← Back to Home

Privacy Policy

Last updated: October 2026

1. Introduction and Scope

This Privacy Policy ("Policy") describes how Hokto ("Hokto", "we", "us", or "our") collects, uses, processes, and discloses your personal data when you access or use our website located at hokto.app, our AI workflow automation platform, integrations, APIs, and any related services (collectively, the "Services"). By accessing or using the Services, you acknowledge that you have read, understood, and agree to the practices described in this Policy. If you do not agree with this Policy, you must not use our Services. This Policy applies to all users of the Services, including customers, end-users, and website visitors. Where Hokto processes personal data on behalf of a customer (e.g., data from a customer's CRM, ERP, or other connected third-party tools), Hokto acts as a Data Processor under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the Serbian Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti, "ZZPL"). Such processing is governed by our Data Processing Addendum (DPA) and Master Subscription Agreement, which take precedence over this Policy in the event of a conflict.

2. Information We Collect

We collect information about you in three primary ways: information you provide directly to us, information collected automatically through your use of the Services, and information we receive from third parties.

A. Information You Provide Directly:
- Account Information: Name, email address, physical address, phone number, company name, job title, and login credentials.
- Payment Information: Billing details, credit card information (processed directly by our PCI-compliant third-party payment processors such as Stripe), and tax identification numbers.
- Communications: Information you provide when contacting our support team, participating in surveys, or subscribing to our newsletters.
- AI Inputs and Prompts: Text, instructions, or configurations you input into our autonomous AI agents to build or execute workflows.

B. Information Collected Automatically:
- Device and Usage Data: IP addresses, browser types, operating systems, referring URLs, pages viewed, and access times. We monitor how you interact with our Services, including workflow execution logs, error rates, and API call volumes.
- Cookies and Tracking Technologies: We use cookies, web beacons, and similar technologies to maintain session state, authenticate users, and analyze platform performance.

C. Information from Third Parties (Integrations):
- Connected Accounts: When you integrate Hokto with third-party platforms (e.g., Salesforce, HubSpot, SAP, Google Workspace, Microsoft 365, or custom APIs), we access and ingest data according to the OAuth scopes and permissions you grant. This includes CRM records, emails, financial data, and metadata necessary for the AI to perform automated tasks. We only pull data explicitly required by the workflows you configure.

3. How We Process and Use Your Information

Hokto uses your data to provide, secure, and improve our Services. Specifically, we process your information for the following purposes:
- Service Delivery: To authenticate you, operate our platform, execute automated workflows across your connected systems, and provide customer support.
- Billing and Administration: To process payments, manage your account lifecycle, and send administrative notices (e.g., changes to our Terms of Service).
- Platform Improvement and Analytics: To analyze usage trends, troubleshoot bugs, and optimize the performance of our infrastructure.
- Security and Fraud Prevention: To detect anomalous activity, prevent malicious attacks, and ensure the integrity of our Services.
- AI and Machine Learning: To interpret prompts and execute autonomous tasks using large language models (LLMs).

Important Notice on AI Training: Hokto prioritizes your data privacy. By default, we do not use your CRM data, API inputs, workflow outputs, or proprietary business data to train our foundational AI models. We utilize zero-retention API endpoints with our enterprise LLM providers (e.g., OpenAI, Anthropic) where available, ensuring your data is not logged or used for their model training. Any opt-in for product improvement utilizing anonymized workflow telemetry requires explicit, separate consent from the organization administrator.

4. Legal Bases for Processing (EEA, UK, Switzerland, and Serbia)

If you are located in the EEA, the UK, Switzerland, or the Republic of Serbia, our legal basis for collecting and using the personal data described above will depend on the context in which we collect it. We process personal data under the following lawful bases, including Article 12 of the ZZPL: Contractual Necessity (to perform our obligations under our Master Subscription Agreement or Terms of Service); Legitimate Interests (provided those interests are not overridden by your data protection rights); Consent (which you may withdraw at any time); and Legal Obligation.

5. How We Share and Disclose Data

We do not sell your personal data. We only share your information in the following circumstances:
- Subprocessors and Service Providers: We use trusted third-party vendors to support our business, including cloud infrastructure hosting (e.g., AWS, Google Cloud), LLM providers (e.g., OpenAI, Anthropic), payment processing, and email delivery. These subprocessors are strictly bound by written agreements requiring them to provide at least the same level of data protection as mandated by this Policy and applicable laws.
- Connected Integrations: To execute your automated workflows, Hokto will push and pull data to and from the third-party platforms (CRMs, ERPs) you have authorized. You are responsible for ensuring that your use of these integrations complies with the third parties' respective terms and privacy policies.
- Corporate Restructuring: In the event of a merger, acquisition, bankruptcy, dissolution, or sale of all or a portion of our assets, your information may be transferred as part of the transaction, subject to standard confidentiality arrangements.
- Legal and Safety: We may disclose your information if required to do so by law, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Hokto, our users, or the public.

