Kolis, portfolio reporting for private equity
Two different relationships run through this service, and the law treats them differently.
| Data | Our role | What that means |
|---|---|---|
| Account data: the names, email addresses and roles of the people who log in | Controller | We decide why and how it is held, because it is how the service authenticates people. |
| Reporting data: financial figures, uploaded documents, and everything a portfolio company files | Processor | The fund (our customer) decides why and how it is processed. We act on their instructions and nothing more. |
Where we act as processor, the fund is the controller and is responsible for having a lawful basis for the data it puts here, and for its own relationship with its portfolio companies. A written data processing agreement governs that relationship and takes precedence over this page where the two differ.
Reporting data is company financial information. It is not, in the ordinary case, personal data, but a management account or an uploaded document may incidentally contain names, salaries or other personal information, and it is treated with the same protection either way.
We record that a request happened: which route, which role, how long it took, and which fund and company it belonged to. We do not log the figures themselves, the contents of a question asked of the assistant, filenames, or email addresses. The log table has no free-form column capable of holding them, and an automated test scans it against a deliberately planted leak to confirm the scan can detect one before reporting that it found none.
| Purpose | Basis (UK/EU GDPR) |
|---|---|
| Operating the service for the customer | Performance of a contract; processor acting on the controller's instructions |
| Authenticating people and enforcing who may see what | Performance of a contract; legitimate interests in securing the service |
| Keeping operational logs to diagnose faults and detect misuse | Legitimate interests in a secure and functioning service |
| Meeting legal, tax and regulatory obligations | Legal obligation |
We do not use reporting data for marketing, for analytics sold to anyone, or to build products for other customers. We do not sell personal data. We do not share it for behavioural advertising.
Two features send data to a third-party model provider, and it is worth being exact about which.
In both cases the request is bounded by the same access rules as the rest of the service: the model is only ever sent data the requesting user was already entitled to read.
These are the third parties that process data on our behalf. We will give notice before adding a new one.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, authentication, and document storage | Germany (Frankfurt) |
| Vercel | Application hosting and delivery | United States (Virginia) |
| Anthropic | Document extraction and question answering (see section 4) | United States |
| Intuit | Where a fund connects QuickBooks, accounting data is drawn from Intuit at the customer's instruction | United States |
Transfers outside the UK and EEA are made under the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, as applicable.
Split deliberately into what is enforced today and what is planned. Nothing planned is described here as current.
Filings are append only, so a correction does not erase what was previously filed. That is deliberate: an audit trail that can be quietly rewritten is not an audit trail. Deletion at the end of a relationship removes the whole record, chain included.
Where UK or EU data protection law applies, individuals have the right to access their personal data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form. There is also a right to complain to a supervisory authority.
Where we act as processor, these requests belong to the fund, not to us. If you are a portfolio company employee or an investor and you make a request to us directly, we will pass it to the fund whose account holds the data and tell you that we have done so.
For account data, where we are the controller, write to omar.husseini77@gmail.com. We respond within one month.
The service uses only cookies necessary to keep you signed in and to protect the session. There are no advertising cookies, no third-party analytics trackers, and no cross-site tracking.
If we become aware of a breach affecting customer data we will notify the affected fund without undue delay and in any event within 72 hours of becoming aware of it, with what we know, what we are doing, and what they may need to do. Where we are the controller, we notify the relevant supervisory authority as required.
This is a business service. It is not directed at children and we do not knowingly collect data from anyone under 16.
If this policy changes materially we will notify account holders by email before the change takes effect. The effective date at the top of this page always reflects the current version.
Omar Husseini · The Courtyard, Wadi Abu Jmiel, Downtown, Beirut, Lebanon · omar.husseini77@gmail.com