Legal

Privacy Policy

Last updated: August 20, 2026

This Privacy Policy is provided by Netrows Labs SL, a company registered in Spain (NIF: B26747097), registered office at CL Venda des Cap 1796 3, 07860 Formentera, Illes Balears, Spain ("Netrows Labs", "we", "us", or "our"), the operator of Kooperativa. It explains how we handle personal data in connection with the website https://kooperativa.io, the dashboard, and the API (together, the "Services"). For questions about this policy or to exercise the rights described in Section 11 or Section 12, contact us at support@kooperativa.io.

1. Purpose

Kooperativa lets registered business Customers access structured B2B people and company data through an API and dashboard, request a demo or account, manage a workspace and its members, and manage billing. This policy covers the personal data of our own Customers and their workspace members. Section 5 covers separately how we handle third-party professional data delivered through the API, since that data is not about you or your workspace.

2. A B2B service, not a consumer product

Kooperativa is offered exclusively to businesses for business purposes. It is not a consumer product, and we do not knowingly collect personal data from individuals acting in a personal or household capacity, whether as a Customer or otherwise. If you believe you have provided personal data to us other than in a business capacity, contact support@kooperativa.io and we will address it, including by deletion where appropriate.

This B2B-only scope also applies downstream: our Customers are contractually prohibited from using the Services, or the professional data obtained through them, to build or operate any consumer-facing product or feature, and are prohibited from using that data as a factor in consumer credit, insurance, employment, housing, or similar decisions about an individual (see the Terms of Service). Kooperativa is not a consumer reporting agency, and the data made available through the Services does not constitute a "consumer report" under the U.S. Fair Credit Reporting Act or any equivalent law.

3. Data we collect

When you request access, create an account, or use the Services, we collect:

  • Account and workspace data: name, business email address, company name, phone number (optional), password (stored hashed, never in plain text), and workspace role.
  • Demo request data: the information submitted through the access request form, including your stated use case and how you heard about us.
  • Billing data: your plan and license status; card and payment details are collected and processed directly by Stripe and are not stored on our servers.
  • Usage data: API request logs, timestamps, and endpoint usage, used for rate limiting, billing, fraud prevention, and troubleshooting.
  • Technical data: IP address, browser and device information, and standard connection logs collected when you use the Site or dashboard.

Please do not submit sensitive personal data (such as government identification numbers, full payment card numbers, or health information) through the demo request form or any other part of the Site; it is not needed for any purpose described in this policy, and we may delete it if received.

4. How we use it

  • To evaluate access requests and verify they are for a genuine business purpose, and, where approved, to create and provision your account and workspace.
  • To provide the API and dashboard, authenticate requests, and enforce rate limits and license status.
  • To process billing through Stripe and communicate about your subscription.
  • To send transactional email: invite and account activation emails, and security or billing notices you cannot opt out of because they are necessary to operate the Services.
  • To respond to support requests sent to support@kooperativa.io.
  • To detect, investigate, and prevent fraud, abuse of the Services (including the conduct described in the Terms of Service), and violations of applicable law.
  • To comply with a legal obligation, or to establish, exercise, or defend a legal claim.

Where we act on the basis of your consent (for example, information submitted through the demo request form before any contract exists), you can withdraw that consent at any time by contacting us. Where we act to perform the contract with you (once you have an account), that legal basis applies for the duration of the relationship. Where we act on our legitimate interest (for example, fraud prevention and enforcing our Terms of Service), you can object as described in Section 11.

Kooperativa does not send marketing or promotional email. We do not use advertising or third-party analytics trackers on the Site.

5. Third-party professional data

Separately from the account data described above, the API gives Customers access to structured records about third-party individuals and companies: professional profiles, employment history, and company information. This data is not about you or your workspace members; it is the product itself.

Scope: no contact data. This data is limited to professional profile and firmographic information. Kooperativa does not collect, hold, or make available anyone's personal contact details, such as email addresses or phone numbers, under any circumstances. If you're trying to trace how an email address or phone number of yours ended up somewhere it shouldn't have, that did not happen through Kooperativa.

How this data is collected. This data is collected using open-source intelligence (OSINT) methods: automated retrieval of information that is already publicly accessible on the internet, without bypassing any login wall, paywall, or technical access control, and without hacking, credential-stuffing, or otherwise gaining unauthorized access to any system. We do not purchase this data from data brokers of consumer information, and we do not fabricate or infer it. Records are aggregated from multiple public sources, normalized, deduplicated, and refreshed on a cycle of up to 90 days.

