Your safety is at the heart of everything we do at Karma.
We're not just about secure coding; it's our culture. With cutting-edge tech and stringent practices, we keep your data locked down.
At Karma, we prioritize your safety and privacy. Our comprehensive security policy encompasses advanced technologies and rigorous practices to safeguard your data at every level.
book free demoYour privacy is sacred. We adhere to global standards like GDPR and CCPA, making your data's confidentiality our top concern.
We blend security into our operations and product design, using the best practices to protect your data.
Expect unwavering reliability. Our scalable infrastructure and transparent performance updates mean you're always in the loop.
Karma’s web application enforces end-to-end encryption across all user interactions, ensuring data is protected both in transit and at rest. All communications between users and Karma’s servers use TLS 1.3 with modern cipher suites, protecting against interception, tampering, and man-in-the-middle attacks. Stored data benefits from AES256 encryption, providing long-term protection at both the application and hardware levels, with multi-layered key management to further enhance security.
Karma integrates security best practices directly into its development lifecycle, including continuous code reviews, automated security scanning, and regular penetration testing. The web app infrastructure is fully containerized, ensuring each service is isolated to minimize the risk of lateral movement during potential incidents. Vulnerabilities are triaged, prioritized, remediated, and retested on a rolling basis to maintain a resilient security posture in line with industry best practices.
Karma’s web app adheres to the principle of least privilege, ensuring users only have access to the data and features necessary for their role. Admin users can configure granular permissions, controlling access to sensitive areas such as data exports, billing, and administrative tools. All login attempts, account changes, and high-risk actions are logged and continuously monitored to detect potential anomalies. Periodic access reviews further enhance security by ensuring permissions remain appropriate over time.
Users have full control over their personal data in the Karma web app, with the ability to request data deletion or anonymization directly via their profile settings. Karma’s data retention policy ensures unnecessary data is automatically purged after predefined periods, minimizing exposure. All deletion requests follow a multi-step verification process, confirming user identity before securely erasing or anonymizing data. These processes ensure full compliance with GDPR, CCPA, and other relevant data protection regulations, offering users transparency, security, and peace of mind.
Karma for Slack follows a strict data retention policy, balancing functionality with privacy. All team data is securely erased 30 days after a workspace fully deletes the bot, ensuring no unnecessary data remains. Customers can also instantly purge all team data using the Billing page > Danger zone option, offering complete control over their information. To protect user privacy, individual profiles are anonymized upon deletion, preserving historical data integrity without retaining personal details. Automatic data shredding processes run daily, ensuring obsolete records are securely removed on schedule.
Karma employs industry-standard encryption protocols to safeguard your Slack workspace data. All data in transit is secured using TLS 1.3, AES256 encryption, and SHA2 signatures, ensuring safe and tamper-proof communication between your workspace and Karma’s servers. Data at rest benefits from AES256 encryption with layered protection at both the storage system and device levels, offering robust defense against unauthorized access. Our infrastructure, hosted on AWS and DigitalOcean in the United States, also leverages Cloudflare’s advanced security services to mitigate external threats and enhance resilience.
Karma’s production environment is secured using DigitalOcean Cloud Firewalls, allowing only traffic from explicitly whitelisted IP addresses and blocking all unauthorized access. Internal systems are continuously monitored for suspicious activity, with strict access controls ensuring only authorized personnel can interact with sensitive data. Combined with hardware RAID configurations and comprehensive backup procedures, these controls ensure data availability and resilience, even in the event of hardware failures or service disruptions.
Karma prioritizes user control and regulatory compliance. Workspace admins and owners can initiate immediate, irreversible data deletion directly from the app’s settings. Individual users can also request the anonymization or deletion of their personal data at any time. Every request triggers a verified support process, confirming the requester’s identity before securely processing the request. While Karma is not HIPAA-compliant, our data handling practices align with GDPR and CCPA principles to ensure transparency, accountability, and user control.
