GDPR Compliance
Last updated: September 2026
1. Introduction
KalHope (“we,” “us,” or “our”) is committed to protecting your personal data and respecting your privacy. This GDPR compliance page explains how we collect, process, and safeguard your information when you use our platform, in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
This policy applies to all users, visitors, and subscribers of the KalHope platform, regardless of their location. We act as the data controller for the personal data you provide.
2. Data Controller
The data controller responsible for your personal data is:
KalHope Technology GroupAddis Ababa, Ethiopia
Email: info@kalhope.com
3. Personal Data We Collect
We collect and process the following categories of personal data:
- Account Information: Your name, email address, username, and password (stored only as a hash). If you add one, your phone number. If you sign in with Google, GitHub, or Facebook, we also receive the account details that provider shares with us, such as your email address and name.
- Security Settings: If you turn on two-factor authentication, we store your two-factor settings, including an encrypted authenticator secret and hashed backup codes, plus counters that track failed sign-in and verification attempts.
- Profile Data: Information you choose to add to your profile and to your public portfolios (classic and Spatial), such as your bio, location, website, profile and cover images, skills, work experience, projects, education, languages, and social media links. Anything on a portfolio you publish is visible to anyone who visits it.
- Workspace Data: Tasks, alarms, bookmarks, uploaded files, calculator history, and other content you create within your private workspace.
- Community Interactions: Direct and group messages (including attachments, reactions, and pinned messages), friend connections, follows, blocks, stories, event RSVPs, giveaway entries, reports you submit, and other community activity.
- Sign-in Session Data: For each device you sign in from, we store the IP address, browser and device details (user agent, device type, and a device label), and when the session was last active. You can review and end your sessions in Settings.
- Payment and Subscription Data: Your plan, billing cycle, and order and transaction records. If you pay for a subscription through Chapa's checkout, we share your name, email address, and (if provided) phone number with Chapa to create the payment. If you pay by manual bank transfer (subscriptions and ad orders), we store the payment reference you enter and the proof-of-payment screenshot you upload. We do not store full card numbers.
- Affiliate Data: Referral relationships, commissions and balances, withdrawal requests, and the payout details you enter (payout method, bank name, account name, and account number).
- Advertiser Data: If you buy an ad, the advertiser name, email address, optional phone number, ad content and images, and payment details described above.
- Contact and Careers Submissions: If you use our contact form or apply through our careers page (whether or not you have an account), the name, email address, message, and any resume or portfolio link you send us.
- Hope AI Conversations: The messages you type to Hope AI, and, when you ask about your own account, the results of the account lookups Hope AI runs for you (see Section 8).
- Technical Data: IP addresses and request information used to limit abuse of sign-in, sign-up, verification, contact, careers, and similar forms (see Section 6), and standard server request data such as browser type and referring URL.
- Cookies & Similar Technologies: Session and security cookies, a referral cookie, a portfolio-view cookie, and a theme preference (see Section 7).
- Cloudinary Credentials: If you choose to connect your own Cloudinary account, we store the cloud name, API key, and API secret you provide.
4. How We Use Your Data (Purposes)
We process your personal data for the following purposes:
- To create and manage your account, including sign-in, two-factor authentication, and account recovery.
- To provide and personalise our portfolio, workspace, community, and Hope AI services.
- To process payments, verify manual payments, and manage subscriptions, ad orders, and affiliate payouts.
- To send transactional emails: email verification codes, password reset and password-changed notices, two-factor codes and notices, and account recovery messages.
- To show you how many times your published portfolio has been viewed (aggregate view counts).
- To prevent fraud, abuse, and misuse of our platform, including rate limiting and reviewing referral activity for signs of abuse (see Section 11).
- To respond to contact messages and job applications.
- To comply with legal obligations.
We do not currently send marketing emails. If that changes, we will ask for your consent first.
5. Legal Bases for Processing
We rely on the following legal bases under GDPR:
- Contractual Necessity: To provide the services you have requested (e.g., account creation, portfolios, workspace tools, subscriptions, and Hope AI when you use it).
