamps and IP address for security purposes.

2. How we use it

To provide and operate the service, enforce the roles and permissions your organization configures, secure accounts, and communicate service-related notices.

3. Data isolation

Data is scoped per tenant at the application layer. Users from one organization cannot access another organization's data through the product.

4. Third parties

Where you connect an integration (Microsoft 365, Google Workspace, or others as they become available), that provider processes data according to the permissions you grant during that connection's own OAuth consent screen — not silently in the background.

5. Retention

Data remains accessible for the duration of your subscription and for a limited period afterward to allow export, per your plan's terms.

6. Your rights

Depending on your jurisdiction, you may have rights to access, correct, or request deletion of personal data. Requests can be directed to hello@koraerp.com.

7. Changes

We'll update this policy as the product changes, and note material changes here.