KofaKnowledge infrastructure
How it works
Product
The workspace
Briefs, sessions and records in one place.
The library
Real records from real engagements — open one and follow the evidence.
Ask Kofa
Ask questions against what you've collected — with the receipts.
Knowledge Currency
Know when it gets old, and what needs refreshing.
For
For Practitioners
Run verified conversations and get paid for your expertise.
For Coordinators
Build and lead a local knowledge network.
Why Kofa
The problem Kofa exists to solve.
The networkWho it's forPricingBlog
Start a brief
Start a brief
  1. Home/
  2. Data & Confidentiality

Data & Confidentiality.

How Kofa handles your brief, your session, and your notes — from submission to deletion. Written for institutional clients: DFIs, impact investors, research organisations, and NGOs.

Version1.1
Last updatedAugust 2026
JurisdictionFederal Republic of Nigeria
Terms of ServicePrivacy PolicyData & Confidentiality
ContentsIWhat this page coversIIThe briefIIIPractitioner matchingIVThe prep roomVThe sessionVIThe decision assetVIIWhat Kofa never doesVIIIThe coordinator networkIXPractitioner confidentialityXCompetitive intelligenceXIStorage & securityXIIRetention & deletionXIIIThird-party sub-processorsXIVClient rightsXVContact & escalation
I

What this page covers and who it is for

This page describes how Kofa Insights Limited handles data generated through the Kofa platform — from the moment a brief is submitted to the moment the engagement record is deleted. It is written for institutional seekers: development finance institutions, impact investors, research organisations, and NGOs who need to understand Kofa's data practices before engaging.

It covers five categories of data: brief content, practitioner matching information, prep room exchanges, session recordings and transcripts, and decision assets. It does not cover general website analytics or marketing data, which are addressed in the Privacy Policy.

For compliance teams

If you require a Data Processing Agreement (DPA), a signed confidentiality undertaking, or responses to a supplier due diligence questionnaire, contact privacy@kofa.network. Kofa will respond within five business days. Requests for sub-processor lists, security documentation, or audit evidence should be directed to the same address.

Where this page uses the word seeker, it means the organisation or individual who submitted the brief. Where it uses practitioner, it means the verified expert who participated in the session. Where it uses coordinator, it means a member of Kofa's coordinator network who sourced or verified the practitioner.

II

The brief — what Kofa holds and who sees it

A brief is the document a seeker submits to define the intelligence they need. It typically contains the decision the seeker is trying to inform, the specific question they need answered, the geographic and sectoral context, and the profile of the practitioner they require.

What the brief contains

Briefs may contain market-sensitive information — unreleased investment theses, non-public programme decisions, confidential portfolio context. Kofa treats all brief content as confidential by default, regardless of whether the seeker has marked it as such.

Who at Kofa sees the brief

Matching teamThe Kofa staff member responsible for finding the right practitioner for this brief. Sees the full brief. Bound by employment contract and confidentiality agreement.
Sourcing coordinatorReceives a brief summary — the sectoral context, geographic requirement, and practitioner profile — sufficient to identify the right person. Does not receive the seeker's organisation name or the full decision context unless the seeker explicitly approves disclosure.
Verifying coordinatorReceives the practitioner profile and the experience requirements to conduct the verification interview. Does not receive the seeker's brief content or organisation name.
No one elseBrief content is not shared with other Kofa clients, other practitioners, other coordinators, or any third party — under any circumstances.

What the practitioner receives from the brief

Before a session is confirmed, the practitioner receives a brief summary — the context of the engagement, the questions they will be asked, and the sector and geography involved. They do not receive the seeker's organisation name unless the seeker explicitly approves this disclosure in the prep room. The practitioner is told why their specific experience was relevant to the brief, but not the seeker's identity or the full decision context.

Retention

Brief content is retained for 24 months from the date of engagement completion. After that period it is permanently deleted unless the seeker requests earlier deletion. Deletion requests are processed within 10 business days.

III

Practitioner matching — what is disclosed during sourcing

Kofa's matching process involves coordinators identifying and verifying practitioners against the requirements of a brief. This process is designed so that the seeker's identity and the full decision context are protected throughout.

