Okodi SocialOKODI SOCIAL

Legal

Privacy policy

Last updated: 18 August 2026 · Effective date: 18 August 2026

Entity placeholder: before publishing this policy, verify the legal entity (e.g. Proferizon (Pty) Ltd trading as Okodi.ai), registration number, Information Officer name, and physical address. These are marked in [square brackets] below and are POPIA-required.

1. Who we are

This policy is issued by [Proferizon (Pty) Ltd], a company incorporated in the Republic of South Africa (registration number [registration number]), trading as Okodi.ai and operating the Okodi Social product at social.okodi.ai(the "Service"). In this policy we refer to ourselves as "Okodi", "we" or "us".

Our Information Officer, appointed under section 55 of the Protection of Personal Information Act 4 of 2013 ("POPIA"), is:

  • Name: [Information Officer full name]
  • Postal address: [physical / postal address, South Africa]
  • Email: privacy@okodi.ai

2. What this policy covers

Okodi Social is a B2B software-as-a-service used by marketing agencies and in-house teams to generate and publish social media content for one or more client "Business" records. This policy explains what personal information Okodi processes about:

  • Portal users — agency operators who sign in to Okodi Social to create, review, approve and publish content;
  • Client contacts— a person nominated by an agency's client to receive approval emails, submit briefs, or connect their social accounts through the client self-connect flow;
  • Social account holders — the identities we access through Meta (Facebook Pages, Instagram Business accounts) and LinkedIn (personal profiles, Company Pages) when a user grants consent through the OAuth flow.

Okodi processes some of this information as a responsible party(POPIA) / data controller — for example, our portal accounts — and other information as an operator / processoron behalf of the agency, on their instructions.

3. Personal information we collect

3.1 Directly from you

  • Account identity: name, email address, and the Clerk-managed authentication credentials.
  • Organisation membership: the Clerk Organization you belong to.
  • Communication preferences: the notification email address you set for a Business.

3.2 About the Businesses you manage

  • Brand sheet content: descriptions, tone-of-voice notes, do's and don'ts, hashtags, platform lists, colour codes.
  • Content briefs and generated posts: source material provided by a user, the writer and editor agent outputs, approval notes, and scheduled dates.
  • Generated images stored on Vercel Blob (publicly reachable URLs).

3.3 From connected social platforms (with consent)

  • LinkedIn: the OpenID Connect subject identifier, name, email address (when granted), and administered Company Page identifiers. We store the issued access token and refresh token to enable posting on your behalf.
  • Meta: the identifiers and access tokens for Facebook Pages you administer, the linked Instagram Business account identifiers and usernames, and the long-lived user access token issued to enumerate your Pages.

3.4 Automatically

  • Standard web request metadata (IP address, user agent, timestamps) for security logging and rate limiting.
  • Session cookies set by Clerk for authentication and short-lived OAuth state cookies (okodi_li_state, okodi_meta_state) used to protect against CSRF during the connect flow.

4. Why we collect it

  • To provide the Service — create accounts, generate content, and publish approved posts.
  • To secure the Service — authenticate users, rate-limit abuse, investigate incidents.
  • To communicate — send approval notifications, transactional email, cron-generated summaries.
  • To meet legal, regulatory and platform-policy obligations.

5. Lawful basis for processing (POPIA section 11)

We rely on one or more of the following justifications:

  • Consent — for example, when you initiate the LinkedIn or Meta OAuth flow you consent to us storing the tokens and posting on the connected identity;
  • Performance of a contract to which you are a party — supplying the Service to your organisation;
  • Compliance with a legal obligation — for example, retaining transactional records for tax purposes;
  • Legitimate interests pursued by Okodi or a third party (for example, security logging), where those interests are not overridden by your fundamental rights.

6. Data received from Meta (Facebook + Instagram)

When you connect a Facebook Page or Instagram Business account through the Meta OAuth flow, Meta shares the following with Okodi in accordance with your consent and Meta's Platform Terms:

  • The list of Facebook Pages you administer, including Page identifier, Page name, and a Page access token.
  • For each Page, the linked Instagram Business account identifier and username, if any.
  • A short-lived user access token which we immediately exchange for a long-lived (~60 day) user access token.

We use this data only to enumerate the Pages available to you and to publish posts you have approved to those Pages or linked Instagram accounts. We do not use it for advertising, we do not sell or rent it, and we do not enrich other datasets with it. Tokens are stored encrypted at rest via our database provider and transmitted over TLS.

You can revoke Okodi's access at any time from your Facebook settings (Settings & Privacy → Settings → Apps and Websites) or from the Publish page inside Okodi ("Disconnect FB / IG"). Revocation deletes the stored tokens.

7. Data received from LinkedIn

When you connect LinkedIn we request the following OAuth scopes: openid, profile, email, w_member_social, r_organization_admin, w_organization_social. LinkedIn returns:

  • Your OpenID Connect subject identifier, name, and email address (if you consented).
  • An access token (short-lived) and a refresh token used to obtain new access tokens.
  • On request, the list of Company Pages on which you hold an administrator role.

