legal · authorities
Law enforcement requests
Purpose
This page is the public protocol for lawful requests from law enforcement and other competent public authorities who need information from Kora. It is published so authorities, users, and payment partners can see how we handle those requests.
Kora is operated by KORA DIGITAL S.R.L., a Romanian limited liability company (CUI 54759299, Trade Register no. J2026034113006). Full company details are on the Imprint. How we process personal data in general is described in our Privacy Policy.
Who may request information
We review requests from law-enforcement agencies, courts, and other public authorities that have a legal power to compel or request information under applicable law (including Romanian law and, where it applies, EU instruments such as a European Investigation Order).
We do not treat informal enquiries, press requests, private investigators, civil litigants, or users asking for another person’s data as law-enforcement requests. Those channels are described at the end of this page.
How to submit a request
Send the request to legal@koraexperiences.com with the subject line “Law enforcement request”. You may also serve process at our registered office:
KORA DIGITAL S.R.L., Attn: Administrator / Legal, Strada Episcopul Chesarie nr. 15, Tronson E, Etaj 4, Ap. 83, Sector 4, București, Romania.
We do not operate a 24/7 law-enforcement hotline. We acknowledge valid requests on business days and aim to reply within two business days. Emergency requests (below) are treated first.
What a request must include
A request should include:
- The name, agency, badge or identification number, official email domain, and contact details of the requesting officer.
- The legal basis for the request (statute, warrant, court order, European Investigation Order, mutual legal assistance, or equivalent).
- A copy of the legal process, unless an applicable emergency exception applies.
- Enough identifying information for us to locate the relevant records (for example an email address, user ID, or booking ID). A name alone is often not enough.
- The specific categories of information sought, the time range, and why the information is needed.
- Any deadline and whether user notice is prohibited, with the legal basis for that prohibition.
We may ask for clarification or additional process before we produce anything. We reject requests that are incomplete, overly broad, or not legally valid.
Legal process we require
We disclose user data to a public authority only where we have a legal obligation or other valid legal basis to do so. We do not provide data in response to informal “fishing” requests, unsigned emails from personal accounts, or demands that are not supported by applicable law.
Where the requesting authority is outside Romania, we generally expect the request to arrive through a recognised cross-border channel (for example a European Investigation Order or mutual legal assistance). We may still acknowledge the request and explain the correct channel.
Emergencies and imminent harm
If there is an imminent risk of death or serious physical harm, mark the email subject “Emergency — imminent harm” and explain the risk, the user or records involved, and why waiting for ordinary process would increase that risk.
We review emergency requests first and may disclose the minimum information needed to address the risk where the law allows. We may still require follow-up legal process. This channel is only for genuine emergencies.
Information we may hold
Depending on the account and the period, we may be able to locate some or all of the following. We only produce what the legal process covers and what we actually have.
- Account. Email address, account identifiers, and account status. Passwords are hashed by our authentication provider; we cannot recover a user’s password.
- Profile. Name, self-declared date of birth, gender and preference fields, photos, bio, and optional lifestyle answers. We confirm age from the date of birth the user entered. We do not run government-ID checks or criminal background checks.
- Activity on the service. Likes and passes, matches, text-only messages, and activity proposals.
- Bookings. Booked activity, counterpart, time, venue snapshot (including address), amount, payment mode, and payment or refund status.
- Payments. Payment and refund records we store. Full card numbers are collected by Stripe; Kora does not see or store them. Card-level data must be requested from Stripe under Stripe’s own process.
- Location. Only if the user allowed it: a single position fix while the app is in use, used to compute approximate distance. We do not keep a continuous location trail.
- Safety reports. Reports a user submitted about another user, and the action we took.
We may not have records if the account was never created, the data was deleted under our retention rules, or the user never used that feature. A fuller description is in the Privacy Policy.
Notice to the user
Unless the law or the legal process forbids it, we may notify the affected user that we received a request for their information, so they can seek legal advice. If notice is prohibited, say so in the request and cite the legal basis. We will not notify where doing so would be unlawful.
Preservation
A competent authority may ask us to preserve specified existing records while legal process is obtained. Send a preservation request to the same address with a clear scope and time range. We will preserve what we reasonably can for a limited period, then delete or release the hold if valid process does not follow.
Requests from outside Romania
Kora is established in Romania. Production of personal data is governed by Romanian and applicable EU law, including the GDPR. Authorities outside Romania should use the appropriate international or EU cooperation mechanism unless a directly applicable legal basis exists.
If you are not a public authority
Users who need to report illegal content or a safety issue should use in-app reporting or write to legal@koraexperiences.com as described in “Reporting illegal content” in our Terms & Conditions and in the Acceptable Use Policy. Privacy requests go to privacy@koraexperiences.com. General support uses support@koraexperiences.com or the contact form.
Contact
Law-enforcement and other competent-authority requests: legal@koraexperiences.com. We aim to acknowledge requests within two business days.