Coordinator disclosureCoordinators are told the sector, geography, and experience requirements the brief demands. They are not told the seeker's organisation name, the specific decision being made, or any market-sensitive content the brief contains.
Seeker identityThe seeker's organisation name is not disclosed to coordinators during sourcing. It is not disclosed to the practitioner before session confirmation unless the seeker explicitly approves this in the prep room.
Practitioner consentBefore a practitioner is confirmed for a session, they receive the brief summary and confirm their participation. They confirm that they have no conflict of interest with the subject matter, that they understand the confidentiality obligations, and that they consent to the session being recorded.
If a practitioner declinesA practitioner may decline to participate after seeing the brief summary. In that case the brief summary they received is deleted from the matching record and Kofa identifies an alternative. The seeker is notified of the delay but not of the practitioner's identity or their reason for declining.
IV

The prep room — what both sides share before the session

The prep room is the structured exchange that takes place before a session. Both sides receive the session brief, confirm the agenda, complete the NDA, and have the opportunity to add context before the conversation begins.

What is exchanged in the prep room

  • The session brief summary — the questions to be addressed and the context the practitioner needs to prepare
  • The practitioner's verified profile — the specific experience that qualified them for this brief
  • The agreed session agenda — the order of questions and the time allocated to each
  • The NDA — executed by both sides before the session opens
  • Any additional context either side chooses to share in advance

NDA coverage

The NDA executed in the prep room binds the practitioner from disclosing the contents of the session, the identity of the seeker organisation (where disclosed), and any information shared in the prep room itself. It binds the seeker from disclosing the practitioner's identity to third parties without the practitioner's consent. The NDA takes effect before the session begins and remains in force for three years from the session date.

Prep room retention

Prep room content — the exchanges, the agreed agenda, and the executed NDA — is retained as part of the engagement record for 24 months. The executed NDA is retained for the full duration of its term (three years) for enforcement purposes and cannot be deleted on request during that period.

V

The session — recording, transcript, and access

Every Kofa session is recorded. The practitioner consents to recording during the matching process. The seeker agrees to recording as part of the platform terms. Recording is required because decision assets are built directly from the transcript — Kofa does not rely on real-time note-taking.

Recording formatAudio and video, stored in encrypted form on Kofa's primary storage infrastructure. See Section XI for storage details.
Who has accessThe Kofa staff member producing the decision asset. No one else within Kofa has routine access to session recordings. The seeker receives the recording on request — it is not delivered by default. The practitioner does not receive a copy of the recording.
Transcript productionTranscripts are produced by Kofa staff from the session recording. Where automated transcription tools are used as a first pass, the output is reviewed and corrected by a Kofa staff member before the decision asset is produced. No automated transcript is delivered to the seeker without human review.
Practitioner copyPractitioners do not receive a copy of the transcript or recording by default. They may request a copy of their own statements — i.e. their portions of the transcript only — within 30 days of the session. This request is subject to the seeker's consent.
Other use of recordingsSession recordings are used for one purpose only: producing the decision asset for the seeker. They are not used for product development, AI training, quality scoring, or any other internal purpose. See Section VII.
Recording retentionRecordings are retained for 12 months from the session date, then permanently deleted. The seeker may request deletion at any time within that period. Earlier deletion is processed within 10 business days.
VI

The decision asset — ownership, access, and use

The decision asset — referred to in earlier versions of this policy as structured notes — is the primary deliverable of a Kofa engagement and the record the seeker owns. It is organised directly from the session transcript, keyed to the original brief questions, with practitioner statements attributed and preserved exactly as said. Kofa's structuring is limited to organising the record — it adds no analysis, conclusions, or recommendations of its own, and its structuring is always presented separately from what practitioners said.

Delivered notes are stored in the seeker's own knowledge library on the platform and can be searched through Ask Kofa, the platform's retrieval feature. Ask Kofa indexes and retrieves only the assets of the organisation using it — retrieval is scoped to that organisation's decision assets and never pools or reveals content across clients. See Section VII.