6. Data Retention and Deletion

We retain personal data only for as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by law.
- Customer Accounts: Account information is retained for the duration of your active subscription and for a brief grace period thereafter to facilitate potential reactivation.
- Workflow Data and Logs: Operational data, API payloads, and execution logs processed by our AI agents are retained for a maximum of 30 days for debugging and audit purposes, after which they are permanently deleted or fully anonymized, unless you configure a custom retention policy within your enterprise workspace.
- Deletion Requests: Upon termination of your account or upon validated request, we will securely delete or anonymize your personal data within 30 days. Backup archives may retain encrypted copies of data for up to 90 days before being automatically overwritten.

7. Security of Your Data

Hokto implements robust, industry-standard technical and organizational measures to protect your data against unauthorized access, loss, destruction, or alteration. These measures include:
- Encryption: All data in transit is encrypted using TLS 1.3 or higher. Data at rest is encrypted using AES-256.
- Access Controls: Strict Role-Based Access Control (RBAC), multi-factor authentication (MFA) for all internal systems, and principle of least privilege access for our engineering team.
- Audits and Penetration Testing: Continuous vulnerability scanning, dependency monitoring, and annual third-party penetration tests in accordance with SOC 2 Type II compliance standards.
- Secrets Management: API keys, OAuth tokens, and CRM credentials entrusted to Hokto are securely hashed, salted, and stored in enterprise-grade key management systems.
While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

8. International Data Transfers

Hokto is headquartered in the United States, and our primary data hosting infrastructure is located in the US. By using our Services, you understand that your personal data will be transferred to, processed, and stored in the United States and other jurisdictions where our subprocessors operate. For data transfers out of the EEA, UK, Switzerland, the United Arab Emirates, and the Republic of Serbia, we ensure adequate protection for your data. We execute the European Commission's Standard Contractual Clauses (SCCs), incorporating UAE-specific addendums where required by the UAE Data Office under the PDPL, and in the exact form adopted by the Serbian Commissioner for Information of Public Importance and Personal Data Protection, pursuant to Articles 64-69 of the ZZPL, or we rely on other recognized legal transfer mechanisms such as the EU-US Data Privacy Framework. Enterprise customers may request our standardized Data Processing Addendum (DPA) to legally govern these international transfers.

9. Your Data Privacy Rights

Depending on your jurisdiction (e.g., GDPR, UK GDPR, ZZPL), you possess several rights regarding your personal data:
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may request correction of inaccurate or incomplete data.
- Right to Erasure ('Right to be Forgotten'): You may request deletion of your data, subject to certain legal exceptions.
- Right to Restriction of Processing: You may request that we limit the processing of your data.
- Right to Data Portability: You may request to receive your data in a structured, commonly used, and machine-readable format.
- Right to Object: You may object to the processing of your data, particularly for direct marketing purposes or when based on legitimate interests.
To exercise these rights, please contact us at hello@hokto.app. We will respond to your request within 30 days. You also have the right to lodge a complaint with your local data protection authority. If you are located in Serbia, you have the right to lodge a complaint directly with the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti).

10. California Privacy Rights (CCPA/CPRA)

This section applies exclusively to California residents as defined by the CCPA and the California Privacy Rights Act (CPRA).
- Categories of Personal Information Collected: In the preceding 12 months, we have collected identifiers (name, IP, email), commercial information (subscription records), internet activity (usage logs, workflow execution telemetry), and professional information. We do not collect 'Sensitive Personal Information' as defined by the CPRA unless explicitly provided by you within a workflow.
- Purpose of Collection and Retention: We collect this information to provide the Service, maintain security, process payments, and improve performance. We retain this data as long as your account is active, plus 90 days for backups, unless a shorter period is required by law.
- Sale, Sharing, and Targeted Advertising: Hokto does not 'sell' your personal information for monetary consideration. We do not 'share' your personal information for cross-context behavioral advertising.
- Global Privacy Control (GPC): We process and honor opt-out preference signals, including the Global Privacy Control (GPC).
- Your Rights: California residents possess the right to: (1) know what personal information is collected; (2) access a copy of such data; (3) request deletion; (4) correct inaccurate data; (5) limit the use and disclosure of sensitive personal information; and (6) not receive discriminatory treatment.
- Exercising Rights: To submit a verifiable consumer request, email hello@hokto.app or call our toll-free number at 1-800-XXX-XXXX. We may require you to verify your identity before processing the request.

11. Cookies and Tracking Technologies

Our Services use cookies, pixels, and local storage to distinguish you from other users, provide seamless navigation, and analyze platform performance.
- Strictly Necessary Cookies: Essential for the operation of the platform (e.g., authentication, security).
- Performance and Analytics Cookies: Help us understand how visitors use the site by collecting anonymous aggregated data.
- Functional Cookies: Remember your preferences and settings.
You can manage your cookie preferences through your browser settings or via the cookie consent banner available on our website. Disabling strictly necessary cookies may impede your ability to use the Hokto platform.

