Changes to this Privacy Notice
We may revise this Privacy Notice from time to time. When we do, we will update the “Last Updated” date at the top. If the changes are material — for example, a new category of data we collect, a new type of disclosure, or a change to your rights — we will make a reasonable effort to tell you about them in advance: by email to the last address you gave us, by a banner on the Services, or by another channel consistent with applicable law. If you do not agree to the updated Notice, please stop using the Services.
Collection & use of information
When you visit or use the Services, we collect certain categories of information about you from a few different sources.
Information you provide to us
Some Services require you to share information directly. You can decline to share it, but doing so may prevent you from using those features. Examples include:
- Contact and account details — name, work email, company name, role, and (if you create an account) a password. We use this to create, maintain, and secure your account, to provide the Services, and to communicate with you about your account and other products or services that may be of interest. If you create an account, you are responsible for keeping your credentials safe — if you believe your account has been compromised, please contact us right away.
- Pilot and demo context — when you request a pilot or schedule a call, we may ask what tools and identity providers you use. We use this to scope a meaningful conversation.
- Billing information — bank account, credit or debit card information, and billing address, processed by our payment providers to bill you for the Services.
- Recruiting information — resume, references, and work history if you apply for a role with us. We use this to evaluate your candidacy.
- Anything else you send us — for example, the content of an email or support message.
Information collected automatically
We use cookies and similar technologies to collect technical information about how you use the Services. This helps us tailor your experience, run analytics, and understand how people use the product. We collect:
- Device information — device type, operating system, unique device identifiers, and IP address.
- Interaction information — browser type, log data, timestamps, page paths, referrer, and click events.
- Product telemetry — the identity that made an API call, the policy decision Sopio rendered, latency, and a hash of the action. Bodies of customer payloads are not part of this telemetry unless a customer explicitly enables verbose audit mode.
Most browsers accept cookies by default; you can adjust your browser settings to control or block them, though blocking may break parts of the Services. Like many websites, ours does not respond to “Do Not Track” signals.
Information collected from other sources
We may receive information about you from third parties, either directly from them or because you choose to connect them to your Sopio account:
- Analytics providers — anonymized usage data we use to improve the Services and our marketing.
- Recruiting platforms such as LinkedIn — if you apply for a role at Sopio.
- Identity providers and SSO such as Google or Okta — to verify the identity of users acting on your behalf during a Sopio policy decision, and to log you in.
Any information we receive from outside sources is handled according to this Notice. We are not responsible for the accuracy of information third parties provide us, or for their own privacy practices — see “Third-party websites & links” below.
In addition to the specific purposes above, we may use the information we collect to operate and improve the Services and to maintain our business relationship with you — including troubleshooting, data analysis, testing, system maintenance, customer support, sending service messages, performing research, complying with legal obligations, enforcing our terms, and protecting our Services and the rights of our employees, customers, and other users. We may also de-identify information so it can no longer reasonably be linked to you, and use de-identified information for any lawful purpose.
Disclosure of your information
We may share your information for legitimate purposes consistent with this Notice. The categories of recipients are:
- Vendors and service providers who help us operate the Services — for example, cloud infrastructure (hosted in EU-Central-1, Frankfurt), email delivery, customer-support tooling, error-monitoring, payment processing, and analytics. Each is bound by a written data-processing agreement and required to apply equivalent security and confidentiality safeguards. A current, named sub-processor list is available on request and to all customers under contract.
- Parties you direct us to share with — for instance, when you connect a third-party tool to your Sopio account, or when you ask us to send a referral.
- Professional advisors such as auditors, law firms, and accountants.
- Parties involved in a corporate event — for example, in connection with a financing, merger, acquisition, restructuring, or sale of all or substantially all of our assets.
We may also disclose information as needed to comply with applicable law or a lawful request from a public authority, to cooperate with law enforcement or judicial processes, to enforce our agreements, or to protect the safety and security of our business, our team, and the people who use the Services.
What we never do. We never sell or rent personal data. We never share data with advertising networks. We never train AI models — ours or anyone else's — on customer data or content that flows through Sopio.
Third-party websites & links
The Services may link to third-party websites, applications, or platforms that we do not own or operate. If you follow a link to a site we are not affiliated with, please review that site's privacy notice and terms — we are not responsible for the privacy or security practices of, or the information found on, those sites. Information you post on public or semi-public third-party platforms may be viewable by other users of those platforms without limit on how they use it. A link to a third-party site does not imply our endorsement of that site or its operators.
Children's privacy
Sopio is a business-to-business product. The Services are not intended for children, and we do not knowingly collect personal information from children under 16. If we learn that we have collected such information, we will make a reasonable effort to delete it. If you are a parent or guardian and believe a child under 16 has provided us with personal information, please contact us using the details below and we will delete it.
Data security & retention
Security is the product. We hold ourselves to the same controls we sell. Concretely, we apply identity-bound, least-privilege access for every internal system; tamper-evident audit logs for production access and policy decisions; encryption in transit (TLS 1.2 or higher) and at rest (AES-256); hardware security keys for administrative access; regular third-party penetration tests; continuous vulnerability scanning; and a documented incident-response runbook. Even so, no security measure is impenetrable — we cannot guarantee “perfect security,” and information you send us electronically may not be secure in transit. We recommend not using insecure channels to share sensitive or confidential information with us.
We retain personal information for as long as reasonably necessary for the purposes described in this Notice. In deciding how long, we consider whether we still need the information to provide the Services, resolve a dispute, enforce a contract, prevent harm, promote safety and integrity, comply with a legal obligation, or protect our rights and property. Concretely:
- Pilot & demo requests — up to 24 months after our last contact, unless you ask us to delete sooner.
- Account information — for the duration of your contract, plus 30 days for safe wind-down, then deleted (subject to any retention required by law, such as accounting records).
- Audit logs — 13 months by default; configurable by the customer in the DPA.
- Marketing list — until you unsubscribe.
If you are in the EU/EEA, UK, or Switzerland, GDPR (and equivalent laws) give you the right to access, correct, delete, restrict, object to, or port the personal data we hold about you, and to withdraw consent at any time for processing that depends on it. You can exercise these rights by emailing info@sopio.ai. You may also lodge a complaint with your local supervisory authority — for residents of Germany, that is the Berlin Commissioner for Data Protection and Freedom of Information.
How to contact us
Questions about our privacy practices or this Notice — including privacy requests, security disclosures, and matters for our Data Protection Officer — can be sent to info@sopio.ai.
Social features
Some parts of the Services let you interact with third-party platforms or social networks (“Social Features”) — for example, links that let you follow Sopio on LinkedIn, share a post, or sign in with a third-party account. When you use a Social Feature, the third party may collect or use information about you, and information you post on their platform may be visible to their users without restriction. We and the third party may both have access to information about you and how you use the connected service. For more on how third parties handle your data, see “Third-party websites & links” below.