OwnershipThe seeker owns the decision asset in full from the moment of delivery. Kofa holds no licence to reproduce, share, or use the asset for any purpose.
Kofa's retained copyKofa retains a copy of the decision asset as part of the engagement record for 24 months — solely for the purpose of resolving disputes about delivery or content accuracy. This copy is not used for any other purpose and is deleted at the end of the retention period or earlier on request.
Third-party sharingKofa's copy of the decision asset is never shared with any third party — including other Kofa clients, practitioners, coordinators, or any external organisation — under any circumstances.
Internal useDecision assets are not used for product improvement, AI training, model development, aggregated market analysis, or any purpose other than the engagement they were produced for.
Delivery formatDecision assets are delivered via the Kofa platform, within 72 hours of the session closing. Your organisation's administrator controls who within the organisation can access them; Kofa implements those access controls and does not decide who within your organisation may see them.
VII

What Kofa never does

This section states explicit limits on Kofa's use of engagement data. These are not aspirations — they are design constraints built into how the platform operates, and violations of them would constitute a material breach of Kofa's obligations to its clients.

Ask Kofa is retrieval, not pooling

Ask Kofa searches the assets of the organisation using it. It does not search across clients, does not share findings between organisations, and does not feed client content into any model. What your organisation searches is what it owns.

Kofa does not
Sell, licence, or otherwise transfer client brief content, session content, or decision assets to any third party
Use brief content, session recordings, transcripts, or decision assets to train, fine-tune, or evaluate any AI or machine learning model
Aggregate intelligence across client engagements to produce market reports, sector analysis, or any derivative work
Disclose the seeker's organisation name to the practitioner without the seeker's explicit approval in the prep room
Disclose the practitioner's identity to the seeker's organisation for any purpose beyond the specific engagement they participated in
Share brief summaries, session content, or notes between clients — including clients operating in the same sector or geography
Retain engagement content beyond the stated retention periods without the seeker's written consent
Use engagement data to approach practitioners on behalf of other clients
Disclose the existence of a specific engagement to any third party, including for marketing or case study purposes, without the seeker's written consent
Verification

Institutional clients who require written confirmation that these limits are contractually binding may request a Data Processing Agreement or supplementary confidentiality undertaking from privacy@kofa.network. These are provided at no cost and are typically executed within five business days.

VIII

The coordinator network — what they know and what they are bound by

Coordinators are the members of Kofa's coordinator network who source and verify practitioners. They are not Kofa employees — they are independent individuals operating under a coordinator agreement that includes binding confidentiality obligations.

What coordinators access

Sourcing coordinators receive a brief summary — the sector, geography, and practitioner profile required. They do not receive the seeker's name, the decision context, or any market-sensitive content. Verifying coordinators receive the practitioner profile and experience requirements for the verification interview. They do not receive the seeker's brief at all.

Confidentiality obligations

Every coordinator signs a confidentiality agreement before accessing any engagement data. The agreement prohibits disclosure of brief summaries, practitioner identities, and session outcomes to any third party — including to other coordinators, to practitioners they did not source, or to any external organisation. Violations are grounds for immediate removal from the network and legal action where applicable.

The separation rule and information leakage

The structural protection against information leakage within the coordinator network is the separation rule: the coordinator who sources a practitioner cannot verify them. This means no single coordinator has access to both the seeker's brief summary and the practitioner's verified profile simultaneously. It limits the information any one coordinator can combine and reduces the risk of inadvertent disclosure.

When a coordinator leaves the network

When a coordinator leaves the Kofa network, their access to engagement data is revoked immediately. Their confidentiality obligations survive the end of their coordinator relationship for five years. Brief summaries and engagement data they accessed during active status are subject to the same deletion schedule as the underlying engagement.

IX

Practitioner confidentiality — protections that run both ways

Confidentiality in a Kofa engagement is not one-directional. Practitioners are bound by obligations to the seeker, but the seeker is also bound by obligations to the practitioner. Both sets of obligations are established before the session begins through the NDA executed in the prep room.

What practitioners cannot discloseThe content of the session, the identity of the seeker organisation where it was disclosed, and any information shared in the prep room. This obligation lasts for three years from the session date.
What the seeker cannot discloseThe practitioner's name, employer, and any identifying information to third parties without the practitioner's written consent. Seekers may cite session findings internally and in board papers, investment memos, and donor reports — but may not name the practitioner without consent.
Practitioner identity disclosureThe practitioner's name is not disclosed to the seeker by default. Seekers receive the practitioner's verified profile — their role, sector, geography, and experience — but not their name. Name disclosure requires the practitioner's explicit consent and is recorded in the engagement log.
If a practitioner violates the NDAKofa will investigate on the seeker's behalf and take enforcement action where possible. The practitioner is removed from the network immediately pending investigation. Kofa will provide the seeker with the documentation required to pursue legal remedies if needed.
X

Competitive intelligence and brief sensitivity

Many briefs submitted to Kofa contain information that is genuinely market-sensitive: unreleased investment theses, non-public programme decisions, pre-approval due diligence, or confidential portfolio context. This section addresses how Kofa handles briefs at that level of sensitivity.

