Effective date: September 13, 2026

Kola CRM Privacy Policy

This Privacy Policy describes information Chestnut Compute Corp collects through Kola CRM, kola CRM-related websites and related services. Kola CRM is a business-to-business product sold to organizations, not consumers.

1. Who we are

Chestnut Compute Corp (“Chestnut Compute”, “we”, “us” or “our”) is an Ontario corporation at 302-1 Brian Peck Crescent, Toronto, Ontario M4G 4J7, Canada. Privacy contact: privacy@kolacrm.com. Privacy Officer: Chestnut Compute Corp.

2. Scope and framework

This Policy applies to information collected through the Kola CRM website, software, licence services, Cloud Backup and support services. Depending on the individuals, location and processing, applicable law may include PIPEDA, Québec’s private-sector privacy legislation, applicable U.S. state privacy laws and other laws. We do not treat this Policy as replacing any notice required by applicable law.

We use information as necessary to perform contracts, provide requested services, comply with law, protect our systems and pursue legitimate business interests. Where consent is required, we will obtain it in the manner required by law.

3. Information we collect

3.1 Purchaser and account information

3.2 Licence-validation information

When Kola CRM loads, the validation service may receive a hashed licence key, hostname for Professional and Business tiers, IP address, timestamp, tier and validation result. We use this information to validate licences, detect sharing or misuse, enforce domain restrictions and revoke confirmed-abuse keys. Validation logs are retained for approximately 12 months unless longer retention is required for security, legal claims or law.

3.3 Cloud Backup

Cloud Backup encrypts CRM data in the customer environment before transmission. Chestnut Compute does not possess the decryption key and cannot ordinarily read the encrypted content. We may store encrypted snapshots and metadata such as account identifier, snapshot time, file size, version, technical logs and service status. Backup content is retained during an active subscription and generally for 30 days after cancellation before scheduled deletion, subject to legal holds, technical limitations and the service process.

3.4 Website and technical information

We may collect IP address, browser and device information, referring URL, pages visited, timestamps, security events and essential-cookie information. We do not use advertising cookies or sell personal information.

3.5 CRM data held by customers

Ordinary CRM data stored on the customer’s device or self-hosted server does not pass through Chestnut Compute’s systems. If a business customer submits personal information through Cloud Backup or support, the customer remains responsible for its authority, notices, purposes, retention and legal compliance. If your information appears in a customer’s CRM, direct privacy requests to that customer first; we will assist where legally required and technically feasible.

3.6 AI

Chestnut Compute does not receive or retain AI prompts, responses or AI-use telemetry. When a customer enables Ask Kola, selected information may travel directly from the customer environment to the AI provider selected by that customer using the customer’s API key. The customer is responsible for the provider’s terms, privacy settings and costs.

4. How we use information

InformationPurposes
Purchase and account informationLicence delivery, billing, renewals, support, fraud prevention, records and legal obligations.
Validation informationLicence verification, misuse detection, security and enforcement.
Cloud Backup metadata and encrypted contentProviding, securing, administering and deleting Cloud Backup.
Website and technical informationSecurity, troubleshooting, operation and service improvement.

We do not use personal information for behavioural advertising, sell it or use it to create advertising profiles.

5. Service providers and disclosures

We may disclose limited information to service providers who help us operate the Service, subject to contractual or other safeguards appropriate to the circumstances:

We may disclose information when required by law, court order or regulatory authority; to protect rights, safety or systems; to investigate fraud or abuse; or in connection with a merger, financing, acquisition or sale of assets. A successor will be required to handle information consistently with applicable law and will be notified where required.

6. Retention

We retain information only as long as reasonably necessary for the purposes described, legal, tax, accounting, security and dispute-resolution needs. As operational targets, purchase records may be retained for up to 7 years, validation logs for about 12 months, website logs for up to 90 days, and Cloud Backup snapshots during the subscription plus about 30 days after cancellation. Periods may vary where law, security investigations, legal holds or technical deletion cycles require it.

7. Security

We use safeguards appropriate to the information and service, including HTTPS in transit, licence-key hashing, client-side encryption for Cloud Backup, access controls and security reviews. No system is perfectly secure. We do not provide a guarantee that information cannot be lost, intercepted or compromised.

We assess security incidents under applicable law and notify regulators, customers and affected individuals where legally required or appropriate. For a confirmed incident affecting Cloud Backup, we will notify the affected business customer without undue delay after confirming reasonably available facts, subject to legal, security and law-enforcement constraints.

8. Your rights

Depending on applicable law, you may request access, correction, deletion, portability, restriction or objection, or withdraw consent where processing is consent-based. We may verify identity and authority before responding. Some records must be retained for legal or security reasons. Contact privacy@kolacrm.com; we will respond within the period required by applicable law.

Under PIPEDA, concerns may be raised with the Office of the Privacy Commissioner of Canada. Québec, U.S. state and other applicable laws may provide additional rights.

9. Québec and cross-border processing

Personal information may be processed in Canada, the United States or other countries where our providers operate. Cross-border processing may make information subject to the laws of those jurisdictions. Where Québec law applies, we will apply required governance, transparency, assessment, security-incident and cross-border-transfer measures.

10. California

Where California privacy law applies, California residents may have rights to know, access, correct, delete, limit certain uses of sensitive personal information, and opt out of sale or sharing where applicable. Chestnut Compute does not sell or share personal information for cross-context behavioural advertising. Requests may be submitted to privacy@kolacrm.com. We will not discriminate unlawfully for exercising a privacy right.

11. Cookies

Our website may use essential cookies and similar technologies needed for operation and security. We do not use advertising pixels. Kola CRM uses browser local storage for application data and settings. Local storage remains on the customer device unless the customer activates Cloud Backup or directly uses an external AI provider.

12. Children

Kola CRM is intended for business use by adults. We do not knowingly collect personal information directly from children. Contact us if you believe a child’s information was submitted.

13. Changes

We may update this Policy. Material changes will be posted at the applicable privacy-policy page and, where we have an email address and law permits, communicated before taking effect. The effective date appears at the top of this Policy. Prior versions may be requested.

14. Contact

Chestnut Compute Corp, Attn: Privacy Officer
302-1 Brian Peck Crescent
Toronto, Ontario M4G 4J7
Canada
privacy@kolacrm.com