Last Updated: 31 March 2026
1. Data Controller
Katanso Solutions Ltd (trading as "Kumo"), a company registered in England and Wales (company number 16264296), is the data controller responsible for your personal data.
Registered Address: 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom Data Protection Contact: support@kumo.earth ICO Registration Number: ZB960147
This Privacy Policy explains how we collect, use, store, and share your personal data when you use the Kumo Platform (platform.kumo.earth), the Kumo Terminal (terminal.kumo.earth), our website (kumo.earth), and any related services (collectively, the "Services"). It applies to all users of our Services, including representatives of our business customers.
We are committed to protecting your personal data in accordance with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, the Data Use and Access Act 2025, and the Privacy and Electronic Communications Regulations 2003 ("PECR"), as amended.
2. What We Collect
We collect and process the following categories of personal data:
Account Data. When you create an account, we collect your name, email address, company name, job title, and password (hashed). If you sign up using single sign-on (SSO), we receive your name and email address from your identity provider.
Billing Data. When you purchase a subscription, we collect your billing address and company VAT number (where applicable). Payment card details are collected and processed directly by Stripe; we do not store your card number, expiry date, or CVC on our systems. We retain a reference to your Stripe customer ID and subscription details.
Usage Data. We collect information about how you interact with the Services, including pages visited, features used, searches performed, session duration, and click patterns. This data is collected to help us understand how the Services are used and to improve them.
Technical Data. When you access the Services, we automatically collect your IP address, browser type and version, operating system, device type, screen resolution, referring URL, and time zone setting.
Project Data (Kumo Platform only). If you use the Kumo Platform, we collect data you upload about your projects, including financial details, cost profiles, revenue projections, carbon credit volumes, and other project-specific information. This data may include personal data relating to project contacts and personnel. Where you upload personal data relating to third parties (such as the names, email addresses, or contact details of project team members, consultants, or other individuals), you are responsible for ensuring that those individuals have been informed of how their data will be processed in accordance with this Privacy Policy before you upload their data to the Services. By uploading such data, you confirm that you have a lawful basis for sharing it with us and that the relevant individuals have been appropriately informed.
Communications Data. When you contact us by email or through the Services, we retain the content of your communications, your email address, and any attachments you provide.
Marketing Data. If you opt in to marketing communications, we collect your email address and your marketing preferences.
3. Lawful Basis for Processing
Under the UK GDPR, we must have a lawful basis for each type of processing we carry out. The table below sets out the lawful basis we rely on for each purpose:
Creating and managing your account — Performance of a contract (Art. 6(1)(b))
Providing and operating the Services — Performance of a contract (Art. 6(1)(b))
Processing payments and billing — Performance of a contract (Art. 6(1)(b))
Responding to support requests — Performance of a contract (Art. 6(1)(b))
Analytics and product improvement — Legitimate interests: improving the Services (Art. 6(1)(f))
Generating anonymised benchmarking data — Legitimate interests: core business function (Art. 6(1)(f))
Security monitoring and fraud prevention — Legitimate interests: protecting our Services and users (Art. 6(1)(f))
Sending marketing communications — Consent (Art. 6(1)(a))
Tax and accounting compliance — Legal obligation (Art. 6(1)(c))
Responding to regulatory or legal requests — Legal obligation (Art. 6(1)(c))
Where we rely on legitimate interests, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms. You may contact us at support@kumo.earth to request a copy of our legitimate interests assessment.
4. How We Use Your Data
We use your personal data to: deliver, maintain, and improve the Services; process subscriptions and payments; authenticate your identity and manage your account; provide customer support; generate anonymised and aggregated benchmarking data (from which individual users and companies cannot be identified); monitor the security and performance of the Services; detect and prevent fraud, abuse, and unauthorised access; comply with applicable legal and regulatory obligations; and, where you have given consent, send marketing communications about our products and services.
5. Data Sharing and Sub-processors
We do not sell your personal data. We may commercialise anonymised and aggregated data from which individual users and companies cannot be identified; such anonymised data is not personal data, and its creation and use is governed by our Terms of Service. We share your personal data only with the third-party service providers ("sub-processors") listed below, and only to the extent necessary for them to perform services on our behalf:
Sub-processorPurposeData ProcessedLocationAuth0 (Okta, Inc.)Authentication and SSOName, email, login credentials (hashed)EUStripe, Inc.Payment processingBilling data, payment card detailsUS (UK IDTA / EU SCCs)Google Cloud Platform (Google LLC)Hosting, storage, BigQuery analyticsAll service dataEU (europe-west3, Frankfurt)Better Stack, s.r.o.Logging and monitoringTechnical data, usage logsEUAirbyte, Inc.Data synchronisationService dataEUBrevo (Sendinblue SAS)Transactional emailName, email addressEUHubSpot, Inc.CRM and customer relationship managementName, email, company, interactionsUS (UK IDTA / EU SCCs)Google LLC (Google Analytics)Website and service analyticsIP address (anonymised), usage data, device and browser dataUS (EU SCCs with UK Addendum)
We may also share your personal data: (a) with professional advisers (lawyers, accountants, auditors) who are bound by professional obligations of confidentiality; (b) with a prospective buyer or investor in connection with a merger, acquisition, or sale of assets, subject to appropriate confidentiality arrangements; or (c) where required by law, regulation, court order, or governmental authority.
