Koolay
Trust Center

Legal & Security at Koolay

Koolay Inc. hosts sensitive nonprofit data — donors, members, applicants, donations, user accounts. These documents describe how we protect it and the terms that govern our relationship with customers.

Policies

🔒 Security Overview

How we protect your data: infrastructure, access control, encryption, incident response.

📜 Privacy Policy

What personal data we collect, how we use it, and the rights you have over it.

📘 Terms of Service

The contract that governs your use of the Koolay platform.

✍️ Data Processing Agreement

Our GDPR-compliant DPA, automatically signed when you accept the Terms.

🔗 Subprocessors

The vendors we use to deliver the Service, with data scope and certifications.

📈 Live Status

Real-time uptime of every Koolay system, with 24-hour timelines and 90-day uptime.

Certifications

Report a Vulnerability

Found a security issue? Email [email protected] with "Security" in the subject. We acknowledge within 5 business days.

Internal Policies (Available on Request)

We maintain 11 internal security policies aligned to SOC 2 Trust Services Criteria, including Access Control, Incident Response, Business Continuity, Backup & Recovery, Change Management, Vendor Management, and Data Retention. These are available to customers under NDA — email [email protected].