Privacy Policy
Last updated: 12 August 2026
This Privacy Policy describes how Kota (“we”, “us”, “our”) collects, uses, stores, and shares personal information when you use our website and application (together, the “Service”). We are committed to protecting your privacy in accordance with the Protection of Personal Information Act, 2013 (POPIA) and other applicable South African law.
Note: This policy is a practical summary for transparency. It is not legal advice. You may wish to have your own legal adviser review it for your circumstances. We may update this policy from time to time; the “Last updated” date above will change when we do.
1. Who is responsible for your information?
The responsible party (operator) for personal information processed through the Service is the entity operating Kota as described on our website or in your agreement with us. For questions about this policy or your information, use the contact details at the end of this document.
2. What personal information do we collect?
Depending on how you use the Service, we may process categories of information including:
- Account and identity: name, email address, authentication identifiers, organisation details.
- Business content you provide: text you type or upload (for example messages, client notes, documents, invoices, knowledge-base entries).
- Technical and usage data: IP address, device/browser type, approximate location derived from network data, log data, and similar metadata needed to run and secure the Service.
- Billing (if applicable): billing contact details and payment-related information processed by our payment service provider (we do not store full card details on our own servers where a provider handles them).
3. How we use personal information (purpose)
We process personal information only for legitimate purposes related to the Service, including:
- creating and managing your account and organisation workspace;
- providing AI-assisted features (see section 5);
- storing, retrieving, and displaying your business data as you direct;
- billing, subscription management, and support;
- security, fraud prevention, abuse detection, and legal compliance;
- improving reliability and performance of the Service (for example error monitoring), without using your content for unrelated advertising or resale.
Where POPIA requires a lawful basis, we rely on one or more of: performance of a contract with you, compliance with law, your consent where appropriate, and legitimate interests that are not overridden by your rights (such as securing our systems).
4. Artificial intelligence and your data
Kota uses third-party AI models to generate responses, summaries, drafts, and similar outputs inside the application. We route those requests through OpenRouter (and the underlying model providers it uses).
Important: When you use AI features, relevant parts of your prompts, conversation context, and business content needed to fulfil your request are transmitted to OpenRouter and those model providers so they can process the request and return a result. That processing is essential to provide the AI functionality you are using; it is not a separate optional add-on.
Every AI request is routed exclusively to providers with a zero data retention (ZDR) commitment. Our preferred provider is SOC 2 and ISO 27001 certified, and any backup provider used during an outage must meet the same zero-retention standard — this is enforced in our routing configuration itself, not left to individual provider defaults. No provider may store your prompts or use them to train their models. The behaviour of each underlying model provider is otherwise governed by their own terms and policies; we encourage you to review OpenRouter’s documentation and policies for current detail.
We do not use your personal information or business content for unrelated purposes such as selling your data to data brokers, building unrelated advertising profiles, or training separate AI products outside operating the Kota Service for you. Processing is for delivering and improving the Service you signed up for, security, and compliance.
5. Subprocessors and sharing
We use the service providers below to operate Kota. They process information on our instructions and for no other purpose. This list is current as at the date at the top of this page; we will update it when it changes.
- Supabase — database, authentication and file storage. Holds your account and all workspace data.
- OpenRouter, and the model providers it routes to (currently DeepInfra, with Anthropic and Google as fallbacks) — AI inference. See section 4.
- Railway and Netlify — application and website hosting.
- Paystack — payment processing, if you subscribe to a paid plan.
- Resend — sending documents and notification emails on your instruction.
- Telegram — only if you choose to connect the optional Telegram assistant.
- Sentry — error reporting. Configured not to attach personal information to error reports.
- PostHog — product analytics. Only loaded if you consent to it.
- Linear — if you submit feedback through the app, your message is filed as an issue there.
Cross-border transfers
Most of these providers are located outside South Africa. We rely on section 72(1) of POPIA to transfer personal information to them, on the basis that the transfer is necessary for the performance of our contract with you — the Service cannot be delivered without hosting, inference, payment and email infrastructure — and, where applicable, that the recipient is bound by an agreement upholding principles of reasonable protection materially similar to POPIA's conditions for lawful processing.
We may disclose information if required by law, court order, or competent authority, or to protect our rights, users, or the security of the Service.
6. Retention
We keep personal information only as long as needed for the purposes above. In practice we treat two kinds of data differently.
Your business records — clients, invoices, quotes, expenses, services, deals and tasks — are yours, and we keep them for as long as your account is open. We do not delete them on a timer: South African tax law requires financial records to be kept for five years, and deciding when they go is your call, not ours. You can delete them at any time from within the app, or delete everything at once (section 8).
Operational data we generate about your use of Kota — activity logs, audit trails, usage records, delivery logs and prior versions of documents — is aged out automatically. Typical periods are 30 days for the change-history snapshots that support Undo, 90 days for usage and audit records, and up to a year for document version history.
After you close your account we may retain limited records where the law requires it, for example for tax or to resolve a dispute.
7. Security
We implement appropriate technical and organisational measures designed to protect personal information against unauthorised access, loss, or misuse. No online service can guarantee absolute security; you should use a strong password and protect your account credentials.
8. Your rights under POPIA
Subject to POPIA and any applicable exceptions, you may have the right to:
- request access to personal information we hold about you;
- request correction or updating of inaccurate information;
- request deletion or restriction of processing in prescribed circumstances;
- object to certain processing (for example direct marketing, if ever applicable);
- withdraw consent where processing is based on consent (without affecting prior lawful processing);
- lodge a complaint with the Information Regulator (South Africa).
To exercise rights, contact us using the details below. We may need to verify your identity before responding. You may also have rights under the Promotion of Access to Information Act, 2000 (PAIA); a PAIA manual may be published separately where we are required to maintain one.
9. Cookies and similar technologies
We may use cookies or similar technologies for session management, security, preferences, and (where enabled) product analytics. You can control cookies through your browser settings; blocking some cookies may affect functionality.
10. Children
The Service is intended for businesses and adults. We do not knowingly collect personal information from children without appropriate parental authority. If you believe we have collected information from a child in error, contact us and we will take steps to delete it where required.
11. Changes
We may update this Privacy Policy to reflect changes to our practices or legal requirements. We will post the updated version on this page and adjust the “Last updated” date. Where changes are material, we will provide additional notice if required by law (for example by email or in-app notice).
12. Contact and Information Officer
Kota has designated an Information Officer as required by POPIA. For any privacy-related requests — including access, correction, deletion, or objection to processing (Data Subject Access Requests) — please contact:
- Email: privacy@getkota.co.za
We will acknowledge your request within 3 business days and respond fully within 30 days as required by POPIA. You may be asked to verify your identity before we process your request.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Regulator (South Africa):
- Website: www.inforegulator.org.za
- Email: inforeg@justice.gov.za
See also our Terms of Service.