Privacy & Data Policy
Last updated: 26 July 2026
This policy explains what information Korda processes when you use the platform, how that information is stored and shared, and the choices available to you and your organisation.
1.Introduction
This Privacy & Data Policy explains what information Korda processes when you use its supplier-resolution and payment-control platform, why we process it, how we store and share it, and the choices available to you and your organisation.
Korda processes information to provide the service to organisations that document supplier incidents, evidence, remedies, payment controls and settlements.
2.Information We Collect
Account information
- Full name
- Email address
- Organisation name
- Job title
- User role within the organisation
- Authentication information (such as password credentials and session identifiers)
Supplier and business information
- Supplier names
- Supplier contacts
- Countries and regions
- Purchase-order details
- Invoice details
- Shipment and product information
- Incident descriptions
- Financial-exposure and recovery information
- Remedy and settlement records
Uploaded evidence
- Photographs
- Videos
- Inspection reports
- Purchase orders
- Invoices
- Specifications
- Supplier communications
- Payment and shipping records
Technical information
- Browser and device information
- IP address
- Login activity
- Error logs
- Security events
- Usage activity within Korda
3.How Information Is Collected
- When an account is created.
- When users enter information directly into Korda.
- When users upload files as evidence.
- Through authentication and security systems.
- Through general use of the application.
- Through communications with Korda's team.
4.How Information Is Used
- Providing and operating the Korda service.
- Authenticating users and securing access.
- Maintaining organisation workspaces and access controls.
- Managing supplier exceptions through the monitor, detect, resolve and learn workflow.
- Processing evidence and related metadata.
- Generating AI-assisted summaries, checklists and workflow suggestions.
- Improving reliability, performance and security of the service.
- Preventing misuse, abuse and fraud.
- Responding to support requests and communications.
- Meeting legal, regulatory and contractual obligations.
5.AI Processing
- When you use an AI-assisted feature, relevant workspace data may be sent to an AI-service provider to generate a response.
- Only the information necessary for the feature should be processed.
- You should not submit unnecessary sensitive personal data or third-party confidential information into AI features.
- All AI output must be reviewed by a qualified human before it is acted on.
Where supported by our provider agreements and configuration, we seek to prevent customer workspace data from being used to train general-purpose models. We cannot make this an absolute promise for every feature at every point in time.
6.Legal Bases
Depending on the jurisdiction and the activity, Korda may process information:
- To perform a contract with you or your organisation.
- For legitimate business, operational and security interests.
- With consent, where consent is legally required.
- To meet legal or regulatory obligations.
This policy uses jurisdiction-neutral language and does not represent full compliance with any specific privacy regime.
8.Organisation Administrators
Workspace owners and authorised users within an organisation may access information stored in that organisation's Korda workspace, including records created by other users in the same organisation. If you use Korda through an employer or organisation, that organisation controls how information is used within its workspace.
9.International Data Transfers
Korda's providers may process data in multiple countries. Where legally required, appropriate safeguards will be used for international transfers. Specific contractual and technical safeguards may vary between providers and are not exhaustively listed here.
10.Data Storage and Security
Korda uses a range of controls to protect information, including:
- Supabase authentication for user identity.
- Organisation-level database access controls.
- Row Level Security policies scoping data to each organisation.
- Private storage buckets for uploaded evidence.
- Role-based access controls within workspaces.
- Encryption provided by our infrastructure providers.
- Monitoring and backups where configured by our providers.
No online service can be guaranteed absolutely secure, and Korda does not promise uncompromisable security.
11.Data Retention
- Account and workspace data is retained while the account is active.
- Information may be retained for a reasonable period after deletion for backups, legal obligations, dispute prevention and security purposes.
- Final production retention periods must be confirmed before launch.
Placeholder: [Confirm production retention periods before launch].
12.Account and Data Deletion
You may request:
- Closure of your account.
- Deletion of your organisation's workspace.
- Deletion or correction of personal information you have provided.
Requests can be sent to privacy@korda.app (placeholder — confirm before launch).
Deletion may be limited or delayed where retention is required by law, needed for the defence of legal claims, or necessary for security purposes.
13.User Rights
Depending on your jurisdiction, you may have rights to:
- Access personal information Korda holds about you.
- Have inaccurate information corrected.
- Have personal information deleted.
- Restrict certain processing.
- Object to certain processing.
- Receive information in a portable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with a data-protection regulator.
The availability and scope of these rights depends on applicable law.
15.Children
Korda is a business service. It is not directed at children and should not be used by them.
16.Data Breaches
Korda will investigate security incidents affecting customer data and notify affected organisations, and where required, relevant authorities, in accordance with applicable law.
17.Changes to the Policy
Korda may update this Privacy & Data Policy from time to time. When it changes, the effective date at the top of this page will be updated and, where appropriate, an in-product notice will be shown.
18.Contact
Privacy questions and requests can be sent to privacy@korda.app (placeholder — confirm before launch).