Privacy Policy
Last Updated: April 24, 2026
✓ ODPC Kenya Compliant
This Privacy Policy complies with the Kenya Data Protection Act, 2019 and regulations issued by the Office of the Data Protection Commissioner (ODPC).
1. Introduction
SokoSauti (the legal entity providing the Service, referred to as "SokoSauti," "we," "our," or "us") is the data controller responsible for your personal information under this Privacy Policy. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered marketing platform.
We are committed to complying with applicable data protection laws, including the Kenya Data Protection Act, 2019, and other relevant international privacy regulations. By using our Service, you consent to the data practices described in this policy.
2a. Legal Basis for Processing
We rely on the following legal bases to process your personal information:
- Performance of a contract: Creating and managing your account, providing the Service, and delivering the features included in your subscription.
- Legitimate interests: Securing the Service against fraud and abuse, troubleshooting, analytics on aggregated usage, and improving our products. We balance these interests against your rights and freedoms.
- Consent: Optional marketing communications from us, non-essential cookies, and any sensitive data you choose to share. You may withdraw consent at any time.
- Legal obligation: Tax, accounting, and regulatory record-keeping (including ODPC obligations), responding to lawful requests from authorities, and meeting our obligations under the Kenya Data Protection Act, 2019.
2. Information We Collect
2.1 Information You Provide
We collect information you voluntarily provide, including:
- Account Information: Name, email address, phone number, business name, and password
- Business Information: Business category, location, website, and description
- Payment Information: M-Pesa details, transaction history, and billing information
- Customer Data: Information about your customers that you upload or input into the Service
- Marketing Content: Ad copy, images, brand assets, and campaign data you create
- Communication Data: Messages, support requests, and feedback you send us
2.2 Information Collected Automatically
When you use our Service, we automatically collect:
- Device Information: IP address, browser type, operating system, and device identifiers
- Usage Data: Pages visited, features used, time spent, and interaction patterns
- Analytics Data: Performance metrics, error logs, and diagnostic information
- Cookies and Tracking: Session cookies, authentication tokens, and similar technologies
2.3 Third-Party Integrations
When you connect third-party services (e.g., M-Pesa, social media platforms, ad platforms), we may receive data from those services as authorized by you. We only access the minimum data necessary to provide the requested functionality.
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve our Service
- Process transactions and manage your subscription
- Generate AI-powered marketing content and recommendations
- Send service-related communications and updates
- Analyze usage patterns to enhance user experience
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations and enforce our Terms of Service
- Train and improve our AI models using anonymized, aggregated data
4. Data Protection and Security
4.1 Security Measures
We implement industry-standard security measures to protect your data, including:
- Encryption: All data is encrypted in transit (TLS/SSL) and at rest (AES-256)
- Access Controls: Role-based access control and Row Level Security (RLS) policies
- Authentication: Secure password hashing and session management
- Monitoring: Security audit logs and anomaly detection systems
- Credential Protection: API keys and sensitive credentials are encrypted and stored securely in our vault
4.2 Data Minimization
We only collect and retain data that is necessary for the purposes described in this policy. We regularly review and delete unnecessary data in accordance with our data retention policies.
4.3 Incident Response
In the event of a data breach, we will notify affected users and relevant authorities within 72 hours as required by applicable law, and take immediate steps to mitigate any harm.
5. Data Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
- Payment Processors (Paystack & M-Pesa): We use Paystack and Safaricom M-Pesa to process subscription and one-time payments. Billing-related personal data (such as name, email, phone number, and payment instrument details) is collected and processed by these providers as separate data controllers under their respective privacy notices.
- Service Providers / Subprocessors: Trusted third-party vendors that help us operate the Service, including cloud hosting and database (Lovable Cloud / Supabase), AI model providers, email and SMS delivery providers (e.g., Sent.dm), and analytics tooling.
- Professional advisers: Legal, accounting, and tax advisers, where strictly necessary.
- Legal Requirements: When required by law, court order, or governmental authority
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: When you explicitly authorize us to share your information
- Aggregated Data: Anonymous, aggregated data that cannot identify individuals may be shared for research or marketing purposes
6. Your Rights
Under the Kenya Data Protection Act and other applicable laws, you have the following rights:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data (subject to legal exceptions)
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to processing of your data for certain purposes
- Restriction: Request limitation of processing in certain circumstances
- Withdrawal of Consent: Withdraw consent at any time where processing is based on consent
To exercise these rights, please contact us at privacy@sokosauti.com. We will respond to your request within 30 days.
7. Customer Data & Marketing Consent (ODPC Compliance)
When you upload customer data to our Service, you act as the data controller for that data, and we act as a data processor. You are responsible for:
- Ensuring you have lawful grounds to collect and share your customers' data with us
- Providing appropriate privacy notices to your customers
- Responding to your customers' data rights requests
- Complying with applicable data protection laws regarding your customers' data
7.1 Marketing Consent Requirements
IMPORTANT: Under the Kenya Data Protection Act and ODPC guidelines, marketing consent is separate from transactional consent. This means:
- Payment Consent ≠ Marketing Consent: Collecting a customer's phone number for M-Pesa payment does NOT authorize you to send promotional SMS messages
- Explicit Opt-In Required: You must obtain explicit, informed consent before sending any marketing communications
- Purpose Limitation: Data collected for one purpose cannot be used for another without separate consent
- Easy Opt-Out: Every marketing message must include a clear way to unsubscribe (e.g., "Reply STOP to unsubscribe")
7.2 Consent Management in SokoSauti
SokoSauti provides built-in consent management tools to help you comply with ODPC requirements:
- Consent Records: We maintain timestamped, append-only records of all marketing consent for audit purposes
- Pre-Send Verification: Our SMS and Email campaign tools verify consent before sending messages
- Automatic Opt-Out: We process STOP/UNSUBSCRIBE requests automatically and immediately
- Audit Trails: Complete logs of all campaigns including consent verification and delivery status
7.3 ODPC Enforcement Reference
⚠️ Warning: ODPC Fines for Non-Compliance
The ODPC has issued significant fines for marketing without consent:
- • Platinum Credit: KES 400,000 for unsolicited SMS marketing
- • Pepinos Pizza: KES 250,000 for using payment data for marketing
SokoSauti's consent management system is designed to help you avoid such penalties.
8. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Essential Cookies: Enable core functionality and security features
- Analytics Cookies: Understand how users interact with our Service
- Preference Cookies: Remember your settings and preferences
You can control cookie preferences through your browser settings. Note that disabling certain cookies may limit functionality of the Service.
9. Data Retention
We retain your personal data for as long as necessary to provide our Service and fulfill the purposes described in this policy. Specifically:
- Account Data: Retained until you delete your account, plus a reasonable period for backup and compliance
- Transaction Data: Retained for 7 years as required by financial regulations
- Analytics Data: Retained in aggregated, anonymized form indefinitely
- Security Logs: Retained for 2 years for security and compliance purposes
10. International Data Transfers
Our Service is hosted on secure cloud infrastructure. Your data may be processed in countries outside Kenya. When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by relevant authorities
- Data processing agreements with all third-party providers
- Verification that recipient countries provide adequate data protection
11. Children's Privacy
Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@sokosauti.com.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last Updated" date. We encourage you to review this policy periodically.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact our Data Protection Officer:
SokoSauti (legal entity) — Data Protection
Email: privacy@sokosauti.com
General Support: wambani@sokosauti.com
Location: Nairobi, Kenya
You also have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya if you believe your data protection rights have been violated.