We maintain an up-to-date list of sub-processors and will notify you of any material changes. You may subscribe to sub-processor change notifications by emailing support@kumo.earth.
6. International Transfers
Your personal data is primarily stored and processed within the European Economic Area (EU) and the United Kingdom. Our primary infrastructure is hosted on Google Cloud Platform in the europe-west3 region (Frankfurt, Germany).
Where we transfer personal data outside the UK and the EEA (currently to Stripe, HubSpot, and Google LLC in the United States), we ensure that appropriate safeguards are in place, including: the UK International Data Transfer Agreement ("UK IDTA") issued by the Information Commissioner's Office; and/or the European Commission's Standard Contractual Clauses ("EU SCCs") with the UK Addendum.
You may request a copy of the relevant transfer mechanisms by contacting us at support@kumo.earth.
7. Data Retention
We retain your personal data only for as long as is necessary for the purposes set out in this Privacy Policy, or as required by law. Our standard retention periods are:
Data CategoryRetention PeriodAccount dataDuration of your account plus 12 months after account closureBilling and payment records7 years from the date of the transaction (HMRC requirement)Usage and analytics data26 months from the date of collectionProject data (Kumo Platform)Duration of your account plus 90 days after account closureMarketing consent recordsUntil consent is withdrawn, plus 12 monthsCommunications data24 months from the date of the communicationTechnical/log data12 months from the date of collection
Anonymised and aggregated data (from which individuals cannot be identified) is not personal data and may be retained indefinitely.
When personal data is no longer required, we securely delete or anonymise it in accordance with our data retention policies.
8. Your Rights
Under the UK GDPR, you have the following rights in relation to your personal data:
Right of access. You have the right to request a copy of the personal data we hold about you, together with information about how we process it.
Right to rectification. You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
Right to erasure. You have the right to request that we delete your personal data in certain circumstances, for example where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent.
Right to restriction of processing. You have the right to request that we restrict the processing of your personal data in certain circumstances, for example while we verify the accuracy of your data or consider your objection to processing.
Right to data portability. You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller where technically feasible.
Right to object. You have the right to object to our processing of your personal data where we rely on legitimate interests as our lawful basis. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Right to withdraw consent. Where we rely on consent as the lawful basis for processing (such as marketing communications), you may withdraw your consent at any time by clicking the "unsubscribe" link in any marketing email or by contacting us.
Right not to be subject to automated decision-making. We do not currently make any decisions based solely on automated processing that produce legal or similarly significant effects on you.
To exercise any of these rights, please email us at support@kumo.earth. We will respond to your request within one (1) calendar month. In complex cases or where we receive a high volume of requests, we may extend this period by up to two additional months, and we will inform you of any extension within the initial one-month period.
We will not charge a fee for responding to your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to act on the request.
9. Cookies
We use cookies and similar technologies on our website and Services. For detailed information about the cookies we use, the purposes for which we use them, and how to manage your cookie preferences, please refer to our Cookie Policy.
In summary, we use: functional cookies that are necessary for authentication and core service functionality (exempt from consent under PECR and the Data Use and Access Act 2025); and analytics cookies (Google Analytics) to understand how the Services are used. We do not use advertising or tracking cookies.
10. Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include: encryption of data in transit using TLS 1.3 and encryption of data at rest; role-based access controls and the principle of least privilege; regular security reviews and vulnerability assessments; multi-factor authentication for internal systems; logging and monitoring of access to personal data; and documented incident response procedures.
No method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
11. Children
Our Services are designed for business professionals and are not directed at individuals under the age of 18. We do not knowingly collect personal data from anyone under 18 years of age. If we become aware that we have collected personal data from a person under 18 without appropriate authorisation, we will take steps to delete that data promptly. If you believe we have inadvertently collected data from a minor, please contact us at support@kumo.earth.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law. For material changes, we will provide notice by email to the address associated with your account and/or by posting a prominent notice on the Services at least thirty (30) days before the changes take effect.
The "Last Updated" date at the top of this page indicates when this Privacy Policy was most recently revised. We encourage you to review this Privacy Policy periodically.
13. Complaints
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection:
Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF Telephone: 0303 123 1113 Website: ico.org.uk
We would appreciate the opportunity to address your concerns before you contact the ICO, so please reach out to us first at support@kumo.earth.
14. Contact Us
If you have any questions about this Privacy Policy, your personal data, or our data protection practices, please contact us:
Data Protection Contact Katanso Solutions Ltd (trading as Kumo) 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom Email: support@kumo.earth
For general enquiries: hello@kumo.earth Website: kumo.earth