Privacy Policy
Shokuin S.R.L.
Effective Date: January 5, 2026. | Last Updated: February 18, 2026.
1. Introduction
This Privacy Policy (the "Policy") explains how Shokuin S.R.L. ("Shokuin," "we," "us," or "our"), a company incorporated under the laws of Romania with its registered office at București Sectorul 1, Strada CLUCERULUI, Nr. 35, Birou 2, Etaj PARTER, collects, uses, stores, shares, and protects personal data when you access or use our AI Workforce Platform available at https://shokuin.com (the "Platform").
Shokuin is a business-to-business (B2B) platform that enables organizations to hire, deploy, and manage AI employees for specific business roles. This Policy applies to all visitors, account holders, and authorized users of the Platform (collectively, "you" or "your"). In this Policy, "Customer" refers to the organization or individual who registers for an account, and "Authorized User" refers to any individual granted access to the Platform by the Customer.
We are committed to protecting your privacy and processing your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Romanian Data Protection Law No. 190/2018, and other applicable data protection legislation.
By accessing or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree with our data processing practices, please do not use the Platform.
2. Data Controller
For the purposes of the GDPR, the data controller is:
Shokuin S.R.L. București Sectorul 1, Strada CLUCERULUI, Nr. 35, Birou 2, Etaj PARTER, Romania
Privacy Contact: privacy@shokuin.com Security Contact: security@shokuin.com
Shokuin acts as the Data Controller with respect to personal data collected for account registration, billing, Platform administration, and website analytics. Shokuin acts as the Data Processor with respect to personal data processed on behalf of our business customers through AI employee interactions, including end-user conversation data and any data accessed through third-party integrations connected by our customers. The distinction between these roles is further described in Section 5.
3. Personal Data We Collect
3.1 Data We Collect Directly from You (Controller Capacity)
Account Registration Data
- Full name, email address, company name, and job title
- Billing address and payment information (processed securely by Stripe; we do not store credit card numbers)
- Account credentials (passwords stored using industry-standard hashing)
Platform Usage Data
- Log data: IP address, browser type, operating system, referring URL, pages viewed, and timestamps
- Feature usage: AI employee configurations, integration settings, and tool assignments
- Analytics data: dashboard views, conversation metrics, and performance reports accessed
Communications Data
- Correspondence with our support team, feedback, and survey responses
3.2 Data We Process on Behalf of Our Customers (Processor Capacity)
When our customers deploy AI employees, those AI employees interact with the customer's end-users (e.g., the customer's clients, website visitors, or internal staff). In this context, Shokuin processes data strictly on behalf of and under the instructions of the customer. This data may include:
End-User Conversation Data
- Messages exchanged between end-users and AI employees across all channels (web chat, email, WhatsApp, Instagram, Telegram, Facebook Messenger, voice, and API)
- Conversation metadata: timestamps, channel identifiers, session identifiers, and language detected
- Sentiment analysis scores and escalation triggers
Third-Party Integration Data
When customers connect third-party services to their Shokuin account, we may access and process data from those services on the customer's behalf. The specific data accessed depends on the permissions granted by the customer during the OAuth authorization flow or API key configuration. Integrations may include:
- Email services (Gmail, Outlook): email content, sender/recipient information, subject lines, and attachments
- Cloud storage (Google Drive, Dropbox, OneDrive): document content for knowledge base indexing
- Spreadsheets (Google Sheets): data for structured information retrieval
- CRM systems (Salesforce, HubSpot, Pipedrive): customer records, lead information, and deal data
- Payment platforms (Stripe, PayPal, Shopify, Magento, MerchantPro): order status and transaction data
- Calendars (Google Calendar, Microsoft Calendar, Calendly): scheduling availability and event details
- Messaging platforms (WhatsApp, Telegram, Slack): message content and user identifiers
- Social media (Instagram, Facebook, Twitter/X, LinkedIn): posts, comments, direct messages, and user profiles
- Documentation tools (Notion, Confluence): page content and workspace data
- Project management (Jira, Asana, Trello): task data and project information
Knowledge Base Data
- Documents, files, and web content uploaded or connected by the customer for AI employee training (PDF, Word, Markdown, CSV, JSON, and website crawls)
Important: Shokuin does not determine the purposes or means of processing end-user data. Our customers are the Data Controllers for their end-users' personal data and are responsible for ensuring they have a lawful basis for such processing, including obtaining any required consents from their end-users.