- Consent: When you connect your own Cloudinary account, when you choose to sign in with Google, GitHub, or Facebook, and for any marketing emails we may send in the future.
- Legitimate Interests: For security monitoring, rate limiting, fraud and abuse prevention (including on the affiliate program), aggregate portfolio view counts, and handling contact and careers submissions.
- Legal Obligation: To comply with applicable laws and regulations.
6. Data Retention and Deletion
We keep your personal data only for as long as necessary for the purposes described above:
- Account data: Kept while your account exists, including your sign-in session records. You can delete your account yourself at any time from Settings by typing your username to confirm.
- What account deletion removes: Deleting your account permanently removes your profile, portfolios, workspace content, sign-in sessions, connected sign-in providers, friend connections, follows, blocks, stories, group memberships and group messages, events and giveaways you created, your direct message conversations (messages you sent and received), your notifications, any account recovery requests linked to your email address, subscription orders and transaction records, affiliate earnings and payout details, and referral records. It also deletes the Spatial portfolio images and payment-proof screenshots you uploaded to KalHope. If you created a group that other people belong to, ownership passes to another member; a group with no other members is deleted. This cannot be undone.
- What account deletion does not remove automatically: The record of any ad you bought (its amount, dates, and ad content stay for our records, but the advertiser name, email, phone number, payment reference, and proof of payment are removed, and any ad still running is ended); and files stored in KalHope's shared upload folder that cannot be linked to an account by where they are stored, such as profile and cover pictures, your classic portfolio photo and resume, message and group attachments, and ad images. To have any of these removed, email us at info@kalhope.com and we will respond within 30 days.
- Contact and careers submissions: Kept for as long as needed to handle your message or application. You can ask us to delete them at any time.
- Rate-limiting records: The IP addresses used to limit repeated requests are kept only for the length of each limit window (a matter of minutes), and anything older than 24 hours is removed by routine automatic cleanup.
- Your own Cloudinary account: Files you store there stay under your control; disconnecting or deleting your KalHope account does not delete anything in your Cloudinary account.
7. Cookies & Similar Technologies
KalHope sets the following:
- Authentication and security cookies: Session, CSRF-protection, and sign-in redirect cookies (plus short-lived ones while you use social sign-in) used to keep you signed in and protect your account. These are essential.
- Referral cookie (
kalhope_ref): Set for 365 days when you open a KalHope referral link, so a sign-up can be credited to the person who referred you. - Portfolio-view cookie (
pf_view_…): When someone views a published portfolio, a cookie that lasts 20 minutes stops the same browser from being counted repeatedly. It holds no personal information and we do not store the visitor's IP address for this purpose. - Browser storage: Your theme choice, and drafts and history from tools such as the DevTools and calculator, are kept in your browser's local or session storage on your own device.
We do not use third-party advertising cookies, third-party analytics, or tracking scripts. You can manage or disable cookies through your browser settings. For more details, see our Cookie Policy.
8. Third‑Party Services
We share data with the following third‑party services to operate our platform:
- AbayHost: Our hosting provider, which runs the KalHope application and its database on servers located in Ethiopia.
- Chapa: Payment processing for subscriptions paid through Chapa's checkout. Chapa receives your name, email address, optional phone number, the payment amount, and a transaction reference. Chapa also notifies us of the payment result, and we confirm it with Chapa directly. Chapa does not have access to your portfolio or workspace data.
- Our web hosting provider (Abay Host): Stores images and files you upload to KalHope, such as portfolio images, ad images, chat attachments, and payment-proof screenshots, on the servers KalHope runs on.
- Cloudinary (your own account): If you choose to connect your own Cloudinary account, files are stored and processed by Cloudinary according to their privacy policy.
- Groq (Hope AI): Hope AI is powered by Groq. When you chat with Hope AI, Groq receives your recent messages (up to the last 10), your username if you are signed in, and the information Hope AI looks up to answer you. Depending on what you ask, that can include your plan and subscription status, portfolio statistics, referral earnings and the usernames of people you referred, withdrawal, order, giveaway, and event status, and the usernames of people who sent you friend requests. Hope AI is instructed to look up your account details only when your question calls for it. We do not save Hope AI conversations in our database. Please avoid typing sensitive information you would not want processed by Groq.
