Policies
How we protect your data: infrastructure, access control, encryption, incident response.
What personal data we collect, how we use it, and the rights you have over it.
The contract that governs your use of the Koolay platform.
Our GDPR-compliant DPA, automatically signed when you accept the Terms.
The vendors we use to deliver the Service, with data scope and certifications.
Real-time uptime of every Koolay system, with 24-hour timelines and 90-day uptime.
Certifications
- 🟡 SOC 2 Type II — Readiness phase, target Q3 2026
- ✅ GDPR — DPA on file, EU SCCs executed
- ✅ CCPA / CPRA — California privacy rights honored
- ✅ PCI DSS — Payment processing via Stripe (PCI Level 1 certified)
Report a Vulnerability
Found a security issue? Email [email protected] with "Security" in the subject. We acknowledge within 5 business days.
Internal Policies (Available on Request)
We maintain 11 internal security policies aligned to SOC 2 Trust Services Criteria, including Access Control, Incident Response, Business Continuity, Backup & Recovery, Change Management, Vendor Management, and Data Retention. These are available to customers under NDA — email [email protected].