4. Legal Bases for Processing
We process personal data on the following legal bases under Article 6(1) GDPR:
| Legal Basis | Purpose | Data Categories |
|---|---|---|
| Contract Performance (Art. 6(1)(b)) | Providing the Platform, managing your account, processing payments, delivering AI employee services | Account data, billing data, Platform usage data |
| Legitimate Interest (Art. 6(1)(f)) | Improving the Platform, security monitoring, fraud prevention, analytics, customer support | Usage data, log data, support communications |
| Legal Obligation (Art. 6(1)(c)) | Tax compliance, financial reporting, responding to lawful requests from authorities | Billing data, account data, transaction records |
| Consent (Art. 6(1)(a)) | Marketing communications, non-essential cookies and analytics (Google Analytics, HubSpot tracking) | Email address, cookie identifiers, browsing behavior |
For data processed in our capacity as Data Processor (end-user conversation data and third-party integration data), the legal basis for processing is determined by our customer (the Data Controller). We process such data solely based on the customer's documented instructions, as set forth in our Data Processing Agreement.
5. Our Role: Data Controller vs. Data Processor
The GDPR distinguishes between Data Controllers (who determine the purposes and means of processing) and Data Processors (who process data on behalf of Controllers). Shokuin operates in both capacities depending on the type of data:
| Data Type | Shokuin's Role | Obligations |
|---|---|---|
| Account registration, billing, website analytics, marketing | Data Controller | Shokuin determines purposes and means; this Policy governs processing |
| End-user conversations, third-party integration data, knowledge base content | Data Processor | Shokuin processes under customer instructions; governed by the Data Processing Agreement (DPA) |
Business customers who use Shokuin's Platform are Data Controllers for the personal data of their end-users. We offer a Data Processing Agreement (DPA) to all customers in compliance with Article 28 GDPR. The DPA governs the processing of personal data that Shokuin carries out on behalf of the customer, including security measures, sub-processor management, breach notification obligations, data deletion, and audit rights. Customers may request a copy of the DPA by contacting privacy@shokuin.com.
6. How We Use Personal Data
6.1 In Our Controller Capacity
- Providing, maintaining, and improving the Platform and its features
- Processing payments and managing subscriptions through Stripe
- Communicating with you about your account, service updates, and technical notices
- Providing customer support and responding to inquiries
- Monitoring Platform security, detecting fraud, and preventing abuse
- Analyzing Platform usage to improve functionality and user experience
- Sending marketing communications (only with your consent; you may opt out at any time)
- Complying with legal obligations, including tax and financial reporting requirements
6.2 In Our Processor Capacity
When processing data on behalf of our customers, we use personal data solely to:
- Facilitate AI employee conversations with end-users across configured channels
- Access and retrieve information from connected third-party integrations as authorized by the customer
- Execute tool actions as configured by the customer (e.g., sending emails, creating tickets, scheduling meetings)
- Index and search knowledge base content for accurate AI employee responses
- Generate analytics and reports for the customer's dashboard
- Maintain conversation logs for the customer's review and quality assurance
We do not: sell personal data, use end-user data for advertising or marketing purposes, use customer data to train AI models, or share end-user data with third parties except as necessary to provide the Platform services (e.g., passing conversation text to LLM providers for inference) or as instructed by the customer.
7. Artificial Intelligence and Large Language Model Processing
Shokuin's AI employees are powered by large language models (LLMs) provided by third-party providers, including OpenAI, Anthropic, and Google. Each AI employee may use a different LLM provider, as configured by the customer.
7.1 How LLM Processing Works
When an end-user sends a message to an AI employee, the following data processing occurs:
- The end-user's message, along with relevant conversation context and retrieved knowledge base content, is transmitted to the selected LLM provider's API for inference (response generation).
- The LLM provider processes the input and returns a generated response.
- Shokuin stores the conversation (both the input and the response) in its infrastructure for the customer's records, analytics, and quality monitoring.