We use this data only to identify the connected LinkedIn account, to let you choose between publishing to your personal profile or to a Company Page you administer, and to publish approved posts. LinkedIn data is never combined with Meta data or shared with third parties for advertising.

You can revoke Okodi's access from your LinkedIn account settings (Settings & Privacy → Data Privacy → Permitted services) or from the Publish page inside Okodi.

8. When we share your personal information

We share personal information only with:

  • Our infrastructure operators acting as sub-operators under written agreement: Vercel Inc. (hosting, edge functions, blob storage), Neon (Postgres database), Clerk (authentication), Resend (transactional email), Anthropic (Claude language models), and the image generation providers we integrate with (BFL, and optionally Vercel AI Gateway or OpenAI depending on your configuration).
  • Meta and LinkedInwhen you publish a post — the post copy, hashtags and any image URL are transmitted to the target platform's API.
  • Regulators, law enforcement and courts where we are legally compelled to disclose.

We do not sell personal information, and we do not use personal information for automated decisions with legal effect under POPIA section 71.

9. Cross-border transfers (POPIA section 72)

Some of our sub-operators host data outside South Africa (primarily in the European Union and the United States). We rely on the following justifications for these transfers:

  • Your consent, granted by using the Service after reading this policy;
  • The transfer is necessary for the performance of the contract; and
  • The recipient is subject to a law, binding corporate rules or binding agreement which effectively upholds principles for reasonable processing that are substantially similar to POPIA (typically GDPR-based commitments).

10. How long we keep personal information

  • Account records: for the life of your organisation's subscription plus 3 years.
  • Generated posts and images: for the life of the parent Business record.
  • Platform access tokens: until the connection is disconnected or the token expires and is not refreshed.
  • Security and audit logs: 12 months.
  • Records required by law (invoices, tax records): 5 years or the period required by applicable law.

On deletion, records are removed from live systems within 30 days and from encrypted backups within 90 days.

11. Security safeguards

  • All traffic is served over TLS 1.2+.
  • Data at rest is encrypted by our database and blob providers.
  • Authentication is delegated to Clerk (SOC 2 Type II).
  • Access to production systems is limited to authorised personnel using multi-factor authentication.
  • Row-level tenant isolation on every data table via a Clerk Organisation identifier.

No system is perfectly secure. If we become aware of a compromise of personal information, we will notify affected parties and the Information Regulator as required by POPIA section 22.

12. Your rights (POPIA sections 23, 24, 25)

You have the right, subject to reasonable verification of your identity, to:

  • be told whether we hold personal information about you (and be provided with a record of it);
  • request correction or deletion of information that is inaccurate, misleading, out of date, or has been unlawfully obtained;
  • object to processing on reasonable grounds relating to your particular situation;
  • withdraw a consent previously given, without affecting the lawfulness of processing that occurred before withdrawal;
  • lodge a complaint with the Information Regulator of South Africa.

To exercise these rights, contact our Information Officer at privacy@okodi.ai. We respond within 30 days.

The Information Regulator can be reached at inforegulator.org.za or POPIAComplaints@inforegulator.org.za.

13. Children

Okodi Social is a business tool and is not directed at children under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, contact us and we will delete it.

14. Data deletion

To request deletion of the personal information we hold about you, follow the instructions on our Data deletion page, or email privacy@okodi.ai. Meta's data-deletion callback (used when a user removes the Okodi app from their Facebook account) is honoured automatically.

15. Cookies and similar technologies

Okodi Social sets a small number of first-party cookies:

  • Session cookies managed by Clerk for authentication and CSRF protection.
  • Short-lived OAuth state cookies (okodi_li_state, okodi_meta_state) set for at most fifteen minutes during the social-platform connect flow. They are httpOnly, secure, and sameSite=lax.

We do not set advertising or tracking cookies and we do not use third-party analytics that profile individual visitors.

16. Namibia-specific notice

For data subjects located in the Republic of Namibia, in the absence of a comprehensive Namibian data-protection statute in force at the effective date of this policy, Okodi processes personal information consistent with Article 13 of the Constitution of the Republic of Namibia (right to privacy), the relevant provisions of the Communications Act 8 of 2009, and the principles set out in this policy as derived from POPIA. If and when the Namibian Data Protection Bill is enacted, we will update this policy to reflect specific obligations arising thereunder. Data subjects in Namibia have the same access, correction and deletion rights described in section 12 above and may contact our Information Officer at privacy@okodi.ai.

17. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email to the account owner or by a notice in the portal at least 14 days before taking effect. The "Last updated" date at the top of this page reflects the current version.

18. Contact us

  • Email: privacy@okodi.ai
  • Postal: [postal address, South Africa]
  • Information Officer: [Information Officer full name]