sokkosai
We host it Your agent on our server — live in minutes Install package We install on a device or VPS you provide Dedicated hosting Managed single-tenant hosting — by quote Custom project Anything irregular — brief me, quote in 24h on business days Care & maintenance We watch it, fix it, add skills on request
More from SoKKoS
Plotmosa ↗ Sketch → render for landscapers CBR-theorie ↗ Dutch driving theory — car and motorcycle nl-learning ↗ Dutch phrases, quiz and an AI tutor
How it works Examples Pricing FAQ
English EN Nederlands NL Polski PL Français FR Deutsch DE Español ES Italiano IT Русский RU Українська UK Português PT Magyar HU Română RO Svenska SV Norsk NO
Sign in Start free Open your agent →
Open your agent Overview Billing Settings Change password ⚙ Admin
Solutions
We host itInstall packageDedicated hostingCustom projectCare & maintenance
How it works Examples Pricing FAQ Sign in Start free
More from SoKKoS
Plotmosa ↗CBR-theorie ↗nl-learning ↗
Legal · GDPR · last updated 2026-08-03

Privacy Policy

What we collect, what we never collect, and who else touches your data. We deliberately keep the surface small — no analytics profiles, and passwords are only ever stored as a one-way hash. One exception worth naming up front: if you call our published number, a short note is kept against your number for up to 30 days (see “If you call our number” below) — the site's forms still have no phone field.

On this page
1. Who we are2. What we collect2a. Privacy-first measurement3. What we never collect4. Sub-processors5. Cookies6. Your rights (GDPR)7. Retention periods8. International transfers9. Security10. Children11. Contact

1. Who we are

SoKKoS AI — eenmanszaak (sole proprietorship in the Netherlands), KvK 42029374, BTW-id NL005441743B74, Beuningen, Gelderland, NL. Contact: [email protected]. We're the data controller for everything described below.

2. What we collect

The smallest amount that lets us run an agent for you and send you a receipt.

  • Withdrawal or cancellation declarations — if you use the withdrawal form or the cancellation page, we record the email address you gave, any contract reference and note, and the date and time your declaration reached us. We need this to act on it, and the law requires us to confirm receipt to you stating exactly that content and that timestamp — so the record is also our proof that we did. Legal basis: performance of the contract and our legal obligation.
  • Email address — required for authentication (magic-link, email + password, or Google OAuth) and billing notifications. Stored in Azure Table Storage (West Europe).
  • Password — only if you set one. If you choose email + password sign-in, we store your password solely as a salted bcrypt one-way hash (cost factor 12). Your plaintext password travels over TLS each time you set, change, reset or sign in with it, is processed in memory only to hash or verify, and is never stored or logged; we can't recover it — a reset issues a new single-use link. Magic-link and Google sign-in remain available if you prefer no password at all.
  • Telegram chat / user ID and bot token — only if you link Telegram (e.g. to reach support via @sokkosai_bot or to run your agent's own Telegram bot). If you connect your own bot, its bot token is stored encrypted at rest (shown to you only as “set”, never displayed again) so your agent can send on your behalf. Used to route messages. Clearing the token removes it from storage; a running agent may keep using its current token until its next restart, when the disconnect takes effect.
  • Google profile basics (name, picture) — only if you choose “Sign in with Google”. Used to greet you in the dashboard. Disconnect any time and we delete the cached copy.
  • LinkedIn publisher data — operator account only. Our internal admin publisher stores the LinkedIn member/Page identifier, granted scopes, token expiry and OAuth access/refresh tokens needed to publish SoKKoS posts. Tokens are encrypted before storage and never shown in the browser or logs. This integration is not offered to customer accounts; disconnecting it deletes the stored authorization.
  • IP address — logged for rate-limiting and fraud prevention. Rate-limit counters are keyed to short time windows and are not used once their window passes; the IP recorded at signup stays with your account record and is deleted with your account.
  • Payment metadata — transaction IDs, amount, currency, method (SEPA / iDEAL / card / PayPal). Processed by Mollie B.V. in Amsterdam. We never see your card number or bank credentials — only the receipt.
  • Server logs — request paths, response codes, timing. No request bodies. Retained 30 days for debugging, then rotated.
  • “Report a problem” submissions — only if you use the bug-report button: your description, the page URL, and the most recent browser console logs (with API keys and tokens automatically masked) so we can debug the issue.
  • Chat messages that show contact intent — if a message shows you want a human to follow up (you include an email or phone number, or ask about pricing / setup) we forward that message to our internal Telegram working channel — access limited to Konstantin — along with which part of the site you were chatting from, so we can follow up if you left us a way to. Your IP address is not included. Nothing is sent for ordinary questions, and repeats are rate-limited. Telegram processes it outside the EU (§8).
  • The chat conversation itself — since 7 August 2026 we keep what you write to the site assistant, and what it answers, for up to 30 days, so a real person can read what people actually ask and fix bad answers. Kept against your account if you are signed in, otherwise against the first-party cookie described below; your IP address, browser and ad identifiers are not part of it. Once the window closes the turns are deleted from our storage by a scheduled job, not merely hidden — and you can ask us to erase yours sooner (§6). Please do not type card numbers or passwords into the chat; you never need to.
  • A short note, so the assistant remembers you next time — separately from the turns above. After a real exchange (roughly four messages or more) the assistant writes a few sentences summarising what you were after, and keeps that — not the messages — for up to 30 days after your last visit, so you do not start from scratch if you come back. Each new conversation rewrites the note rather than adding to it, so it stays a few sentences however often you visit. If you stop coming back it lapses on its own, and is deleted from our storage, not merely hidden.