7.2 LLM Provider Data Handling
We have entered into Data Processing Agreements with our LLM providers. Under these agreements:
- LLM providers process data solely for the purpose of generating responses to API requests.
- LLM providers do not use customer or end-user data to train, retrain, or improve their models (we use API configurations that opt out of training data usage where applicable).
- LLM providers are contractually obligated to maintain appropriate security measures and to delete input data after processing in accordance with their data retention policies.
- Data transmitted to LLM providers is encrypted in transit using TLS 1.3.
7.3 AI Transparency
We require our customers to inform their end-users that they are interacting with an AI employee, in compliance with the EU AI Act (Regulation (EU) 2024/1689) and applicable transparency requirements. Shokuin provides configurable disclosure messages to support this obligation. Customers bear the responsibility of ensuring appropriate disclosure is made to their end-users.
8. Google API Services User Data Policy Compliance
Shokuin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8.1 Google Data We Access
When a customer connects their Google account to the Platform, we request access to the following scopes based on the customer's selected integrations:
- Google Account Information: Email address and basic profile information (for authentication and account identification).
- Gmail (Read-Only): View email messages and settings, enabling AI employees to monitor and respond to incoming emails as configured by the customer.
- Gmail (Send): Send email messages on behalf of the authenticated user, enabling AI employees to respond to customer inquiries and send notifications.
- Google Drive (Read-Only): View and download files stored in Google Drive, enabling AI employees to access documents for knowledge base indexing and information retrieval.
- Google Sheets: View, edit, create, and delete spreadsheets, enabling AI employees to read and update structured data as configured by the customer.
- Google Calendar: View, edit, share, and manage calendar events, enabling AI employees to schedule meetings and check availability.
8.2 Limited Use Compliance
Shokuin strictly complies with Google's Limited Use Requirements:
- We only use Google user data to provide and improve the Platform's functionality as described in this Policy. We do not use Google user data for any purpose other than providing the features the customer has explicitly authorized.
- We do not transfer Google user data to third parties except: (a) as necessary to provide or improve the Platform features requested by the user (e.g., transmitting email content to LLM providers for AI employee inference); (b) to comply with applicable laws; or (c) as part of a merger, acquisition, or asset sale with notice to users.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read Google user data unless: (a) we have the user's affirmative consent for specific messages; (b) it is necessary for security purposes (e.g., investigating abuse); (c) it is necessary to comply with applicable law; or (d) the data is aggregated and anonymized for internal operations.
8.3 Google Data Storage and Security
- All Google user data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3.
- Google OAuth tokens are stored in AWS Secrets Manager with strict access controls.
- Customers may revoke Shokuin's access to their Google account at any time through their Google Account permissions settings or by disconnecting the integration within the Platform.
- Upon disconnection or account termination, Google user data is deleted in accordance with Section 12 (Data Retention and Deletion) of this Policy.
9. Meta Platform Data Policy Compliance
Shokuin integrates with Meta platforms, including Instagram and WhatsApp Business, to enable AI employees to interact with end-users on these channels.
9.1 Instagram Integration
When a customer connects their Instagram Business or Creator account, we may access:
- Basic account information (profile details, follower count)
- Posts and media (to enable AI employees to understand and reference content)
- Comments on posts (to enable AI employees to read and respond to comments)
- Direct messages (to enable AI employees to receive and respond to messages)
We use Instagram data exclusively to enable AI employee functionality as configured by the customer. We do not use Instagram data for advertising, profiling, or any purpose other than providing the Platform services.
9.2 WhatsApp Business Integration
Shokuin integrates with the WhatsApp Business API (via Meta's Cloud API) to enable AI employees to communicate with end-users via WhatsApp. Data processed includes:
- Message content (text, media, and documents sent and received)
- Sender and recipient phone numbers and WhatsApp identifiers
- Message timestamps and delivery/read status
9.3 Meta Data Use Restrictions
- We do not sell Meta platform data to any third party.
- We do not use Meta platform data for advertising or marketing purposes beyond providing the Platform services.
- We process Meta platform data solely for the purposes described in this Policy and as configured by the customer.
- We comply with all applicable Meta Platform Terms and Developer Policies.
- Customers may disconnect Meta integrations at any time. Upon disconnection, cached Meta data is deleted within 30 days.
