Privacy Policy

Sokol by KSoft.TECH
Effective and last updated: 31 July 2026

Sokol provides necessary platform security and optional Analytics. Security checks can take place before a request reaches a protected service. Analytics starts only after a valid affirmative choice.

1. Scope

This Policy explains how Sokol processes information about visitors to protected websites and applications, requests that are evaluated, challenged, limited or blocked, users of optional Analytics, and customer administrators. The operator of each protected service must also provide its own privacy information.

2. Operator and roles

Sokol is operated by KSoft.TECH. Contact details are in section 20.

The protected-service operator normally decides why Sokol is used for its service and is the controller for that site-specific processing. KSoft.TECH normally processes those data as the operator's processor under a data-processing agreement and documented instructions.

KSoft.TECH acts as a separate controller when it determines the purposes and essential means of Sokol platform security, cross-client and cross-product threat protection, account administration, legal compliance, or legal claims. Customers and products do not receive another customer's specific events, raw telemetry, browsing records, or request content.

3. Data Sokol processes

Request and security data

Sokol may process request, event, site, resource and agent identifiers; timestamps and sequence; HTTP method, scheme, protocol and response status; request origin and a normalized referrer without its query string; User-Agent and selected client hints; request-header order and a derived hash; security policy revision; WAF rule identifiers; challenge state and result; rate-limit, allow, observe, challenge or block outcome; automation and behaviour signals; risk score; and internal reason codes.

The source IP is used to route and protect requests. Security records may contain the full public IP as a temporary indicator, a truncated address, an IP-derived pseudonymous identifier, IP version, country and continent, ASN and network owner, and VPN, proxy, Tor, datacentre or known-threat classifications.

A local WAF may inspect configured request headers and a bounded request body in memory. Central edge telemetry does not contain request headers, cookies, authentication values, or request and response bodies.

Browser security signals

Where enabled as necessary platform security, signals can include WebDriver, headless or automation-framework hints; platform and browser properties; plugin and language counts; hardware concurrency and device memory; and counts or timing summaries for pointer, click, form, focus and scroll activity. Sokol does not intend to collect values typed into form fields. These security records do not use the Analytics TID or Analytics session identifiers.

Optional Analytics

After valid Analytics consent, Sokol may process a TID, fingerprint hash, session ID, normalized page URL and path, page title, referrer and attribution, allowlisted query values, device/browser/OS information, country/continent, viewport, timezone and language, connection and performance information, entry and exit page, custom events, counts and duration. URL fragments and non-allowlisted query parameters are removed.

Consent evidence

Sokol stores a first-party consent-choice cookie on the protected site. The backend keeps a minimal consent record containing a random evidence ID, site, consent scope and issuing origin, category choices, policy and configuration version, issue and expiry times, and any revocation time. It does not contain an IP address, TID, name, email address, or other civil identity. A signed, revocable proof is required before Analytics data are accepted or a TID is created.

The site operator may explicitly configure the consent-choice cookie for its registered domain so one choice applies across that domain and its subdomains. Each participating origin must still be explicitly allowed by the site configuration. Optional processing remains disabled while a new or changed choice is awaiting a valid server proof.

4. Security and abuse prevention

Sokol processes necessary security information to operate request protection, detect attacks and automation, classify network reputation, apply rate limits and WAF policies, issue and verify challenges, prevent replay, investigate incidents, and create time-limited security indicators.

The protected-service operator and KSoft.TECH generally rely on legitimate interests under GDPR Article 6(1)(f): protecting services, users and infrastructure and preventing fraud and abuse. Each controller remains responsible for necessity, proportionality and safeguards. Security processing is not described as consent merely because a person uses the protected service.

Some customers use only Analytics and do not enable customer-controlled WAF features. Limited Sokol platform security and threat indicators still apply so KSoft.TECH can protect the service and its clients and products.