- Google, GitHub, and Facebook: If you choose to sign in with one of these providers, that provider handles your sign-in and shares basic account details with us, such as your email address and name.
- SMTP (mail.kalhope.com): Our own email server, used exclusively for the transactional emails described in Section 4.
We do not sell, rent, or trade your personal data to any other third parties.
9. International Data Transfers
KalHope's application and database are hosted in Ethiopia. When you access our platform from outside Ethiopia, your data is transferred to our servers. Ethiopia currently does not have an adequacy decision from the European Commission, but we implement appropriate safeguards, including standard contractual clauses, to protect your data.
Some of our service providers, including Groq, and Google, GitHub, and Facebook (for sign-in), are operated by companies outside Ethiopia and the European Economic Area, including in the United States. Data you send through those services is processed under their own terms and privacy policies.
10. Data Security
We use the following measures to protect your data:
- Encryption in transit (HTTPS/TLS) with strict transport security.
- Passwords stored only as salted hashes; two-factor backup codes stored as hashes and authenticator secrets stored encrypted.
- Optional two-factor authentication (email code or authenticator app), account lockout after repeated failed sign-ins, and limits on verification and reset attempts.
- Rate limiting on sign-in, sign-up, verification, password reset, account recovery, contact, careers, public ad-image uploads, and Hope AI.
- Session controls: you can view your active sessions, end other sessions, and choose to have inactive sessions ended automatically (this is applied the next time you open your session list).
- Content checks on uploaded images, and standard security headers, including a Content-Security-Policy that we currently run in report-only mode.
- Escaping of Hope AI responses before they are displayed, and periodic review of our code and third-party dependencies for known vulnerabilities.
While we strive to protect your data, no method of electronic storage is 100% secure. We encourage you to use strong, unique passwords, turn on two-factor authentication, and keep your login credentials confidential.
11. Fraud Prevention and Automated Processing
To protect the affiliate program from abuse, we automatically compare signals such as the IP address and device details recorded for sign-in sessions, and payout account details, across accounts (for example, whether a referred account shares an IP address, device, or payout account with the person who referred it, or whether one IP address or device appears on several accounts). These comparisons produce risk flags and a severity score that our administrators can see.
A flag is a signal for a person to review, not a decision. We do not make decisions that have legal or similarly significant effects on you based solely on automated processing. Shared networks, VPNs, and households can trigger flags on their own, so a flag alone is not treated as proof of wrongdoing. If you disagree with an outcome that affects you, you can contact us and ask for a human review, express your view, or object (see Section 12).
12. Your Rights Under GDPR
As a data subject, you have the following rights:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can correct inaccurate or incomplete data. Most profile, portfolio, and account details can be edited directly in your dashboard and Settings.
- Right to Erasure (“Right to be Forgotten”): You can delete your account yourself from Settings (see Section 6 for what is and is not removed automatically), or request deletion of other data by email.
- Right to Restriction of Processing: You can request that we limit how we use your data.
- Right to Data Portability: You can request your data in a structured, commonly used format. We currently provide this on request by email rather than through a self-service export tool.
- Right to Object: You can object to processing based on legitimate interests, including the fraud-prevention checks in Section 11.
- Rights Related to Automated Decision‑Making: As described in Section 11, we do not make decisions with legal or similarly significant effects solely by automated means.
- Privacy controls: You can choose whether your email address, location, and activity are shown on your profile in your privacy settings.
To exercise any of these rights, please contact us at info@kalhope.com. We will respond within 30 days.
13. Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection supervisory authority. We encourage you to contact us first so we can address your concerns directly.
14. Changes to This Policy
We may update this GDPR compliance page from time to time. We will notify you of any material changes via email or through a notice on our platform.
15. Contact Us
If you have any questions about this policy or how we handle your data, please contact us at:
KalHope Technology GroupEmail: info@kalhope.com
Phone: +251 935961028 / +251 911720932