Legal basis for collecting this data. The individuals whose professional information appears in our data lake have not given us their consent directly, since the information comes from public sources rather than from them signing up with us. Our legal basis for this collection is legitimate interest (Article 6(1)(f) GDPR): providing a B2B data enrichment service is a legitimate business activity, the information collected is limited to what is already publicly available and professional in nature (not sensitive, private, or special category data), and we balance that interest against the individual's rights by:

  • collecting only information already made public by the individual or by their employer, not information obtained through any private, restricted, or unauthorized channel;
  • limiting collection to professional and business-relevant fields (for example name, job title, employer, and professional profile URL), not personal or private-life information;
  • being transparent about the collection through this policy, which is publicly accessible without an account; and
  • honoring an objection or erasure request from any individual, enforced at the API level as described below and in Section 11.

Roles. Netrows Labs makes this data available through the API, but the Customer determines whether and how to process it once retrieved. Under the GDPR, the Customer acts as an independent data controller for its own use of that data, and is responsible for having a lawful basis for processing it, providing appropriate notices to the individuals concerned, and responding to their rights requests. Netrows Labs does not disclose this data to any party other than the paying Customer that requested it through the API (see Section 6 on what that means under the CCPA), and contractually prohibits Customers from using it for consumer-facing or consumer-reporting purposes (see Section 2).

If this data is about you. If you are an individual (not a Kooperativa Customer) and you have questions about publicly available professional data concerning you that may be available through the Services, or wish to exercise a right described in Section 11 with respect to that data, submit a data removal request, or contact us directly at support@kooperativa.io. Either way, we verify your identity (a removal request is confirmed by email before we act on it) and respond within the timeframe required by applicable law.

A validated erasure or objection request is enforced technically, not just recorded on paper: your record is flagged at the API level, and every endpoint that would otherwise return it responds instead with an HTTP 451 ("Unavailable due to privacy protection") for as long as the flag is in place, across the entire data lake, not only for the specific query that triggered the request. This means a Customer querying our API cannot retrieve your record even indirectly once your request has been actioned. The flag does not itself delete the underlying data pending our retention obligations described in Section 8, but it stops any Customer from receiving it going forward. We aim to complete verified requests within 30 days.

6. Who we share data with

The professional data described in Section 5 is our product: it is made available to Customers as part of a paid subscription, which under the CCPA's broad definition of "sale" may itself qualify as one, regardless of whether we describe it that way commercially. Section 12 explains what that means in practice and how to opt out. Beyond that, we do not sell your account or workspace data (Section 3). We share data only with the service providers that help us operate the Services, each acting under its own data protection commitments and bound by contract to use the data only for the purpose we engage them for, and only to the extent needed for that purpose:

  • Supabase — database and authentication. Our data is hosted in Supabase's Zurich, Switzerland region.
  • Cloudflare — hosting, content delivery, and transactional email delivery (Cloudflare Email Sending), for the Site, dashboard, and API.
  • Stripe — payment processing; PCI-DSS certified. Our contracting entity is Stripe Payments Europe, Limited, based in Ireland (EU). Stripe's own infrastructure may still process data outside the EEA as part of delivering the service; Stripe's published privacy and transfer terms govern that processing. Netrows Labs does not receive or store full card numbers.
  • Hetzner — hosts the backend infrastructure that stores and serves the professional data lake described in Section 5, from Hetzner's Nuremberg, Germany data center.

Nuremberg and Zurich are addressed specifically in Section 7: Nuremberg is within the EU, and Zurich is covered by an EU adequacy decision, so neither one is a transfer requiring Standard Contractual Clauses. Stripe's contracting entity is based in Ireland (EU), though Stripe's own infrastructure may process data further afield as part of delivering its service. Cloudflare's infrastructure is global by design and is the clearest case of processing outside the EEA, including in the United States, which is where Section 7's safeguards are actually doing the most work.

We may also disclose personal data where required by law, in response to a valid, legally binding request from a public or judicial authority, or where necessary to protect the rights, property, or safety of Netrows Labs, our Customers, or others. Where legally permitted, we will notify the affected party before complying with such a request.

