Legal
OverviewTerms of ServiceAcceptable Use PolicyAI TermsPrivacy PolicyRefund PolicyData Processing AddendumSub-processorsService Level AgreementCookies StatementData Act AddendumTrust CenterBourbon Science Inc.
Bourbon Science Inc., a Delaware corporation trading as Zoko ("Zoko", "we", "our", "us"), takes the privacy of the people whose data we handle seriously. This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have.
This Policy covers two different groups, and it is important to know which applies to you:
This Policy forms part of the Zoko Terms of Service. Processing carried out on behalf of our customers is governed by the Data Processing Addendum. Our use of cookies is described in the Cookies Statement.
Age. The Services are sold to businesses and are not directed at children. Section 8 of the Terms of Service requires every user of a Zoko Account to be at least 18 years old, or the age of majority where they live if that is higher. We do not knowingly collect personal data from anyone under 18 in connection with an Account. If you believe someone under 18 has registered or provided us with personal data, contact contact@zoko.io and we will delete it.
Separately, the people our customers message may be of any age. Zoko processes their data as a processor on the customer's instructions and does not control who is messaged. Responsibility for age-appropriate communication, for any age verification the law requires, and for not marketing age-restricted goods or services to minors rests with the customer, under Section 5 of the Terms of Service and Sections 2 and 9 of the Acceptable Use Policy.
When you connect a third-party service, we receive data from it as needed to provide the Services. This typically includes your WhatsApp Business Account and phone number details, business profile, message templates and their status, and conversation content; and from Shopify, your store details, product catalogue, customer records, and order data. What we receive is determined by the permissions you grant and by that platform's own rules.
On behalf of our customers, we process the contact details, message content, attachments, conversation metadata, order and cart data, tags and segments, and consent records of the people they message. We process this as a processor, on the customer's instructions, under the Data Processing Addendum. We do not use it for our own purposes, do not sell it, and do not use it to build profiles or advertise to those individuals.
| Purpose | Legal basis (UK and EU GDPR) |
|---|---|
| Providing the Services, operating your Account, and delivering messages you send | Performance of a contract |
| Billing, collections, and tax records | Contract, and legal obligation |
| Support, onboarding, and service notices such as outage alerts and billing reminders | Contract, and legitimate interests in supporting our customers |
| Securing the platform, preventing fraud and abuse, and enforcing our terms | Legitimate interests in protecting the Services, our customers, and the public |
| Maintaining, troubleshooting, and improving the Services, including aggregated analytics | Legitimate interests in operating and improving our product |
| Marketing to business contacts about our own products | Legitimate interests, or consent where required by local law |
| Non-essential cookies and analytics on our website | Consent |
| Complying with law, responding to lawful requests, and establishing or defending legal claims | Legal obligation, and legitimate interests |
Where we rely on legitimate interests, we have considered whether those interests are outweighed by the rights of the individuals concerned. You may object to that processing as described in Section 8.
We do not sell personal data, and we do not share it for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act.
We create aggregated and anonymised statistics from the operation of the Services, for example benchmark response and conversion rates, delivery and read rates, and feature adoption across our customer base. This data is created so that it does not identify, and cannot reasonably be used to identify, any customer, end user, or individual, and does not reveal the content of any message. We use it for product development, benchmarking, research, and marketing. Section 4.1 of the Terms of Service governs this.
Zoko is established in the United States and our sub-processors are located in the United States and elsewhere. Where we transfer personal data out of the United Kingdom, the European Economic Area, or another jurisdiction with transfer restrictions, we rely on an appropriate safeguard, which is ordinarily the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer risk assessment and appropriate technical measures.
You can request details of the safeguard applying to a particular transfer by contacting contact@zoko.io.
| Category | Retention |
|---|---|
| Account and profile data | For the life of the Account, then deleted in the ordinary course after closure |
| Customer Content, including conversations and contacts | For the life of the Account, subject to any retention period you configure, then deleted after the export window in Section 12 of the Terms of Service |
| Billing and tax records | As required by tax and accounting law, ordinarily seven years |
| Support correspondence | For as long as needed to resolve the matter and to handle any related query or claim, then deleted in the ordinary course |
| Security, audit, and access logs | For as long as needed for security monitoring, incident investigation, and compliance, then deleted in the ordinary course |
| Aggregated and anonymised data | Indefinitely, as it no longer identifies anyone |
If an Account is inactive for eighteen consecutive months we may notify you and, if you do not respond within thirty days, close it and delete its data. We may retain data for longer where we are required to by law or where it is needed to establish or defend a legal claim.
Depending on where you are, you may have the right to access your personal data, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable format, to withdraw consent, and not to be discriminated against for exercising these rights. Residents of the European Economic Area and the United Kingdom have these rights under the GDPR and UK GDPR; residents of California, Brazil, and other jurisdictions have comparable rights under their local law.
To exercise a right, contact contact@zoko.io. We will respond within the period required by applicable law, ordinarily one month. We may need to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.
If you are unhappy with how we have handled your data, you may complain to your local supervisory authority. In the United Kingdom that is the Information Commissioner's Office; in the European Economic Area it is the authority in your country of residence. We would appreciate the chance to address your concern first.
If a business contacted you on WhatsApp using Zoko, that business decided to message you, holds your contact details, and is the controller of your data. Zoko only carries the message on its behalf.
To stop receiving messages, reply to the business directly with STOP, or use whatever opt-out method the message offers. To access, correct, or delete your data, contact that business. If you are not sure who they are or cannot reach them, contact us at contact@zoko.io and we will pass your request to the relevant customer and support them in responding, which is what the Data Processing Addendum requires of us. We cannot action the request ourselves without that customer's instruction, because the data is theirs.
If you believe a business is misusing the platform, you can report it under Section 11 of the Acceptable Use Policy.
We operate an information security management system aligned to ISO 27001 v2022, including encryption in transit and at rest, access control on a least-privilege basis, logging and monitoring, vulnerability management, and personnel confidentiality obligations. Current detail is published in our Trust Center at https://zoko.trust.site/.
Notice of a security breach. If a security incident results in unauthorised access to personal data for which Zoko is the controller, and it is likely to result in a risk to your rights and freedoms, we will notify you without undue delay after becoming aware of it. That notice will describe the nature of the breach, the measures taken to mitigate its effects, and the steps we have taken to prevent recurrence. Where Zoko processes personal data on a customer's behalf, notification is handled under Section 8 of the Data Processing Addendum and the customer is responsible for notifying the individuals concerned.
No system is completely secure. You are responsible for safeguarding your own credentials and for the security obligations in Section 2.2 of the Terms of Service, including notifying us promptly of any suspected compromise.
This Section applies if you are a resident of California, or of another US state with a comprehensive privacy law such as Virginia, Colorado, Connecticut, Utah, or Texas. It supplements the rights in Section 8.
In the twelve months before the date of this Policy, we have collected the categories of personal data described in Section 2, namely identifiers such as name, email address, phone number, and IP address; commercial information such as subscription and transaction records; internet and network activity such as usage and device data; and the content you create or submit through the Services. We collect these from the sources described in Section 2 and use them for the purposes described in Section 3.
We disclose these categories for business purposes to the providers listed in our Sub-processor List, and to the other recipients described in Section 5.
ZOKO DOES NOT SELL PERSONAL DATA, AND DOES NOT SHARE PERSONAL DATA FOR CROSS-CONTEXT BEHAVIOURAL ADVERTISING, AS THOSE TERMS ARE DEFINED UNDER THE CALIFORNIA CONSUMER PRIVACY ACT. WE HAVE NOT SOLD OR SHARED PERSONAL DATA IN THE TWELVE MONTHS BEFORE THE DATE OF THIS POLICY. WE DO NOT KNOWINGLY SELL OR SHARE THE PERSONAL DATA OF ANYONE UNDER 16.
We do not collect sensitive personal information for the purpose of inferring characteristics about you, and we do not use or disclose it beyond the purposes permitted without a right to limit. Please do not submit sensitive personal information to the Services.
Subject to your state's law, you may request to know the personal data we hold about you and how we use and disclose it, request a copy in a portable format, request correction or deletion, opt out of any sale, sharing, or targeted advertising, limit the use of sensitive personal information, and opt out of profiling that produces legal or similarly significant effects. Submit a request to contact@zoko.io. We will verify your identity before responding, and will respond within the period your state's law requires.
Authorised agents. You may use an authorised agent to submit a request. We may ask the agent for proof of your written permission and may ask you to verify your identity directly.
Appeals. If we decline a request, you may appeal by replying to our decision with the subject line "Privacy Appeal". We will respond with our decision and reasons within the period your state's law requires. If your appeal is denied you may contact your state attorney general.
We will not discriminate against you for exercising these rights. We will not deny you goods or services, charge different prices or rates, provide a different level or quality of service, or suggest that you will receive a different price or level of service, except as permitted by law.
