1. Who we are
Sokohuru Ltd is the controller of personal data collected through the Platform. We are registered in Nairobi, Kenya. Our data protection officer can be reached at dpo@sokohuru.com.
2. What we collect
Account data: name, email, phone number, country of residence, and where relevant your KRA / NIN / South African ID number for tax purposes.
Profile and content: handles for connected social platforms, audience demographics, content submitted to campaigns, and messages sent through the Platform.
Financial data: bank or M-Pesa details, payout history, invoice records. Card payment details are tokenised by our payments provider and are never stored on our servers.
Technical data: device, browser, IP address, app version and crash logs.
3. Why we use it
To operate the Platform — matching creators with briefs, processing payments, enforcing contracts, and providing support.
To meet legal obligations — KYC checks, tax reporting, anti-fraud, sanctions screening, and responding to lawful requests.
To improve the product — aggregated, de-identified analytics to spot bugs, improve matching and inform roadmap decisions.
To communicate with you — service announcements (always sent) and product newsletters (opt-in only).
5. Your rights
You may access, correct or delete your personal data, object to or restrict certain processing, and request a portable copy of the data you have provided. To exercise these rights, write to privacy@sokohuru.com — we respond within 30 days.
You may withdraw consent for optional processing (e.g. newsletters) at any time from Settings → Notifications.
6. How long we keep it
Account data: for as long as your account is active, plus 7 years afterwards to meet tax and accounting law in our markets.
Campaign content: indefinitely, unless you ask us to remove it and we are not required by law or contract to keep it.
Technical logs: 12 months.
7. International transfers
We host primarily in af-south-1 (Cape Town) and eu-west-1 (Dublin). Where data is transferred outside your country of residence, we rely on Standard Contractual Clauses or equivalent safeguards.
8. Security
We use TLS in transit and AES-256 at rest, role-based access, audit logging and quarterly third-party penetration testing. Breaches affecting personal data are notified to regulators within 72 hours where required, and to affected users without undue delay.
9. Children
The Platform is not intended for anyone under 18. If we learn we have collected personal data from a minor, we will delete it.
10. Changes
We will notify you of material changes at least 30 days before they take effect, by email and in-app banner. Questions? privacy@sokohuru.com.