5. Optional Analytics and consent

Optional usage, attribution, event and performance Analytics relies on consent under GDPR Article 6(1)(a) where required. The platform default is off. Optional choices are not preselected. If the consent service is disabled or unavailable, Analytics remains off.

Refusing Analytics does not prevent ordinary access, although necessary security checks still apply. Withdrawal is as easy as granting: it stops future Analytics collection, aborts pending Analytics requests, revokes the proof and expires the TID. Withdrawal does not automatically erase information collected lawfully before withdrawal; applicable erasure rights remain available.

6. Cookies and similar storage

ItemPurposeDuration
sokol_consent_<site-id> Remember the choice and signed proof on the protected site 180 days by default; 365 days maximum
tid Recognise a visitor for consented Analytics One year maximum; expired on withdrawal
sokol_challenge_trust Avoid immediately repeating a successfully completed challenge One hour by default; seven days maximum
obf Protect contact-information reveal material Browser session

Challenge tokens normally expire after five minutes and never after more than 30 minutes. Challenge replay information is retained only within the challenge validity window.

7. Automated security evaluation

Sokol can combine configured rules, threat indicators, request characteristics, frequency, WAF results and behaviour evidence to allow, observe, challenge, rate-limit or block a request. Exact thresholds, signatures and technical reasons are not published where disclosure would weaken security.

Sokol is not intended for automated decisions that produce legal or similarly significant effects. KSoft.TECH does not knowingly offer deployments for healthcare, employment, finance, utilities, public services or another high-impact context without a new assessment, appropriate human intervention and stricter controls.

8. Cross-client threat protection

KSoft.TECH may derive temporary IP, network or salted client indicators from high-confidence security events and use them across Sokol clients and products. Derived records can include a score band, reason categories, evidence counts and first/last-seen times. They do not disclose which customer's event produced the indicator.

Country and network information can contribute to a security assessment but is not presented as proof of abuse or as the sole basis for a high-impact decision. Public threat lists are downloaded and matched locally. Visitor IPs are not sent to list suppliers or to MaxMind during request-time matching.

PurposeTypical controllerGDPR basis
Routing, correlation and requested functionsSite operator; KSoft.TECH for its platformArticle 6(1)(b) and/or 6(1)(f)
WAF, challenges, rate limits, abuse and incident preventionSite operator; KSoft.TECH for platform securityArticle 6(1)(f)
Optional AnalyticsProtected-service operatorArticle 6(1)(a) consent where required
Accounts, legal duties and claimsRelevant controllerArticle 6(1)(b), 6(1)(c) and/or 6(1)(f)

10. Customer configuration

Customers control their protected domains and routes, optional Analytics, customer WAF policies, custom events, and third-party scripts. They must provide a lawful site-specific notice, obtain any required consent, and avoid sending passwords, authentication tokens, payment data, special-category data or unnecessary personal data in URLs and event properties.

KSoft.TECH may disable unsafe or misleading configurations. Customer duties in product terms and the DPA do not remove duties that apply directly to KSoft.TECH as processor or controller. Third-party tags added by a customer remain that customer's integration unless KSoft.TECH determines or implements their processing.

11. Recipients and infrastructure

Sokol information may be accessed by the protected-service operator's authorised administrators, authorised KSoft.TECH personnel who need it to operate or support Sokol, contracted infrastructure providers, professional advisers, and authorities where disclosure is legally required.

Sokol does not sell or rent personal data and does not provide it for advertising.

12. EU/EEA processing

Sokol's primary services, databases, live replica and rolling backups are operated in the EU/EEA. Customer integrations can create separate recipients or transfers for which the customer is responsible. If Sokol introduces a restricted transfer, the applicable safeguards and notice will be updated before that processing begins.