12. Children's Privacy

Hokto's Services are explicitly designed for and directed at B2B professionals and enterprise use. We do not knowingly collect, solicit, or maintain personal information from anyone under the age of 18. If we become aware that we have inadvertently collected personal information from a child under 18, we will take prompt steps to delete that information from our records. If you believe a child has provided us with personal data, please contact us immediately at hello@hokto.app.

13. Changes to this Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by updating the 'Last Updated' date at the top of this Policy, posting a notice within the Hokto dashboard, or sending you an email notification prior to the changes taking effect. Your continued use of the Services after the effective date of the revised Policy constitutes your acceptance of the updated terms.

14. Contact Information and Global Representatives

If you have any questions, concerns, or requests regarding this Privacy Policy, our data practices, or our Data Processing Addendum (DPA), please contact our Data Protection Officer (DPO) at:

Email: hello@hokto.app

For the purposes of the General Data Protection Regulation (GDPR) and the UK GDPR, if you are located in the European Economic Area (EEA), Hokto EU B.V. acts as the Data Controller for your account and billing information, and as the Data Processor for your CRM/ERP data. Our Data Protection Officer (DPO) can be contacted at hello@hokto.app. For EEA residents, our appointed EU Representative pursuant to Article 27 of the GDPR is Hokto EU Representative Services, located at Keizersgracht 123, 1015 CJ Amsterdam, Netherlands. You may direct any inquiries regarding our EU data processing activities to this representative. You also maintain the right to lodge a complaint with your applicable national Data Protection Authority (DPA) or the Lead Supervisory Authority.

In accordance with Article 44 of the Serbian Law on Personal Data Protection (ZZPL), to the extent Hokto is not established in the Republic of Serbia but processes personal data of individuals located in Serbia, Hokto has designated a local representative in Serbia for data protection matters. The Commissioner and data subjects may contact our representative regarding all issues related to processing to ensure compliance with the ZZPL. Please contact hello@hokto.app to obtain the contact details of our current Serbian representative.

Note: The specific Hokto legal entity responsible for your data depends on your country of residence and the language/localization of the Services you are using. Different regional branches of Hokto are responsible for different jurisdictions. Please contact us at hello@hokto.app to clarify the responsible legal entity for your specific account.

15. Automated Decision-Making and AI Profiling (GDPR Article 22)

In accordance with Article 22 of the GDPR, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Hokto’s AI agents execute workflows based on parameters set by Customer administrators. Hokto does not independently subject data subjects to automated decision-making that produces legal effects. Where Customer configurations result in such automated decision-making, the Customer acts as the Data Controller and is solely responsible for obtaining necessary explicit consents, providing meaningful information about the logic involved, and ensuring the right to obtain human intervention, express a point of view, and contest the decision.

16. Data Breach Notification (GDPR Article 33/34)

In the event of a personal data breach, Hokto will notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where Hokto acts as a Data Processor on behalf of a Customer, we will notify the Customer (the Data Controller) without undue delay after becoming aware of a personal data breach, providing sufficient information to allow the Customer to meet any obligations to report or inform data subjects. Our standard Data Processing Addendum outlines the specific procedures, cooperation, and remediation steps we take in the event of a security incident.

17. United Arab Emirates Privacy Rights (UAE PDPL)

For residents of the United Arab Emirates, this section supplements our Privacy Policy in accordance with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, 'PDPL'). Hokto acts as a Data Processor for Customer data and a Data Controller for account administration data. We process your personal data based on your explicit consent, contractual necessity, or our legitimate interests, provided they do not override your fundamental rights. Under the PDPL, you have the right to obtain information about the processing of your data, request the transfer of your personal data (data portability), request correction or erasure, restrict or stop processing, and object to automated decision-making that has legal or significant effects. In the event of a data breach that prejudices your privacy or confidentiality, Hokto will notify the UAE Data Office and you without undue delay as required by the PDPL. Cross-border transfers of UAE personal data outside the UAE are conducted in compliance with PDPL requirements. To exercise your rights under the UAE PDPL, contact us at hello@hokto.app.

18. Multi-State US Privacy Rights (VCDPA, CPA, CTDPA, UCPA)

Residents of Virginia, Colorado, Connecticut, Utah, Texas, and other U.S. states with applicable comprehensive privacy laws are granted specific rights regarding their personal data.
- Rights: You have the right to confirm whether we process your personal data, access it, correct inaccuracies, delete it, and obtain a portable copy.
- Opt-Out Rights: You have the right to opt out of the processing of your personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects. Hokto does not sell your personal data or engage in such profiling.
- Appeals: If we decline to take action regarding your privacy request, you have the right to appeal our decision by emailing hello@hokto.app. If the appeal is denied, you may contact your state's Attorney General to submit a complaint.
- Automated Decision-Making and AI Profiling: While Hokto utilizes AI to execute workflows, we do not use your personal data to train foundational models, nor do we use it for automated decision-making that affects your legal rights without human intervention. Customers deploying our agents must independently assess their use-cases for state-level AI bias and profiling compliance.