Data Protection
Last updated: September 20, 2026
Our Commitment to Data Protection
At Soso Career AI, we are committed to protecting your personal information and respecting your right to privacy. This Data Protection Policy explains how we handle, store, and protect your information in compliance with:
- •South Africa's Protection of Personal Information Act 4 of 2013 (POPIA)
- •The European Union's General Data Protection Regulation (EU) 2016/679 (GDPR)
We believe transparency is essential, and we strive to give you full control over your personal information at all times.
Data Protection Principles
We process your personal information in accordance with the eight conditions for lawful processing under POPIA and the six principles under GDPR Article 5:
- •Lawfulness, Fairness, and TransparencyWe process personal information lawfully, fairly, and in a transparent manner, always disclosing our purposes at the point of collection.
- •Purpose Limitation (Specification)We collect personal information only for specified, explicit, and legitimate purposes, and do not process it in a manner incompatible with those purposes.
- •Data Minimisation (Minimality)We collect only the personal information that is adequate, relevant, and necessary for the stated purpose.
- •AccuracyWe take reasonable steps to ensure personal information is accurate, complete, and kept up to date where necessary.
- •Storage Limitation (Retention)We retain personal information only for as long as necessary to fulfil the collection purpose or as required by law.
- •Integrity and Confidentiality (Security)We protect personal information with appropriate technical and organisational security measures against loss, damage, or unauthorised access.
- •AccountabilityWe are responsible for compliance with these principles and can demonstrate compliance when required.
Your Data Protection Rights
Under POPIA (South Africa)
Right to be Notified
You have the right to be informed when your personal information is being collected and the purpose for which it is collected.
Right of Access
You may request confirmation of whether we hold personal information about you and obtain a copy of that information.
Right to Correction or Deletion
You may request that we correct or delete personal information that is inaccurate, irrelevant, excessive, out of date, or misleading.
Right to Object
You have the right to object to the processing of your personal information on reasonable grounds relating to your particular situation.
Right to Lodge a Complaint
You may lodge a complaint with the Information Regulator of South Africa if you believe your rights under POPIA have been infringed (see contact details below).
Under GDPR (EU / EEA)
Right of Access (Article 15)
You may request copies of your personal data along with information on how it is being processed.
Right to Rectification (Article 16)
You have the right to request correction of inaccurate personal data and to complete incomplete data.
Right to Erasure (Article 17)
You have the right to request deletion of your personal data where it is no longer necessary, where you withdraw consent, or where processing is unlawful.
Right to Restriction of Processing (Article 18)
You may request that we restrict processing of your personal data in certain circumstances, such as while contesting its accuracy.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly-used, machine-readable format and to transmit it to another controller.
Right to Object (Article 21)
You have the right to object to processing based on legitimate interests or for direct marketing purposes at any time.
Rights Related to Automated Decision-Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on you.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
How to Exercise Your Rights
To exercise any of your data protection rights, please:
- •Contact our Information Officer at privacy@sosocareerai.com with the subject line Data Subject Request
- •Clearly state which right you wish to exercise
- •Provide sufficient information to allow us to verify your identity
We will respond to your request within 30 days of receipt. Where a request is complex or we receive a high volume of requests, we may extend this period by a further two months and will notify you of the extension and reasons within the initial 30-day period.
Data Security Measures
We implement comprehensive technical and organisational measures to protect your personal information, including:
- •Encryption of data in transit (TLS) and at rest
- •Role-based access controls and multi-factor authentication
- •Regular security audits and vulnerability assessments
- •Staff training on data protection obligations
- •Incident response and breach notification procedures
- •Data Processing Agreements with all third-party service providers
Data Breach Notification
In the event of a personal information breach that is likely to result in a risk to your rights and freedoms, we will:
- •GDPR: Notify the relevant supervisory authority within 72 hours of becoming aware of the breach
- •POPIA: Notify the Information Regulator and affected data subjects as soon as reasonably possible
- •Provide clear information about the nature, scope, and likely consequences of the breach
- •Describe the measures taken or proposed to address the breach and mitigate its effects
Cross-Border Transfers of Personal Information
Your personal information may be transferred to and processed in countries outside South Africa or the European Economic Area (EEA) — for example, via cloud infrastructure and AI API providers. When such transfers occur, we ensure appropriate safeguards are in place:
- •POPIA (Section 72): Transfers outside South Africa are made only to countries with adequate protection, or under binding contractual obligations that uphold equivalent standards.
- •GDPR (Chapter V): Transfers outside the EEA are made under Standard Contractual Clauses (SCCs) approved by the European Commission, or to countries with an adequacy decision.
- •All third-party processors are bound by Data Processing Agreements that require equivalent levels of data protection.
Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, including:
- •Delivering and improving our career coaching services
- •Complying with applicable legal and regulatory obligations
- •Resolving disputes and enforcing our agreements
Upon account deletion, we will securely delete or anonymise your personal information within 30 days, unless a longer retention period is required by applicable law.
Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected information from a minor, please contact us immediately at privacy@sosocareerai.com and we will take prompt steps to delete it.
South Africa — POPIA Compliance
In terms of POPIA, Soso Career AI acts as the Responsible Party when processing your personal information. We adhere strictly to all eight lawful processing conditions outlined in Chapter 3 of POPIA:
- •Accountability: We have appointed a dedicated Information Officer responsible for ensuring compliance with POPIA across all processing activities.
- •Processing Limitation: Personal information is processed only with your knowledge or consent, or where another lawful ground applies.
- •Purpose Specification & Minimisation: We collect only the data needed to personalise your career coaching and generate professional documents.
- •Right of Access & Correction: You can view, edit, or update your profile details at any time via your Account Profile page.
- •Right to Erasure: You may request full deletion of your account and associated data by contacting our Information Officer.
- •Cross-Border Transfers: Any transfer outside South Africa is made under binding contractual obligations requiring equivalent data protection standards, in accordance with Section 72 of POPIA.
EU / EEA — GDPR Compliance
For users in the EU and EEA, Soso Career AI acts as the Data Controller under the GDPR. Key commitments include:
- •Lawful basis for all processing: Every processing activity is mapped to a lawful basis under GDPR Article 6 (and Article 9 for any special categories of data).
- •Data Protection by Design and Default: Privacy considerations are embedded into our product development process from the outset.
- •Records of Processing Activities (ROPA): We maintain internal records of all processing activities as required by GDPR Article 30.
- •Data Processing Agreements: All third-party processors are bound by GDPR-compliant Data Processing Agreements under Article 28.
Supervisory Authorities
You have the right to lodge a complaint with the relevant supervisory authority:
Information Regulator (South Africa) — POPIA
Website: www.justice.gov.za/inforeg
Complaints: POPIAComplaints@inforegulator.org.za
General enquiries: enquiries@inforegulator.org.za
EU / EEA Data Protection Supervisory Authorities — GDPR
A full list of EU/EEA supervisory authorities is available from the European Data Protection Board at edpb.europa.eu. Please contact the authority in your country of residence or establishment.
Contact Our Information Officer
For any questions about data protection, to exercise your rights under POPIA or GDPR, or to raise a concern, please contact our Information Officer / Data Protection Officer:
Email: privacy@sosocareerai.com
Subject line: Data Subject Request