1. Who we are
SoKKoS AI — eenmanszaak (sole proprietorship in the Netherlands), KvK 42029374, BTW-id NL005441743B74, Beuningen, Gelderland, NL. Contact: [email protected]. We're the data controller for everything described below.
2. What we collect
The smallest amount that lets us run an agent for you and send you a receipt.
- Email address — required for authentication (magic-link, email + password, or Google OAuth) and billing notifications. Stored in Azure Table Storage (West Europe).
- Password — only if you set one. If you choose email + password sign-in, we store your password solely as a salted bcrypt one-way hash (cost factor 12). Your plaintext password travels over TLS each time you set, change, reset or sign in with it, is processed in memory only to hash or verify, and is never stored or logged; we can't recover it — a reset issues a new single-use link. Magic-link and Google sign-in remain available if you prefer no password at all.
- Telegram chat / user ID and bot token — only if you link Telegram (e.g. to reach support via @sokkosai_bot or to run your agent's own Telegram bot). If you connect your own bot, its bot token is stored encrypted at rest (shown to you only as “set”, never displayed again) so your agent can send on your behalf. Used to route messages. Clearing the token removes it from storage; a running agent may keep using its current token until its next restart, when the disconnect takes effect.
- Google profile basics (name, picture) — only if you choose “Sign in with Google”. Used to greet you in the dashboard. Disconnect any time and we delete the cached copy.
- LinkedIn publisher data — operator account only. Our internal admin publisher stores the LinkedIn member/Page identifier, granted scopes, token expiry and OAuth access/refresh tokens needed to publish SoKKoS posts. Tokens are encrypted before storage and never shown in the browser or logs. This integration is not offered to customer accounts; disconnecting it deletes the stored authorization.
- IP address — logged for rate-limiting and fraud prevention. Rate-limit counters are keyed to short time windows and are not used once their window passes; the IP recorded at signup stays with your account record and is deleted with your account.
- Payment metadata — transaction IDs, amount, currency, method (SEPA / iDEAL / card / PayPal). Processed by Mollie B.V. in Amsterdam. We never see your card number or bank credentials — only the receipt.
- Server logs — request paths, response codes, timing. No request bodies. Retained 30 days for debugging, then rotated.
- “Report a problem” submissions — only if you use the bug-report button: your description, the page URL, and the most recent browser console logs (with API keys and tokens automatically masked) so we can debug the issue.
- Chat messages that show contact intent — the site assistant does not store your conversation, but if a message shows you want a human to follow up (you include an email or phone number, or ask about pricing / setup) we forward that message to our operator over Telegram so we can reply. Nothing is sent for ordinary questions.
2a. Privacy-first measurement
We measure how the site is doing — which pages people open, when a buy button is clicked — with a small, first-party setup that stays entirely on our own infrastructure: no Google Analytics, no Hotjar, no third-party tracking script running by default (see §3 and §5). The one exception is the Meta Pixel, which loads only after you explicitly opt in via the cookie banner — see the third item below.
- Anonymous funnel events. When you open the “payment opening soon” popup or click a buy / register button, your browser sends us a tiny event — the event name, the package it referred to, and the page path. We store these in our own Azure database. No IP address, no email, no name, no cookie, and no raw browser fingerprint are attached — we keep only a coarse, one-way hash of the browser type so we can tell humans from bots in aggregate.
- Advertising click-ids. If you reach us from an online ad, the link may
carry a Google click identifier (
gclid) or a Meta click identifier (fbclid) and campaign tags (utm_*). We keep these in your browser's local storage (first-party, up to 90 days) so that, if you later sign up or send a brief, we can tell which ad worked. We do not share this data with third parties for their own purposes; we only use it ourselves, and — if you convert — may upload the click-id back to the ad platform it came from (Google Ads or Meta) to mark that one conversion (“offline / enhanced conversions”). You can clear it any time by clearing site data in your browser. - Meta Pixel — opt-in only. To measure how well our ads on Meta platforms (Facebook / Instagram) perform and to build ad audiences, the site may load the Meta Pixel, a measurement script from Meta Platforms Ireland Ltd. It loads strictly after you click “Accept” in the cookie banner. If you decline — or simply ignore the banner — no pixel code runs and no request to Meta is made. You can withdraw consent at any time via the “Cookie preferences” link in the footer; the pixel then stops loading from your next page view. How Meta handles this data: facebook.com/privacy/policy.
The first-party measurement needs no cookie banner: the funnel events are anonymous and the click-id is stored only when you arrived from an ad you already clicked. The Meta Pixel is exactly why the banner exists — it never runs unless you've agreed. If you prefer not to be measured at all, decline the banner and browse with local storage disabled — the site works exactly the same.
3. What we never collect
- Plaintext passwords. If you set a password we keep only a salted bcrypt hash (see §2); the plaintext is never stored, logged or recoverable. You can also sign in with a magic link or Google and set no password at all.
- Your AI API keys in plaintext. Your model-provider keys (Google Gemini, OpenAI, Anthropic, OpenRouter, Groq and others) are encrypted before they are stored (EU Azure storage) and decrypted server-side only to inject into your container's environment (at launch, and when you apply or rotate keys). They are never logged, never shared with third parties, and deleted with your account.
- Voice recordings beyond live processing. If you use the voice agent, audio is streamed to the model provider in real time and discarded immediately after the response. We do not persist recordings.
- Tracking / analytics cookies — none without consent. No Google Analytics, no Hotjar, no analytics cookie of our own. The only third-party measurement script we use at all is the Meta Pixel, and it loads strictly after you opt in via the cookie banner (§2a) — decline or ignore the banner and nothing fires. Our baseline measurement is the first-party, cookieless setup described in §2a. See §5.
