Skip to main content

TL;DR

  • Any data your end users provide through the Komo Engagement Engine is your data — Komo does not claim ownership of it.
  • You control what is collected, how consent is presented, and how that data is used; Komo processes and stores data on your behalf to deliver the platform.
  • Komo keeps data secure and only shares it with sub-processors required to run the service.
  • Marketing communications require explicit opt-in before any message is sent.

Contents

Please note that the information and advice that Komo provides regarding privacy, consent, data processing, or any other matter of this nature is of a general basis only, and we suggest you seek your own legal advice specific to your needs.

Roles and ownership

Any data captured on the Komo Engagement Engine is owned by you, not Komo. We do not place any rights on the data other than what is required to deliver the service under our Terms of Service.You represent and warrant that you have obtained all necessary rights and permissions to collect and use the data you submit to the platform.
In general, you decide what personal data to collect, the legal basis for collection, and how end-user data is used for your campaigns and communications. Komo processes that data on your behalf to operate the Engagement Engine — hosting, delivery, support, security, and integrations you configure.The relationship is governed by our Terms of Service and, where applicable, a Data Processing Agreement (DPA). This FAQ is general guidance only; your legal team should confirm roles and obligations for your jurisdiction and use case.
No. Komo does not sell, rent, or license your Customer Data to third parties for their own marketing or data enrichment purposes. Data is processed solely to deliver the services covered under our Terms of Service.
Komo personnel may access Customer Data only when authorised and typically only to resolve a support issue. All Komo staff are bound by confidentiality obligations and NDAs. See Are Komo staff under an NDA? in Security.

What data is collected

Komo collects only the data you configure the platform to capture. This typically falls into:
  • Identity and contact details — name, email address, mobile number, and any contact properties you create (e.g. date of birth, postcode, favourite team).
  • Competition and form responses — answers submitted through data capture forms, including free-text responses, poll and quiz answers, and receipt uploads.
  • Engagement and behavioural data — card interactions, game progress, badge achievements, hub visits, and entry history tied to a contact profile.
  • Consent records — terms and conditions acceptance, communication subscription opt-ins, and cookie consent preferences.
  • Technical metadata — IP address, timestamps, and device/session information used for fraud prevention, analytics, and platform operation.
You decide which fields appear on each form and which are required. Komo does not automatically append third-party enrichment data to your contacts.
Komo classifies end users based on what they have shared:
  • Anonymous — visited your Engagement Hub but has not provided identifying information.
  • Identified — the end user has supplied identifying information (for example through a public data capture form), but Komo has not verified who they are. There is no email validation at this stage, and this is not the same as Authenticated (account login or SSO). Think of a standard competition or form submission where someone enters their details without proving their identity.
  • Authenticated — created an account within your Engagement Hub and completed the required profile fields.
See Contacts for more detail on how contact profiles are built over time.

How data is collected

Data is collected when end users interact with your Engagement Hub and the experiences you configure:
  • Data capture forms — attached to competitions, games, polls, and other cards. You configure the fields, required status, and consent checkboxes for each form. See Data Capture.
  • Account registration and profiles — when authentication is enabled, users can create accounts and build profiles over repeat visits.
  • Passive engagement tracking — card views, completions, and gameplay events are recorded against a session or contact profile for analytics and personalisation.
  • Integrations — data can flow to or from external systems (CRM, email platforms, tag managers) based on rules and filters you configure. See Integrations & Tag Management.
Komo does not collect data independently of the experiences you publish. You are responsible for ensuring you have the appropriate legal basis and notices in place for the data you choose to collect.
Yes. Every data capture form is fully configurable. You can:Nothing is collected through a form unless you have added the field and the end user submits it.

