Logo
FeaturesPricing
Log InStart Now
Solutions
StoreChama
FeaturesPricing
x.com
A product of 2labs
Privacy PolicyTerms of Service
© Sokili 2025

Privacy Policy

Last Updated: November 6, 2025

1. Introduction

Welcome to Sokili. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our AI-powered WhatsApp business management services. By using Sokili, you consent to the data practices described in this policy.

Sokili is committed to protecting your privacy and complying with applicable data protection laws, including the Kenya Data Protection Act (2019) and the European Union General Data Protection Regulation (GDPR).

Data Controller: Ted Too (Sole Proprietorship)
Contact: [email protected]
Data Protection Officer: [email protected]

2. Information We Collect

2.1 Information You Provide

We collect information you directly provide when setting up and using our service:

  • Account Information: Phone number, name, business name, and business details
  • Transaction Data: M-Pesa transaction references, payment amounts, customer payment details
  • Message Content: WhatsApp messages related to transactions and customer purchase inquiries (in Store mode)
  • Business Configuration: Inventory details, pricing information, and business settings

2.2 Information We Collect Automatically

  • Usage Data: Service interactions, feature usage, and system logs collected via PostHog analytics
  • Device Information: Browser type, IP address, and device identifiers

3. How We Use Your Information

We use your personal information for the following purposes:

  • Service Delivery: To operate the AI agent, respond to customer messages, track transactions, and generate reconciliation reports
  • AI Processing: To process your messages through our AI providers (OpenAI, Anthropic Claude, and Google Gemini) to deliver intelligent, context-aware responses
  • Payment Management: To track payment references and send payment reminders
  • Service Improvement: To analyze usage patterns and improve our service quality
  • Communication: To send service updates, notifications, and respond to your inquiries
  • Legal Compliance: To comply with applicable laws and regulations

4. Data Storage and Security

4.1 Where We Store Your Data

Your data is stored on secure cloud infrastructure provided by Netcup in Nuremberg, Germany (European Union). We maintain encrypted backups in secure cloud storage to ensure data durability and disaster recovery.

4.2 Data Retention

We retain your personal information until you delete your account or request data deletion, unless a longer retention period is required by law. Upon account deletion, your data will be permanently removed from our systems within 30 days.

4.3 Security Measures

We implement industry-standard security measures to protect your data:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure authentication and access controls
  • Regular security audits and monitoring
  • Secure API key and credential management

In the event of a data breach, we will notify affected users as soon as possible and take immediate action to mitigate any harm.

5. Data Sharing and Third-Party Services

5.1 AI Service Providers

To deliver our AI-powered features, we share your message content and business data with the following AI providers:

  • OpenAI (ChatGPT/GPT models)
  • Anthropic (Claude)
  • Google (Gemini)

These providers have data processing agreements in place and process your data solely to provide AI services to Sokili. They do not use your data to train their models without consent.

5.2 WhatsApp Business API

We use the official WhatsApp Business API (provided by Meta) to send and receive messages. Your use of Sokili is subject to Meta's Terms of Service and WhatsApp's Privacy Policy.

5.3 Analytics

We use PostHog for product analytics to understand how users interact with our service and improve user experience. PostHog collects anonymized usage data.

5.4 We Do Not Sell Your Data

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

6. Your Data Rights

Under the Kenya Data Protection Act and GDPR (where applicable), you have the following rights:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing of your data
  • Right to Withdraw Consent: Withdraw consent at any time

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 5 business days.

You can delete your account at any time directly from your dashboard, which will permanently remove your data from our systems.

7. Cookies and Tracking

We use cookies and similar tracking technologies to improve your experience on our website. These include:

  • Essential Cookies: Required for basic site functionality
  • Analytics Cookies: PostHog analytics to understand usage patterns

You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features.

8. International Data Transfers

While Sokili primarily serves users in Kenya, your data is stored in the European Union (Germany). By using our service, you consent to the transfer and processing of your data in the EU, which provides a high level of data protection under GDPR.

Data shared with AI providers (OpenAI, Anthropic, Google) may be processed in various jurisdictions where these providers operate. We ensure that all third-party processors have appropriate data protection measures in place.

9. Children's Privacy

Sokili is intended for business use. While we do not have specific age restrictions, we do not knowingly collect personal information from individuals under the age of 18 without parental consent. If you believe a minor has provided us with personal information, please contact us at [email protected].

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes via WhatsApp or email. Your continued use of Sokili after such changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

  • General Inquiries: [email protected]
  • Data Protection: [email protected]

12. Complaints and Regulatory Authority

If you believe your data rights have been violated, you have the right to lodge a complaint with the relevant data protection authority:

  • Kenya: Office of the Data Protection Commissioner (ODPC)
  • EU: Your local data protection supervisory authority