- Phone numbers. Support is asynchronous; we have no phone field.
4. Sub-processors
To run the service we rely on a small set of named processors. Each has its own privacy policy you can read.
- Google LLC — Sign in with Google (OAuth) & Gemini API. policies.google.com/privacy
- LinkedIn Corporation — operator-only OAuth and publication of SoKKoS posts to our personal profile and company Page. LinkedIn receives only the post and destination chosen by the operator. linkedin.com/legal/privacy-policy
- Your chosen model provider(s) — when you connect a BYO API key (e.g. OpenAI, Anthropic, OpenRouter, Groq, NVIDIA, DeepSeek, or a custom OpenAI-compatible endpoint), your agent sends prompts directly to that provider under your own account and the provider's terms. You choose this processor; disconnect its key to stop the flow.
- Mollie B.V. (Amsterdam, NL) — payment processing. mollie.com/privacy
- Resend — transactional email (magic-link, billing receipts). resend.com/legal/privacy-policy
- Microsoft Azure — hosting for the public site and customer database (region: West Europe / Sweden Central).
- Cloudflare, Inc. — DNS, edge proxy, DDoS mitigation.
- Hetzner Online GmbH — per-customer VPS hosting (region: Germany or Finland, your choice or auto-selected by proximity).
- Telegram FZ-LLC — only if you link Telegram: support chat via @sokkosai_bot and/or your agent's own Telegram bot. telegram.org/privacy
If we add or change a sub-processor that materially affects what data is processed, we'll update this page and notify active customers by email at least 30 days before the change takes effect (see Terms §10).
6. Your rights (GDPR Articles 15–22)
If you're in the EU/EEA, you have the right to:
- Access — ask what data we hold about you.
- Rectify — correct anything that's wrong.
- Erase (“right to be forgotten”) — delete your account and associated data.
- Restrict — pause processing while a question is unresolved.
- Port — receive a machine-readable copy of your data.
- Object — object to processing based on legitimate interest.
Most of these are self-service in your dashboard. For anything that isn't, email [email protected] and we'll respond within 30 days. See the GDPR rights page for the exact request format and how each right maps to a self-service action.
7. Retention periods
- Account record — until you delete your account.
- Session cookie — 90 days, sliding (resets on each visit).
- Magic-link & password-reset tokens — single-use, and rejected once used or after 15 minutes.
- LinkedIn OAuth tokens — until the operator disconnects or replaces the authorization. Expired tokens remain encrypted only so the console can report connection status and cannot be used without reauthorization; publisher drafts and delivery receipts remain in the internal queue until administratively removed.
- Payment records — 7 years (mandatory under Dutch tax law, Art. 52 AWR).
- Server logs — 30 days raw, then aggregated.
- IP addresses — the signup IP is kept with the account record and deleted with the account; rate-limit counters only serve their short time window.
- Anonymous funnel events & ad click-ids (§2a) — up to 12 months, then deleted or aggregated. The click-id (
gclid/fbclid) in your browser's local storage expires after 90 days. - Cookie-consent choice (§5) — kept in your browser's local storage until you change it via “Cookie preferences” or clear site data.
- VPS container after cancellation — 14 days grace, then destroyed (see Terms §7).
8. International transfers
Your SoKKoS-hosted data — your agent's environment, config, logs, integrations and key management — stays inside the EU/EEA: Azure (West Europe / Sweden Central), Hetzner (Germany / Finland), Mollie (Amsterdam). The AI model you connect is your own choice and is covered separately below.
Some processors may transfer data outside the EU under Standard Contractual Clauses (SCCs) approved by the European Commission, or their own published safeguards:
- Google (OAuth login + the Gemini API you choose to use) — the prompts and context needed to generate a response are processed by Google under its terms; some processing may occur in the US.
- LinkedIn (operator-only publishing) — OAuth identifiers and the posts we deliberately publish are processed on LinkedIn's global infrastructure and may be transferred outside the EU under LinkedIn's published safeguards.
- Cloudflare — edge proxy with global PoPs; traffic may transit US infrastructure even though your origin is in the EU.
- Telegram (only if you link it) — the messages, chat/user IDs and bot API calls you route through Telegram are processed on its global infrastructure and may leave the EU under its own terms. Don't link Telegram if you need to keep this flow inside the EU.
These processors publish their cross-border safeguards. You can opt out of Google by using magic-link sign-in and bringing an EU-region API key from another provider.
9. Security
- TLS 1.3 for everything in transit (Cloudflare-terminated, modern cipher suites).
- HttpOnly + Secure + SameSite=None cookies; not readable by JavaScript.
- Encryption at rest on Azure Storage (AES-256) and on Hetzner volumes (LUKS).
- No plaintext passwords stored anywhere — when you set a password we keep only a salted bcrypt hash (cost 12).
- Secrets in a KV store, not in code repositories.
- Least-privilege access — a single admin account; destructive admin actions require an explicit type-to-confirm step. Hardware-key step-up (WebAuthn) for admin is on the roadmap.
If you find a security issue, please email [email protected] with “security” in the subject. We acknowledge within 48h.
10. Children
The service is not directed at people under 16. We don't knowingly collect data from minors. If you believe a minor has signed up, email us and we'll delete the account.
11. Contact & complaints
Data-protection questions — [email protected]. We respond within 30 days.
You can also lodge a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens.
SoKKoS AI
KvK 42029374 · BTW NL005441743B74
Beuningen, Gelderland, NL
Last updated 2026-07-19