KOAACH GLOBAL PRIVACY POLICY

Effective Date: 28 August 2026|Last Updated: 28 August 2026|Global platform for organisations, trainers, coaches, facilitators and learning professionals
1. INTRODUCTION

Koaach (“Koaach”, “we”, “us”, “our”) is a global digital platform that enables organisations to discover, evaluate and connect with trainers, coaches, facilitators and other learning professionals. Trainers and learning professionals may create professional profiles, receive enquiries and connect with organisations.

This Privacy Policy explains how Koaach collects, receives, uses, discloses, stores, transfers, secures and otherwise processes personal data when you access or use www.koaach.com, Koaach applications, products, features, communications and related services (collectively, the “Platform” or “Services”).

This Policy is intended for users globally. It is designed to describe Koaach’s practices in a manner that recognises applicable privacy and data-protection requirements in different jurisdictions. Where a mandatory local law gives you additional rights or imposes additional obligations on Koaach, that law will apply to the extent required.

2. WHO OPERATES KOAACH

Koaach is operated by:

Legal Entity: SIEGER TRAINING INDIA

Brand: Koaach

Registered Office: No. 85, Parvathy Nagar North, Santhinikethan Colony, Madambakkam, Chennai, Tambaram, Tamil Nadu 600126, India

Privacy Contact: hello@koaach.com

Website: www.koaach.com

For jurisdictions where a separate controller, representative, Data Protection Officer or privacy contact is legally required, Koaach may designate or appoint the appropriate contact and publish the applicable details in an updated version of this Policy or through the relevant privacy notice.

3. SCOPE

This Policy applies to personal data processed when you:

  • visit, browse or interact with the Koaach website;
  • create, maintain or use a Koaach account;
  • register as a trainer, coach, facilitator, consultant or learning professional;
  • register as an organisation, company, HR/L&D professional or other business user;
  • search for or evaluate trainers or learning professionals;
  • create, update or publish a professional profile;
  • submit a training requirement, enquiry, proposal or request;
  • communicate with Koaach or another Platform user;
  • purchase, subscribe to or use a paid Service;
  • submit reviews, ratings, feedback, testimonials or other content;
  • download or use a Koaach mobile application, where available; or
  • otherwise interact with Koaach, its communications or associated Services.

This Policy does not govern third-party websites, applications, payment services or other services that Koaach does not control. Those services have their own privacy notices.

4. DEFINITIONS
  • “Personal Data” or “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual, as defined by applicable law.
  • “User” means any person accessing or using Koaach.
  • “Trainer” means a trainer, coach, facilitator, consultant, speaker, instructor or learning professional using Koaach.
  • “Organisation” means a company, employer, institution, HR/L&D team or other entity using Koaach.
  • “Processing” includes collection, recording, organisation, storage, use, disclosure, transfer, analysis, modification, retrieval and deletion, as applicable under local law.
  • “Service Provider” or “Processor” means a third party processing personal data on Koaach’s behalf.
5. CATEGORIES OF PERSONAL DATA WE MAY COLLECT
5.1 Identity and Account Data
  • name and display name
  • email address
  • telephone/mobile number
  • account credentials and authentication information
  • profile photograph
  • country, state/province and city
  • account status and preferences
5.2 Professional Data
  • job title/designation
  • organisation/company
  • industry
  • professional biography
  • years of experience
  • areas of expertise
  • training categories
  • specialisations
  • qualifications
  • certifications
  • professional memberships
  • languages
  • locations served
  • delivery formats
  • availability
  • professional website and social links
  • client/project experience voluntarily provided
  • professional references or testimonials
5.3 Organisation and Requirement Data
  • organisation name and business details
  • work contact details
  • role/designation
  • training topics
  • learning objectives
  • participant numbers
  • preferred dates and locations
  • programme duration
  • audience type
  • budget or commercial requirements
  • purchase-order or invoicing information
  • communications and enquiries
5.4 Transaction and Payment Data
  • order or booking information
  • subscription information
  • transaction reference
  • payment status
  • amount and currency
  • billing information
  • invoice information
  • tax information
  • limited payment details received from payment providers

Koaach generally does not intend to store complete payment-card numbers or banking credentials on its own servers. Payment providers may process those details under their own privacy policies and contractual arrangements.