How data is used

Komo uses Customer Data only to:
  • Operate and deliver the Engagement Engine (competitions, communications, CRM, analytics, and integrations you configure).
  • Provide customer support when you or your end users raise an issue.
  • Maintain platform security, monitor performance, and prevent fraud.
  • Comply with legal obligations.
Optional AI features process data only when you enable those features. Komo uses aggregated and anonymised platform data internally to improve the product. Komo does not use your Customer Data for Komo’s own marketing to your end users.
As the data owner, you decide how to use the first-party data captured through Komo — for example:
  • Segmenting contacts and running prize draws.
  • Sending marketing communications to opted-in subscribers.
  • Syncing opted-in contacts to external CRMs and email platforms via workflows and integrations.
  • Exporting data for reporting, fulfilment, or transfer to your own systems.
You must comply with your own privacy policy and all applicable laws governing how you use personal information.

Storage and retention

Customer Data — the data your end users submit through the platform, including contacts, entries, form responses, and engagement history — is stored on infrastructure provided by Google LLC in one of the following data regions.US1 and AU1 are platform data regions. They determine which admin portal you use, which country your data is stored in and how your published Engagement Hub URLs are routed — not where Customer Data is physically stored:Content is delivered globally via Cloudflare, Inc., which routes traffic to the nearest edge data centre for performance. See Sharing and sub-processors for how third-party providers fit into delivery and storage.Komo may disclose data to overseas service providers as described in our Terms of Service. We take reasonable steps to ensure data is handled in accordance with applicable privacy standards, including GDPR Standard Contractual Clauses and UK international data transfer mechanisms where applicable.Komo Technologies Pty Ltd is based in Perth, Western Australia.
You control retention of your Customer Data during your subscription. You can export or delete contacts at any time from the Komo portal — see Access, export, and deletion.After a subscription ends, you may export Customer Data for up to 30 days using the platform’s export features. Komo may retain automated backup copies for up to 30 days from creation before they are destroyed.You are solely responsible for meeting your own data retention obligations under applicable law.

Access, export, and deletion

You can access your data at any time through the Komo portal:
  • Contacts — view, search, filter, and export your full contact list as CSV. See Contacts.
  • Entries — export competition entry data including form responses and consent status. See Entry Management.
  • Integrations — push data to external CRMs, webhooks, and automation tools based on rules you define.
During your subscription and for up to 30 days after it ends, you can export Customer Data at no additional charge using the platform’s existing export features.
Yes. You can delete individual contacts or bulk-delete from the Contacts area. Deletion is permanent and cannot be undone.Komo will not modify User data except as agreed with you in writing.
If an end user contacts Komo directly with a data access, correction, or deletion request (for example under GDPR or CCPA), Komo will promptly notify you unless required by law to act otherwise. You, as the organisation that collected the data, action the request through the portal — export, update, or delete the relevant contact or entry records.For privacy or DPA questions about this process, contact [email protected].

