Kolis, portfolio reporting for private equity. This is the agreement referred to in section 1 of the Privacy Policy and section 5 of the Terms of Service.
This agreement applies whenever we process personal data on the Customer's behalf in the course of providing the service. It forms part of the Terms of Service. Where this agreement and any other document conflict on the handling of personal data, this agreement prevails.
"UK GDPR", "EU GDPR", "controller", "processor", "personal data", "processing", "personal data breach" and "data subject" carry the meanings given in the applicable data protection law. "Applicable law" means the UK GDPR, the EU GDPR, and any national law implementing or supplementing either, to the extent each applies.
Two different relationships run through this service and the law treats them differently. The split below is the same one stated in section 1 of the Privacy Policy.
| Data | Customer | Us |
|---|---|---|
| Reporting data. Financial figures filed by portfolio companies, documents uploaded in support, and accounting data drawn from a connected system. | Controller | Processor |
| Account data. The names, email addresses and roles of the people who sign in. | Controller of the instruction to create accounts | Controller, because we decide how authentication works |
Reporting data is company financial information and is not, in the ordinary case, personal data. But a set of management accounts or an uploaded document may incidentally contain names, salaries or other personal information. This agreement governs that data whenever it does, and we apply the same protections either way rather than sorting it first.
The Customer is responsible for having a lawful basis for the data it puts into the service, including in respect of its portfolio companies, and for its own relationship with them. We are not in a position to establish that basis and do not purport to.
We process personal data only on the Customer's documented instructions, including on transfers to a third country, unless required to do otherwise by law. Where the law requires it, we will tell the Customer before processing unless that law forbids us from saying so.
The instructions are: the Terms of Service, this agreement, and the Customer's own use of the service. Configuring a company, connecting an accounting system, running an extraction, asking the assistant a question: each is an instruction. There is no separate ticket system for them.
We will tell the Customer if, in our opinion, an instruction infringes applicable law. We do not use reporting data for any purpose of our own. Specifically, and as also stated in the Terms of Service: we do not sell it, we do not use it to train artificial intelligence models, we do not use it to serve another customer, and we do not use it to build products.
Any person we authorise to process the Customer's personal data is bound by a duty of confidence, whether by contract or by statute, and that duty survives the end of their engagement. Access is limited to those who need it to provide or support the service.
We implement appropriate technical and organisational measures under Article 32. The measures actually in place, and the ones that are planned rather than current, are set out in Annex C and are separated there on purpose. Nothing planned is described as current, in this agreement or anywhere else.
The Customer gives general authorisation for us to engage sub-processors. Those engaged today are listed in Annex B, which names each one, what it does, and where it is.
Before adding or replacing a sub-processor we will give the Customer at least 30 days' written notice. If the Customer reasonably objects on data protection grounds within that period, we will work in good faith to offer an alternative. If we cannot, the Customer may terminate the affected part of the service and receive a refund of fees paid for the unused remainder of the term.
We impose data protection obligations on each sub-processor that are no less protective than those in this agreement, and we remain fully liable to the Customer for their performance.
Where an individual makes a request to us directly and it concerns data we hold as processor, we will not answer it ourselves. We will pass it to the Customer without undue delay and tell the individual that we have done so.
We will help the Customer respond, by appropriate technical and organisational measures and so far as is reasonably possible, to requests for access, rectification, erasure, restriction, portability and objection.
On termination, and at the Customer's choice, we will return or delete all personal data processed on its behalf, and delete existing copies, unless applicable law requires us to keep it. Absent a different written instruction, the default is deletion within 60 days of termination.
Deletion at the end of a relationship removes the whole record, the append-only chain included. Backups are overwritten on their normal cycle, which completes within the same 60 days. Operational logs, which record that a request happened and never what was in it, are kept for 12 months as stated in the Privacy Policy.
We will notify the Customer without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting its personal data. The notification will describe what we know, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once we will provide it in phases without further undue delay.
We will assist the Customer with its own notification obligations to a supervisory authority and to affected individuals. We will not notify a supervisory authority on the Customer's behalf in respect of data we hold as processor, and we will not make a public statement identifying the Customer without its consent, unless we are required to by law.
We will provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority, taking into account the nature of the processing and the information available to us.
The database is in the European Union. Application hosting, and two of the four sub-processors, are in the United States, so transfers do occur and are set out in Annex B rather than glossed.
Transfers of personal data outside the UK or the EEA are made under the European Commission's Standard Contractual Clauses (Decision 2021/914, module three, processor to processor) and the UK International Data Transfer Addendum, as applicable, which are incorporated into this agreement by reference. Where a transfer mechanism is invalidated, we will work with the Customer in good faith to put a valid alternative in place, and will suspend the affected transfer if none is available.
We will make available the information reasonably necessary to demonstrate compliance with this agreement, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
In practice this means: once in any twelve month period on 30 days' notice, and additionally at any time following a personal data breach affecting the Customer, during business hours, without unreasonable disruption, and subject to confidentiality. We will first offer the report of the independent security review described in Annex C, and the Customer is free to decide it does not answer the question.
The limitations and exclusions of liability in the Terms of Service apply to this agreement and to any claim arising under it, except where applicable law does not permit them to.
This agreement takes effect when the Customer subscribes, and continues for as long as we process personal data on its behalf. Sections 4, 8, 9 and 13 survive its end.
| Subject matter | Provision of a portfolio reporting service to the Customer. |
|---|---|
| Duration | The term of the subscription, plus the deletion period in section 8. |
| Nature and purpose | Collection, storage, structuring, standardisation, retrieval, display and, where the Customer uses those features, extraction of figures from documents and generation of answers about figures the requesting user is already permitted to see. |
| Types of personal data | Names, business email addresses and assigned roles of Authorised Users. Any personal data incidentally contained in financial figures or in documents uploaded by portfolio companies, which may include names and remuneration information. We do not require or request special category data and the service is not designed to hold it. |
| Categories of data subject | The Customer's staff. Finance and management staff of the Customer's portfolio companies. The Customer's investors. Individuals named incidentally in submitted documents. |
| Frequency | Continuous for the duration of the subscription. |
As at the effective date of this agreement.
| Sub-processor | What it does | Where |
|---|---|---|
| Supabase | Database, authentication and document storage | Germany (Frankfurt, eu-central-1) |
| Vercel | Application hosting and delivery | United States (Virginia) |
| Anthropic | Document extraction and question answering | United States |
| Intuit | Where the Customer connects QuickBooks, accounting data is drawn from Intuit at the Customer's instruction | United States |
Split into what is enforced today and what is planned. Nothing planned is described here as current.