5.5 Communications and User Content
  • messages and enquiries
  • support requests
  • reviews and ratings
  • feedback
  • survey responses
  • uploaded documents
  • images and videos
  • training materials
  • profile descriptions
  • testimonials
  • other content voluntarily submitted
5.6 Technical and Usage Data
  • IP address
  • browser and operating system
  • device type and identifiers
  • language and regional settings
  • pages and features accessed
  • referring URLs
  • session information
  • date and time of access
  • diagnostic and performance information
  • security logs
  • cookie and similar technology information
5.7 Location Data

Koaach may process approximate location derived from IP address or location information you voluntarily provide. Precise location will only be collected or used where necessary, permitted and appropriately disclosed.

5.8 Sensitive or Special-Category Data

Koaach does not generally require sensitive or special-category personal data to use the Platform. Please do not submit health, biometric, financial-account credentials, government identification, precise location, racial/ethnic, religious, sexual-orientation, political, union or other sensitive information unless it is specifically requested for a lawful and disclosed purpose. Where applicable law provides additional protections, Koaach will apply them.

6. SOURCES OF PERSONAL DATA

We may obtain personal data:

  • directly from you when you register, communicate, purchase or submit content;
  • from your organisation where the organisation creates or manages an account or submits your information lawfully;
  • from another Platform user when necessary to facilitate a connection or enquiry;
  • from publicly available professional sources where permitted by law;
  • from service providers supporting authentication, payments, analytics, security or communications;
  • from devices and browsers through technical logs and similar technologies; and
  • from lawful third-party sources where permitted.
7. PURPOSES OF PROCESSING
  • create and manage user accounts;
  • authenticate users and maintain account security;
  • provide and operate the Platform;
  • enable trainer discovery and organisation discovery;
  • match or recommend trainers based on stated requirements and professional information;
  • facilitate enquiries, communications and potential engagements;
  • process bookings, subscriptions, invoices and payments;
  • provide customer support;
  • verify or review professional information where appropriate;
  • personalise Platform functionality and user experience;
  • conduct analytics, measurement and service improvement;
  • detect fraud, abuse, security threats and policy violations;
  • maintain records and business operations;
  • send service, security and administrative communications;
  • send marketing communications where permitted and, where required, with consent;
  • comply with legal, regulatory and law-enforcement requirements;
  • establish, exercise or defend legal claims; and
  • protect the rights, safety and property of Koaach, users and others.
8. LEGAL BASES FOR PROCESSING

Where a law such as the GDPR requires a legal basis, Koaach may rely on one or more of the following, depending on the context:

  • Performance of a contract: processing necessary to provide the Services, manage accounts, facilitate transactions or fulfil an agreement.
  • Consent: processing where you have provided valid consent, such as certain optional marketing or non-essential cookies.
  • Legitimate interests: processing necessary for legitimate business interests such as security, fraud prevention, service improvement, analytics, communications and platform administration, provided those interests are not overridden by applicable rights.
  • Legal obligation: processing required to comply with applicable law, regulatory obligations or lawful requests.
  • Vital interests or other lawful grounds: where recognised by applicable law and appropriate to the circumstances.

Where consent is the legal basis, you may withdraw consent as described in this Policy. Withdrawal does not affect processing that was lawful before withdrawal.

9. TRAINER PROFILES AND DISCOVERABILITY

Koaach is a professional marketplace. Information you choose to place in a discoverable trainer profile may be visible to organisations or authorised Platform users. This may include your name, professional photograph, biography, expertise, experience, qualifications, certifications, industries, locations, languages, professional links and other profile information.