    If you are signed in, the note is kept against your account. If you are not, it is kept against a small first-party cookie that identifies the browser — not you. Because a browser can be shared, in that case the assistant uses the note quietly for context and will never claim to recognise you. Sign in later and the two are joined up, so you are one conversation rather than two. We do not use your IP address to recognise you: one address can be a household, an office, or a mobile network's whole pool of customers, so it cannot tell people apart, and we only use it to rate-limit abuse.

    Legal basis: our legitimate interest in giving continuous, useful answers to someone who contacted us (GDPR Art. 6(1)(f)). The note is used for nothing else, shared with no one, and never used to train models. You can have it deleted at any time — ask by email or WhatsApp, no reason needed.

2a. Privacy-first measurement

We measure how the site is doing — which pages people open, when a buy button is clicked — with a small, first-party setup that stays entirely on our own infrastructure: no Google Analytics, no Hotjar, no advertising or cross-site trackers (see §3 and §5). Two narrow additions to that baseline: Cloudflare Web Analytics — a cookieless, aggregate traffic beacon served by Cloudflare, the CDN already in front of this site (§4); it sets no cookies, stores nothing on your device and builds no visitor profiles — and the Meta Pixel, which loads only after you explicitly opt in via the cookie banner (see the third item below).

  • Anonymous funnel events. When you open the “payment opening soon” popup or click a buy / register button, your browser sends us a tiny event — the event name, the package it referred to, and the page path. We store these in our own Azure database. No IP address, no email, no name, no cookie, and no raw browser fingerprint are attached — we keep only a coarse, one-way hash of the browser type so we can tell humans from bots in aggregate.
  • Advertising click-ids. If you reach us from an online ad, the link may carry a Google click identifier (gclid) or a Meta click identifier (fbclid) and campaign tags (utm_*). We keep these in your browser's local storage (first-party, up to 90 days) so that, if you later sign up or send a brief, we can tell which ad worked. We do not share this data with third parties for their own purposes; we only use it ourselves, and — if you convert — may upload the click-id back to the ad platform it came from (Google Ads or Meta) to mark that one conversion (“offline / enhanced conversions”). You can clear it any time by clearing site data in your browser.
  • Meta Pixel — opt-in only. To measure how well our ads on Meta platforms (Facebook / Instagram) perform and to build ad audiences, the site may load the Meta Pixel, a measurement script from Meta Platforms Ireland Ltd. It loads strictly after you click “Accept” in the cookie banner. If you decline — or simply ignore the banner — no pixel code runs and no request to Meta is made. You can withdraw consent at any time via the “Cookie preferences” link in the footer; the pixel then stops loading from your next page view. How Meta handles this data: facebook.com/privacy/policy.

The first-party measurement needs no cookie banner: the funnel events are anonymous and the click-id is stored only when you arrived from an ad you already clicked. The Meta Pixel is exactly why the banner exists — it never runs unless you've agreed. If you prefer not to be measured at all, decline the banner and browse with local storage disabled — the site works exactly the same.

