Kolis kolis.io

Data Processing Agreement

Kolis, portfolio reporting for private equity. This is the agreement referred to in section 1 of the Privacy Policy and section 5 of the Terms of Service.

Effective 5 September 2026 · Between the Customer and Omar Husseini, The Courtyard, Wadi Abu Jmiel, Downtown, Beirut, Lebanon · Contact omar.husseini77@gmail.com

What this document is for Where we handle personal data on the Customer's behalf, UK and EU data protection law requires a written contract setting out what we may do with it, what we must do to protect it, and what happens when the relationship ends. This is that contract. It is published so a fund's counsel can read it before asking for it, and it is signed as part of the subscription.

1. When this applies, and what it overrides

This agreement applies whenever we process personal data on the Customer's behalf in the course of providing the service. It forms part of the Terms of Service. Where this agreement and any other document conflict on the handling of personal data, this agreement prevails.

"UK GDPR", "EU GDPR", "controller", "processor", "personal data", "processing", "personal data breach" and "data subject" carry the meanings given in the applicable data protection law. "Applicable law" means the UK GDPR, the EU GDPR, and any national law implementing or supplementing either, to the extent each applies.

2. Who is responsible for what

Two different relationships run through this service and the law treats them differently. The split below is the same one stated in section 1 of the Privacy Policy.

DataCustomerUs
Reporting data. Financial figures filed by portfolio companies, documents uploaded in support, and accounting data drawn from a connected system.ControllerProcessor
Account data. The names, email addresses and roles of the people who sign in.Controller of the instruction to create accountsController, because we decide how authentication works

Reporting data is company financial information and is not, in the ordinary case, personal data. But a set of management accounts or an uploaded document may incidentally contain names, salaries or other personal information. This agreement governs that data whenever it does, and we apply the same protections either way rather than sorting it first.

The Customer is responsible for having a lawful basis for the data it puts into the service, including in respect of its portfolio companies, and for its own relationship with them. We are not in a position to establish that basis and do not purport to.

3. We act on the Customer's instructions and nothing else

We process personal data only on the Customer's documented instructions, including on transfers to a third country, unless required to do otherwise by law. Where the law requires it, we will tell the Customer before processing unless that law forbids us from saying so.

The instructions are: the Terms of Service, this agreement, and the Customer's own use of the service. Configuring a company, connecting an accounting system, running an extraction, asking the assistant a question: each is an instruction. There is no separate ticket system for them.

We will tell the Customer if, in our opinion, an instruction infringes applicable law. We do not use reporting data for any purpose of our own. Specifically, and as also stated in the Terms of Service: we do not sell it, we do not use it to train artificial intelligence models, we do not use it to serve another customer, and we do not use it to build products.

4. Confidentiality

Any person we authorise to process the Customer's personal data is bound by a duty of confidence, whether by contract or by statute, and that duty survives the end of their engagement. Access is limited to those who need it to provide or support the service.

5. Security

We implement appropriate technical and organisational measures under Article 32. The measures actually in place, and the ones that are planned rather than current, are set out in Annex C and are separated there on purpose. Nothing planned is described as current, in this agreement or anywhere else.

6. Sub-processors

The Customer gives general authorisation for us to engage sub-processors. Those engaged today are listed in Annex B, which names each one, what it does, and where it is.

Before adding or replacing a sub-processor we will give the Customer at least 30 days' written notice. If the Customer reasonably objects on data protection grounds within that period, we will work in good faith to offer an alternative. If we cannot, the Customer may terminate the affected part of the service and receive a refund of fees paid for the unused remainder of the term.

We impose data protection obligations on each sub-processor that are no less protective than those in this agreement, and we remain fully liable to the Customer for their performance.

7. Helping with individuals' rights

Where an individual makes a request to us directly and it concerns data we hold as processor, we will not answer it ourselves. We will pass it to the Customer without undue delay and tell the individual that we have done so.

We will help the Customer respond, by appropriate technical and organisational measures and so far as is reasonably possible, to requests for access, rectification, erasure, restriction, portability and objection.

One thing to raise with counsel early: filings cannot be edited or deleted The service is append-only by design. A filed quarter cannot be rewritten or removed; a correction is filed as a new record that supersedes the previous one, and both remain. This is deliberate, because an audit trail that can be quietly rewritten is not an audit trail, and it is stated in section 6 of the Terms of Service.

