Effective date: 18 August 2026
This Privacy Policy explains how Sliday LTD ("Sliday", "we", "us", or "our") collects, uses, shares, and protects personal data. It covers both the Karma application (for Microsoft Teams, Slack, Telegram, and the web) and the https://karmabot.chat website.
The data controller is Sliday LTD, a private limited company registered in Cyprus under company number HE450506, with its principal place of business at Pavlou Valdaseridi 2A, 1st floor, Larnaka, Cyprus, 6018.
For any privacy-related enquiry, or to exercise your data protection rights, contact us at hi@karmabot.chat.
Privacy matters are overseen by our Legal Advisor / Operational Security Manager, Stas Kulesh. A dedicated Data Protection Officer has not been appointed, as Sliday LTD is not required to appoint one under Article 37 of the GDPR; privacy responsibilities are held by the Legal Advisor.
Personal data we handle and where it comes from
From the Karma application
When your organisation installs and uses Karma, we process the following personal data, obtained from Microsoft Teams / Microsoft Entra ID (Azure AD) and from your use of the application:
- Display name — from Microsoft Teams / Microsoft Graph
- Email address — from Microsoft Teams / Microsoft Graph
- User Principal Name (UPN) — from Microsoft Graph (
/me) - Microsoft Entra (Azure AD) object ID and tenant ID — from Microsoft authentication
- Profile photo — from Microsoft Graph (
/me/photo) - Team and channel names — from Microsoft Teams
- Karma activity (karma given and received, associated messages) — from your use of the app
Where Karma is used with Slack or Telegram, the equivalent identity and workspace data is obtained from that platform instead.
From this website
- Contact details you give us — such as your email address and name when you subscribe to updates, request a demo, or contact support
- Usage and device data — IP address, browser type and version, pages visited, date, time and duration of visit, referring page, and similar diagnostic data
- Cookies and similar technologies — see "Cookies and website analytics" below
Why we process personal data
We process personal data to:
- Identify you and link you to your organisation's Karma workspace
- Operate the core recognition ("karma") features, leaderboards, and adaptive cards
- Display your name and profile photo within the app
- Deliver notifications and service communications
- Administer subscriptions and billing
- Provide customer support and respond to your enquiries
- Monitor, secure, maintain, and improve the service, and detect and address technical issues
- Send newsletters, marketing, or promotional material where you have chosen to receive it — you can opt out at any time via the unsubscribe link in any email, or by contacting us
Lawful basis for processing
We process personal data on the following lawful bases under the GDPR:
- Performance of a contract — to provide the Karma service to your organisation
- Legitimate interests — to operate, secure, and improve the service, where not overridden by your rights
- Consent — for marketing communications and for non-essential cookies and analytics, where consent is required
- Legal obligation — where we are required by law to retain or disclose data, including for tax and accounting purposes
Where your organisation is the controller and we act as processor, processing is carried out on your organisation's documented instructions.
Who we share personal data with
We share personal data only with the sub-processors listed below, each of which is necessary to deliver the service and is engaged under an appropriate data processing agreement. This is the complete list of sub-processors with access to personal data. We do not sell personal data.
Service sub-processors
- DigitalOcean — application hosting and managed database
- Amazon Web Services (AWS) — profile photo storage (S3)
- Cloudflare — edge delivery and web application firewall
- Microsoft — authentication, the Teams platform, and Microsoft Graph
- Stripe — subscription billing and payment processing
- Sentry — error monitoring
- MailerLite — notification and marketing email delivery
We do not store or collect your payment card details. That information is provided directly to Stripe, our payment processor, whose use of your personal information is governed by its own privacy policy (https://stripe.com/privacy). Stripe adheres to the standards set by PCI-DSS as managed by the PCI Security Standards Council.
Website analytics and marketing providers
The https://karmabot.chat website additionally uses:
We may also disclose personal data where required to do so by law or in response to a valid request by a public authority, or where necessary to protect our legal rights, prevent or investigate wrongdoing, or protect the safety of users or the public.