7. International transfers

Storing or processing data outside the European Economic Area (EEA) is not automatically allowed under the GDPR: it requires a specific legal safeguard showing the data stays protected to the same standard once it leaves the EEA. This does not mean we personally hold a "transfer certificate"; it means each service provider in Section 6 that may process data outside the EEA has one of the following in place, and we rely on it:

  • the location is already within the EEA (Hetzner's Nuremberg data center) or covered by the European Commission's own adequacy decision, meaning the Commission has formally determined that country's data protection law is equivalent to the GDPR (Supabase's Zurich, Switzerland region falls under Switzerland's adequacy decision) — in both cases, no further safeguard is legally required;
  • the Standard Contractual Clauses (SCCs), a contract template pre-approved by the European Commission that we and the provider are bound by, obligating the provider to protect the data to EU standard regardless of where it is physically processed; or
  • the provider's own participation in a transfer framework the European Commission has separately recognized as adequate (for example, an EU-US data transfer framework), where the provider has self-certified compliance and that certification is independently verifiable.

In short: no provider in Section 6 moves your data outside the EEA on a bare promise. Each transfer is covered by one of the mechanisms above, which is the standard the GDPR itself requires for this to be lawful, not an optional extra. We will inform you, to the extent legally permitted, of any government request concerning your personal data that we become aware of.

8. Retention

  • Demo requests that are not approved are retained for a limited period to allow the request to be reviewed and, where relevant, for the applicant to be contacted, and are deleted thereafter.
  • Account and workspace data is retained for as long as your account is active, and for a reasonable period afterward to meet legal, accounting, fraud-prevention, or dispute-resolution obligations.
  • Billing records are retained for as long as required by applicable tax and accounting law.
  • API usage logs are retained for a limited period sufficient for billing, rate limiting, and security purposes, then deleted or aggregated.
  • Validated erasure or objection flags under Section 5 are retained indefinitely, since the flag itself is what keeps the record from being returned by the API (HTTP 451) going forward; removing the flag would defeat the request it was created to honor.

9. Security

We use industry-standard measures to protect personal data, including encryption in transit (TLS) for all connections to the Site, dashboard, and API; encryption at rest for stored data; hashed storage of passwords and API keys (never in plain text); row-level security on our database; access to production systems limited to personnel who need it; and signed, verifiable webhook deliveries for monitors (see the Terms of Service).

No system is completely secure. If a breach affecting your personal data occurs, we will notify you and the relevant supervisory authority without undue delay and in any event within the timeframe required by applicable law, and take reasonable steps to contain and remediate it. Our ability to detect, contain, or remediate an incident may itself be limited by a force majeure event as defined in the Terms of Service (for example, an outage or attack affecting one of the service providers in Section 6); in that case we still notify you as required by law, but our response timeline reasonably reflects that underlying constraint.

10. Cookies

We use only the cookies strictly necessary for the Site and dashboard to function: an authentication cookie (Supabase) to keep you signed in, and a security cookie (Cloudflare) used to protect the Site against automated abuse. We do not use advertising, tracking, or analytics cookies. Because these cookies are essential to the Services, they cannot be disabled from within the Site; you can block or delete cookies through your browser settings, but doing so will prevent you from staying signed in.

11. Your rights

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with similar protections, you have the following rights over your personal data, subject to the conditions and exceptions set out in applicable law:

  • Access and rectification — request a copy of your personal data, or correct it if inaccurate or incomplete.
  • Erasure — request deletion of your personal data where it is no longer needed, you have withdrawn consent, or it was processed unlawfully. You can also delete your own account directly from the dashboard's account settings.
  • Objection and restriction — object to certain processing, including processing based on our legitimate interest, or ask us to restrict it while a request is being resolved.
  • Portability — request your data in a structured, commonly used, machine-readable format.
  • Withdraw consent — where processing is based on consent, withdraw it at any time, without affecting processing already carried out.
  • Lodge a complaint — with your local data protection authority, if you believe your rights have not been respected.

To exercise any of these rights, contact us at support@kooperativa.io. We may ask you to confirm your identity before acting on a request, to protect against fraudulent requests made in someone else's name, and will respond within the timeframe required by applicable law.