3. What we never collect

  • Plaintext passwords. If you set a password we keep only a salted bcrypt hash (see §2); the plaintext is never stored, logged or recoverable. You can also sign in with a magic link or Google and set no password at all.
  • Your AI API keys in plaintext. Your model-provider keys (Google Gemini, OpenAI, Anthropic, OpenRouter, Groq and others) are encrypted before they are stored (EU Azure storage) and decrypted server-side only to inject into your container's environment (at launch, and when you apply or rotate keys). They are never logged, never shared with third parties, and deleted with your account.
  • Audio recordings. Whether you use the voice agent on this site or call our published number, the audio itself is streamed to the model provider in real time and discarded immediately after the response. We keep no audio files. We do, however, keep a written transcript and a short note — see “If you call our number, or use the voice agent” below, because that is the part people usually mean when they ask what we store.

If you call our number, or use the voice agent

The phone number published on this site is answered by an AI voice agent, not by a person. The voice orb on the homepage is the same kind of agent. In both cases, this is what actually happens to your data — stated plainly, because “we don't record calls” on its own would give you the wrong idea:

  • No audio is stored. Nothing is written to disk as sound.
  • A written transcript of the conversation is produced and sent to our internal Telegram working channel — access limited to Konstantin (the operator) — so a request made by voice does not get lost. For the site's voice orb, the server-side session record behind it is kept for at most 90 days (in practice usually much shorter — it is cleared by routine service updates); phone calls keep no server-side transcript at all — only that channel's copy of the report. Either is deleted on request, any time.
  • For phone calls, a short note is kept against your phone number — a few sentences summarising what you wanted — for up to 30 days after your last call, so the agent has context if you call back. If you keep calling, the note keeps being refreshed; if you stop, it lapses on its own. It is used for nothing else and shared with no one.
  • You can have it deleted at any time. Ask on WhatsApp or by email and it is removed — you do not have to give a reason.

Legal basis: our legitimate interest in answering and following up on enquiries (GDPR Art. 6(1)(f)). You are told at the start of the call that you are speaking to an AI and that a short note is kept, which is also what the EU AI Act requires.

  • Tracking / analytics cookies — none without consent. No Google Analytics, no Hotjar, no analytics cookie of our own. The only third-party measurement script we use at all is the Meta Pixel, and it loads strictly after you opt in via the cookie banner (§2a) — decline or ignore the banner and nothing fires. Our baseline measurement is the first-party, cookieless setup described in §2a. See §5.
  • Phone numbers you type into this site. There is no phone field in any form here. (Separately: if you call our published number, that call is handled by an AI voice agent — see "If you call our number" below.)

4. Sub-processors

To run the service we rely on a small set of named processors. Each has its own privacy policy you can read.

  • Google LLC — Sign in with Google (OAuth) & Gemini API. policies.google.com/privacy
  • LinkedIn Corporation — operator-only OAuth and publication of SoKKoS posts to our personal profile and company Page. LinkedIn receives only the post and destination chosen by the operator. linkedin.com/legal/privacy-policy
  • Your chosen model provider(s) — when you connect a BYO API key (e.g. OpenAI, Anthropic, OpenRouter, Groq, NVIDIA, DeepSeek, or a custom OpenAI-compatible endpoint), your agent sends prompts directly to that provider under your own account and the provider's terms. You choose this processor; disconnect its key to stop the flow.
  • Mollie B.V. (Amsterdam, NL) — payment processing. mollie.com/privacy
  • Resend — transactional email (magic-link, billing receipts). resend.com/legal/privacy-policy
  • Microsoft Azure — hosting for the public site and customer database (region: West Europe / Sweden Central).
  • Microsoft Azure OpenAI — the model behind our own chat, the voice orb and the phone line, and behind the agent we host for you when you have not connected your own model key. In that case the text of your prompts and your agent's replies is processed on our account. Our Azure resource is in the EU (Sweden Central) and holds data at rest there, but the deployments run on Azure's global standard tier, so the inference itself may be performed in a Microsoft datacentre outside the EU. We would rather tell you that than imply a guarantee our configuration does not give. Connect your own model key and your prompts go to your provider instead — but if your agent started without a key, our included endpoint stays configured for its memory search (embeddings) until you ask us to remove it.
  • Simyo and Zadarma — only if you call our published phone number. That number is a Dutch mobile line (Simyo), and a call to it is forwarded to our telephony provider (Zadarma) before it reaches the AI. Both carriers see your number and the call audio, as any carrier does — we name both because the chain, not just its last link, is what your call actually crosses. zadarma.com/legal/privacy
  • Cloudflare, Inc. — DNS, edge proxy, DDoS mitigation.
  • Hetzner Online GmbH — per-customer VPS hosting (region: Germany or Finland, your choice or auto-selected by proximity).
  • Telegram FZ-LLC — in three cases. If you link Telegram: support chat via @sokkosai_bot and/or your agent's own Telegram bot. And, whether or not you link anything, if a message you send our website chat shows you want a human to follow up (see §2) — that message is forwarded to our internal Telegram working channel (access limited to Konstantin) so we can reply. telegram.org/privacy

