Legal
Privacy Policy
What Kolora collects, why, who it goes to, how long it is kept — and what you can demand at any time.
Effective: August 2, 2026 · version 1.1
This policy describes how Nadav Alluf ("Kolora", "we") collects, processes, stores and transfers personal data through the platform at kolora.io, its application and related services (the "Service").
It is written to comply with the Israeli Protection of Privacy Law, 5741-1981 and its regulations (including the Information Security Regulations and Amendment 13), the Communications (Telecommunications and Broadcasting) Law, 5742-1982 as it applies to marketing messages, and the Consumer Protection Law, 5741-1981. For users in the EU and the UK we also act in accordance with the GDPR.
The Service is built for hair-colour professionals. Some of the data it holds is therefore not about the user but about the user's own clients — including photographs. The division of responsibility for that data has its own section below, and it is the most important section in this document for anyone uploading photographs of other people.
You are under no legal obligation to give us any data. Providing it is voluntary — but without it we cannot provide the Service, in whole or in part.
1.Who we are and how to reach us
The controller of account and usage data is Nadav Alluf, Nachal Lachish 27, Ashdod 7770604, Israel.
- Privacy requests — privacy@kolora.io
- General support — support@kolora.io
- Marketing opt-out — unsubscribe@kolora.io
We answer any privacy request — access, correction, deletion, objection to marketing, or a complaint — within 30 days of receiving it, and will tell you if a complex request needs longer.
2.What we collect
Data reaches us four ways: what you enter, what your use of the Service generates, what is collected automatically, and what our providers report back.
- Account data — Email address and password (hashed one-way by our authentication provider and not accessible to us), full name, salon name, and the mobile number given at signup or during onboarding.
- Client records — What you enter about your clients: name, phone, email, colour history, formulas, techniques, professional notes, appointment times, and before/after photographs stored as part of the client record.
- Content submitted for analysis — Hair photographs you capture or upload, your answers to the diagnostic questionnaire, the requested goal, your preferred colour brand, free text you write in the professional chat — and the outputs produced for you: the analysis, the formula, and the result simulation.
- Payment data — Card details are given directly to our payment processor; they never pass through our systems and we do not store them. We store your customer id at the processor, plan, price, currency, billing and renewal dates, and subscription status.
- Usage and analytics — Pages viewed, clicks on key actions, signup and onboarding steps, analysis quota use, device type, operating system, browser, language, and acquisition data (UTM parameters, ad click identifiers, referring URL, landing path and first-seen timestamp).
- Communications — The content of WhatsApp messages sent to and from you through our messaging provider and their delivery status, in-app support chat conversations, email correspondence, and push notification subscriptions.
- Technical and diagnostic records — IP address, device and browser identifiers, request timestamps, errors, and logs of AI calls — duration, cost, model used, the analysis input and its result, and a downscaled copy of the before/after photographs for quality control and support. These logs are accessible to Kolora's operations staff only and are deleted automatically after 90 days.
We do not knowingly collect sensitive data the Service does not need — medical, political, religious, genetic or criminal-record data. Do not enter such data into free-text fields. Photographs of faces or hair are not used by us for biometric identification, no biometric template is derived from them, and they are not used to identify anyone.
3.Your clients' data — who is responsible for what
When you create a client record or upload a client's photograph, you — not we — decide what is collected and for what purpose. In legal terms you are the controller of that data and we hold and process it for you and on your instructions (processor).
Before uploading a client's photograph or entering their details you must obtain their informed consent. Tell the client that the photograph and details are stored in an external digital service, that the photograph is analysed by AI tools, and who to contact for deletion. Failing to obtain that consent breaches these terms and the law, and the responsibility for it is yours.
- We use client data only to provide the Service to you, support you and comply with the law — not for our own independent purposes, not for marketing, and never for sale to a third party.
- If one of your clients contacts us directly we will refer them to you, unless the law requires us to handle the request ourselves. We will help you locate, correct, export or delete client data on your request.
- Deleting your account deletes the client records in it, on the timetable set out in the retention section.
- The sub-processors listed below are the sub-processors we engage in order to provide the Service; your use of the Service is your authorisation of them.
