Who we are
Sozuri (“Sozuri”, “we”, “us”) is a communications platform operated by Sozuri Limited, a company registered in Kenya. Businesses use Sozuri to send and receive SMS, WhatsApp messages and voice calls, to take payments, and to automate conversations with their customers, through our website, dashboard and API.
This policy covers sozuri.net, the Sozuri dashboard and API, and the messages that pass through them. Questions about it go to privacy@sozuri.net.
Our role, and our customers’
Who decides what happens to personal data depends on whose data it is:
- Our own customers and visitors. For the people who create Sozuri accounts, the members of their teams, and visitors to our website, Sozuri decides why and how the data is used. Here we are the data controller.
- Our customers’ contacts. When a business uses Sozuri to message its own customers, the business decides who to contact, what to say and what to keep. The contact lists, phone numbers and messages involved belong to that business, which is the data controller, and we process them on its behalf and on its instructions. If a business messaged you through Sozuri, that business is the one to ask about your data; we help where we can.
What we collect
| Data | What it includes |
|---|---|
| Account and team | Name, email address, phone number and password (stored only in hashed form); each person’s role on each project; when you sign in, and the IP address and browser you signed in from. |
| Business and verification | Your business name, requests for sender IDs and shortcodes, and the documents you upload to support them, such as a certificate of incorporation. |
| Billing and payments | Top-ups, charges and invoices; for M-Pesa, the paying phone number, the transaction code and the payer name M-Pesa returns. Card payments are made with Flutterwave: we do not receive or store card numbers. |
| Messages and calls | The SMS, WhatsApp messages and voice calls sent and received through your account: the numbers involved, the message text, files and media, delivery reports from the network, and call durations. If you turn on call recording, the recordings. |
| Contacts | The contact lists you upload or build (names, phone numbers and any fields you add), and records of people who asked not to be messaged. |
| Link clicks | When a message carries a Sozuri tracked link and someone opens it: the time, and the IP address and browser or device details of whoever opened it. |
| AI features | The instructions, notes, documents and website addresses you give an AI agent, the pages we fetch from those websites, and a record of each AI reply: what it was asked, which tools it used, and what it cost. See AI features. |
| Emails we send | The recipient, subject, content and delivery status of each email Sozuri sends, including one-time sign-in codes, so we can prove an email was delivered and fix problems. |
| Support and feedback | Support tickets and their replies, feedback ratings and comments, and, with a support ticket, the page, browser and IP address it was sent from, to help us reproduce the problem. |
| Activity log | A record of significant actions in your account — who did what, when, and from which IP address and browser — for security and to settle disputes. |
| Sign-in with Google or GitHub | If you choose to sign in that way, the name, email address and profile ID that provider shares. |
Data from Meta and WhatsApp
Sozuri offers two ways to connect a WhatsApp number.
The official WhatsApp channel (WhatsApp Business Platform)
When a customer connects a number through Meta’s sign-up window, Meta shares with Sozuri, with the customer’s permission:
- the IDs of the customer’s business portfolio and WhatsApp Business Account, its business name, and the phone numbers they chose, with each number’s display name, verification and quality status and messaging limits;
- an access token that lets Sozuri operate that WhatsApp Business Account on the customer’s behalf;
- the customer’s message templates and Meta’s review decisions on them.
Once connected, Meta sends Sozuri the messages the customer’s WhatsApp number receives — the sender’s WhatsApp number or WhatsApp user ID, their profile name, and the message text, media, location or reply — and the status of the messages it sends (sent, delivered, read, failed), with Meta’s pricing category for each. Every hour we also ask Meta whether the connection still works: whether the access token is valid, whether the account is still subscribed to notifications, whether a payment method is on file, and whether each number can send.
If a customer chooses to keep using the WhatsApp Business app on the same number, then with their permission, and once only, when they connect, Meta shares the contacts saved in that app and the recent chat history Meta makes available. After that, copies of the messages the customer sends from the app reach Sozuri too, so its inbox stays complete.
The QR-code channel
When a customer links a WhatsApp number by scanning a QR code, Sozuri keeps a linked-device session for that number, in the same way as WhatsApp on a computer. The messages that number sends and receives from then on pass through Sozuri; the chats already on the phone are not copied. The session’s login keys are stored on our server so the number stays linked.
How we use it — and how we do not
We use data from Meta and WhatsApp only to provide the WhatsApp service the customer set up: to send and receive their messages; to show them in the customer’s dashboard and inbox; to deliver them to the systems the customer points us to (such as their webhook); to run the automations the customer switched on; to bill and to support the customer; and to keep the connection working and secure.
We do not sell it, do not use it for advertising, and do not use it to build profiles of people. The access token is stored encrypted, with a key used for nothing else, and is never shown to anyone, including the customer. We share this data only as described below, and a customer can end our access and have it deleted at any time.
AI features
Sozuri’s AI features use OpenAI. They are off until a customer turns them on, and they send OpenAI only what the feature needs:
- AI agent (automatic replies on SMS and WhatsApp): the incoming message, the recent conversation with that contact, the agent’s instructions and notes, and relevant passages from the documents and web pages the customer gave it.
- AI steps in workflows: the text the workflow asks the AI to read, such as a message to classify.
- Campaign assistant and insights: the customer’s description of a campaign, and summaries of their account’s own activity.
We also use OpenAI to summarise the feedback and support tickets people send us, so we can see what needs attention first.
AI replies are sent automatically in the name of the business that set them up, and under its control: a person can take over any conversation, and the agent then stops replying to it. Sozuri does not use AI to make decisions about you that have legal or similarly significant effects.
