Effective date: September 13, 2026
This Privacy Policy describes information Chestnut Compute Corp collects through Kola CRM, kola CRM-related websites and related services. Kola CRM is a business-to-business product sold to organizations, not consumers.
Chestnut Compute Corp (“Chestnut Compute”, “we”, “us” or “our”) is an Ontario corporation at 302-1 Brian Peck Crescent, Toronto, Ontario M4G 4J7, Canada. Privacy contact: privacy@kolacrm.com. Privacy Officer: Chestnut Compute Corp.
This Policy applies to information collected through the Kola CRM website, software, licence services, Cloud Backup and support services. Depending on the individuals, location and processing, applicable law may include PIPEDA, Québec’s private-sector privacy legislation, applicable U.S. state privacy laws and other laws. We do not treat this Policy as replacing any notice required by applicable law.
We use information as necessary to perform contracts, provide requested services, comply with law, protect our systems and pursue legitimate business interests. Where consent is required, we will obtain it in the manner required by law.
When Kola CRM loads, the validation service may receive a hashed licence key, hostname for Professional and Business tiers, IP address, timestamp, tier and validation result. We use this information to validate licences, detect sharing or misuse, enforce domain restrictions and revoke confirmed-abuse keys. Validation logs are retained for approximately 12 months unless longer retention is required for security, legal claims or law.
Cloud Backup encrypts CRM data in the customer environment before transmission. Chestnut Compute does not possess the decryption key and cannot ordinarily read the encrypted content. We may store encrypted snapshots and metadata such as account identifier, snapshot time, file size, version, technical logs and service status. Backup content is retained during an active subscription and generally for 30 days after cancellation before scheduled deletion, subject to legal holds, technical limitations and the service process.
We may collect IP address, browser and device information, referring URL, pages visited, timestamps, security events and essential-cookie information. We do not use advertising cookies or sell personal information.
Ordinary CRM data stored on the customer’s device or self-hosted server does not pass through Chestnut Compute’s systems. If a business customer submits personal information through Cloud Backup or support, the customer remains responsible for its authority, notices, purposes, retention and legal compliance. If your information appears in a customer’s CRM, direct privacy requests to that customer first; we will assist where legally required and technically feasible.
Chestnut Compute does not receive or retain AI prompts, responses or AI-use telemetry. When a customer enables Ask Kola, selected information may travel directly from the customer environment to the AI provider selected by that customer using the customer’s API key. The customer is responsible for the provider’s terms, privacy settings and costs.
| Information | Purposes |
|---|---|
| Purchase and account information | Licence delivery, billing, renewals, support, fraud prevention, records and legal obligations. |
| Validation information | Licence verification, misuse detection, security and enforcement. |
| Cloud Backup metadata and encrypted content | Providing, securing, administering and deleting Cloud Backup. |
| Website and technical information | Security, troubleshooting, operation and service improvement. |
We do not use personal information for behavioural advertising, sell it or use it to create advertising profiles.
We may disclose limited information to service providers who help us operate the Service, subject to contractual or other safeguards appropriate to the circumstances:
We may disclose information when required by law, court order or regulatory authority; to protect rights, safety or systems; to investigate fraud or abuse; or in connection with a merger, financing, acquisition or sale of assets. A successor will be required to handle information consistently with applicable law and will be notified where required.
We retain information only as long as reasonably necessary for the purposes described, legal, tax, accounting, security and dispute-resolution needs. As operational targets, purchase records may be retained for up to 7 years, validation logs for about 12 months, website logs for up to 90 days, and Cloud Backup snapshots during the subscription plus about 30 days after cancellation. Periods may vary where law, security investigations, legal holds or technical deletion cycles require it.
We use safeguards appropriate to the information and service, including HTTPS in transit, licence-key hashing, client-side encryption for Cloud Backup, access controls and security reviews. No system is perfectly secure. We do not provide a guarantee that information cannot be lost, intercepted or compromised.
We assess security incidents under applicable law and notify regulators, customers and affected individuals where legally required or appropriate. For a confirmed incident affecting Cloud Backup, we will notify the affected business customer without undue delay after confirming reasonably available facts, subject to legal, security and law-enforcement constraints.
Depending on applicable law, you may request access, correction, deletion, portability, restriction or objection, or withdraw consent where processing is consent-based. We may verify identity and authority before responding. Some records must be retained for legal or security reasons. Contact privacy@kolacrm.com; we will respond within the period required by applicable law.
Under PIPEDA, concerns may be raised with the Office of the Privacy Commissioner of Canada. Québec, U.S. state and other applicable laws may provide additional rights.
Personal information may be processed in Canada, the United States or other countries where our providers operate. Cross-border processing may make information subject to the laws of those jurisdictions. Where Québec law applies, we will apply required governance, transparency, assessment, security-incident and cross-border-transfer measures.
Where California privacy law applies, California residents may have rights to know, access, correct, delete, limit certain uses of sensitive personal information, and opt out of sale or sharing where applicable. Chestnut Compute does not sell or share personal information for cross-context behavioural advertising. Requests may be submitted to privacy@kolacrm.com. We will not discriminate unlawfully for exercising a privacy right.
Our website may use essential cookies and similar technologies needed for operation and security. We do not use advertising pixels. Kola CRM uses browser local storage for application data and settings. Local storage remains on the customer device unless the customer activates Cloud Backup or directly uses an external AI provider.
Kola CRM is intended for business use by adults. We do not knowingly collect personal information directly from children. Contact us if you believe a child’s information was submitted.
We may update this Policy. Material changes will be posted at the applicable privacy-policy page and, where we have an email address and law permits, communicated before taking effect. The effective date appears at the top of this Policy. Prior versions may be requested.
Chestnut Compute Corp, Attn: Privacy Officer
302-1 Brian Peck Crescent
Toronto, Ontario M4G 4J7
Canada
privacy@kolacrm.com