Kolis kolis.io

Privacy Policy

Kolis, portfolio reporting for private equity

Effective 4 September 2026 · Operated by Omar Husseini, The Courtyard, Wadi Abu Jmiel, Downtown, Beirut, Lebanon · Contact omar.husseini77@gmail.com

The short version This service holds financial information belonging to private companies and to the funds that invest in them. We do not sell it, we do not use it to train anything, and we do not use it for any purpose other than operating the service for the customer who put it there. The rest of this page says the same thing precisely, and says which third parties are involved.

1. Who is responsible for what

Two different relationships run through this service, and the law treats them differently.

DataOur roleWhat that means
Account data: the names, email addresses and roles of the people who log inControllerWe decide why and how it is held, because it is how the service authenticates people.
Reporting data: financial figures, uploaded documents, and everything a portfolio company filesProcessorThe fund (our customer) decides why and how it is processed. We act on their instructions and nothing more.

Where we act as processor, the fund is the controller and is responsible for having a lawful basis for the data it puts here, and for its own relationship with its portfolio companies. A written data processing agreement governs that relationship and takes precedence over this page where the two differ.

2. What we hold

Account data

Reporting data

Reporting data is company financial information. It is not, in the ordinary case, personal data, but a management account or an uploaded document may incidentally contain names, salaries or other personal information, and it is treated with the same protection either way.

Operational logs

We record that a request happened: which route, which role, how long it took, and which fund and company it belonged to. We do not log the figures themselves, the contents of a question asked of the assistant, filenames, or email addresses. The log table has no free-form column capable of holding them, and an automated test scans it against a deliberately planted leak to confirm the scan can detect one before reporting that it found none.

3. Why we hold it, and on what basis

PurposeBasis (UK/EU GDPR)
Operating the service for the customerPerformance of a contract; processor acting on the controller's instructions
Authenticating people and enforcing who may see whatPerformance of a contract; legitimate interests in securing the service
Keeping operational logs to diagnose faults and detect misuseLegitimate interests in a secure and functioning service
Meeting legal, tax and regulatory obligationsLegal obligation

We do not use reporting data for marketing, for analytics sold to anyone, or to build products for other customers. We do not sell personal data. We do not share it for behavioural advertising.

4. Artificial intelligence in this service

Two features send data to a third-party model provider, and it is worth being exact about which.

In both cases the request is bounded by the same access rules as the rest of the service: the model is only ever sent data the requesting user was already entitled to read.

Stated plainly, because it is the question a fund partner will ask Our current agreement with the model provider is their standard commercial arrangement, under which customer inputs and outputs are not used to train their models. A zero data retention agreement is planned and is not yet in place. Until it is, request data may be retained by the provider for a limited period under their standard terms. We will not represent otherwise, and no real client data enters this system before that and the independent security review below are complete.

5. Sub-processors

These are the third parties that process data on our behalf. We will give notice before adding a new one.

ProviderWhat it doesWhere
SupabaseDatabase, authentication, and document storageGermany (Frankfurt)
VercelApplication hosting and deliveryUnited States (Virginia)
AnthropicDocument extraction and question answering (see section 4)United States
IntuitWhere a fund connects QuickBooks, accounting data is drawn from Intuit at the customer's instructionUnited States

Transfers outside the UK and EEA are made under the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, as applicable.

6. How the data is protected

Split deliberately into what is enforced today and what is planned. Nothing planned is described here as current.

Enforced today

Planned, and stated as planned

7. How long we keep it

Filings are append only, so a correction does not erase what was previously filed. That is deliberate: an audit trail that can be quietly rewritten is not an audit trail. Deletion at the end of a relationship removes the whole record, chain included.

8. Your rights

Where UK or EU data protection law applies, individuals have the right to access their personal data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form. There is also a right to complain to a supervisory authority.

Where we act as processor, these requests belong to the fund, not to us. If you are a portfolio company employee or an investor and you make a request to us directly, we will pass it to the fund whose account holds the data and tell you that we have done so.

For account data, where we are the controller, write to omar.husseini77@gmail.com. We respond within one month.

9. Cookies

The service uses only cookies necessary to keep you signed in and to protect the session. There are no advertising cookies, no third-party analytics trackers, and no cross-site tracking.

10. Security incidents

If we become aware of a breach affecting customer data we will notify the affected fund without undue delay and in any event within 72 hours of becoming aware of it, with what we know, what we are doing, and what they may need to do. Where we are the controller, we notify the relevant supervisory authority as required.

11. Children

This is a business service. It is not directed at children and we do not knowingly collect data from anyone under 16.

12. Changes

If this policy changes materially we will notify account holders by email before the change takes effect. The effective date at the top of this page always reflects the current version.

13. Contact

Omar Husseini · The Courtyard, Wadi Abu Jmiel, Downtown, Beirut, Lebanon · omar.husseini77@gmail.com