New

Now in Claude, ChatGPT, Cursor & more with our MCP server

Back to Koji
Koji Compliance

Compliance contacts

Five email addresses cover every compliance question. Each is monitored by the responsible team and acknowledged within one business day.

Last updated: May 2026Applies to: All compliance, security, and privacy inquiries

Email addresses

Security questionnaires, suspected incidents, vulnerability reports, technical security architecture questions.

  • Send a completed CAIQ or SIG questionnaire
  • Report a suspected security incident
  • Submit a vulnerability disclosure
  • Request the latest pen-test summary under NDA

Legal & compliance

[email protected]

DPA, BAA, MSA negotiation, sub-processor change subscription, contract questions, audit requests.

  • Request a counter-signed DPA
  • Request a Business Associate Agreement (BAA)
  • Subscribe to sub-processor change notifications
  • Request the SOC 2 report when available

Privacy & data protection

[email protected]

Data-subject rights requests, privacy policy questions, GDPR / CCPA inquiries, data-protection-officer contact.

  • Exercise GDPR rights (access, erasure, portability)
  • Exercise CCPA / CPRA consumer rights
  • Ask a question about the privacy notice
  • Report a privacy concern

Vulnerability disclosure

[email protected]

Responsible disclosure of security vulnerabilities. See the dedicated policy for scope and safe harbor.

  • Report a security finding
  • Request our PGP key for encrypted submission
  • Ask about scope or coordinated disclosure timing

Accessibility

[email protected]

Reports of accessibility issues, requests for our Voluntary Product Accessibility Template (VPAT), questions about conformance.

  • Report an accessibility barrier
  • Request the VPAT
  • Ask about screen-reader or keyboard support

Postal address

Koji B.V.

Registered in the Netherlands

For a postal correspondence address, contact [email protected].

Response times

  • Acknowledgement: within one business day for all addresses above.
  • Standard responses (DPA counter-signature, standard questionnaire responses, sub-processor subscriptions): within two business days.
  • Custom questionnaires and bespoke document requests: within five business days.
  • Suspected incidents: acknowledged within one hour during business hours, four hours otherwise.

Privacy of your correspondence

Emails sent to the addresses above are handled by Koji personnel under confidentiality obligations. We retain correspondence as required by law and to support the legitimate interest of resolving and tracking compliance inquiries.

Questions about this document? Contact compliance.Back to compliance hub