GDPR
Privacy Policy
This explains what personal data we process to operate KoraGate, why, and what rights you have.
Last updated: August 9, 2026
Data controller
The data controller is Jitka Hořavová, Company ID (IČO) 88201856, registered address Jiráskova 436/8, 789 85 Mohelnice, Czech Republic, trading under the business name Codecron.
For privacy-related questions, contact support@koragate.tech.
What data we process
Identification and contact details: name and email address.
Access data: passwords are stored only as an irreversible hash.
Workspace data: company/workspace name and team role.
Content you create in the app: projects, tasks, comments, attachments and client requests.
Billing data: for paid plans, the details needed to issue an invoice.
Technical data: IP address, login time and basic operational logs used to secure the service.
Purpose and legal basis
Operating your account and providing the service, based on contract performance (GDPR Art. 6(1)(b)).
Issuing accounting records and meeting tax obligations, based on legal obligation (GDPR Art. 6(1)(c)).
Security, misuse prevention and technical support, based on legitimate interest (GDPR Art. 6(1)(f)).
Any future optional features requiring consent will always ask for a separate, active opt-in.
Cookies
We use a necessary technical (session) cookie that keeps you signed in. The app would not function without it, so no consent is required for it.
Your dark/light theme choice is stored locally in your browser (not a cookie in the technical sense).
We do not currently use marketing or analytics tracking cookies. If we introduce any in the future, we will ask for separate consent.
Who we share data with
Our hosting provider, which runs KoraGate's infrastructure, acting as a processor under a data processing agreement.
Our email provider, used to send notifications and invitations, acting as a processor.
A payment gateway when activating a paid plan, acting as an independent controller of payment data.
We do not share data with third parties for marketing purposes.
International data transfers
Data is primarily stored and processed on servers within the European Union (Frankfurt, Germany).
The payment gateway may operate outside the EU/EEA; in that case the transfer is safeguarded by standard contractual clauses or another appropriate GDPR safeguard.
Retention period
We process data for as long as your account exists. After account closure, workspace content is deleted within a reasonable period, no later than 30 days, unless you request earlier deletion.
Accounting records are kept for as long as required by law (typically 10 years from the end of the relevant tax period).
Your rights
You have the right to access, correct, delete or restrict processing of your data, to data portability, and to object to processing.
Any consent you gave for optional processing can be withdrawn at any time.
We respond to requests regarding these rights without undue delay, no later than one month.
You have the right to file a complaint with the Czech Office for Personal Data Protection (uoou.cz).
Automated decision-making
The application does not perform automated decision-making or profiling that would have legal effects on users.
Security
Data in transit is encrypted (HTTPS), passwords are stored as an irreversible hash, and each workspace's data is kept separate within the application.