No integrations, no fuss. Access Karma in any browser and start recognizing teammates in seconds.

Celebrate achievements with public shoutouts or private thanks seamlessly on our platform. Instant kudos foster an appreciative culture, uplifting and motivating your team.
See how it works
Choose from automated gift cards across various brands, engage in group rewards for collective celebration, or create custom rewards unique to your company culture.
See rewards
Dive into the heart of your team's activity, spotlighting recognition, engagement, and value alignment, all in one dynamic dashboard.
See analytics
Link every recognition to your company values — making them visible, meaningful, and part of daily team life.

Tailor everything to match your brand — from point names and colors to logos — for a fully personalized experience.

If you're ready to get started with Karma, sign up now and explore the benefits of the recognition for your team. You can also reach out for a free demo.
Effective date: 18 August 2026
This Privacy Policy explains how Sliday LTD ("Sliday", "we", "us", or "our") collects, uses, shares, and protects personal data. It covers both the Karma application (for Microsoft Teams, Slack, Telegram, and the web) and the https://karmabot.chat website.
The data controller is Sliday LTD, a private limited company registered in Cyprus under company number HE450506, with its principal place of business at Pavlou Valdaseridi 2A, 1st floor, Larnaka, Cyprus, 6018.
For any privacy-related enquiry, or to exercise your data protection rights, contact us at hi@karmabot.chat.
Privacy matters are overseen by our Legal Advisor / Operational Security Manager, Stas Kulesh. A dedicated Data Protection Officer has not been appointed, as Sliday LTD is not required to appoint one under Article 37 of the GDPR; privacy responsibilities are held by the Legal Advisor.
When your organisation installs and uses Karma, we process the following personal data, obtained from Microsoft Teams / Microsoft Entra ID (Azure AD) and from your use of the application:
/me)/me/photo)Where Karma is used with Slack or Telegram, the equivalent identity and workspace data is obtained from that platform instead.
We process personal data to:
We process personal data on the following lawful bases under the GDPR:
Where your organisation is the controller and we act as processor, processing is carried out on your organisation's documented instructions.
We share personal data only with the sub-processors listed below, each of which is necessary to deliver the service and is engaged under an appropriate data processing agreement. This is the complete list of sub-processors with access to personal data. We do not sell personal data.
We do not store or collect your payment card details. That information is provided directly to Stripe, our payment processor, whose use of your personal information is governed by its own privacy policy (https://stripe.com/privacy). Stripe adheres to the standards set by PCI-DSS as managed by the PCI Security Standards Council.
The https://karmabot.chat website additionally uses:
We may also disclose personal data where required to do so by law or in response to a valid request by a public authority, or where necessary to protect our legal rights, prevent or investigate wrongdoing, or protect the safety of users or the public.
Cookies are small pieces of data stored on your device. We use cookies and similar technologies (including beacons, tags, and scripts) to operate the website, remember your preferences, keep the service secure, and understand how the site is used.
The cookies we use fall into these categories:
You can instruct your browser to refuse all cookies or to notify you when a cookie is set. If you refuse cookies, some parts of the website may not function correctly.
We do not currently respond to browser "Do Not Track" (DNT) signals.
We retain personal data for the duration of your organisation's active subscription and for six (6) months after subscription cancellation, after which it is deleted. This applies to customer account and identity data, profile photos, and karma transaction records.
Full details are set out in our Data Retention and Disposal Policy.
Subject to applicable law, you have the right to:
To exercise any of these rights, contact us at hi@karmabot.chat. We may ask you to verify your identity before responding.
To submit a Subject Access Request, contact us at hi@karmabot.chat. We respond to all SARs within one month, as required by the GDPR, unless the request is complex or numerous, in which case we may extend the response time by a further two months and will tell you if we do. We maintain a data mapping process that lets us locate and retrieve all personal data held about a specific data subject across our systems — principally the production database and the profile photo object storage — so that a SAR can be fulfilled thoroughly.
Karma production data is hosted in the United States (DigitalOcean SFO region). As Sliday LTD is established in the EU (Cyprus), this involves a transfer of personal data to a third country.
Such transfers — and transfers to other sub-processors located outside the EU/EEA, including Microsoft, AWS, Cloudflare, Stripe, Sentry, and the analytics providers listed above — are protected by appropriate safeguards, principally the Standard Contractual Clauses (SCCs) incorporated into each sub-processor's Data Processing Agreement, supplemented by those providers' certification frameworks, including the EU–US Data Privacy Framework where the provider participates.
Sliday LTD takes all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.
You have the right to lodge a complaint with a data protection supervisory authority.
Our lead supervisory authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus:
You may also lodge a complaint with the supervisory authority in your own country of residence.
The security of your data is important to us. We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, vulnerability scanning, and error monitoring. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.
Our service is not directed at anyone under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us and we will take steps to remove it.
Our service may contain links to sites we do not operate. We have no control over, and assume no responsibility for, the content or privacy practices of any third-party site. We encourage you to review the privacy policy of every site you visit.
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the effective date at the top. Where changes are significant, we will notify you by email and/or a prominent notice on our service before the change takes effect. We encourage you to review this policy periodically.
If you have any questions about this Privacy Policy, contact us: