Privacy Policy
Last Updated: 12 June 2026
Draft notice
This document is a working template covering Korastratum's public website (korastratum.com) and the Korastratum business-to-business financial infrastructure platform. The final version intended to be legally binding will be issued by counsel and published in place of this draft. Until that version is published, the controlling terms applicable to customer use of the Korastratum platform are the executed Master Services Agreement (and any related Order Forms) the customer has signed with Korastratum.
For questions about this draft, email legal@korastratum.com.
1. Introduction
Korastratum (“Korastratum,” “we,” “us,” or “our”) provides a business-to-business financial infrastructure platform that helps banks, fintechs, and other financial institutions build identity verification, compliance screening, core banking, and digital banking products. This Privacy Policy explains what personal information we collect from visitors to korastratum.com and authorised users of the Korastratum platform, how we use it, who we share it with, and the choices and rights individuals have in relation to that information.
Korastratum is not a consumer-facing service and does not operate any money-transmission, remittance, or wallet services. We do not act as the data controller for the end customers of our institutional customers; instead, we act as a data processor or service provider on behalf of those customers and process end-customer data only under the instructions set out in the executed Master Services Agreement.
2. Information We Collect
We collect information in the following categories. Each category is collected only where it is reasonably necessary for the purpose identified.
Business contact information
- Identity: Full name, job title, and employer.
- Contact details: Work email address, work phone number, and country.
- Inquiry context: The product or solution you indicated interest in, your stated use case, and any free-form notes you choose to provide.
Platform account information
- Authentication: Email address, hashed password, and any multi-factor authentication factors you enrol.
- Authorisation: Roles, tenant identifiers, and permission scopes assigned to your account by your employer.
- Session activity: Sign-in timestamps, IP address, user agent, and the API or admin actions you take, recorded for audit and security.
Usage and analytics data
- Site analytics: Pages visited on korastratum.com, referring URL, approximate location derived from IP, device and browser characteristics, and aggregate engagement metrics.
- Cookies: Strictly necessary cookies used to maintain a session, plus optional analytics cookies you can decline.
Information processed on behalf of customers
- End-customer data: When an institutional customer runs identity, compliance, banking, or digital-banking workloads on the Korastratum platform, the platform processes data about that institution's own end customers strictly as a processor under the executed Master Services Agreement.
3. How We Use Your Information
We use the information described above for the following purposes:
- Respond to your inquiries, schedule product demonstrations, and progress sales conversations.
- Operate, secure, and continuously improve the Korastratum platform and the korastratum.com website.
- Authenticate authorised users, prevent unauthorised access, detect fraud, and meet our regulatory obligations as a financial-technology service provider.
- Communicate platform notices, security advisories, and (where you have not opted out) marketing communications related to Korastratum products.
- Comply with applicable law, respond to legal process, and defend our legitimate interests.
5. Data Retention
We retain personal information for as long as needed to fulfil the purposes for which it was collected, to comply with our legal and regulatory obligations, to resolve disputes, and to enforce our agreements. Specific retention periods are set out in our internal records schedule and, for data processed on behalf of an institutional customer, in the executed Master Services Agreement with that customer.
6. Data Security
Korastratum implements administrative, technical, and physical safeguards designed to protect personal information from unauthorised access, disclosure, alteration, or destruction. These include encryption in transit and at rest for sensitive data, role-based access controls, multi-factor authentication for privileged accounts, network segmentation, vulnerability management, and continuous security monitoring. No method of transmission or storage is perfectly secure; if you believe your account has been compromised, please contact security@korastratum.com immediately.
7. Your Rights and Choices
Depending on where you are located, you may have the right to request access to, correction of, deletion of, portability of, or restriction of processing of your personal information; to object to certain processing; and to withdraw consent where consent is the legal basis for processing. To exercise any of these rights, contact privacy@korastratum.com. We will respond within the time period required by applicable law. Where personal information is processed on behalf of an institutional customer, requests should be directed to that customer; Korastratum will support the customer in responding to the request.
8. International Data Transfers
Korastratum is headquartered in the United States and operates infrastructure in multiple regions, including North America, Europe, and Africa. By using the platform or the website, you understand that your personal information may be transferred to, stored in, and processed in countries other than the country in which it was originally collected. Where required by law (including under EU/UK GDPR), Korastratum relies on appropriate transfer mechanisms such as Standard Contractual Clauses.
10. Children's Privacy
The Korastratum platform and korastratum.com are intended for business use and are not directed at children. Korastratum does not knowingly collect personal information from children under the age of 16. If you believe a child has provided personal information to Korastratum, please contact us so that we can investigate and, if appropriate, delete the information.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date at the top of the policy and, where required, provide additional notice. Your continued use of the platform or website after an update takes effect constitutes acceptance of the revised policy.
12. Contact Us
For any questions about this Privacy Policy or the way Korastratum handles personal information, please contact:
Korastratum
Attn: Privacy Office
Email: privacy@korastratum.com