Cookies and website analytics
Cookies are small pieces of data stored on your device. We use cookies and similar technologies (including beacons, tags, and scripts) to operate the website, remember your preferences, keep the service secure, and understand how the site is used.
The cookies we use fall into these categories:
- Essential cookies — required to operate the website and keep it secure
- Preference cookies — to remember your settings and choices
- Analytics and marketing cookies — set by the providers listed above to measure traffic and advertising performance
You can instruct your browser to refuse all cookies or to notify you when a cookie is set. If you refuse cookies, some parts of the website may not function correctly.
We do not currently respond to browser "Do Not Track" (DNT) signals.
How long we keep personal data
We retain personal data for the duration of your organisation's active subscription and for six (6) months after subscription cancellation, after which it is deleted. This applies to customer account and identity data, profile photos, and karma transaction records.
- Database backups operate on a rolling 7-day point-in-time recovery window, so any backup containing erased data is automatically superseded within 7 days.
- Upon a verified data deletion request, we action it as promptly as reasonably possible and in any event within one month, as required by the GDPR.
- Billing and accounting records may be retained for longer where required by law.
- Operational data — error telemetry, security logs, and backups — is disposed of automatically as it ages out of the relevant service's retention window.
Full details are set out in our Data Retention and Disposal Policy.
Your data protection rights
Subject to applicable law, you have the right to:
- Be informed about how your personal data is used
- Access the personal data we hold about you
- Rectification — to have inaccurate or incomplete data corrected
- Erasure — to have your personal data deleted
- Restriction — to request that we restrict processing of your personal data
- Data portability — to receive your data in a structured, commonly used, machine-readable format
- Object to our processing of your personal data
- Rights relating to automated decision-making and profiling — Karma does not carry out automated decision-making producing legal or similarly significant effects
- Withdraw consent at any time, where we rely on your consent
To exercise any of these rights, contact us at hi@karmabot.chat. We may ask you to verify your identity before responding.
Making a Subject Access Request (SAR)
To submit a Subject Access Request, contact us at hi@karmabot.chat. We respond to all SARs within one month, as required by the GDPR, unless the request is complex or numerous, in which case we may extend the response time by a further two months and will tell you if we do. We maintain a data mapping process that lets us locate and retrieve all personal data held about a specific data subject across our systems — principally the production database and the profile photo object storage — so that a SAR can be fulfilled thoroughly.
International transfers and safeguards
Karma production data is hosted in the United States (DigitalOcean SFO region). As Sliday LTD is established in the EU (Cyprus), this involves a transfer of personal data to a third country.
Such transfers — and transfers to other sub-processors located outside the EU/EEA, including Microsoft, AWS, Cloudflare, Stripe, Sentry, and the analytics providers listed above — are protected by appropriate safeguards, principally the Standard Contractual Clauses (SCCs) incorporated into each sub-processor's Data Processing Agreement, supplemented by those providers' certification frameworks, including the EU–US Data Privacy Framework where the provider participates.
Sliday LTD takes all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.
Your right to complain to a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority.
Our lead supervisory authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus:
You may also lodge a complaint with the supervisory authority in your own country of residence.
Security of data
The security of your data is important to us. We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, vulnerability scanning, and error monitoring. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.
Children's privacy
Our service is not directed at anyone under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us and we will take steps to remove it.
Links to other sites
Our service may contain links to sites we do not operate. We have no control over, and assume no responsibility for, the content or privacy practices of any third-party site. We encourage you to review the privacy policy of every site you visit.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the effective date at the top. Where changes are significant, we will notify you by email and/or a prominent notice on our service before the change takes effect. We encourage you to review this policy periodically.
If you have any questions about this Privacy Policy, contact us:
- By email: hi@karmabot.chat
- By post: Sliday LTD, Pavlou Valdaseridi 2A, 1st floor, Larnaka, Cyprus, 6018