Some browsers transmit a Do Not Track signal. Because no common industry standard for these signals has been adopted, we do not currently alter our practices when we receive one. You can manage cookies and tracking through our cookie preferences tool and the controls described in our Cookies Statement.
ZOKO IS GDPR COMPLIANT. OUR COMPLIANCE STATUS IS PUBLISHED AND CONTINUOUSLY MONITORED IN OUR TRUST CENTER.
The General Data Protection Regulation is the comprehensive data protection law of the European Union, and governs how organisations must protect personal data and privacy. It applies to Zoko both as a controller of our own customer and website data, and as a processor of the end user data our customers handle.
The table below maps each principal obligation to where it is met in this Policy and in our Data Processing Addendum. The internal policies, controls, and evidence behind it are published in our Trust Center, described in Section 13.
| Requirement | How we meet it |
|---|---|
| Lawful basis for processing | Set out for each purpose in Section 3. We rely on contract, legal obligation, legitimate interests, or consent, depending on the purpose. |
| Transparency | This Policy, our Cookies Statement, and our Sub-processor List, all published and kept current. |
| Controller and processor roles | Defined in Section 1. Zoko is controller for its own customer and website data, and processor for the end user data its customers handle. |
| Processor obligations (Article 28) | The Data Processing Addendum, which applies automatically to every customer and requires processing only on documented instructions. |
| Data subject rights | Section 8 for data we control. Section 9 explains how requests reach the right party where a customer is the controller, and Section 7 of the Data Processing Addendum sets out the assistance we give. |
| Security (Article 32) | Section 10 of this Policy and Section 4 of the Data Processing Addendum. We are ISO 27001 v2022 compliant, and our controls are documented in our Trust Center. |
| Personal data breaches (Articles 33 and 34) | Section 10 of this Policy for data we control, and Section 8 of the Data Processing Addendum where we process on a customer's behalf. |
| International transfers (Chapter V) | Section 6 of this Policy and Section 6 of the Data Processing Addendum, using the Standard Contractual Clauses and the UK International Data Transfer Addendum. |
| Sub-processors (Article 28(2) and (4)) | General written authorisation, a published list, and thirty days' notice of changes with a right to object. |
| Storage limitation | Section 7, which sets out how long each category is kept. |
| Data protection by design | Controls available to customers for consent capture, opt-out handling, retention, and access management, described in the Terms of Service. |
| Records of processing (Article 30) | We maintain records of processing activities and data flow maps, listed in our Trust Center and available to customers on request. |
| Assistance with impact assessments | Section 3 of the Data Processing Addendum. |
| Automated decision-making (Article 22) | Restricted under Section 10 of the Zoko AI Terms. |
| Portability and switching | Section 12 of the Terms of Service, and for EU customers the Data Act Addendum. |
Where Zoko acts as processor, our customers remain the controllers of their end users' personal data. They are responsible for having a lawful basis and any required consent, for providing privacy notices to the people they message, for honouring opt-outs and data subject requests, and for deciding what data they send to the Services and to any platform they connect. Sections 5 and 8 of the Terms of Service set out those obligations, and the Data Processing Addendum governs the relationship.
For any data protection question, to exercise a right, to request our Data Processing Addendum, or to raise a concern, write to contact@zoko.io with the subject line "Data protection". We will route your request to the person responsible.
You may also complain to your local supervisory authority, as described in Section 8.
ISO 27001 v2022: COMPLIANT.
Zoko recognises that the confidentiality, integrity, and availability of the information and data we create, maintain, and host are vital to the success of our business and to the privacy of our partners. We operate an information security management system aligned to ISO 27001 v2022, monitored continuously, and covering data security, network security, application security, endpoint security, and corporate security.
We publish our security posture, compliance status, controls, and documentation in our Trust Center at https://zoko.trust.site/. It is the authoritative and current source for all of it, and we encourage you to review it before and during your use of the Services.
What you will find there:
To request access to a document that is not publicly viewable, use the request access option in the Trust Center, or write to contact@zoko.io.
We may update this Policy from time to time. We will change the effective date at the top, and where changes are material we will notify you by email or in-product notice before they take effect.
This document forms part of the Zoko Terms of Service and is governed by the laws of the State of Delaware, USA, in accordance with Section 24 of those Terms. Disputes follow the escalation path and arbitration provisions in Sections 23 and 24 of the Terms of Service.
Bourbon Science Inc., trading as Zoko
Attn: Privacy
8080 Westpark Drive, STE 50836
Houston, TX 77063, USA
Email: contact@zoko.io