Privacy Policy
Introduction
Welcome to Koladen. We are committed to protecting the privacy of the institutions and individuals who use our platform. This Privacy Policy explains how we collect, use, and protect information when you use Koladen. By using Koladen, you agree to the practices described in this policy.
Information We Collect
Institutional Information. When your institution registers for Koladen, we collect information such as your institution's name, address, charter type, asset size, and authorized contact information.
Core Banking Data. To deliver our intelligence services, Koladen connects to your institution's core banking systems and processes deposit, lending, and relationship data. This data is processed solely to generate risk scores, opportunity signals, and retention recommendations for your institution's internal use. Each institution's data is used exclusively to generate outputs for that institution and is not used to train shared or cross-institution models.
User Account Data. We collect information about authorized users of the platform, including name, email address, job title, and login credentials.
Usage Data. We collect information about how the platform is accessed and used, including IP addresses, browser type, pages visited, time and date of access, and other diagnostic data, solely for the purpose of maintaining and improving the platform.
Cookies and Tracking Technologies. We use cookies and similar technologies to maintain session integrity and platform functionality. You may configure your browser to refuse cookies, though some platform features may be affected.
How We Use Your Information
To Deliver Our Services. To operate the Koladen platform, generate intelligence outputs, and provide retention and embedded finance capabilities to your institution.
To Improve the Platform. To understand how institutions interact with Koladen and to improve platform performance, accuracy, and reliability.
To Communicate With You. To send service updates, security notices, and other information relevant to your account and service agreement.
To Process Payments. To manage billing and service fee transactions with your institution.
To Comply With Legal Obligations. To meet applicable regulatory requirements, including the Gramm-Leach-Bliley Act (GLBA) and its safeguards requirements for nonpublic personal information, and to protect the rights, property, and safety of Koladen and its users.
Sharing Your Information
We do not sell or rent your institution's data or your customers' data to any third party.
We may share information in the following limited circumstances:
Technology Partners. We may share data with vetted infrastructure and embedded finance partners solely as necessary to deliver contracted services. All partners are bound by data protection agreements consistent with this policy.
Service Providers. We may engage third-party providers to support platform operations, security, or analytics. These providers access only the minimum data necessary to perform their function and are contractually prohibited from using it for any other purpose.
Legal Requirements. We may disclose information if required by law or in response to valid requests from regulatory or governmental authorities, including banking regulators.
Business Transfers. In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice before your information becomes subject to a different privacy policy.
Data Security
Koladen maintains industry-standard security practices to protect institutional and customer data, including encryption in transit and at rest, access controls, and regular security reviews. Our data handling practices are designed to align with GLBA and applicable safeguards requirements for financial institution data. However, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security. You agree to notify us immediately at legal@koladen.com if you suspect any unauthorized access to your account or data.
Your Data Protection Rights
Depending on your jurisdiction, your institution and its authorized users may have the following rights:
Access. The right to request copies of information we hold about your institution or its authorized users.
Rectification. The right to request correction of inaccurate or incomplete information.
Erasure. The right to request deletion of your information, subject to applicable legal and regulatory retention requirements.
Restriction of Processing. The right to request that we limit processing of your information under certain conditions.
Data Portability. The right to request that we provide your institution's data in a portable format upon termination of services, as governed by your Data Processing Agreement.
As a California-based company, Koladen's practices are also designed with the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) in mind. Additional California-specific disclosures will be finalized with counsel.
Retention
We retain institutional and customer data for as long as necessary to deliver our services and comply with applicable legal and regulatory obligations. Data return and deletion schedules upon contract termination are governed by your executed Data Processing Agreement.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify affected institutions of material changes with at least 30 days advance notice. Continued use of the platform following notice of changes constitutes acceptance of the updated policy.
Contact Us
For questions about this Privacy Policy, your data rights, or to report a suspected security incident, contact us at legal@koladen.com.