Skip to main content
This Privacy Policy explains what personal data Soneka collects, why we collect it, who we share it with, and what rights you have over it. It applies to everyone who uses the Soneka platform, operated by Databit Limited (124 Manyani East Road, Nairobi, Kenya). This policy was last updated on March 14, 2026.

1. Data We Collect

When you sign up for Soneka, we collect:
  • Name, email address, and phone number
  • Country and timezone
  • Password (stored as a one-way hash — we never store your password in plain text)
  • Profile photo (if you choose to upload one)
This information is needed to create and manage your account.
As you use Soneka, we collect data about your workspace configuration, integrations you have connected, team members you have invited, billing details, and support interactions.
When you use Soneka to communicate with your customers, those conversations and contact records are stored in your workspace. You are the data controller for this information — Soneka acts only as a data processor on your behalf. We process this data solely to provide the service to you, not for our own purposes.
We collect anonymised usage analytics to understand how the platform is used and where we can improve it. This data cannot be linked back to individual users.

2. How We Use Your Data

We use your data to:
  • Provide and improve the Soneka service, including processing messages through WhatsApp
  • Process your payments and manage your subscription
  • Send transactional emails such as invoices, password resets, and important account notifications
  • Provide customer support when you contact us
  • Detect abuse and enforce our Acceptable Use Policy
  • Comply with legal obligations such as tax record-keeping
We never sell your personal data to third parties. We do not use your data for advertising or share it with data brokers.

3. Who We Share Data With

We share data only with trusted service providers necessary to operate Soneka, and only to the extent required for them to perform their function: We may also disclose data when required by law (e.g., a court order or regulator request), or in the event of a business transfer such as a merger or acquisition — in which case we will notify you in advance.

4. Cookies

We use first-party cookies only — there are no advertising or third-party tracking cookies on Soneka. Cookies are used for session management, security (CSRF protection), and anonymised product analytics. See our Cookie Policy for the full list of cookies and how to control them.

5. Data Retention

6. Security

We take the security of your data seriously. Our safeguards include:
  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for all data at rest
  • SOC 2 Type II and ISO 27001 certifications
  • Two-factor authentication required for all Soneka staff
  • Quarterly penetration testing by independent security researchers
  • A bug bounty programme — report vulnerabilities to security@soneka.africa

7. Your Privacy Rights

If you are in the EU or UK, you have the right to:
  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data (“right to be forgotten”)
  • Export your data in a portable format
  • Object to processing or request that we restrict it
  • Withdraw consent at any time where processing is based on consent
To exercise any of these rights, email privacy@soneka.africa. We will respond within 30 days.
California residents have the right to know what personal information we collect, request deletion of their data, and opt out of the sale of personal information. We do not sell personal information. To make a request, contact privacy@soneka.africa.
If you are in India, you have rights under the Digital Personal Data Protection Act 2023, including the right to access, correct, and erase your personal data. Contact privacy@soneka.africa to exercise these rights.

8. International Data Transfers

Soneka operates globally. Your data may be processed in countries outside your own. We protect cross-border transfers using Standard Contractual Clauses (SCCs) approved by the European Commission.
Enterprise plan: Enterprise customers can request data residency in the EU, US, or India to keep their data within a specific geographic region.

9. Google API Disclosure

Soneka integrates with Google services. We request access to the following Google API scopes:
  • Google Calendar — to sync appointment scheduling
  • Google Docs & Sheets — to read and write data for automation workflows
  • Google Forms — to trigger workflows from form submissions
Our use of Google API data complies with Google’s Limited Use Policy: we use this data only to provide the Soneka service to you, not for advertising or any secondary purpose. We do not share Google user data with third parties except as necessary to deliver the service.

10. How to Delete Your Data

You have three ways to request deletion of your data:
  1. Revoke the Facebook app connection in your Meta Business settings
  2. Email privacy@soneka.africa with a deletion request
  3. In your Soneka workspace, go to Admin → Settings → Delete Account
After deletion, customer data is removed within 90 days. Financial records are retained for 10 years as required by law.

11. Contact and Data Protection Officers

If you have a concern about how we handle your data and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.