10. Data Sharing and Sub-Processors
We do not sell your personal data. We share personal data only in the following circumstances:
10.1 Sub-Processors
We engage the following categories of sub-processors to provide the Platform:
| Sub-Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, hosting, data storage, CDN (CloudFront), email delivery (SES) | All Platform data | EU (eu-west-1, Ireland) |
| OpenAI | LLM inference for AI employees | Conversation content, knowledge base excerpts | United States |
| Anthropic | LLM inference for AI employees | Conversation content, knowledge base excerpts | United States |
| Google Cloud (Vertex AI) | LLM inference for AI employees | Conversation content, knowledge base excerpts | EU/US (per configuration) |
| Stripe | Payment processing | Billing data, payment card details | United States / EU |
| Google Analytics | Website analytics | Anonymized usage data, cookie identifiers | EU/US |
| HubSpot | Marketing analytics, CRM | Contact information, website interaction data | United States / EU |
| Sentry | Error monitoring and reporting | Technical error data, anonymized user context | United States |
We maintain Data Processing Agreements with all sub-processors. An up-to-date list of sub-processors is available upon request. We will notify customers of any material changes to our sub-processor list in advance, allowing customers to object if they have legitimate grounds.
10.2 Other Disclosures
We may also disclose personal data:
- To comply with law: When required by applicable law, regulation, legal process, or governmental request.
- To protect rights and safety: When we believe disclosure is necessary to protect the rights, property, or safety of Shokuin, our customers, or the public.
- In connection with a business transfer: If Shokuin is involved in a merger, acquisition, reorganization, or sale of assets, personal data may be transferred as part of that transaction. We will notify affected users and provide choices regarding their data.
11. International Data Transfers
Shokuin's primary data storage is located in the European Union (AWS eu-west-1, Ireland). However, some sub-processors are located in the United States, which means personal data may be transferred outside the European Economic Area (EEA).
When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs): We have executed the European Commission's Standard Contractual Clauses (2021/914) with sub-processors located outside the EEA, including supplementary measures where required by the Schrems II decision.
- EU-U.S. Data Privacy Framework: Where applicable, we rely on sub-processors' certification under the EU-U.S. Data Privacy Framework as an adequate transfer mechanism.
- Transfer Impact Assessments: We conduct transfer impact assessments to evaluate the level of data protection in the recipient country and implement additional technical and organizational measures where necessary.
You may request a copy of the relevant transfer safeguards by contacting privacy@shokuin.com.
12. Data Retention and Deletion
12.1 Retention Periods
| Data Category | Default Retention | Notes |
|---|---|---|
| Account data | Duration of account + 30 days | Retained while account is active; 30-day grace period after cancellation |
| Billing and transaction records | As required by law (typically 10 years under Romanian fiscal law) | Retained for tax and financial compliance |
| Conversation data (Processor) | Configurable (default: 12 months) | Customer may configure shorter periods; deleted 90 days after account termination |
| Analytics data | 24 months | Aggregated and anonymized where possible |
| Audit logs | 24 months | Required for security and compliance |
| Knowledge base content | Duration of account | Deleted upon account termination or disconnection of source |
12.2 Account Termination
Upon cancellation of a customer's account:
- A 30-day grace period is provided, during which the account can be reactivated and all data remains intact.
- After the grace period, all customer data, end-user conversation data, knowledge base content, and AI employee configurations are permanently deleted within 90 days.
- Data stored in encrypted backups is purged on the next backup rotation cycle (typically within 90 days).
- Customers may request immediate deletion at any time by contacting privacy@shokuin.com. We will process such requests within 30 days.
- Aggregated, anonymized analytics data that cannot be used to identify any individual may be retained beyond the deletion period for internal reporting purposes.
13. Data Security
We implement comprehensive technical and organizational measures to protect personal data, including:
13.1 Technical Measures
- Encryption in transit: All data transmitted between users, the Platform, and third-party services is encrypted using TLS 1.3.
- Encryption at rest: All stored data is encrypted using AES-256 encryption. Encryption keys are managed through AWS Key Management Service (KMS).
