Legal

Privacy Policy

How Kordio collects, uses, and protects personal information when you visit kordio.io or use the Kordio ledger API.

Last updated: 16 July 2026

1. Who we are

Kordio is an agent control layer and a double-entry ledger API, operated by SouthPay LLC, a Wyoming limited liability company (filing ID 2026-002019288), with its principal place of business at 1200 Brickell Avenue, Ste 1950 #103, Miami, FL 33131, United States ("Kordio", "we", "us", "our"). SouthPay LLC is the data controller for the personal information described in this policy. It explains what we collect, why we collect it, how we use it, and the choices you have about it.

2. Scope of this policy

This policy covers the Kordio marketing website (kordio.io) and the Kordio product available at app.kordio.io. It applies to people who visit our site, sign up for a Kordio account, contact us, or otherwise interact with Kordio in an individual capacity.

When you use Kordio to record and process business data on behalf of your own end users, you are the data controller for that data and Kordio acts as your data processor. That relationship is governed by the Data Processing Addendum in the Service Agreement you enter into when you sign up.

3. Information we collect

3.1 Information you provide to us

  • Account information: name, email address, company, role, and password when you register for a Kordio account.
  • Billing information: company legal name, tax ID, billing address. Card details are handled by our payment processor; we do not store full card numbers on our systems.
  • Communications: messages, tickets, and attachments you send when you contact support or sales.
  • Configuration data: API keys, webhook endpoints, chart-of-accounts templates, and other setup you provide as part of using the product.

3.2 Information we collect automatically

  • Log data: IP address, browser type, device identifiers, timestamps, referrer, and pages viewed on kordio.io.
  • API telemetry: endpoints called, request and response metadata, HTTP status codes, and latency. We collect this to monitor the service, investigate abuse, bill accurately, and improve performance.
  • Cookies and similar technologies: see section 8.

3.3 Information we receive from third parties

  • Payment processor: payment status, last four digits of the card, and billing outcomes.
  • Analytics providers: aggregated usage information from Google Analytics.
  • Advertising providers: Reddit, which receives a signal that a page was visited so we can measure whether an advert worked and reach similar audiences.
  • Fraud and identity providers: signals used to detect abuse of the free tier or the API, where we engage such providers.

4. How we use personal information

  • Provide, secure, and maintain kordio.io and the Kordio product.
  • Create and administer your account and process payments.
  • Send transactional messages (account, billing, security, and service notices).
  • Send product updates, developer newsletters, and marketing where lawful. You can unsubscribe at any time.
  • Analyse usage to improve the product, the docs, and the site.
  • Detect, investigate, and prevent abuse, fraud, or violations of our Acceptable Use Policy.
  • Comply with legal obligations and respond to lawful requests.

5. Legal bases for processing (EEA and UK)

If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR:

  • Performance of a contract: to provide the service you signed up for.
  • Legitimate interests: to secure the service, prevent abuse, understand product usage, and market to existing customers about related services.
  • Consent: for non-essential cookies and, where required, direct marketing.
  • Legal obligation: to comply with tax, accounting, anti-money-laundering, and other applicable laws.

6. How we share personal information

We share personal information with:

  • Sub-processors that help us run Kordio (cloud hosting, email delivery, payment processing, analytics, customer support tooling). Each is bound by a contract requiring appropriate confidentiality and security safeguards. A current list is available on request.
  • Professional advisers such as auditors, lawyers, and accountants, where necessary.
  • Authorities and regulators where required by law, court order, or to protect our rights, property, or the safety of others.
  • Acquirers and successors in the event of a merger, acquisition, financing, or sale of business assets.

We do not sell personal information.

7. International transfers

Kordio and its sub-processors may operate in multiple jurisdictions, including the United States and the European Union. Where personal data is transferred outside your region, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or equivalent protections.

8. Cookies and similar technologies

We use cookies and similar technologies for the following purposes:

  • Strictly necessary: sign-in, session state, security. These cannot be disabled without breaking the site.
  • Analytics: measure how the site and product are used so we can improve them.
  • Functionality: remember preferences such as layout or language.
  • Advertising: measure whether an advert led to a visit, and build audiences for future adverts. These are set by Reddit.

You can control cookies through your browser settings and, where required, through the consent banner shown on your first visit.

9. Data retention

  • Account data: kept for as long as your account is active, plus a reasonable period after closure to comply with legal, tax, and accounting obligations (typically up to seven years).
  • Log data and API telemetry: retained for as long as needed to operate, secure, and improve the service, typically twelve months.
  • Ledger data you submit: held for the term of your subscription. On termination we will delete or return it according to your instructions in the Service Agreement, subject to any legal requirement to retain it.

10. Security

We use technical and organisational safeguards designed to protect personal information, including:

  • Encryption in transit (TLS 1.2 or higher) and at rest for stored data.
  • Least-privilege access controls and audit logging for employee access.
  • Regular vulnerability scanning, patching, and security review.
  • Employees and contractors bound by confidentiality obligations.

No system is completely secure. If you become aware of a security concern, please contact us at tech@southpay.io.

11. Your rights

Depending on where you live, you may have the right to:

  • Access, correct, or delete the personal information we hold about you.
  • Object to or restrict certain kinds of processing.
  • Receive a portable copy of your personal information.
  • Withdraw consent where processing relies on consent.
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights, email tech@southpay.io. We will respond within the timeframe required by applicable law.

12. Children

Kordio is a business-to-business product and is not directed to individuals under the age of 18. We do not knowingly collect personal information from children.

13. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or the law. When we do, we will update the "Last updated" date at the top of the page. For material changes we will provide additional notice, such as an email to account holders.

14. Contact

For any questions about this policy or how we handle personal information, email tech@southpay.io.