12. Our approach to GDPR and CCPA

There is no official government or industry seal that certifies a company as "GDPR approved" or "CCPA approved," and we do not claim one. What we can tell you concretely is how our processing is actually structured to meet the substance of both frameworks.

GDPR (EU General Data Protection Regulation). As a company established in Spain, we are directly subject to the GDPR for everything we do, not only for EU visitors. In practice, this means:

  • we identify and document a specific legal basis for every purpose we process data for: consent or contract for your own account data (Section 4), and legitimate interest for the third-party professional data in our data lake (Section 5), rather than processing data without one;
  • we give effect to the rights in Section 11 (access, rectification, erasure, objection, restriction, portability, and withdrawal of consent) on request, not only where a law happens to force us to;
  • we apply data minimization: we collect what a given purpose actually requires (Section 3) and do not ask for more "in case it's useful later";
  • we apply storage limitation through the retention periods in Section 8, rather than keeping data indefinitely by default;
  • where a service provider processes personal data outside the EEA, we rely on the Standard Contractual Clauses or an equivalent recognized safeguard (Section 7); and
  • for the account data of a Customer's own workspace members, our Data Processing Agreement sets out the controller/processor relationship in full, consistent with Article 28 GDPR.

CCPA / CPRA (California Consumer Privacy Act, as amended). The Services are built for businesses, not California consumers, and we do not knowingly collect personal information from California residents in a personal capacity. To the extent the CCPA/CPRA applies to any personal information we hold about you as an individual (for example, a workspace member's account data, or a data subject whose professional information appears in our data lake as described in Section 5):

  • Sale of professional data. The CCPA defines "sale" broadly enough that making personal information available to a paying Customer, which is what the professional data lake in Section 5 does, may qualify as a sale under that definition, even though it is not what we would ordinarily call selling data. We do not sell or share your own account or workspace data (Section 3), and we do not sell or share anything for cross-context behavioral advertising.
  • The categories of personal information we may hold, mapped to the CCPA's categories, are: identifiers (name, email, IP address); commercial information (billing and subscription history); internet activity (API usage logs); and, for professional data in our data lake, professional or employment-related information. We do not collect biometric information, precise geolocation, or the other sensitive categories defined by the CPRA.
  • California residents have the right to know what personal information we hold and where it came from, to request deletion, to request correction of inaccurate information, to opt out of the sale described above, and to not be discriminated against for exercising any of these rights.
  • You can exercise any of these rights, including an opt-out, by emailing support@kooperativa.io. You may also designate an authorized agent to submit a request on your behalf; we will ask the agent for proof of that authorization and may separately verify your identity directly before completing the request. We aim to complete verified requests within 30 days.

If you believe either framework requires something specific from us that this policy does not already describe, tell us at support@kooperativa.io and we will look into it.

13. Account deletion

Requesting deletion from the dashboard sends a deletion request to our support team rather than erasing data automatically and immediately; a person reviews and carries out every account deletion by hand, since removing a workspace can affect other members and billing history that needs to be handled correctly, and since we may need to retain certain records after deletion to meet a legal or accounting obligation as described in Section 8. We aim to action deletion requests promptly and will confirm with you once it is complete.

14. Children

The Services are intended for business use by adults acting in a professional capacity. We do not knowingly collect personal data from children, and the Services are not directed at them. If we become aware that we have inadvertently collected personal data from a child, we will delete it promptly.

15. Limitation of liability

This Privacy Policy is provided for informational purposes and does not itself create any liability beyond what applicable data protection law requires. Any claim arising from or related to this Privacy Policy or our processing of personal data is subject to the liability limitations set out in Section 17 of the Terms of Service, including the liability cap and the exclusion of indirect and consequential damages, to the extent permitted by applicable law. For the avoidance of doubt, those limitations do not restrict any right or remedy that cannot lawfully be limited, including your rights under Section 11 above.

16. Changes to this policy

We may update this Privacy Policy from time to time, in particular to reflect changes in the Services or in applicable law. Material changes will be notified by email or through a notice on the Site or dashboard before they take effect. We encourage you to review this page periodically.

17. Contact

For any question about this Privacy Policy or about how your personal data is handled, contact us at support@kooperativa.io or by post at Netrows Labs SL, CL Venda des Cap 1796 3, 07860 Formentera, Illes Balears, Spain.

Questions about this document? Contact us at support@kooperativa.io.