Data & Confidentiality.
How Kofa handles your brief, your session, and your notes — from submission to deletion. Written for institutional clients: DFIs, impact investors, research organisations, and NGOs.
What this page covers and who it is for
This page describes how Kofa Insights Limited handles data generated through the Kofa platform — from the moment a brief is submitted to the moment the engagement record is deleted. It is written for institutional seekers: development finance institutions, impact investors, research organisations, and NGOs who need to understand Kofa's data practices before engaging.
It covers five categories of data: brief content, practitioner matching information, prep room exchanges, session recordings and transcripts, and decision assets. It does not cover general website analytics or marketing data, which are addressed in the Privacy Policy.
If you require a Data Processing Agreement (DPA), a signed confidentiality undertaking, or responses to a supplier due diligence questionnaire, contact privacy@kofa.network. Kofa will respond within five business days. Requests for sub-processor lists, security documentation, or audit evidence should be directed to the same address.
Where this page uses the word seeker, it means the organisation or individual who submitted the brief. Where it uses practitioner, it means the verified expert who participated in the session. Where it uses coordinator, it means a member of Kofa's coordinator network who sourced or verified the practitioner.
The brief — what Kofa holds and who sees it
A brief is the document a seeker submits to define the intelligence they need. It typically contains the decision the seeker is trying to inform, the specific question they need answered, the geographic and sectoral context, and the profile of the practitioner they require.
What the brief contains
Briefs may contain market-sensitive information — unreleased investment theses, non-public programme decisions, confidential portfolio context. Kofa treats all brief content as confidential by default, regardless of whether the seeker has marked it as such.
Who at Kofa sees the brief
What the practitioner receives from the brief
Before a session is confirmed, the practitioner receives a brief summary — the context of the engagement, the questions they will be asked, and the sector and geography involved. They do not receive the seeker's organisation name unless the seeker explicitly approves this disclosure in the prep room. The practitioner is told why their specific experience was relevant to the brief, but not the seeker's identity or the full decision context.
Retention
Brief content is retained for 24 months from the date of engagement completion. After that period it is permanently deleted unless the seeker requests earlier deletion. Deletion requests are processed within 10 business days.
Practitioner matching — what is disclosed during sourcing
Kofa's matching process involves coordinators identifying and verifying practitioners against the requirements of a brief. This process is designed so that the seeker's identity and the full decision context are protected throughout.
The prep room — what both sides share before the session
The prep room is the structured exchange that takes place before a session. Both sides receive the session brief, confirm the agenda, complete the NDA, and have the opportunity to add context before the conversation begins.
What is exchanged in the prep room
- The session brief summary — the questions to be addressed and the context the practitioner needs to prepare
- The practitioner's verified profile — the specific experience that qualified them for this brief
- The agreed session agenda — the order of questions and the time allocated to each
- The NDA — executed by both sides before the session opens
- Any additional context either side chooses to share in advance
NDA coverage
The NDA executed in the prep room binds the practitioner from disclosing the contents of the session, the identity of the seeker organisation (where disclosed), and any information shared in the prep room itself. It binds the seeker from disclosing the practitioner's identity to third parties without the practitioner's consent. The NDA takes effect before the session begins and remains in force for three years from the session date.
Prep room retention
Prep room content — the exchanges, the agreed agenda, and the executed NDA — is retained as part of the engagement record for 24 months. The executed NDA is retained for the full duration of its term (three years) for enforcement purposes and cannot be deleted on request during that period.
The session — recording, transcript, and access
Every Kofa session is recorded. The practitioner consents to recording during the matching process. The seeker agrees to recording as part of the platform terms. Recording is required because decision assets are built directly from the transcript — Kofa does not rely on real-time note-taking.
The decision asset — ownership, access, and use
The decision asset — referred to in earlier versions of this policy as structured notes — is the primary deliverable of a Kofa engagement and the record the seeker owns. It is organised directly from the session transcript, keyed to the original brief questions, with practitioner statements attributed and preserved exactly as said. Kofa's structuring is limited to organising the record — it adds no analysis, conclusions, or recommendations of its own, and its structuring is always presented separately from what practitioners said.
Delivered notes are stored in the seeker's own knowledge library on the platform and can be searched through Ask Kofa, the platform's retrieval feature. Ask Kofa indexes and retrieves only the assets of the organisation using it — retrieval is scoped to that organisation's decision assets and never pools or reveals content across clients. See Section VII.
What Kofa never does
This section states explicit limits on Kofa's use of engagement data. These are not aspirations — they are design constraints built into how the platform operates, and violations of them would constitute a material breach of Kofa's obligations to its clients.
Ask Kofa searches the assets of the organisation using it. It does not search across clients, does not share findings between organisations, and does not feed client content into any model. What your organisation searches is what it owns.
Institutional clients who require written confirmation that these limits are contractually binding may request a Data Processing Agreement or supplementary confidentiality undertaking from privacy@kofa.network. These are provided at no cost and are typically executed within five business days.
The coordinator network — what they know and what they are bound by
Coordinators are the members of Kofa's coordinator network who source and verify practitioners. They are not Kofa employees — they are independent individuals operating under a coordinator agreement that includes binding confidentiality obligations.
What coordinators access
Sourcing coordinators receive a brief summary — the sector, geography, and practitioner profile required. They do not receive the seeker's name, the decision context, or any market-sensitive content. Verifying coordinators receive the practitioner profile and experience requirements for the verification interview. They do not receive the seeker's brief at all.
Confidentiality obligations
Every coordinator signs a confidentiality agreement before accessing any engagement data. The agreement prohibits disclosure of brief summaries, practitioner identities, and session outcomes to any third party — including to other coordinators, to practitioners they did not source, or to any external organisation. Violations are grounds for immediate removal from the network and legal action where applicable.
The separation rule and information leakage
The structural protection against information leakage within the coordinator network is the separation rule: the coordinator who sources a practitioner cannot verify them. This means no single coordinator has access to both the seeker's brief summary and the practitioner's verified profile simultaneously. It limits the information any one coordinator can combine and reduces the risk of inadvertent disclosure.
When a coordinator leaves the network
When a coordinator leaves the Kofa network, their access to engagement data is revoked immediately. Their confidentiality obligations survive the end of their coordinator relationship for five years. Brief summaries and engagement data they accessed during active status are subject to the same deletion schedule as the underlying engagement.
Practitioner confidentiality — protections that run both ways
Confidentiality in a Kofa engagement is not one-directional. Practitioners are bound by obligations to the seeker, but the seeker is also bound by obligations to the practitioner. Both sets of obligations are established before the session begins through the NDA executed in the prep room.
Competitive intelligence and brief sensitivity
Many briefs submitted to Kofa contain information that is genuinely market-sensitive: unreleased investment theses, non-public programme decisions, pre-approval due diligence, or confidential portfolio context. This section addresses how Kofa handles briefs at that level of sensitivity.
Briefs containing non-public information
If a brief contains information the seeker considers material non-public information — an investment decision not yet announced, a programme not yet approved, a market entry not yet disclosed — the seeker should mark the brief as sensitive at submission. Sensitive briefs receive the following additional protections:
- The brief summary shared with coordinators is reduced to the minimum required to identify a practitioner — sector and geography only, with the specific decision context withheld entirely
- The seeker's organisation name is not disclosed to the practitioner under any circumstances without the seeker's written instruction
- The engagement record is flagged for priority deletion at the seeker's request
- Access to the brief within Kofa is logged and can be audited on request
Kofa employee obligations
Kofa staff with access to briefs are bound by employment contracts that include confidentiality provisions covering client brief content, session content, and decision assets. Staff are prohibited from using brief content for personal investment decisions, from disclosing brief content to any third party, and from retaining copies of client data outside Kofa's systems.
Access logging
Every access to a brief, prep room record, session recording, or decision asset by a Kofa staff member is logged with a timestamp and user identifier. This log is retained for the full duration of the engagement record and is available to the seeker on written request within five business days.
Data storage and security
Retention and deletion
The following table sets out the retention period for each category of engagement data and the conditions under which early deletion can be requested.
| Data type | Standard retention | Early deletion available? | Cannot be deleted |
|---|---|---|---|
| Brief content | 24 months from engagement completion | Yes — on written request, within 10 business days | — |
| Brief summary (coordinator copy) | Deleted when practitioner is confirmed | Automatic — no request needed | — |
| Prep room content | 24 months from engagement completion | Yes — on written request | — |
| Executed NDA | 3 years from session date (NDA term) | No — required for enforcement during NDA term | During NDA term |
| Session recording | 12 months from session date | Yes — on written request, within 10 business days | — |
| Raw transcript | 12 months from session date | Yes — on written request | — |
| Decision asset (Kofa's copy) | 24 months from delivery | Yes — on written request | — |
| Access log | Duration of engagement record | No — required for audit purposes | Always |
| Payment records | 7 years (statutory requirement) | No — statutory obligation | Always |
| Coordinator log | 24 months from engagement completion | Yes — with engagement deletion request | — |
How to request deletion
Deletion requests should be submitted in writing to privacy@kofa.network with the subject line "Deletion Request — [Engagement Reference]". Include the engagement reference number, the data category you wish to delete, and the reason for early deletion if applicable. Kofa will confirm receipt within two business days and complete the deletion within 10 business days.
Third-party sub-processors
Kofa uses a small number of third-party services that may process engagement data as part of delivering the platform. Every sub-processor is contractually bound by confidentiality and data protection obligations equivalent to those Kofa holds itself to. Kofa does not use sub-processors whose privacy terms permit them to use client data for their own purposes.
Institutional clients who require a full list of sub-processors including provider names, data categories processed, and jurisdiction of operation may request this from privacy@kofa.network. The list is provided within five business days and is updated whenever a sub-processor is added or removed.
Client rights
Seekers have the following rights with respect to the engagement data Kofa holds on their behalf.
Contact and escalation
All data and confidentiality enquiries should be directed to Kofa's designated data contact. For routine requests — deletion, access, correction, sub-processor lists — email is sufficient. For urgent matters involving a potential breach or a compliance deadline, mark your subject line accordingly and Kofa will respond within one business day.
Escalation path
If a data or confidentiality concern is not resolved to your satisfaction within the stated response times, you may escalate to the founder directly at aminu@kofa.network. Escalation responses are provided within two business days.
Updates to this policy
Kofa will notify active clients by email when material changes are made to this policy. The version number and last-updated date at the top of this page reflect the current version. The previous version will remain available on request for 12 months after any update.