Briefs containing non-public information

If a brief contains information the seeker considers material non-public information — an investment decision not yet announced, a programme not yet approved, a market entry not yet disclosed — the seeker should mark the brief as sensitive at submission. Sensitive briefs receive the following additional protections:

  • The brief summary shared with coordinators is reduced to the minimum required to identify a practitioner — sector and geography only, with the specific decision context withheld entirely
  • The seeker's organisation name is not disclosed to the practitioner under any circumstances without the seeker's written instruction
  • The engagement record is flagged for priority deletion at the seeker's request
  • Access to the brief within Kofa is logged and can be audited on request

Kofa employee obligations

Kofa staff with access to briefs are bound by employment contracts that include confidentiality provisions covering client brief content, session content, and decision assets. Staff are prohibited from using brief content for personal investment decisions, from disclosing brief content to any third party, and from retaining copies of client data outside Kofa's systems.

Access logging

Every access to a brief, prep room record, session recording, or decision asset by a Kofa staff member is logged with a timestamp and user identifier. This log is retained for the full duration of the engagement record and is available to the seeker on written request within five business days.

XI

Data storage and security

Storage locationEngagement data — briefs, prep room records, session recordings, transcripts, and decision assets — is stored on infrastructure located within the European Economic Area or equivalent jurisdiction with adequate data protection standards as recognised under Nigerian data protection law.
Encryption at restAll engagement data is encrypted at rest using AES-256 or equivalent. Encryption keys are managed by Kofa and rotated on a regular schedule.
Encryption in transitAll data transmitted between Kofa's systems and clients is encrypted using TLS 1.2 or higher. Connections using older protocols are rejected.
Access controlsAccess to engagement data within Kofa is restricted on a need-to-know basis. Staff members are granted access to specific engagements relevant to their role. Access is reviewed and revoked when no longer required. All access is logged.
Incident responseIn the event of a data security incident affecting client engagement data, Kofa will notify affected clients within 72 hours of becoming aware of the incident. Notification will include the nature of the incident, the data affected, and the steps being taken to contain and remediate.
Regulatory complianceKofa's data practices are designed to comply with the Nigeria Data Protection Act 2023 (NDPA). For clients whose own obligations require GDPR compliance, Kofa will execute a Data Processing Agreement on request that maps its practices to GDPR requirements.
XII

Retention and deletion

The following table sets out the retention period for each category of engagement data and the conditions under which early deletion can be requested.

Data typeStandard retentionEarly deletion available?Cannot be deleted
Brief content24 months from engagement completionYes — on written request, within 10 business days—
Brief summary (coordinator copy)Deleted when practitioner is confirmedAutomatic — no request needed—
Prep room content24 months from engagement completionYes — on written request—
Executed NDA3 years from session date (NDA term)No — required for enforcement during NDA termDuring NDA term
Session recording12 months from session dateYes — on written request, within 10 business days—
Raw transcript12 months from session dateYes — on written request—
Decision asset (Kofa's copy)24 months from deliveryYes — on written request—
Access logDuration of engagement recordNo — required for audit purposesAlways
Payment records7 years (statutory requirement)No — statutory obligationAlways
Coordinator log24 months from engagement completionYes — with engagement deletion request—

How to request deletion

Deletion requests should be submitted in writing to privacy@kofa.network with the subject line "Deletion Request — [Engagement Reference]". Include the engagement reference number, the data category you wish to delete, and the reason for early deletion if applicable. Kofa will confirm receipt within two business days and complete the deletion within 10 business days.

XIII

Third-party sub-processors

Kofa uses a small number of third-party services that may process engagement data as part of delivering the platform. Every sub-processor is contractually bound by confidentiality and data protection obligations equivalent to those Kofa holds itself to. Kofa does not use sub-processors whose privacy terms permit them to use client data for their own purposes.

