Legal centre

Privacy Policy

How SOCIOS A.I USA LLC collects, uses, shares and protects personal data on the Negoc.IA platform, including the merchants' end customers' data processed on their behalf, in line with the GDPR and the other data protection laws that apply where you operate.

Updated on 2026-08-01

Controller

SOCIOS A.I USA LLC

Privacy contact

socio@sociosai.com

We do not sell data

No personal data is sold or shared for third-party advertising

Deletion

Requests answered within 15 days

1. Who is responsible for your data

For your account, billing and platform usage data, the controller is SOCIOS A.I USA LLC, with its registered office at 7550 Futures Drive, Suite 204, Orlando, FL 32819, United States.

Contact channel for any privacy matter: socio@sociosai.com.

For your end customers' data (name, phone, email, carts, orders and the content of conversations), you, the merchant, are the controller: you decide the purposes and means of the processing. The platform acts as processor and handles that data strictly on your instructions.

It is your responsibility to have a valid legal basis to contact your customers and to instruct us to process their data, including when you connect your store or import lists.

2. Data we process

We process only what is needed to run the sales recovery service, charge for the service and meet legal obligations.

  • Merchant account data: name, email, phone, access credentials, language, time zone and, for companies, legal name and tax identification.
  • Billing data: plan, invoice history and the transaction identifiers issued by the payment processor, which is PCI DSS certified. We do not store full card numbers.
  • End customer data, processed on behalf of the merchant: name, phone, email, abandoned carts, orders, purchase history, subscription status and the content of conversations across WhatsApp, SMS and email.
  • Usage data: access logs, IP address, session identifier, browser and actions taken in the dashboard.
  • Support data: messages, attachments and ticket history.

3. Why we use data and on what legal basis

Each processing activity has a specific purpose and a matching legal basis among those recognised by applicable data protection law.

For end customer data, the purposes are defined by you, the merchant, within the limits of the service: recovering abandoned carts, following up after the sale, reactivating subscribers and sending email marketing campaigns.

  • Performance of the contract: creating and maintaining your account, sending the recovery, follow-up and reactivation messages you configure, personalising messages with AI, processing payments and providing support.
  • Legal or regulatory obligation: tax documents, retention of access logs for the period required by applicable law and responses to competent authorities.
  • Legitimate interest: platform security, fraud and abuse prevention, aggregate product metrics and usability improvements.
  • Consent: non-essential cookies and marketing communications. Consent can be withdrawn at any time.

4. Artificial intelligence features

AI personalisation is at the core of the service: it tailors cart recovery, post-sale follow-up, subscriber reactivation and email marketing messages to each end customer's context, always on the merchant's behalf.

To generate the messages, the relevant cart, order and conversation content is sent to AI model providers only at the moment an AI feature runs. These providers are contractually barred from using the content to train models.

Your store's data feeds only your account's AI: it is not used to train our own models and is not shared with other merchants.

5. Connected channels and integrations

Messages are sent through the channels you enable: WhatsApp through the official WhatsApp Business API, SMS and email.

E-commerce integrations connect your store to the platform with your authorisation. We receive only the data needed to deliver the contracted features: carts, orders and your end customers' contact data.

Data obtained through Meta APIs, including the WhatsApp Business API, is handled in accordance with the Meta Platform Terms and Developer Policies. We do not use it for advertising, external profiling or resale.

You can revoke access at any time by disconnecting the channel or integration in the dashboard or in the provider's own settings.

6. Who we share data with

We do not sell personal data. We share only what is necessary and always under a data protection agreement.

The complete and current list of subprocessors, with each one's purpose and our advance notice of changes, is published on this site's Subprocessors page.

  • Providers of infrastructure, managed database and authentication, message delivery, transactional email, storage and payment processing.
  • AI model providers, only when an AI feature runs, as described in section 4.
  • Providers of the channels you enable and the e-commerce integrations you connect, to the extent needed to send and receive messages, carts and orders.
  • Public authorities, when there is a substantiated legal request.
  • Third parties in a corporate transaction, with prior notice and the same safeguards maintained.

7. International transfers

Our infrastructure and AI providers may operate in a country other than yours. In those cases we apply appropriate contractual safeguards, including the European Commission's Standard Contractual Clauses where the GDPR applies.

8. How long we keep data

We keep data for as long as the purposes above and legal deadlines require.

  • Account data: while the account is active. After cancellation or the end of the trial period, data is kept for 90 days to allow reactivation and, after that period, can be permanently deleted on request.
  • End customer data: for as long as you, the merchant, determine. You can export this data at any time and request the deletion of specific records or of the entire base; when the account is permanently deleted, this data is erased with it.
  • Access logs: 6 months, or the longer period required by applicable law.
  • Tax and billing documents: for the period required by applicable tax law.
  • Channel and integration credentials and tokens: revoked immediately on disconnection.

9. Your rights

As a data subject you have the rights below, recognised by the GDPR and equivalent laws. Write to socio@sociosai.com and we will respond within 15 days.

If you are a customer of a store that uses the platform, please direct your request first to that store, which is the controller of your data; we will support the handling of the request according to its instructions and applicable law.

  • Confirmation that processing exists, and access to the data.
  • Correction of incomplete, inaccurate or outdated data.
  • Anonymisation, blocking or deletion of unnecessary or non-compliant data.
  • Portability of your data to another provider.
  • Deletion of data processed on the basis of consent.
  • Information about data sharing and about your option to refuse consent.
  • Withdrawal of consent and objection to processing based on legitimate interest.

To delete your account and data, follow the Data Deletion Instructions. You may also lodge a complaint with the competent data protection authority in your country.

10. Security

We apply technical and organisational measures proportionate to the risk: encryption in transit (TLS), encryption of credentials and tokens at rest, managed database and authentication, role-based access control, data isolation between accounts, audit logging and regular backups.

In the event of a security incident involving relevant risk, we will notify you and the competent authority within the deadlines required by applicable law.

11. Children and teenagers

The platform is not intended for people under 18 and we do not knowingly collect data about children or teenagers. Where identified, such data will be deleted.

12. Cookies

We use strictly necessary cookies for authentication and session, preference cookies (theme and language) and first-party attribution cookies for the partner programme. Details and controls are on the Cookie Policy page.

13. Updates to this policy

We may update this Policy. Material changes are announced by email or through a dashboard notice before they take effect. The last update date is shown at the top of this page.

SOCIOS A.I USA LLC · 7550 Futures Drive, Suite 204, Orlando, FL 32819, United States

Questions about this document? Write to socio@sociosai.com