Karma for Microsoft Teams is a Microsoft Publisher Attested App, meaning it meets Microsoft’s rigorous security and compliance requirements for Teams applications. Karma undergoes annual PCI DSS assessments and holds CSA STAR certification, demonstrating our commitment to safeguarding customer data. Karma also complies with global data protection laws, including GDPR and CCPA, ensuring transparent data handling and robust privacy protections. All data transmitted between Teams clients and Karma services is encrypted using TLS 1.1+, providing a secure communication channel across your Microsoft collaboration environment.
Karma for Microsoft Teams follows the principle of least privilege, limiting access strictly to the data necessary for functionality. When required for core features, the app may access specific personal information (e.g., phone numbers, postal addresses, URLs) within active messages — however, Karma cannot read or modify other mailbox items. Any data transmitted to third-party services follows strict encryption standards, ensuring secure handling. By applying data minimization practices, Karma reduces the exposure and retention of personal data.
Security is embedded into Karma’s development lifecycle through secure coding practices, regular security reviews, vulnerability scanning, and continuous testing at every development stage. Karma’s production environment is continuously monitored, with all systems operating under segmented, firewall-protected networks to minimize risk. Regular penetration testing, combined with real-time anomaly detection and multi-layered access controls, ensures Karma maintains a strong security posture aligned with Microsoft’s evolving security standards.
Karma puts data control in the hands of Teams admins and users. Admins can configure permissions and manage access directly within the Microsoft 365 Admin Center, tailoring access rights to specific roles and data sensitivity levels. All user data is processed under strict data retention and deletion policies, and users can request their personal data be deleted or anonymized at any time. Each request undergoes a verified multi-step process, ensuring requester identity is confirmed before secure processing. By combining robust data controls with adherence to GDPR and CCPA, Karma ensures transparency, privacy, and user empowerment across your Teams environment.
Karma for Telegram ensures secure message exchange by leveraging Telegram’s infrastructure, which uses MTProto encryption for client-server communication. All bot communications are encrypted in transit via HTTPS/TLS, protecting against interception or tampering. Karma never stores message content beyond what is necessary for feature delivery, and no messages are accessible to third parties outside Telegram’s own infrastructure.
Karma follows the principle of data minimization, requesting only the minimum required permissions to function. The bot does not access contact lists, group histories, or user metadata beyond what is essential for operations. All data handled via the bot is processed ephemerally — Karma does not retain user messages unless explicitly required for scoring, reporting, or analytics functions, and even then only temporarily.
Karma’s Telegram bot backend runs in containerized, sandboxed environments hosted on DigitalOcean and AWS infrastructure in the United States. Each bot instance is isolated to reduce attack surface and limit blast radius in case of incident. Firewalls and automated threat detection systems help mitigate unauthorized access attempts, and all backend services operate over secure, whitelisted channels only.
Users and group admins have full control over the Karma bot’s presence. The bot can be removed at any time, and users can request data removal through direct support or automated in-app flows. All requests undergo identity verification before secure deletion or anonymization is completed. Karma’s data practices comply with GDPR and CCPA principles, offering privacy by design and user autonomy at all times.
With DigitalOcean cloud firewalls, we carefully filter traffic, allowing only whitelisted IP addresses and blocking unauthorized access.
Advanced encryption protocols such as TLS 1.3, X25519 and AES_128_GCM protect your data both in transit and at rest.
Our servers are protected against data loss, with backup plans in place that include hardware RAID and strict backup procedures.
We closely monitor the health of our system, ensuring optimal performance around the clock with DigitalOcean Monitoring.
If you're ready to get started with Karma, sign up now and explore the benefits of the recognition for your team.
Effective date: 18 August 2026
This Privacy Policy explains how Sliday LTD ("Sliday", "we", "us", or "our") collects, uses, shares, and protects personal data. It covers both the Karma application (for Microsoft Teams, Slack, Telegram, and the web) and the https://karmabot.chat website.
The data controller is Sliday LTD, a private limited company registered in Cyprus under company number HE450506, with its principal place of business at Pavlou Valdaseridi 2A, 1st floor, Larnaka, Cyprus, 6018.