Video conferencingUsed to host sessions. Processes audio and video during the session. Does not retain recordings after the session ends — the recording is transferred to Kofa's storage immediately on session close.
Cloud storageUsed to store session recordings, transcripts, and decision assets. Data is encrypted at rest. The provider does not access stored content.
Document deliveryUsed to deliver decision assets to seekers. Processes document content in transit only. Does not retain copies after delivery.
Payment processingUsed to process seeker and practitioner payments. Processes billing information only — does not access brief content, session content, or decision assets.
TranscriptionUsed to produce transcripts of session recordings. Processes session audio; the output is always reviewed and corrected by Kofa staff before a decision asset is produced, and the provider does not retain the audio or transcripts after processing.
AI retrieval (Ask Kofa)Where Ask Kofa is powered by a third-party model service, that service processes your organisation's decision assets only to answer a query from your organisation. Retrieval is scoped to that organisation's assets, and the provider is contractually bound not to retain or train on the content. Clients may request the name of the current provider from privacy@kofa.network.
Full sub-processor list

Institutional clients who require a full list of sub-processors including provider names, data categories processed, and jurisdiction of operation may request this from privacy@kofa.network. The list is provided within five business days and is updated whenever a sub-processor is added or removed.

XIV

Client rights

Seekers have the following rights with respect to the engagement data Kofa holds on their behalf.

Right to accessYou may request a copy of any engagement data Kofa holds that relates to your organisation — briefs, prep room records, decision assets (Kofa's copy), and access logs. Requests are fulfilled within 10 business days.
Right to correctionIf engagement data Kofa holds about your organisation is inaccurate, you may request correction. Kofa will review and correct within 10 business days and confirm the change in writing.
Right to deletionYou may request deletion of any engagement data within the standard retention period, subject to the exceptions listed in Section XII. Deletion requests are processed within 10 business days and confirmed in writing.
Right to auditInstitutional clients may request an audit of the access log for a specific engagement — confirming which Kofa staff accessed which data and when. Audit logs are provided within five business days. Clients requiring more extensive security audit access should contact privacy@kofa.network to discuss available options.
Right to a DPAClients whose own compliance obligations require a Data Processing Agreement may request one at any time. Kofa provides a standard DPA at no cost and will negotiate amendments within reason. Contact privacy@kofa.network.
XV

Contact and escalation

All data and confidentiality enquiries should be directed to Kofa's designated data contact. For routine requests — deletion, access, correction, sub-processor lists — email is sufficient. For urgent matters involving a potential breach or a compliance deadline, mark your subject line accordingly and Kofa will respond within one business day.

Data & confidentiality enquiriesprivacy@kofa.networkStandard response time: 2 business days for acknowledgement, 10 business days for resolution. Urgent matters (breach notifications, compliance deadlines): 1 business day.
Legal & contractual matterslegal@kofa.networkFor DPA negotiations, NDA enforcement, and supplier due diligence questionnaires.
Registered addressKofa Insights Limited · Federal Republic of NigeriaKofa is registered under Nigerian law. For clients whose GDPR obligations require an EU representative, contact legal@kofa.network to discuss arrangements.

Escalation path

If a data or confidentiality concern is not resolved to your satisfaction within the stated response times, you may escalate to the founder directly at aminu@kofa.network. Escalation responses are provided within two business days.

Updates to this policy

Kofa will notify active clients by email when material changes are made to this policy. The version number and last-updated date at the top of this page reflect the current version. The previous version will remain available on request for 12 months after any update.

KofaKnowledge infrastructure

Research infrastructure for organisations and individuals that make decisions. Turn every conversation into knowledge that lasts.

Product

How it worksThe workspaceAsk KofaKnowledge CurrencyThe libraryPricing

Kofa

The networkWho it's forWhy KofaPractitionersCoordinatorsFounding country partner

Legal

Terms of ServicePrivacy PolicyData & Confidentiality

Connect

BlogStart a briefContact
© 2026 Kofa. All rights reserved.Every engagement belongs to the client. Recordings, transcripts and structured notes remain confidential and are never shared beyond the engagement.

Kofa uses Google Analytics to understand how visitors use our site — which pages are most useful and how we can improve. Analytics is configured without advertising features, and your data is never used for advertising. Privacy Policy.