The consequence for erasure and rectification: within a live account we can correct forward but cannot unwrite history. Where an erasure request cannot be satisfied any other way, deletion of the whole record under section 8 below is the mechanism. We would rather say this plainly at the start than have it discovered during a request.

8. Deletion and return

On termination, and at the Customer's choice, we will return or delete all personal data processed on its behalf, and delete existing copies, unless applicable law requires us to keep it. Absent a different written instruction, the default is deletion within 60 days of termination.

Deletion at the end of a relationship removes the whole record, the append-only chain included. Backups are overwritten on their normal cycle, which completes within the same 60 days. Operational logs, which record that a request happened and never what was in it, are kept for 12 months as stated in the Privacy Policy.

9. Personal data breaches

We will notify the Customer without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting its personal data. The notification will describe what we know, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once we will provide it in phases without further undue delay.

We will assist the Customer with its own notification obligations to a supervisory authority and to affected individuals. We will not notify a supervisory authority on the Customer's behalf in respect of data we hold as processor, and we will not make a public statement identifying the Customer without its consent, unless we are required to by law.

10. Impact assessments

We will provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority, taking into account the nature of the processing and the information available to us.

11. International transfers

The database is in the European Union. Application hosting, and two of the four sub-processors, are in the United States, so transfers do occur and are set out in Annex B rather than glossed.

Transfers of personal data outside the UK or the EEA are made under the European Commission's Standard Contractual Clauses (Decision 2021/914, module three, processor to processor) and the UK International Data Transfer Addendum, as applicable, which are incorporated into this agreement by reference. Where a transfer mechanism is invalidated, we will work with the Customer in good faith to put a valid alternative in place, and will suspend the affected transfer if none is available.

12. Audit and information

We will make available the information reasonably necessary to demonstrate compliance with this agreement, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.

In practice this means: once in any twelve month period on 30 days' notice, and additionally at any time following a personal data breach affecting the Customer, during business hours, without unreasonable disruption, and subject to confidentiality. We will first offer the report of the independent security review described in Annex C, and the Customer is free to decide it does not answer the question.

13. Liability

The limitations and exclusions of liability in the Terms of Service apply to this agreement and to any claim arising under it, except where applicable law does not permit them to.

14. Term

This agreement takes effect when the Customer subscribes, and continues for as long as we process personal data on its behalf. Sections 4, 8, 9 and 13 survive its end.

Annex A. Details of the processing

Subject matterProvision of a portfolio reporting service to the Customer.
DurationThe term of the subscription, plus the deletion period in section 8.
Nature and purposeCollection, storage, structuring, standardisation, retrieval, display and, where the Customer uses those features, extraction of figures from documents and generation of answers about figures the requesting user is already permitted to see.
Types of personal dataNames, business email addresses and assigned roles of Authorised Users. Any personal data incidentally contained in financial figures or in documents uploaded by portfolio companies, which may include names and remuneration information. We do not require or request special category data and the service is not designed to hold it.
Categories of data subjectThe Customer's staff. Finance and management staff of the Customer's portfolio companies. The Customer's investors. Individuals named incidentally in submitted documents.
FrequencyContinuous for the duration of the subscription.

Annex B. Sub-processors

As at the effective date of this agreement.

Sub-processorWhat it doesWhere
SupabaseDatabase, authentication and document storageGermany (Frankfurt, eu-central-1)
VercelApplication hosting and deliveryUnited States (Virginia)
AnthropicDocument extraction and question answeringUnited States
IntuitWhere the Customer connects QuickBooks, accounting data is drawn from Intuit at the Customer's instructionUnited States
Stated plainly, because it is the question that gets asked Our agreement with the model provider is their standard commercial arrangement, under which customer inputs and outputs are not used to train their models. A zero data retention agreement is planned and is not yet in place. Until it is, request data may be retained by the provider for a limited period under their standard terms. We will not represent otherwise. No real client data enters this system before that and the independent security review in Annex C are complete.

Annex C. Technical and organisational measures

Split into what is enforced today and what is planned. Nothing planned is described here as current.

In place

Planned, and stated as planned