If we add or change a sub-processor that materially affects what data is processed, we'll update this page and notify active customers by email at least 30 days before the change takes effect (see Terms §11).

5. Cookies

Consent-free, we set three first-party cookies — all functional (Art. 5(3) ePrivacy exemption: strictly necessary, or explicitly requested by you):

  • sokkosai_session (HttpOnly, Secure, SameSite=None, Domain=.sokkosai.com so it works across our subdomains) — keeps you signed in. Lifetime: 90 days, sliding window.
  • lang — remembers the site language you pick in the language switcher. Lifetime: 1 year.
  • sokkosai_device — a random identifier that lets the site assistant pick up where a conversation left off (§2). Set only after you start a conversation, never on an ordinary visit, and used for nothing else — no analytics, no advertising, no tracking across other sites. Lifetime: 30 days, matching how long the note itself is kept.

With your consent only: if you click “Accept” in the cookie banner, the Meta Pixel (§2a) may set its own cookies (such as _fbp) for ad measurement. If you decline or ignore the banner, no Meta cookie is ever set. You can withdraw consent at any time via the “Cookie preferences” link in the footer.

No analytics cookies of our own. No advertising cookies without opt-in. The first-party ad click-id from §2a lives in your browser's local storage, not a cookie. The cookie banner exists for exactly one thing — the opt-in Meta Pixel; everything else on this site works without it.

6. Your rights (GDPR Articles 15–22)

If you're in the EU/EEA, you have the right to:

  • Access — ask what data we hold about you.
  • Rectify — correct anything that's wrong.
  • Erase (“right to be forgotten”) — delete your account and associated data.
  • Restrict — pause processing while a question is unresolved.
  • Port — receive a machine-readable copy of your data.
  • Object — object to processing based on legitimate interest.

Most of these are self-service in your dashboard. For anything that isn't, email [email protected] and we'll respond within 30 days. See the GDPR rights page for the exact request format and how each right maps to a self-service action.

7. Retention periods

  • Account record — until you delete your account.
  • Session cookie — 90 days, sliding (resets on each visit).
  • Magic-link & password-reset tokens — single-use, and rejected once used or after 15 minutes.
  • LinkedIn OAuth tokens — until the operator disconnects or replaces the authorization. Expired tokens remain encrypted only so the console can report connection status and cannot be used without reauthorization; publisher drafts and delivery receipts remain in the internal queue until administratively removed.
  • Payment records — 7 years (mandatory under Dutch tax law, Art. 52 AWR).
  • Server logs — 30 days raw, then aggregated.
  • IP addresses — the signup IP is kept with the account record and deleted with the account; rate-limit counters only serve their short time window.
  • Anonymous funnel events & ad click-ids (§2a) — up to 12 months, then deleted or aggregated. The click-id (gclid / fbclid) in your browser's local storage expires after 90 days.
  • Cookie-consent choice (§5) — kept in your browser's local storage until you change it via “Cookie preferences” or clear site data.
  • Site-chat conversation — what you typed and what the assistant answered, up to 30 days from the message, then deleted by a scheduled job (§2). Erased earlier on request, and with your account if you delete it.
  • Site-assistant note — a few sentences summarising what you were after, 30 days sliding from your last visit, then deleted from storage. Kept against your account if you are signed in, otherwise against a first-party cookie identifying the browser. The conversation itself is kept separately for 30 days (see §2).
  • A chat message forwarded to our internal Telegram working channel (§2, access limited to Konstantin) — we do not delete it on a schedule: it is how we know to reply to you. Ask us to remove it (“GDPR: erase”) and we do, within 30 days.
  • Voice-conversation records — phone: a short note against the caller's number, 30 days sliding from the last call, no server-side transcript; site voice orb: server-side session record (transcript + technical metadata) at most 90 days, in practice cleared sooner by service updates. That channel's report copy is removed on request.
  • VPS container after cancellation — 14 days grace, then destroyed (see Terms §7).
  • Withdrawal and cancellation declarations — what you sent through the withdrawal form or the cancellation page: your email address, any contract reference and note, and the date and time it reached us. Kept 7 years, because a declaration that ends a paid contract is part of the accounting record we are required to keep (Art. 52 AWR) — and because it is the evidence that we confirmed receipt to you as the law requires. A weekly job deletes them once that period is over — the period is not a statement of intent, it is what the job runs on.