Sharing and sub-processors

Yes, but only with sub-processors engaged to deliver aspects of the platform, and only to the extent necessary to provide the services covered under the Terms of Service. Komo remains responsible for sub-processor handling of your data per our instructions.The authoritative sub-processor list is maintained on our trust site and in Annex 1 of our Terms of Service. A summary table is below and may lag behind live updates.
The following third-party sub-processors may process data in connection with the Komo platform. Optional services are only engaged when you enable the relevant feature.For the current list, see komo.trust.site/subprocessors. Annex 1 of our Terms of Service is also authoritative.
Sub-processorPurposeApplicable serviceLocation
Google, LLCHosting & infrastructure — server and data hostingCore platformUnited States
Cloudflare, Inc.Content delivery network — web infrastructure, security, DDoS mitigation, DNSCore platformUnited States (global data centres; traffic routed to nearest)
PostHog Inc.Product analytics and in-app behaviour insightsCore platformUnited States
DataDog, Inc.Infrastructure monitoring — uptime, performance, securityCore platformUnited States
HubSpotCRM, customer support, and marketing websiteKomo internal operationsUnited States
StripeOnline paymentsBillingUnited States
SprintoSecurity and compliance monitoringKomo internal operationsUnited States
XeroAccountingKomo internal operationsAustralia
OpenAIAI language-model inferenceOptional AI featuresUnited States (optional)
Twilio, Inc.SMS sendingOptional SMS communicationsUnited States (optional)
ActiveCampaign, LLCEmail sending via Postmark (transactional and broadcast)Optional email communicationsUnited States (optional)
This summary may be updated from time to time. Always refer to the live sub-processor list or Annex 1 of the Terms of Service for the current version.
Komo provides layered consent controls so you can align collection and communications with your privacy policy and legal requirements. Consent is managed at three levels:
  1. Hub-level cookie and privacy consent — enable a cookie consent banner in your Hub’s GDPR settings. End users see this when they first load the Engagement Hub and can accept or manage preferences before engaging with content.
  2. Form-level consent for data collection — every data capture form supports a mandatory terms and conditions acceptance checkbox, linked to your uploaded T&Cs. You can add additional required or optional fields for specific consents.
  3. Marketing opt-in via Communication Subscriptions — create workspace-level Communication Subscriptions and add them to your forms. End users must explicitly opt in before they can receive marketing emails. Marketing communications cannot be sent to contacts who have not subscribed. Transactional email and SMS subscription controls are evolving — see the Communication Subscriptions FAQ for current scope.
You configure the copy, required fields, and consent labels for each layer. Komo records consent status against each contact and entry, and this is visible in Entry Management and contact profiles.
Yes. Komo uses cookies for the following purposes:
  • Remember users when returning to the Engagement Hub
  • Remember users who create an account so they do not have to re-enter information when entering competitions
  • Remember where a user got up to in a given game
  • Remember when a user has consented to a data and privacy consent form
You must post a privacy policy on your Hub that provides notice of cookie use, and must not circumvent any opt-out mechanisms that are part of the platform.

Security

Komo implements commercially reasonable technical and organisational security measures, including:
  • Encryption of data in transit and at rest
  • Access controls limiting Komo personnel access to authorised support scenarios — see Can Komo staff access our data?
  • Regular third-party penetration testing, code review, and grey-box testing
  • Security and compliance monitoring via sub-processors such as Sprinto and DataDog
  • Internal policies covering physical access, IT asset management, and data handling
In the event of a security breach affecting Customer Data, Komo will notify you within 48 hours of confirming the nature and extent of the breach, or sooner if required by law.
Yes. Komo engages third-party security experts to conduct penetration tests against our software. We also conduct code review and grey-box testing. See How does Komo protect our data? for our broader security programme.
Yes. We maintain several policies covering physical access and control of data and IT systems, including an IT Asset Register, IT Asset Decommissioning Policy, Physical Data Policy, and Technology Equipment Agreement.
Yes. All Komo staff are required to commit to confidentiality obligations and an NDA. For when staff may access Customer Data, see Can Komo staff access our data?.
Komo maintains separate Terms of Service for Australia/New Zealand and US/International customers. Use the version that matches your contract and region:The sub-processor list is in Annex 1 of the Terms of Service. The live sub-processor list on our trust site may also be useful.
Komo maintains separate Privacy Policies for Australia/New Zealand and US/International customers. Use the version that matches your contract and region:
Our trust centre is available at https://komo.trust.site. It includes security, compliance, and privacy documentation — including the sub-processor list — that may be useful when sharing information with your legal or policy teams.
Yes. Komo complies with EU GDPR obligations, including Standard Contractual Clauses for international data transfers from the EU. For how end-user access and deletion requests are handled, see How do end-user access or deletion requests work?.
Yes. Komo complies with the California Consumer Privacy Act (CCPA). End-user requests directed to Komo are routed to you as described in How do end-user access or deletion requests work?.
Yes. Komo is happy to sign a DPA — please send agreements to [email protected] for review.

Contact

Email [email protected] for privacy, DPA, and data processing questions. For platform support, contact [email protected].