Information we collect
Account & profile data
When you sign up we collect your name, work email, phone number, country, timezone, password (hashed via bcrypt), and any profile photo you upload.
Workspace & operational data
To deliver the Service we process: workspace name, connected WhatsApp numbers, broadcast templates, flow definitions, contact lists, team-member emails and roles, billing details, and audit-log events.
Customer message data
Soneka stores the messages, attachments, and metadata that flow through your workspace. You are the data controller for this content; we act as a processor under our DPA.
Usage & telemetry
Anonymous usage events (page views, feature clicks, performance metrics) and standard server logs (IP address, browser type, request time) are captured for security and product improvement.
How we use your information
We use the data we collect to:
- Provide, maintain, and improve the Service
- Process payments, send invoices, and manage your subscription
- Respond to support requests and security incidents
- Detect, prevent, and address abuse, fraud, and security threats
- Send transactional emails (receipts, security alerts, product updates you opted into)
- Comply with legal obligations including tax, accounting, and law-enforcement requests
We never sell your data or your customers' data.
Sharing of information
We share data only in these limited circumstances:
- Sub-processors — AWS (hosting), Stripe (payments), SendGrid (email), Anthropic + OpenAI (AI features, redacted of PII). Full list at legal/subprocessors.
- Meta WhatsApp Cloud API — to dispatch messages on your behalf.
- Legal requirements — subpoenas, court orders, or to protect rights, safety, and integrity.
- Business transfers — in the event of a merger, acquisition, or sale of assets, with prior notice.
Cookies & tracking
We use first-party cookies for session management, security, and analytics. We do not use cross-site advertising cookies. Detailed list in our Cookie Policy.
Data retention
We retain personal data for as long as your account is active. After account termination:
- Customer data: exportable for 30 days, then deleted within 90 days
- Audit logs: 7 years for Scale plans (regulatory) or 12 months (other plans)
- Invoices & billing records: 10 years (tax law requirement)
- Backups: encrypted, fully purged within 90 days
Data security
We implement industry-standard safeguards:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- SOC 2 Type II certified (audited annually)
- ISO 27001 certified
- Mandatory 2FA for all staff with production access
- Quarterly third-party penetration testing
- Bug bounty program — report to security@soneka.africa
Your rights
Depending on your jurisdiction (GDPR, CCPA, India DPDP Act 2023) you may have rights to:
- Access — request a copy of personal data we hold about you
- Rectification — correct inaccurate information
- Erasure — request deletion ("right to be forgotten")
- Portability — export data in a machine-readable format
- Objection — opt out of certain processing
- Withdraw consent — for any consent-based processing
Email privacy@soneka.africa to exercise any right. We respond inside 30 days.
International transfers
Customer data is hosted in the region you select (EU, US, or India on Scale plans). Where data crosses borders we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and supplementary measures for adequate protection.
Children's privacy
Soneka is a business tool not intended for users under 18. We do not knowingly collect data from children. If you believe we have, email privacy@soneka.africa.
Changes to this policy
Material changes to this Privacy Policy will be notified by email at least 30 days before they take effect. The "Updated" date at the top reflects the latest revision.
Google API Services User Data Policy Compliance
This section governs how Soneka (developed and operated by Databit Limited) accesses, uses, stores, and transfers data obtained through Google API Services. We are committed to protecting the privacy of our users and ensuring total transparency regarding our integrations with Google Workspace.
Scopes Accessed & How We Use Google User Data
Soneka only requests access to the minimum necessary Google API scopes required to facilitate features actively initiated and configured by you. Below are the specific scopes our application utilizes:
• Google Calendar (.../auth/calendar): Used to allow your agents and users to view calendar availability, schedule, reschedule, edit, or delete customer follow-up appointments and meetings directly from the WaDesk dashboard.
• Google Documents (.../auth/documents): Used to read document templates and programmatically create, edit, or generate standard client contract drafts, proposals, or chat transcripts from your active conversations.
• Google Spreadsheets (.../auth/spreadsheets): Used to allow users to export conversational lead logs to Google Sheets or dynamically import customer contact sheets to trigger automated WhatsApp messages.
• Google Forms (.../auth/forms.body.readonly): Used to read Google Form structures and submissions in real-time so that WaDesk can instantly trigger automated, personalized greeting messages to lead phone numbers.
Limited Use Disclosure
Soneka's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data Storage, Security, and Retention
Any Google data processed through our workflows is transmitted securely using modern encryption protocols (HTTPS/TLS) and is stored encrypted at rest on our secure databases. Access and refresh OAuth tokens are treated as highly sensitive data and are strongly encrypted. We do not store the content of your documents, spreadsheets, or forms on our servers longer than necessary to execute your initiated automation tasks. Once you disconnect your Google Account from WaDesk, all associated tokens are instantly and permanently purged from our database.
Human Access, Sharing, and Prohibited Uses
• No Sale of Data: We will never sell, lease, or trade your Google user data to any third party under any circumstances.
• No Advertising: We do not use, process, or transfer Google user data to serve advertisements, including personalized, retargeted, or interest-based advertising.
• No Human Access: No personnel, employees, or contractors at Databit will ever read or access your private Google user data, except under extremely limited circumstances where you have given explicit consent to resolve a technical bug, or to comply with applicable laws.
Data Deletion Instructions
Data Deletion Instructions
At WaDesk, we prioritize your privacy and are committed to giving you full control over your personal data. In compliance with Meta (Facebook) Platform policies, we provide a clear and simple mechanism for you to request the deletion of your data, or to disconnect your Facebook account from our systems.
Method 1: Revoking Facebook App Permissions (Self-Service)
If you signed into Soneka using Facebook, or authorized our app to access your Facebook Business or Page assets, you can remove our app and request deletion of access tokens directly through your Facebook account:
1. Go to your personal Facebook Profile and click on your profile picture in the top right.
2. Select Settings & Privacy, then click on Settings.
3. In the left-hand navigation sidebar, scroll down and click on Apps and Websites.
4. Find Soneka in the active applications list.
5. Click the Remove button next to it.
6. (Optional) Check the box to confirm you want to delete all posts, videos, or events Soneka may have posted on your behalf.
7. Click Remove again to finalize the revocation.
Method 2: Requesting Manual Database Purge (Via Email)
If you want us to completely erase your synced contact records, workspace metadata, and platform chat histories from our servers permanently, please submit a deletion ticket:
Support Email: support@soneka.africa
Subject Line: Data Deletion Request - WaDesk
Details Required: Please state the registered email address or your workspace URL. (For safety reasons, never include passwords, credentials, or credit card numbers in this request).
Method 3: In-App Workspace Deletion
If you have active access to your WaDesk admin workspace dashboard, you can trigger an automated deletion request yourself:
1. Log into your panel at soneka.africa.
2. Navigate to Admin → Settings → Account Profile.
3. Scroll to the bottom of the portal page and click the Delete Account & Workspace button.
4. Confirm the action by typing your administrator password to initiate the database wipe.
What Happens Post-Deletion?
Once you initiate or request a data purge on our platform:
• All linked tokens, active API logins, and background WhatsApp queues are instantly destroyed.
• All user-profiles, custom fields, and cached logs are permanently wiped from our active databases within 30 business days.
• Our encrypted physical backups are entirely rotated and overwritten within 60 business days, ensuring no traces of your personal customer databases remain.
Contact Information
Data Protection Officer: privacy@soneka.africa
EU Representative: eu-rep@soneka.africa
Mailing address: Databit Limited. · 124 Manyani East Road, Nairobi, Kenya