8. International transfers

Your SoKKoS-hosted data at rest — your agent's environment, config, logs, integrations and key management — is stored inside the EU/EEA: Azure (West Europe / Sweden Central), Hetzner (Germany / Finland), Mollie (Amsterdam). Storage location is not the same as processing location, so the model calls are listed separately below — both the provider you connect and the one we include.

Some processors may transfer data outside the EU under Standard Contractual Clauses (SCCs) approved by the European Commission, or their own published safeguards:

  • Google (OAuth login + the Gemini API you choose to use) — the prompts and context needed to generate a response are processed by Google under its terms; some processing may occur in the US.
  • LinkedIn (operator-only publishing) — OAuth identifiers and the posts we deliberately publish are processed on LinkedIn's global infrastructure and may be transferred outside the EU under LinkedIn's published safeguards.
  • Microsoft Azure OpenAI — our included model. If you have not connected your own model key, your agent's prompts and replies go here (see §4). Our Azure resource is in the EU (Sweden Central) and holds data at rest there, but its deployments run on Azure's global standard tier, which serves inference from Microsoft datacentres worldwide — so the processing itself may take place outside the EU, under Microsoft's published safeguards. Connect your own key and your prompts go to that provider instead. This is the same caveat we give for the provider you choose; we are not claiming a guarantee for ours that we deny for yours.
  • Cloudflare — edge proxy with global PoPs; traffic may transit US infrastructure even though your origin is in the EU.
  • Telegram — the messages, chat/user IDs and bot API calls you route through Telegram are processed on its global infrastructure and may leave the EU under its own terms. This applies to anything you link (support chat, your agent's own bot) and to a website-chat message of yours that we forward to our internal Telegram working channel because it asks for a human (§2). If you need to keep a question inside the EU, email it to us instead — declining to link Telegram does not by itself keep a website-chat message in the EU.

These processors publish their cross-border safeguards. You can opt out of Google by using magic-link sign-in and bringing an EU-region API key from another provider.

9. Security

  • TLS 1.3 for everything in transit (Cloudflare-terminated, modern cipher suites).
  • HttpOnly + Secure + SameSite=None cookies; not readable by JavaScript.
  • Encryption at rest on Azure Storage (AES-256). Your model keys and bot tokens are encrypted again at the application layer before we store them. Agent state on our hosting node is protected by host access controls and container isolation — not by full-disk encryption.
  • No plaintext passwords stored anywhere — when you set a password we keep only a salted bcrypt hash (cost 12).
  • Secrets in a KV store, not in code repositories.
  • Least-privilege access — a single admin account; destructive admin actions require an explicit type-to-confirm step. Hardware-key step-up (WebAuthn) for admin is on the roadmap.

If you find a security issue, please email [email protected] with “security” in the subject. We acknowledge within 48h.

10. Children

The service is not directed at people under 16. We don't knowingly collect data from minors. If you believe a minor has signed up, email us and we'll delete the account.

11. Contact & complaints

Data-protection questions — [email protected]. We respond within 30 days.

You can also lodge a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens.

SoKKoS AI
KvK 42029374 · BTW NL005441743B74
Beuningen, Gelderland, NL
Last updated 2026-08-03

↑ Back to top

sokkosai
Bring your own keys — no platform run limits on them. Export anytime. Hosted by me — or installed in your environment.
Product How it works Examples Pricing
Account Sign in Dashboard Billing Export your data Sign out
Legal Privacy Terms GDPR Cookie preferences
Contact [email protected] Telegram WhatsApp no sales calls — support is async
More from SoKKoS Plotmosa ↗ CBR-theorie ↗ nl-learning ↗
© 2026 SoKKoS AI · Beuningen, NL · Imprint & legal · Vertrag widerrufen · Verträge hier kündigen

We use the Meta Pixel for ad measurement — only if you agree. Privacy policy

Report a problem