- Credential security: All OAuth tokens, API keys, and integration credentials are stored in AWS Secrets Manager with AES-256 encryption and strict IAM access policies. No Shokuin employee has access to stored credentials in plaintext.
- Data isolation: Tenant-level and project-level data separation enforced through row-level security. No cross-tenant data access is possible.
- DDoS protection: AWS Shield provides protection against distributed denial-of-service attacks.
13.2 Organizational Measures
- Access control: Role-based access control (RBAC) with four permission levels: Administrator, Manager, Operator, and Viewer. All access is logged.
- Audit logging: All actions on the Platform are logged with full attribution (who, what, when, where), including configuration changes, integration connections, and data access.
- Incident response: We maintain a documented incident response procedure: detection, assessment, containment, notification, and remediation. Critical security issues are acknowledged within 4 hours.
- Employee access: Access to production systems and personal data is limited to authorized personnel on a need-to-know basis.
13.3 Compliance
Shokuin designs its security practices around recognized industry standards. For current information about our security and compliance posture, please contact us.
14. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:
- Right of Access (Art. 15): You have the right to request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): You have the right to request correction of inaccurate or incomplete personal data.
- Right to Erasure (Art. 17): You have the right to request deletion of your personal data, subject to legal retention obligations.
- Right to Restriction (Art. 18): You have the right to request restriction of processing in certain circumstances.
- Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., CSV or JSON).
- Right to Object (Art. 21): You have the right to object to processing based on legitimate interests, including profiling.
- Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority. For Romania, this is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) at www.dataprotection.ro.
To exercise any of these rights, please contact us at privacy@shokuin.com. We will respond to your request within 30 days. If we need to extend this period, we will inform you within the initial 30-day period, providing the reasons for the extension.
Note for end-users of our customers: If you are an end-user interacting with an AI employee deployed by one of our customers, your personal data is controlled by that customer. Please direct any data subject requests to the business you interacted with. If the customer directs us to assist with your request, we will do so promptly.
15. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You may request information about the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to legal exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out: You have the right to opt out of the sale or sharing of your personal information. Shokuin does not sell personal information and does not share personal information for cross-context behavioral advertising.
- Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To exercise these rights, contact us at privacy@shokuin.com. We will verify your identity and respond within 45 days.
16. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website. For detailed information about the cookies we use, their purposes, and how to manage your preferences, please refer to our Cookies Policy.
In summary, we use:
- Strictly necessary cookies: Required for the Platform to function (session management, security).
- Analytics cookies: Google Analytics (with your consent) to understand how visitors use our website.
- Marketing cookies: HubSpot tracking (with your consent) for marketing analytics and lead management.
You may manage your cookie preferences at any time through the cookie consent banner on our website or through your browser settings.
Web Chat Widget: When Customers deploy Shokuin's embeddable web chat widget on their websites, the widget may set functional cookies (session identification and returning visitor recognition) on the end-user's device. These cookies are strictly necessary for the chat service to function. Customers who embed the widget are responsible for disclosing these cookies in their own cookies policies and consent mechanisms.
17. Children's Privacy
The Platform is a B2B service intended for use by businesses and their authorized representatives who are at least 18 years of age. We do not knowingly collect personal data from individuals under 18. If we become aware that we have collected personal data from a person under 18, we will take steps to delete that data promptly. If you believe a minor has provided us with personal data, please contact us at privacy@shokuin.com.
Our customers who deploy AI employees on channels accessible to the general public (e.g., website chat widgets, social media) are responsible for implementing appropriate age verification or parental consent mechanisms where required by applicable law.
18. Changes to This Privacy Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this Policy.
- Notify registered users by email at least 30 days before material changes take effect.
- Post a prominent notice on the Platform for significant changes affecting data processing.
Your continued use of the Platform after the effective date of a revised Policy constitutes your acceptance of the changes. If you do not agree with the revised Policy, you should discontinue use of the Platform and contact us to delete your account.
19. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
Shokuin S.R.L. București Sectorul 1, Strada CLUCERULUI, Nr. 35, Birou 2, Etaj PARTER, Romania
Privacy Contact: privacy@shokuin.com Security Contact: security@shokuin.com Website: https://shokuin.com
For data protection complaints in Romania, you may contact the national supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București, Romania www.dataprotection.ro