4.What we use data for
- Providing the Service — Creating and authenticating your account, analysing photographs, producing formulas and simulations, storing client records and treatment history.
- Billing and subscription management — Processing payments, renewals, cancellations, enforcing plan quotas and preventing abuse.
- Support — Answering enquiries, reproducing faults, and reviewing AI calls that failed or returned a poor result.
- Improving the Service — Measuring usage, A/B tests, comparing models and output quality — to the minimum extent needed, and on aggregated or de-identified data wherever that is possible.
- Security and fraud prevention — Detecting unusual use, protecting accounts, retaining logs so incidents can be investigated.
- Operational communications — Signup confirmation, password reset, receipts, notices about changes to the Service or to these documents, quota alerts.
- Marketing communications — Only with prior, explicit consent, as set out in the marketing section.
- Legal compliance — Bookkeeping and tax duties, responding to lawful demands from competent authorities, and defending our rights in legal proceedings.
5.Legal basis for processing
In Israel, processing rests on your consent and on the necessity of performing our agreement with you. For users to whom the GDPR applies, the bases are:
- Performance of a contract — Everything required to deliver the Service you bought and to bill for it.
- Legitimate interests — Security, fraud prevention, basic usage measurement and product improvement — balanced against your rights.
- Consent — Marketing messages, push notifications, non-essential cookies and advertising pixels. Consent can be withdrawn at any time.
- Legal obligation — Retaining billing records, responding to lawful demands.
6.AI processing
The core of the Service is analysis of images and text by third-party AI models. To produce the analysis, photographs and questionnaire answers are sent to those providers in real time over secure APIs:
- Anthropic (Claude) — Professional analysis of hair condition, formula construction, and the professional chat.
- Google (Gemini) — Alternative or complementary analysis, and result simulation.
- OpenAI — Visual result simulation, when it is the active provider.
- Black Forest Labs (FLUX) — Visual result simulation, when it is the active provider.
We do not train models on your photographs or data, and we do not supply them for anyone else's model training. Under the business terms of the providers named above, data sent through their APIs is not used to train their models, and is retained by them for a limited period for abuse monitoring only. Using the Service constitutes your consent to sending this content to those providers for that purpose.
AI output is a professional aid only. It does not replace your professional judgement, a patch or sensitivity test, or the manufacturer's instructions. The full limitation of liability is in the Terms of Use.
8.Transfers outside Israel
Our sub-processors store and process data outside Israel, principally in the United States and the European Union. Such transfers are made in accordance with the Protection of Privacy Regulations (Transfer of Data Abroad), 5761-2001, relying on the provider's undertaking to maintain an adequate level of protection and on standard contractual clauses where the law requires them. A copy of the relevant contractual framework is available on written request.
9.Marketing by email, WhatsApp, SMS and push
This section applies to every message whose purpose is to encourage a purchase or spending — promotional content, offers, launches and marketing material — on any channel: email, WhatsApp, SMS, automated calls and push notifications.
We will not send you an advertising message without prior, explicit and recorded consent, as required by section 30A of the Israeli Communications Law. Consent is collected by an active tick — it is never pre-ticked, it is never part of accepting the Terms, and it is never a condition of using the Service.
- What we keep as proof of consent — The time consent was given, the channels approved, the version of these documents shown, and the IP address and browser it came from.
- What every message contains — An advertising message is labelled as an advertisement, names us and our address and how to contact us, and includes a simple, free and clear way to opt out.
- How to opt out — Click the unsubscribe link in any email; reply "STOP" or "הסר" to a WhatsApp message; turn the permission off in your account screen; or write to unsubscribe@kolora.io. We act without delay and in any event within 3 business days.
- What is not marketing — Operational messages that are not advertisements and do not depend on marketing consent: address verification, password reset, receipts and invoices, quota alerts, and notices of faults or of changes to these documents. These are sent while your account is active, including to people who have opted out of marketing.
- WhatsApp messages — Sending and receiving happen on Meta's WhatsApp platform through our messaging provider; those platforms' own terms and privacy notices also apply. Message content and delivery status are recorded by us for support and proof of delivery.