For any privacy-related enquiry, or to exercise your data protection rights, contact us at hi@karmabot.chat.
Privacy matters are overseen by our Legal Advisor / Operational Security Manager, Stas Kulesh. A dedicated Data Protection Officer has not been appointed, as Sliday LTD is not required to appoint one under Article 37 of the GDPR; privacy responsibilities are held by the Legal Advisor.
When your organisation installs and uses Karma, we process the following personal data, obtained from Microsoft Teams / Microsoft Entra ID (Azure AD) and from your use of the application:
/me)/me/photo)Where Karma is used with Slack or Telegram, the equivalent identity and workspace data is obtained from that platform instead.
We process personal data to:
We process personal data on the following lawful bases under the GDPR:
Where your organisation is the controller and we act as processor, processing is carried out on your organisation's documented instructions.
We share personal data only with the sub-processors listed below, each of which is necessary to deliver the service and is engaged under an appropriate data processing agreement. This is the complete list of sub-processors with access to personal data. We do not sell personal data.
We do not store or collect your payment card details. That information is provided directly to Stripe, our payment processor, whose use of your personal information is governed by its own privacy policy (https://stripe.com/privacy). Stripe adheres to the standards set by PCI-DSS as managed by the PCI Security Standards Council.
The https://karmabot.chat website additionally uses:
We may also disclose personal data where required to do so by law or in response to a valid request by a public authority, or where necessary to protect our legal rights, prevent or investigate wrongdoing, or protect the safety of users or the public.
Cookies are small pieces of data stored on your device. We use cookies and similar technologies (including beacons, tags, and scripts) to operate the website, remember your preferences, keep the service secure, and understand how the site is used.
The cookies we use fall into these categories:
You can instruct your browser to refuse all cookies or to notify you when a cookie is set. If you refuse cookies, some parts of the website may not function correctly.
We do not currently respond to browser "Do Not Track" (DNT) signals.
We retain personal data for the duration of your organisation's active subscription and for six (6) months after subscription cancellation, after which it is deleted. This applies to customer account and identity data, profile photos, and karma transaction records.
Full details are set out in our Data Retention and Disposal Policy.
Subject to applicable law, you have the right to:
To exercise any of these rights, contact us at hi@karmabot.chat. We may ask you to verify your identity before responding.
To submit a Subject Access Request, contact us at hi@karmabot.chat. We respond to all SARs within one month, as required by the GDPR, unless the request is complex or numerous, in which case we may extend the response time by a further two months and will tell you if we do. We maintain a data mapping process that lets us locate and retrieve all personal data held about a specific data subject across our systems — principally the production database and the profile photo object storage — so that a SAR can be fulfilled thoroughly.
Karma production data is hosted in the United States (DigitalOcean SFO region). As Sliday LTD is established in the EU (Cyprus), this involves a transfer of personal data to a third country.
Such transfers — and transfers to other sub-processors located outside the EU/EEA, including Microsoft, AWS, Cloudflare, Stripe, Sentry, and the analytics providers listed above — are protected by appropriate safeguards, principally the Standard Contractual Clauses (SCCs) incorporated into each sub-processor's Data Processing Agreement, supplemented by those providers' certification frameworks, including the EU–US Data Privacy Framework where the provider participates.
Sliday LTD takes all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.
You have the right to lodge a complaint with a data protection supervisory authority.
Our lead supervisory authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus:
You may also lodge a complaint with the supervisory authority in your own country of residence.
The security of your data is important to us. We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, vulnerability scanning, and error monitoring. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.
Our service is not directed at anyone under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us and we will take steps to remove it.
Our service may contain links to sites we do not operate. We have no control over, and assume no responsibility for, the content or privacy practices of any third-party site. We encourage you to review the privacy policy of every site you visit.
We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the effective date at the top. Where changes are significant, we will notify you by email and/or a prominent notice on our service before the change takes effect. We encourage you to review this policy periodically.
If you have any questions about this Privacy Policy, contact us: