Shokuin

Privacy Policy

Shokuin S.R.L.

Effective Date: January 5, 2026. | Last Updated: February 18, 2026.


1. Introduction

This Privacy Policy (the "Policy") explains how Shokuin S.R.L. ("Shokuin," "we," "us," or "our"), a company incorporated under the laws of Romania with its registered office at București Sectorul 1, Strada CLUCERULUI, Nr. 35, Birou 2, Etaj PARTER, collects, uses, stores, shares, and protects personal data when you access or use our AI Workforce Platform available at https://shokuin.com (the "Platform").

Shokuin is a business-to-business (B2B) platform that enables organizations to hire, deploy, and manage AI employees for specific business roles. This Policy applies to all visitors, account holders, and authorized users of the Platform (collectively, "you" or "your"). In this Policy, "Customer" refers to the organization or individual who registers for an account, and "Authorized User" refers to any individual granted access to the Platform by the Customer.

We are committed to protecting your privacy and processing your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Romanian Data Protection Law No. 190/2018, and other applicable data protection legislation.

By accessing or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree with our data processing practices, please do not use the Platform.


2. Data Controller

For the purposes of the GDPR, the data controller is:

Shokuin S.R.L. București Sectorul 1, Strada CLUCERULUI, Nr. 35, Birou 2, Etaj PARTER, Romania

Privacy Contact: privacy@shokuin.com Security Contact: security@shokuin.com

Shokuin acts as the Data Controller with respect to personal data collected for account registration, billing, Platform administration, and website analytics. Shokuin acts as the Data Processor with respect to personal data processed on behalf of our business customers through AI employee interactions, including end-user conversation data and any data accessed through third-party integrations connected by our customers. The distinction between these roles is further described in Section 5.


3. Personal Data We Collect

3.1 Data We Collect Directly from You (Controller Capacity)

Account Registration Data

Platform Usage Data

Communications Data

3.2 Data We Process on Behalf of Our Customers (Processor Capacity)

When our customers deploy AI employees, those AI employees interact with the customer's end-users (e.g., the customer's clients, website visitors, or internal staff). In this context, Shokuin processes data strictly on behalf of and under the instructions of the customer. This data may include:

End-User Conversation Data

Third-Party Integration Data

When customers connect third-party services to their Shokuin account, we may access and process data from those services on the customer's behalf. The specific data accessed depends on the permissions granted by the customer during the OAuth authorization flow or API key configuration. Integrations may include:

Knowledge Base Data

Important: Shokuin does not determine the purposes or means of processing end-user data. Our customers are the Data Controllers for their end-users' personal data and are responsible for ensuring they have a lawful basis for such processing, including obtaining any required consents from their end-users.


4. Legal Bases for Processing

We process personal data on the following legal bases under Article 6(1) GDPR:

Legal BasisPurposeData Categories
Contract Performance (Art. 6(1)(b))Providing the Platform, managing your account, processing payments, delivering AI employee servicesAccount data, billing data, Platform usage data
Legitimate Interest (Art. 6(1)(f))Improving the Platform, security monitoring, fraud prevention, analytics, customer supportUsage data, log data, support communications
Legal Obligation (Art. 6(1)(c))Tax compliance, financial reporting, responding to lawful requests from authoritiesBilling data, account data, transaction records
Consent (Art. 6(1)(a))Marketing communications, non-essential cookies and analytics (Google Analytics, HubSpot tracking)Email address, cookie identifiers, browsing behavior

For data processed in our capacity as Data Processor (end-user conversation data and third-party integration data), the legal basis for processing is determined by our customer (the Data Controller). We process such data solely based on the customer's documented instructions, as set forth in our Data Processing Agreement.


5. Our Role: Data Controller vs. Data Processor

The GDPR distinguishes between Data Controllers (who determine the purposes and means of processing) and Data Processors (who process data on behalf of Controllers). Shokuin operates in both capacities depending on the type of data:

Data TypeShokuin's RoleObligations
Account registration, billing, website analytics, marketingData ControllerShokuin determines purposes and means; this Policy governs processing
End-user conversations, third-party integration data, knowledge base contentData ProcessorShokuin processes under customer instructions; governed by the Data Processing Agreement (DPA)

Business customers who use Shokuin's Platform are Data Controllers for the personal data of their end-users. We offer a Data Processing Agreement (DPA) to all customers in compliance with Article 28 GDPR. The DPA governs the processing of personal data that Shokuin carries out on behalf of the customer, including security measures, sub-processor management, breach notification obligations, data deletion, and audit rights. Customers may request a copy of the DPA by contacting privacy@shokuin.com.


6. How We Use Personal Data

6.1 In Our Controller Capacity

6.2 In Our Processor Capacity

When processing data on behalf of our customers, we use personal data solely to:

We do not: sell personal data, use end-user data for advertising or marketing purposes, use customer data to train AI models, or share end-user data with third parties except as necessary to provide the Platform services (e.g., passing conversation text to LLM providers for inference) or as instructed by the customer.


7. Artificial Intelligence and Large Language Model Processing

Shokuin's AI employees are powered by large language models (LLMs) provided by third-party providers, including OpenAI, Anthropic, and Google. Each AI employee may use a different LLM provider, as configured by the customer.

7.1 How LLM Processing Works

When an end-user sends a message to an AI employee, the following data processing occurs:

7.2 LLM Provider Data Handling

We have entered into Data Processing Agreements with our LLM providers. Under these agreements:

7.3 AI Transparency

We require our customers to inform their end-users that they are interacting with an AI employee, in compliance with the EU AI Act (Regulation (EU) 2024/1689) and applicable transparency requirements. Shokuin provides configurable disclosure messages to support this obligation. Customers bear the responsibility of ensuring appropriate disclosure is made to their end-users.


8. Google API Services User Data Policy Compliance

Shokuin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

8.1 Google Data We Access

When a customer connects their Google account to the Platform, we request access to the following scopes based on the customer's selected integrations:

8.2 Limited Use Compliance

Shokuin strictly complies with Google's Limited Use Requirements:

8.3 Google Data Storage and Security


9. Meta Platform Data Policy Compliance

Shokuin integrates with Meta platforms, including Instagram and WhatsApp Business, to enable AI employees to interact with end-users on these channels.

9.1 Instagram Integration

When a customer connects their Instagram Business or Creator account, we may access:

We use Instagram data exclusively to enable AI employee functionality as configured by the customer. We do not use Instagram data for advertising, profiling, or any purpose other than providing the Platform services.

9.2 WhatsApp Business Integration

Shokuin integrates with the WhatsApp Business API (via Meta's Cloud API) to enable AI employees to communicate with end-users via WhatsApp. Data processed includes:

9.3 Meta Data Use Restrictions


10. Data Sharing and Sub-Processors

We do not sell your personal data. We share personal data only in the following circumstances:

10.1 Sub-Processors

We engage the following categories of sub-processors to provide the Platform:

Sub-ProcessorPurposeData ProcessedLocation
Amazon Web Services (AWS)Cloud infrastructure, hosting, data storage, CDN (CloudFront), email delivery (SES)All Platform dataEU (eu-west-1, Ireland)
OpenAILLM inference for AI employeesConversation content, knowledge base excerptsUnited States
AnthropicLLM inference for AI employeesConversation content, knowledge base excerptsUnited States
Google Cloud (Vertex AI)LLM inference for AI employeesConversation content, knowledge base excerptsEU/US (per configuration)
StripePayment processingBilling data, payment card detailsUnited States / EU
Google AnalyticsWebsite analyticsAnonymized usage data, cookie identifiersEU/US
HubSpotMarketing analytics, CRMContact information, website interaction dataUnited States / EU
SentryError monitoring and reportingTechnical error data, anonymized user contextUnited States

We maintain Data Processing Agreements with all sub-processors. An up-to-date list of sub-processors is available upon request. We will notify customers of any material changes to our sub-processor list in advance, allowing customers to object if they have legitimate grounds.

