1. Data controller
The data controller is Kora S.r.l., based in Italy. For any privacy question contact us at privacy@kora.com.
2. Data we collect
When you browse kora.com we collect aggregated, anonymous browsing data (pages visited, time on page, device, country — no third-party cookies without consent).
If you fill a contact form we collect name, email and company — only to respond, never for marketing profiling.
If you are a user of SponsorIQ, PitchPartner or other Kora products, we collect the data needed to deliver the service (see product-specific terms).
3. Social Hub module (Kora Suite)
Kora Suite (our internal admin tool) includes a "Social Hub" module to manage statistics of Kora S.r.l.'s official social pages (Facebook + Instagram Business). This module is for authenticated Kora staff only — never exposed publicly nor to third parties or end users.
Through this module Kora collects aggregated stats of its own social pages: follower count, reach, impressions, engagement, demographics anonymized by Meta (gender × age, country, city with statistical minimums set by Meta for privacy).
We do NOT collect personal data of individual users interacting with the pages (no user IDs, no comment authors, no DMs). Data is stored in our EU infrastructure (PostgreSQL + ClickHouse, GCP europe-west) and encrypted at rest.
4. Legal basis
We process data based on: legitimate interest (aggregated analytics and site security), consent (contact forms, optional marketing/analytics cookies), contract execution (SaaS product users).
5. Your rights (GDPR)
You have the right to access, correct, delete your data, restrict processing, object, and to data portability.
To exercise a right write us at privacy@kora.com — response within 30 days per GDPR Art. 12.
You also have the right to lodge a complaint with the Italian DPA (www.garanteprivacy.it).
6. Data retention
Browsing data: 24 months.
Contact forms: until request completed + 12 months for audit.
Internal social stats (Social Hub): accounts 36 months, posts 24 months, demographics 24 months.
SaaS user data: for contract duration + product-specific terms.
7. Sub-processors
We rely on third-party processors (Google Cloud Platform EU hosting, ClickHouse Cloud, Stripe for payments, Resend for email, Anthropic and OpenAI for AI features with SCC). See /sub-processors for the live list.