1. Data We Collect
Account and profile data
Account and profile data
When you sign up for Soneka, we collect:
- Name, email address, and phone number
- Country and timezone
- Password (stored as a one-way hash — we never store your password in plain text)
- Profile photo (if you choose to upload one)
Workspace and operational data
Workspace and operational data
As you use Soneka, we collect data about your workspace configuration, integrations you have connected, team members you have invited, billing details, and support interactions.
Customer message data
Customer message data
When you use Soneka to communicate with your customers, those conversations and contact records are stored in your workspace. You are the data controller for this information — Soneka acts only as a data processor on your behalf. We process this data solely to provide the service to you, not for our own purposes.
Usage telemetry
Usage telemetry
We collect anonymised usage analytics to understand how the platform is used and where we can improve it. This data cannot be linked back to individual users.
2. How We Use Your Data
We use your data to:- Provide and improve the Soneka service, including processing messages through WhatsApp
- Process your payments and manage your subscription
- Send transactional emails such as invoices, password resets, and important account notifications
- Provide customer support when you contact us
- Detect abuse and enforce our Acceptable Use Policy
- Comply with legal obligations such as tax record-keeping
3. Who We Share Data With
We share data only with trusted service providers necessary to operate Soneka, and only to the extent required for them to perform their function:
We may also disclose data when required by law (e.g., a court order or regulator request), or in the event of a business transfer such as a merger or acquisition — in which case we will notify you in advance.
4. Cookies
We use first-party cookies only — there are no advertising or third-party tracking cookies on Soneka. Cookies are used for session management, security (CSRF protection), and anonymised product analytics. See our Cookie Policy for the full list of cookies and how to control them.5. Data Retention
How long we keep your data
How long we keep your data
6. Security
We take the security of your data seriously. Our safeguards include:- TLS 1.3 encryption for all data in transit
- AES-256 encryption for all data at rest
- SOC 2 Type II and ISO 27001 certifications
- Two-factor authentication required for all Soneka staff
- Quarterly penetration testing by independent security researchers
- A bug bounty programme — report vulnerabilities to security@soneka.africa
7. Your Privacy Rights
GDPR rights (EU/UK users)
GDPR rights (EU/UK users)
If you are in the EU or UK, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data (“right to be forgotten”)
- Export your data in a portable format
- Object to processing or request that we restrict it
- Withdraw consent at any time where processing is based on consent
CCPA rights (California users)
CCPA rights (California users)
California residents have the right to know what personal information we collect, request deletion of their data, and opt out of the sale of personal information. We do not sell personal information. To make a request, contact privacy@soneka.africa.
DPDP Act rights (India users)
DPDP Act rights (India users)
If you are in India, you have rights under the Digital Personal Data Protection Act 2023, including the right to access, correct, and erase your personal data. Contact privacy@soneka.africa to exercise these rights.
8. International Data Transfers
Soneka operates globally. Your data may be processed in countries outside your own. We protect cross-border transfers using Standard Contractual Clauses (SCCs) approved by the European Commission.Enterprise plan: Enterprise customers can request data residency in the EU, US, or India to keep their data within a specific geographic region.
9. Google API Disclosure
Soneka integrates with Google services. We request access to the following Google API scopes:- Google Calendar — to sync appointment scheduling
- Google Docs & Sheets — to read and write data for automation workflows
- Google Forms — to trigger workflows from form submissions
10. How to Delete Your Data
You have three ways to request deletion of your data:- Revoke the Facebook app connection in your Meta Business settings
- Email privacy@soneka.africa with a deletion request
- In your Soneka workspace, go to Admin → Settings → Delete Account
11. Contact and Data Protection Officers
If you have a concern about how we handle your data and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.