10.2 Other Disclosures

We may also disclose personal data:


11. International Data Transfers

Shokuin's primary data storage is located in the European Union (AWS eu-west-1, Ireland). However, some sub-processors are located in the United States, which means personal data may be transferred outside the European Economic Area (EEA).

When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, including:

You may request a copy of the relevant transfer safeguards by contacting privacy@shokuin.com.


12. Data Retention and Deletion

12.1 Retention Periods

Data CategoryDefault RetentionNotes
Account dataDuration of account + 30 daysRetained while account is active; 30-day grace period after cancellation
Billing and transaction recordsAs required by law (typically 10 years under Romanian fiscal law)Retained for tax and financial compliance
Conversation data (Processor)Configurable (default: 12 months)Customer may configure shorter periods; deleted 90 days after account termination
Analytics data24 monthsAggregated and anonymized where possible
Audit logs24 monthsRequired for security and compliance
Knowledge base contentDuration of accountDeleted upon account termination or disconnection of source

12.2 Account Termination

Upon cancellation of a customer's account:


13. Data Security

We implement comprehensive technical and organizational measures to protect personal data, including:

13.1 Technical Measures

13.2 Organizational Measures

13.3 Compliance

Shokuin designs its security practices around recognized industry standards. For current information about our security and compliance posture, please contact us.


14. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:

To exercise any of these rights, please contact us at privacy@shokuin.com. We will respond to your request within 30 days. If we need to extend this period, we will inform you within the initial 30-day period, providing the reasons for the extension.

Note for end-users of our customers: If you are an end-user interacting with an AI employee deployed by one of our customers, your personal data is controlled by that customer. Please direct any data subject requests to the business you interacted with. If the customer directs us to assist with your request, we will do so promptly.


15. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

To exercise these rights, contact us at privacy@shokuin.com. We will verify your identity and respond within 45 days.


16. Cookies and Tracking Technologies

We use cookies and similar tracking technologies on our website. For detailed information about the cookies we use, their purposes, and how to manage your preferences, please refer to our Cookies Policy.

In summary, we use:

You may manage your cookie preferences at any time through the cookie consent banner on our website or through your browser settings.

Web Chat Widget: When Customers deploy Shokuin's embeddable web chat widget on their websites, the widget may set functional cookies (session identification and returning visitor recognition) on the end-user's device. These cookies are strictly necessary for the chat service to function. Customers who embed the widget are responsible for disclosing these cookies in their own cookies policies and consent mechanisms.


17. Children's Privacy

The Platform is a B2B service intended for use by businesses and their authorized representatives who are at least 18 years of age. We do not knowingly collect personal data from individuals under 18. If we become aware that we have collected personal data from a person under 18, we will take steps to delete that data promptly. If you believe a minor has provided us with personal data, please contact us at privacy@shokuin.com.

Our customers who deploy AI employees on channels accessible to the general public (e.g., website chat widgets, social media) are responsible for implementing appropriate age verification or parental consent mechanisms where required by applicable law.


18. Changes to This Privacy Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

Your continued use of the Platform after the effective date of a revised Policy constitutes your acceptance of the changes. If you do not agree with the revised Policy, you should discontinue use of the Platform and contact us to delete your account.


19. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

Shokuin S.R.L. București Sectorul 1, Strada CLUCERULUI, Nr. 35, Birou 2, Etaj PARTER, Romania

Privacy Contact: privacy@shokuin.com Security Contact: security@shokuin.com Website: https://shokuin.com


For data protection complaints in Romania, you may contact the national supervisory authority:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București, Romania www.dataprotection.ro