1. What this policy covers
This policy covers kohasolutions.com, myopac.com and the Koha Cloud platform, the Koha Certificate training portal, and the enquiry, quotation and enrolment forms on those sites. It does not cover a library’s own website or any third-party site we link to.
2. The two roles we play — and why the difference matters to you
Almost every complaint about a hosted library system comes from confusing these two roles, so they are the first thing in this policy rather than a clause near the end.
- For our own visitors, customers and trainees we are the controller. We decide what to collect from someone who fills in a quotation form or enrols on the course, and this policy is the answer for what happens to it.
- For the data inside a library’s catalogue we are only the processor. Patron records, loans, holds, fines and reading history belong to the library. The library decides what is collected, how long it is kept and who may see it; we hold it and act on that library’s instructions.
If you are a library member asking about your own borrowing record, contact your library — not us. They control that record, and we are not permitted to disclose or change it on your say-so. We will always help your library answer you.
3. What we collect, and why
| Who | What | Why |
|---|---|---|
| Site visitors | Pages viewed, the site that referred you, campaign parameters in the link you arrived on, an irreversible hash of your IP address, a short-lived random visit identifier, and whether the request looked automated. | To understand which pages answer real questions and which fail, and to keep the sites secure. This is our own measurement — see section 5. |
| People who contact us | Name, institution, email address, phone number if given, and whatever you write in the message or quotation request. | To answer you, prepare a quotation, and keep a record of what was agreed. |
| Trainees | Enrolment details, contact details, invoice and payment references, attendance, assignment results and course progress. | To run the course, issue invoices and certificates, and prove completion later if you need us to. |
| Library staff accounts | Name, email, role, password stored only as a hash, two-factor secret if enabled, and an audit record of the actions taken from the account. | To authenticate the right people and let a library see who changed what in its own system. |
| Hosted catalogue data | Whatever the library holds — bibliographic records, holdings, patron records, loans, holds, fines, notices. | To provide the catalogue and circulation service to that library. We are the processor here, not the controller. |
| Support access records | Which of our staff opened access to a library’s system, when, why, and when it ended. | So a library can see every occasion we were inside its data, and revoke it. |
We do not buy personal data, we do not sell it, and we do not build advertising profiles. We do not ask for special-category data about anyone, and we ask you not to send it to us through a contact form.
4. The grounds we rely on
- Performing a contract — running a hosted catalogue, delivering a course, doing quoted work, invoicing for it.
- Legitimate interests — answering an enquiry, keeping the platform secure, understanding how our own website performs, and keeping records of what was agreed. We use the least data that achieves it.
- Consent — marketing email, which you opt into and can leave at any time from a link in the message.
- Legal obligation — accounting and tax records, and responding to a lawful request we are actually required to comply with.
5. Website measurement — no third-party trackers
Our sites carry no Google Analytics, no advertising pixel, no social-network tracker and no third-party tag manager. Nothing loads a script from another company to watch you.
What we do run is our own measurement, built into the platform, designed to answer "which pages help" without identifying anybody:
- Your IP address is never stored. It is hashed with a salt that changes daily and truncated, which lets us count a visitor twice in a day without being able to recognise them tomorrow.
- Only the host of the referring site is kept, never the full referring URL.
- Campaign parameters from the link you clicked are kept, but anything that looks like a credential — tokens, keys, codes, email addresses — is discarded before storage.
- The path you visited is stored without its query string.
- The visit identifier is a random first-party value, not a fingerprint of your device.
8. Where data is stored
We serve libraries on every continent, so data may be stored or processed in a country other than yours. Where your institution requires a particular location or a specific safeguard for transfers, tell us before an engagement starts — it is a normal requirement and we would rather design for it than discover it later.
9. How long we keep things
- Enquiries and quotations: kept while the conversation is live and for a reasonable period afterwards, so we can pick it up if you come back.
- Customer and trainee records: for the engagement, then as long as accounting and certification records require.
- Catalogue and patron data: for as long as the library asks us to hold it. Deletion inside the catalogue is the library’s decision to make, and its own retention policy governs.
- Audit and security logs: kept long enough to investigate an incident, then aged out.
- Measurement data: kept in aggregate; the parts that could relate to a single visit are short-lived by design.
- Backups: kept on a rotation and then overwritten. Deleting something from the live system does not instantly erase it from a backup, but that copy stays protected and expires on the rotation.
10. How it is protected
Some of these are ordinary and expected; the last two are the ones worth reading, because they are where hosted systems usually leak.
- Traffic is encrypted in transit, including on a library’s own domain name.
- Passwords are stored only as hashes and are never recoverable — a reset issues a new one.
- Two-factor authentication is available for staff and administrator accounts.
- Every library’s data is separated at the database level, and every query is scoped to the library it belongs to. One library cannot see another’s records.
- Our own staff have no standing access to your data. Reaching a library’s system requires a time-boxed grant that is re-authenticated at the moment it is opened, is recorded against the individual who opened it in that library’s own audit log, emails the library when it starts, and can be revoked by the library at any time — after which the session ends on the next request.
- Actions taken in a library’s system are written to an audit log the library itself can read.
No system is perfectly secure. If a breach affects your data, we will tell you what happened, what it affected and what we did, within the time any applicable law requires and as soon as we reasonably can regardless.
11. Automated and AI-assisted features
The platform includes features that suggest rather than decide — assisted cataloguing, search that understands a phrase rather than a keyword, and recommendations. They operate on catalogue metadata about books, not on profiles of people, and a member of staff always confirms the result.
We do not use one library’s patron data to build features for another, and we do not hand your data to a third party to train their models. No decision with a legal or similarly significant effect on a person is made automatically.
12. Your rights
Depending on where you are, you may have the right to ask for a copy of your personal data, to have it corrected, to have it deleted, to restrict or object to how it is used, to receive it in a portable form, and to withdraw consent you have given. We honour these requests wherever we are the controller.
- Ask through the contact page. We may need to verify who you are before we act — that check protects you.
- We answer within one month, and tell you if a request is genuinely complex enough to need longer.
- If your request concerns a library’s catalogue record about you, we will pass it to that library, because they are the controller for it.
- If you are unhappy with our answer, you may complain to the data protection authority for your country.
13. Children
Our website, our course and our sales process are aimed at institutions and adults, and we do not knowingly collect data from children through them. A school or public library’s catalogue may of course contain records about young members; that data belongs to the library, is governed by its own policy and safeguarding rules, and is held by us only on its behalf.
14. Changes to this policy
When what we do changes, this page changes with it, and the revision date at the top moves. A change that materially affects how we handle a customer’s data is notified directly rather than published quietly.
15. Contact us about privacy
Write to us through the contact page and mark it for the attention of privacy. Questions are welcome even when they are not formal requests — if a clause here is unclear, that is a fault in the clause.