Trainers should not publish information they do not wish to share with prospective clients. Koaach may use profile information to provide search, ranking, filtering, matching and recommendation functionality.

10. ORGANISATION DATA AND TRAINING REQUIREMENTS

Organisations may submit requirements to help Koaach and trainers understand a potential engagement. Organisations should provide only information reasonably necessary for the purpose and should avoid uploading unnecessary personal or confidential employee information.

Where an organisation provides personal data about employees, participants or other individuals, the organisation is responsible for having the necessary authority and lawful basis to provide that information.

11. COMMUNICATIONS BETWEEN USERS

Koaach may facilitate communications between organisations and trainers. Communications may be processed for delivery, security, support, dispute handling, abuse prevention and compliance. Users should avoid exchanging unnecessary sensitive personal data through the Platform.

12. AI, SEARCH, MATCHING AND AUTOMATED FEATURES

Koaach may use algorithms, machine learning or artificial intelligence to improve search, categorisation, recommendations, matching, content organisation, support and other Platform functions.

Automated systems may consider information such as professional expertise, experience, industry, location, language, programme category and stated requirements.

Koaach will not represent that an automated recommendation is a guarantee of suitability. Users remain responsible for professional and commercial decisions.

Where applicable law provides rights regarding solely automated decisions that produce legal or similarly significant effects, Koaach will provide the rights and safeguards required by that law.

13. COOKIES AND SIMILAR TECHNOLOGIES

Koaach may use cookies, pixels, SDKs, local storage, tags and similar technologies.

  • Strictly necessary technologies for authentication, security, sessions and core functionality;
  • Preference technologies for settings and user experience;
  • Analytics technologies for traffic, performance and feature measurement; and
  • Advertising or marketing technologies where permitted and, where required, after obtaining consent.

For detailed information, users should refer to the Koaach Cookie Policy.

14. MARKETING

Where permitted, Koaach may send information about Services, features, events, opportunities, updates and other relevant communications. You may opt out of promotional email communications using the unsubscribe mechanism or by contacting hello@koaach.com.

Essential account, transactional, security and legal communications may continue after marketing opt-out.

15. DATA SHARING AND DISCLOSURE

Koaach does not sell personal data as a general business practice. We may disclose personal data in the following circumstances:

  • to relevant Platform users when necessary to facilitate a professional connection or requested Service;
  • to hosting, infrastructure, analytics, authentication, communication, customer-support and security providers;
  • to payment processors and financial service providers for transactions;
  • to professional advisers, auditors, insurers or legal representatives where appropriate;
  • to authorities, courts or regulators where required or permitted by law;
  • to protect rights, safety, security and property;
  • as part of a merger, acquisition, financing, restructuring or sale of assets; and
  • with your direction or consent.
16. SERVICE PROVIDERS AND PROCESSORS

Koaach may appoint third parties to process personal data on its behalf. Depending on the service, providers may support hosting, cloud storage, authentication, analytics, customer support, communications, payments, security, fraud prevention and other infrastructure.

Koaach will seek appropriate contractual, technical and organisational safeguards for processors where required by applicable law.

17. INTERNATIONAL DATA TRANSFERS

Because Koaach is a global Platform, personal data may be processed in countries other than the country where you reside.

Where applicable law restricts international transfers, Koaach will use an appropriate transfer mechanism or safeguard, which may include an adequacy decision, contractual safeguards, recognised transfer instruments, consent where legally permitted, or another lawful mechanism.

The safeguards used may vary according to the jurisdictions involved and the nature of the transfer.

18. DATA SECURITY

Koaach uses reasonable technical, organisational and administrative measures designed to protect personal data against unauthorised access, loss, misuse, alteration, destruction or disclosure.

  • access controls and role-based permissions
  • authentication and account-security measures
  • secure hosting and infrastructure controls
  • encryption or pseudonymisation where appropriate
  • logging and monitoring
  • backup and recovery controls
  • vendor and processor safeguards
  • incident response procedures

No method of transmission or storage can be guaranteed to be completely secure. Users are responsible for protecting account credentials and should notify Koaach promptly of suspected unauthorised access.

19. DATA BREACH AND SECURITY INCIDENTS

If Koaach becomes aware of a personal-data breach or security incident, it will assess and respond according to applicable law and its incident-response procedures. Where notification to affected individuals, regulators or other parties is legally required, Koaach will provide the required notice within the applicable timeframe.

A security incident may include unauthorised access, loss, disclosure, alteration or destruction of personal data.

20. DATA RETENTION

Koaach retains personal data for as long as reasonably necessary for the purposes described in this Policy, including providing Services, maintaining accounts, fulfilling contracts, supporting transactions, security, fraud prevention, dispute resolution and legal compliance.

Retention periods vary by data category and purpose. When personal data is no longer required, Koaach may delete, anonymise or securely dispose of it, subject to legal, tax, accounting, security, dispute-resolution and other lawful retention requirements.

Anonymised information that can no longer reasonably identify an individual may be retained for analytics, research and business purposes.

21. YOUR PRIVACY RIGHTS — GENERAL

Depending on your jurisdiction, you may have some or all of the following rights:

  • right to know or be informed about processing;
  • right to access personal data;
  • right to correct inaccurate or incomplete data;
  • right to delete or erase data where applicable;
  • right to restrict processing in applicable circumstances;
  • right to object to certain processing, including direct marketing;
  • right to withdraw consent where processing is based on consent;
  • right to data portability where applicable;
  • right to opt out of certain sales, sharing or targeted advertising where applicable;
  • right to limit certain uses of sensitive personal information where applicable;
  • right to object to or obtain safeguards concerning certain automated decision-making or profiling; and
  • right to lodge a complaint with a competent privacy regulator.
22. HOW TO EXERCISE YOUR RIGHTS

Privacy requests may be submitted to hello@koaach.com. Please identify the account or information involved and describe the request. We may need to verify your identity before fulfilling a request.

Koaach will respond within the timeframe required by applicable law. If a request cannot be fully completed, we will explain the applicable limitation where legally permitted.

Where local law permits an authorised agent or representative to submit a request, Koaach may request evidence of authorisation.

23. EUROPEAN ECONOMIC AREA / EU GDPR

If the GDPR applies to Koaach’s processing of your personal data, Koaach will apply the principles and rights required by the GDPR, including lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.

Where applicable, GDPR rights include access, rectification, erasure, restriction, portability, objection, withdrawal of consent and rights concerning certain automated decision-making. You may also lodge a complaint with the competent supervisory authority.

Where required, Koaach will provide information concerning purposes, categories, legal bases, recipients, retention, international transfers and automated processing. The GDPR requires transparent information and recognises rights including access, rectification, erasure, restriction, portability and objection.

If Koaach appoints an EU representative or Data Protection Officer where legally required, the relevant contact details will be published in this Policy or the applicable regional notice.

24. UNITED KINGDOM

Where UK data-protection law applies, Koaach will recognise applicable UK GDPR and UK data-protection rights and requirements. Requests may be submitted to hello@koaach.com. Where a UK representative or Data Protection Officer is legally required and appointed, the applicable details will be provided in the relevant notice.

25. CALIFORNIA PRIVACY RIGHTS

If the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to Koaach’s processing, California residents may have rights including the right to know, delete, correct, opt out of sale or sharing, limit certain uses and disclosures of sensitive personal information, and receive equal treatment for exercising privacy rights.

Koaach does not sell personal information as a business practice. If Koaach engages in a practice that constitutes “sale” or “sharing” under applicable California law, Koaach will provide the legally required notice and opt-out mechanisms.

Requests may be submitted to hello@koaach.com. Koaach may use reasonable verification procedures. California residents may use authorised agents where permitted by law.

Koaach does not discriminate against individuals for exercising rights where prohibited by applicable law.

26. INDIA — DPDP FRAMEWORK

Koaach is operated from India and may process digital personal data subject to India’s Digital Personal Data Protection framework. The Digital Personal Data Protection Act, 2023 establishes a framework concerning processing of digital personal data and rights and obligations relating to such processing.

India’s DPDP Rules, 2025 were notified on 14 November 2025 and provide operational requirements alongside the Act.

Koaach will apply applicable obligations concerning notice, consent or other lawful processing grounds, security safeguards, retention, user rights, grievance handling and other requirements to the extent applicable to its processing.

Where Koaach’s role, the applicable law or future regulatory notifications require a specific Data Protection Officer, consent manager, grievance officer or other designated contact, Koaach will provide the applicable contact information.

27. OTHER JURISDICTIONS

Koaach may have users in jurisdictions with privacy laws that provide additional rights or obligations, including countries in Asia-Pacific, the Middle East, Africa, the Americas and Europe. Koaach will apply mandatory local requirements where they legally apply to the relevant processing.

Nothing in this Policy is intended to contractually waive a mandatory privacy right that cannot lawfully be waived.

28. CHILDREN AND MINORS

Koaach is primarily intended for adults and professional users. Koaach does not knowingly seek to collect personal data from children for purposes unrelated to the Services.

Where a Service is intended to involve minors, the organisation using Koaach is responsible for ensuring appropriate notices, permissions, safeguarding measures and lawful bases for processing participant data. Koaach may require additional controls where legally necessary.

29. DATA PROVIDED ABOUT OTHER PEOPLE

If you provide Koaach with another person’s personal data, you represent that you have the authority or lawful basis to provide it. This includes employee, participant, colleague, trainer and client information.

You should provide only information reasonably necessary for the relevant purpose and should not upload unnecessary sensitive information.

30. PROFESSIONAL AND PUBLIC INFORMATION

Information intentionally published in a professional profile may be visible to other Platform users and may be copied, viewed or processed by recipients outside Koaach’s control. Users should consider carefully what they publish.

Koaach may allow professional profile information to appear in search results or recommendations within the Platform and, where expressly configured, in public-facing professional pages.

31. THIRD-PARTY LINKS AND SERVICES

Koaach may contain links, integrations or references to third-party websites and services. Their privacy practices are governed by their own notices. Koaach is not responsible for third-party processing that it does not control.

32. PAYMENT AND FINANCIAL INFORMATION

Payments may be processed through third-party payment providers. Koaach may receive transaction status, references, amount, currency and billing information. Payment providers may process payment credentials directly. Users should review the privacy terms of the applicable payment provider.

33. MARKETING AND COMMUNICATION PREFERENCES

You may unsubscribe from promotional email communications. Depending on jurisdiction and communication type, you may also have rights to object to direct marketing. Transactional, security and legally required messages may continue.

34. USER REVIEWS, RATINGS AND TESTIMONIALS

Koaach may display reviews, ratings or testimonials submitted by users. If a review contains personal information, the submitting user should ensure it is appropriate to publish. Koaach may moderate or remove content that violates applicable law or Platform policies.

35. ACCOUNT DELETION

You may request account deletion by contacting hello@koaach.com. Deletion may not result in immediate or complete removal of information that Koaach is required or permitted to retain, information contained in legal or financial records, security logs, dispute records, or information lawfully retained by other users.

36. AUTOMATED SECURITY AND FRAUD DETECTION

Koaach may use automated systems to detect suspicious logins, fraud, abuse, spam, malicious activity or security threats. Such processing may involve device, account, transaction and usage signals. Where applicable law grants rights concerning significant automated decisions, Koaach will provide required safeguards.

37. DATA ACCURACY

Users should keep their personal and professional information accurate and current. Koaach may rely on information supplied by users and is not responsible for inaccuracies caused by user submissions.

38. CORPORATE TRANSACTIONS

If Koaach or its assets are involved in a merger, acquisition, financing, restructuring, reorganisation, insolvency proceeding or sale, personal data may be transferred as part of that transaction subject to applicable law and appropriate protections.

39. LEGAL DISCLOSURES

Koaach may disclose personal data when reasonably necessary to comply with law, court orders, lawful government requests, regulatory requirements, legal proceedings, fraud investigations or to establish, exercise or defend legal rights.

40. DATA RETENTION SCHEDULE — GENERAL GUIDANCE
Data CategoryTypical PurposeRetention Approach
Account dataAccount administration and ServicesWhile account is active and for lawful post-account retention
Trainer profileProfessional discovery and matchingWhile profile is active and as reasonably necessary thereafter
Organisation dataRequirements, communication and ServicesWhile relationship is active and for lawful retention
Transaction dataPayments, accounting and taxAs required by applicable financial/tax laws
Security logsSecurity, fraud and incident responseFor a reasonable security period or longer where legally required
Support recordsCustomer support and disputesAs reasonably necessary to resolve and document the matter
Marketing preferencesConsent/opt-out managementUntil no longer necessary or as required to demonstrate compliance

These are general categories rather than fixed universal retention periods. Actual retention may vary based on law, purpose, account status, disputes, security and contractual requirements.

41. YOUR SECURITY RESPONSIBILITIES
  • Use a strong and unique password where passwords are used.
  • Do not share authentication credentials.
  • Use appropriate security controls on your device.
  • Notify Koaach if you suspect unauthorised access.
  • Do not upload unnecessary confidential or sensitive information.
  • Use reasonable care when communicating with other Platform users.
42. GRIEVANCE REDRESSAL

For privacy questions, complaints, requests or concerns, contact hello@koaach.com. Please provide sufficient information for Koaach to understand and investigate the matter.

Where applicable law provides a right to complain to a regulator or supervisory authority, nothing in this Policy prevents you from exercising that right.

43. CHANGES TO THIS POLICY

Koaach may update this Policy to reflect changes in Services, technology, processing practices, legal requirements or business operations. Material changes may be communicated through the Platform, email or other reasonable means.

The effective date and last-updated date will be revised when the Policy is materially updated.

44. GOVERNING LAW, JURISDICTION AND MANDATORY PRIVACY RIGHTS

This Privacy Policy and the processing of personal data by Koaach are governed by applicable laws, including the laws of India to the extent applicable to Koaach's activities and processing.

Koaach is operated by SIEGER TRAINING INDIA, with its registered office in Chennai, Tamil Nadu, India.

Where permitted by applicable law, any dispute, claim or proceeding arising out of or relating to this Privacy Policy or Koaach's processing of personal data shall be subject to the jurisdiction of the courts located in Chennai, Tamil Nadu, India.

However, nothing in this Privacy Policy is intended to exclude, restrict, limit or waive any mandatory privacy, data-protection or regulatory right available to an individual under the laws applicable to that individual.

Where the laws of a user's country or jurisdiction provide mandatory rights, remedies, regulatory complaint mechanisms, supervisory-authority rights, or a right to bring proceedings in a particular jurisdiction that cannot lawfully be excluded by contract, those rights shall continue to apply.

Users located outside India acknowledge that Koaach is operated by an entity based in India and that personal data may be processed in India and other countries, subject to the safeguards and requirements described in this Privacy Policy and applicable law.

For privacy and data-protection matters, users may contact:

Koaach

Legal Entity: SIEGER TRAINING INDIA

Registered Office: No. 85, Parvathy Nagar North, Santhinikethan Colony, Madambakkam, Chennai, Tambaram, Tamil Nadu 600126, India

Email: hello@koaach.com

Website: www.koaach.com

© 2026 Koaach / SIEGER TRAINING INDIA. All rights reserved.