How we use data
The Data Protection Act, 2019 requires a lawful basis for each use. Ours are:
| Purpose | Lawful basis |
|---|---|
| Providing the service | Performing our contract with the customer: creating accounts, sending and delivering messages and calls, running the features the customer turns on, and showing results in the dashboard and API. |
| Billing | Performing our contract, and our legal obligations on tax and accounting records. |
| Security and abuse prevention | Our legitimate interest in keeping Sozuri, our customers and message recipients safe: the activity log, sign-in records, detecting spam and fraud, and honouring opt-outs. |
| Support and improvement | Our legitimate interest in fixing problems and improving the service, using support tickets, feedback and service records. |
| Telling you about the service | Performing our contract for service and account messages; for news and offers, your consent, which you can withdraw at any time. |
| Complying with the law | Our legal obligations, including requests from regulators such as the Communications Authority of Kenya and the ODPC, and lawful requests from authorities. |
| Processing for our customers | For our customers’ contacts, the customer’s instructions; the customer is responsible for having a lawful basis to message them. |
Data outside Kenya
Some of the providers above, such as Meta, OpenAI, Mailgun and Google, process data outside Kenya. We transfer personal data out of Kenya only where the Data Protection Act, 2019 permits it, and with appropriate safeguards in place for its protection.
How long we keep data
We keep personal data only as long as we need it for the purpose it was collected for, then delete it. Where a period is fixed, a scheduled job deletes what is older.
| Data | How long |
|---|---|
| Accounts, projects, contacts and message history | While the account is open, so customers can see their history and check their bills; deleted when the customer asks (see How to delete your data) |
| Invoices and payment records | For the period tax and accounting law requires |
| Activity log | 400 days |
| Emails we send, including their content | 180 days |
| AI reply records | 90 days. The text of an AI conversation is kept for 30 days, and only for a sample of ordinary replies, plus every reply that failed or looked like an attempt to misuse the agent |
| Workflow run history | 90 days (7 days for test runs) |
| Notifications received from Meta | 30 days once processed; one that could not be processed is kept until it is resolved |
| Opt-out records | For as long as needed to keep honouring the request |
| Backups | Replaced on a rolling basis; deleted data can remain in a backup until that backup is replaced |
Security
Connections to Sozuri are encrypted (HTTPS). Passwords are stored only in hashed form. The access tokens Meta issues for customers’ WhatsApp accounts, and the credentials customers store for their AI agents’ API actions, are encrypted with keys kept separate from the rest of the application. Access within each project is limited by role, significant actions are recorded in the activity log, and you can require a one-time code at sign-in.
No system is perfectly secure. If a breach puts your personal data at risk, we will notify the ODPC and the people affected as the Data Protection Act, 2019 requires.
Your rights
Under the Data Protection Act, 2019 you have the right to:
- be told how your personal data is used, which is what this policy does;
- access the personal data we hold about you;
- have false or misleading data about you corrected or deleted;
- object to our processing your data, and withdraw any consent you gave;
- receive your data in a format you can take elsewhere; and
- not be subject to a decision based solely on automated processing that significantly affects you.
To use any of these rights, email privacy@sozuri.net. We respond within 14 days. If your data is held for one of our customers, we pass your request to that customer and help them answer it.
If you are not satisfied with our answer, you can complain to the Office of the Data Protection Commissioner (www.odpc.go.ke).
How to delete your data
How you ask depends on how your data reached us. Whichever applies, you do not need a reason, and it costs nothing.
If you have a Sozuri account
- Email privacy@sozuri.net from the email address on the account, with the subject “Delete my data”, or open a support ticket from your dashboard. Say whether you want the whole account deleted or particular projects, and whether you want a copy of your data first.
- We reply to confirm we have your request and give you a reference number. We then check that the request comes from the account owner or a project administrator, so nobody else can delete your data.
- Within 14 days we export your data if you asked for a copy, then delete it: your account and team details, your projects, contacts, message history, WhatsApp connections, AI agent settings and knowledge, and the files you uploaded.
- We tell you when it is done, and name anything we had to keep and why. The law requires us to keep invoices and payment records for the period set by tax law, and we keep a record that a person asked not to be messaged so that request keeps being honoured. Everything we keep is used for that purpose only and deleted when the period ends.
If you connected an official WhatsApp number (Meta)
- You can end Sozuri’s access at any time by removing Sozuri’s access to your WhatsApp Business Account in your Meta Business settings. Meta then revokes the access token Sozuri holds, and no new messages or account details reach Sozuri.
- Removing access stops new data arriving; it does not delete what Sozuri already holds. To have that deleted as well (the stored access token, your number’s details, your templates, and the messages and media from that number), send the request described above.
If a business messaged you through Sozuri
- The business that messaged you decides what happens to your phone number and your messages with it; we process them on its behalf. Ask that business to delete your data or to stop messaging you. Where the business offers it, you can also reply STOP.
- If you cannot reach the business, email privacy@sozuri.net with your phone number and the name the messages came from. We will pass your request to the business, and stop further messages from that sender to your number.
Everyone else
If you contacted us, gave us feedback on our website or otherwise shared information with us, email privacy@sozuri.net and we will delete it within 14 days, apart from anything the law requires us to keep.
Children
Sozuri is a service for businesses. Accounts are for people aged 18 or over, and we do not knowingly collect personal data from children except where it is part of the messages our customers send.
Changes to this policy
When we change this policy we update the date at the top. If a change matters, we tell account holders by email or in the dashboard before it takes effect.
Contact us
Sozuri Limited
Haji Issa Complex, Kuguru Loop Road, Nairobi, Kenya
Email: privacy@sozuri.net
Phone: +254 722 117 850