13. Retention

RecordMaximum
Raw Analytics events90 days
Raw security and edge events90 days
Analytics sessions and linkable reports365 days
Consent evidenceOne year after expiry or withdrawal
Active internal threat indicator30 days, followed by hard deletion
Edge change history30 days by default; 90 days maximum
Live operational queues24 hours
Failure queues and offline edge spoolsSeven days
Application and infrastructure logsSeven days
Rolling backupsSix snapshots taken every six hours; 36 hours maximum

The German database replica is a live availability copy, not a backup, and reflects live deletion. Expired security rules and indicators are removed after deletion state is published to edge services. Deliberately permanent global rules require explicit creation and annual review. A narrowly scoped legal hold can preserve specific records only for an active legal duty or claim, with restricted access and periodic review.

Statistics may be kept separately only after identifiers have been removed and the result has been documented as not reasonably linkable to a person. Pseudonymous reports remain subject to the limits above.

14. Safeguards

Safeguards include tenant separation, least-privilege access, separate Analytics and security queues, server-verified consent proofs, origin and assignment checks, bounded payloads and local request-body inspection, normalized URLs, signed challenge tokens, replay protection, short operational queues, expiry enforcement and log minimisation. Hashing or truncating an identifier generally makes it pseudonymous rather than anonymous.

15. Your rights

Subject to the GDPR and lawful exceptions, you may request access, correction, erasure, restriction, portability or information about processing, and may withdraw consent for future consent-based processing.

Where legitimate interests apply, you may object on grounds relating to your situation. The controller will stop unless it demonstrates compelling overriding grounds or needs the processing for legal claims. Necessary security may therefore continue after an individual assessment; it is not categorically exempt from objections.

You should contact the protected-service operator first for site-specific processing. KSoft.TECH assists customers under the DPA and responds directly for processing for which KSoft.TECH is controller.

16. Locating your information

Provide only information reasonably available to you: the affected domain, approximate date and time, Sokol request ID and, where relevant, an Analytics TID you can access. The embedded ?sokol-whoami=1 diagnostic can display existing request, consent and identifier information without granting Analytics consent or creating a new fingerprint.

If KSoft.TECH cannot identify the relevant record after reasonable assistance, GDPR Article 11 may limit additional identification duties. This does not make pseudonymous data anonymous or remove processor-assistance obligations.

17. False positives and block reviews

If you believe a block is incorrect, contact the protected-service operator first and include the request ID shown on the page. Do not send passwords, tokens or sensitive page content. If the operator cannot resolve the issue, use the protected KSoft.TECH contact below for final platform escalation.

Reviews are performed by a person. The response target is seven business days, excluding Slovenian public holidays. KSoft.TECH may withhold signatures, thresholds and other technical details where disclosure would weaken protection, while still providing information required by law.

18. Children, high-impact services and sensitive data

Sokol is infrastructure and is not knowingly directed to children. Customers must assess their audience and provide age-appropriate information and safeguards. A parent or guardian may exercise applicable rights for a child. These responsibilities do not remove KSoft.TECH's direct legal duties.

Customers must not send sensitive information through Analytics. A deployment subject to stricter sector rules requires a new assessment and tighter configuration before use.

19. Incidents and policy changes

KSoft.TECH notifies an affected customer of a personal-data breach without undue delay, with a contractual target of 48 hours after awareness, so the customer can meet its own statutory duties. Any available information is supplied in phases if the investigation is incomplete.

Material Policy changes will be published with a new effective date. Continued use is not treated as consent to a new purpose; a new valid choice or other legal basis will be obtained where required.

20. Contact information

Operator: KSoft.TECH

Email:

Postal address:

† JavaScript is required for the obfuscation-and-CAPTCHA reveal. If unavailable, use the protected-service operator's contact route or the supervisory-authority website.

21. Complaints

You may complain to the Slovenian Information Commissioner or the supervisory authority in the EU/EEA country where you live or work, or where the alleged infringement occurred. The Slovenian authority is the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, SI-1000 Ljubljana, gp.ip@ip-rs.si, www.ip-rs.si.