- Push notifications — Sent only after explicit permission in your browser or device, and can be revoked at any time in device or app settings.
Opting out of marketing does not affect your right to keep using the Service, and is not a cancellation of your subscription.
11.How long we keep data
- Account data and client records — For as long as the account is active. After account deletion — up to 30 days to remove from live systems, and up to a further 90 days to age out of encrypted backups.
- AI call logs, including the photograph copies in them — 90 days, after which they are deleted automatically by a scheduled job.
- WhatsApp message records — Up to 24 months, for support, proof of delivery and proof of consent.
- Billing records and invoices — 7 years, as tax and bookkeeping law requires.
- Marketing consent and opt-out records — While the consent is in force and for 3 years after it is withdrawn, as evidence of compliance with the Communications Law.
- Security and error logs — Up to 12 months.
- Aggregated or de-identified analytics — Indefinitely, so long as no individual can be identified from it.
12.Information security
We apply organisational and technical safeguards in line with the Protection of Privacy (Information Security) Regulations, 5777-2017:
- Encryption in transit (TLS) on every path, and encryption at rest with our storage providers.
- Row-level security, so a user can reach only their own data; cross-tenant tables are entirely closed to end users.
- Operations access to sensitive data only to the extent needed, through an admin interface behind separate authentication.
- Downscaling the photographs kept in logs, and limiting that retention to 90 days.
- Monitoring, access logging, and periodic review of permissions and providers.
No system is completely secure. Keeping your login credentials confidential is your responsibility, and you must tell us immediately if you suspect unauthorised use.
13.Your rights
- Access — To receive details of the data held about you and its source.
- Correction — To have data that is inaccurate, incomplete, unclear or out of date corrected; if a request is refused you receive a reasoned notice and a right to object.
- Deletion — To have data or your account deleted, subject to retention duties imposed by law.
- Portability and export — To receive a copy of the data you entered in a machine-readable format.
- Objection and restriction — To object to a particular processing activity or ask that it be restricted, including processing for product improvement.
- Withdrawal of consent — To withdraw consent to marketing, push notifications or non-essential cookies at any time, without affecting the lawfulness of processing carried out beforehand.
- Complaint — To complain to the Israeli Privacy Protection Authority at the Ministry of Justice, and — for EU users — to the supervisory authority where you live.
To exercise a right, write to privacy@kolora.io from the address registered on the account. We verify identity before disclosing data, and reply within 30 days. Exercising a right is free, except for requests that are repetitive or manifestly excessive.
14.Age
The Service is for adult professionals (18+) and is not intended for children. We do not knowingly collect data from minors as users. If a client whose details you enter is under 18, obtaining a parent's or guardian's consent before entering their details or photograph is your responsibility. If we learn that data about a minor was collected without the required consent, we will delete it.
15.Automated decisions
The Service runs automated models to produce a professional recommendation, but makes no decision with legal or similarly significant effect on any person. Quota enforcement and abuse prevention follow defined rules, and any account block is open to human review on request.
16.Security incidents
If a serious security incident occurs we will contain and document it and notify the Israeli Privacy Protection Authority and affected people as the law requires. For users to whom the GDPR applies — notification to the supervisory authority within 72 hours of becoming aware, where the incident requires it. If the incident concerns client data you entered, we will notify you so that you can meet your own reporting duties.
17.Changes to this policy
We may update this policy. A material update — a new processing purpose, a new sub-processor that affects your data, or a change to retention — takes effect 14 days after it is published, and notice will be given by email or by a prominent notice in the Service. The version and effective date appear at the top. Continuing to use the Service after the effective date constitutes acceptance of the updated text; if you do not agree you can stop using the Service and delete your account.
18.Contact, governing law and jurisdiction
- Operator — Nadav Alluf, Nachal Lachish 27, Ashdod 7770604, Israel
- Privacy — privacy@kolora.io
- Support — support@kolora.io
This policy is governed by the laws of the State of Israel, and the competent courts of the Tel Aviv-Yafo District have exclusive jurisdiction over any matter arising from it. In the event of any discrepancy between the Hebrew text and this translation, the Hebrew text prevails.