Back to home

    Privacy Policy

    1. Introduction

    Sohaara helps professionals, entrepreneurs, students, and businesses build readiness, stay relevant, connect with people and resources, and pursue professional or business opportunities. This Privacy Policy applies when you visit or use Sohaara websites, mobile applications, learning and readiness programs, community and messaging features, AI-powered services, events, and other services that link to this Policy (together, the “Services”).

    This Policy applies to registered users (“Members”), people who visit the Services without an account (“Visitors”), program applicants and participants, experts and coaches, business or institutional customers, and other people who interact with Sohaara. A separate notice or agreement may apply to a specific program, enterprise service, research activity, event, or partner service. If there is a conflict, the more specific notice will govern for that activity.

    The company identified in the Publication information section is the controller or business responsible for the personal data described in this Policy, except when Sohaara processes data solely on behalf of an enterprise customer under that customer’s instructions.

    2. Personal data we collect

    2.1. Data you provide

    • Account and contact data, such as your name, email address, telephone number, password or authentication information, preferred language, country, city, and time zone.
    • Profile and professional data, such as your photo, headline, biography, education, employment history, skills, credentials, certifications, portfolio, business information, interests, availability, target roles, target markets, and opportunity preferences.
    • Readiness and learning data, such as applications, assessments, answers, assignments, quiz results, course progress, attendance, coaching notes, feedback, certificates, interview practice, portfolio work, and evidence of readiness.
    • Opportunity and connection data, such as jobs, funding interests, client or partner needs, events, mentors, experts, peers, introductions requested, connection requests, applications, and outcomes you choose to report.
    • Content and communications, such as posts, comments, reactions, messages, group activity, support requests, survey responses, audio, video, files, and other content you submit.
    • Soha AI interactions, including prompts, questions, voice inputs, uploaded materials, responses, feedback, and actions you ask Soha to take. Voice input may be converted to text by a service provider.
    • Transaction data, such as subscription or program purchased, amount, currency, billing address, payment status, refunds, and invoices. Payment card details are generally collected and processed by our payment provider rather than stored by Sohaara.
    • Identity or eligibility information when reasonably necessary for verification, program admission, licensing support, fraud prevention, or compliance. We will provide additional notice or obtain consent when required.

    You are not required to provide optional profile information. However, incomplete information may reduce the accuracy of readiness guidance, recommendations, or matching. Do not place sensitive personal data, confidential business information, patient information, or another person’s personal data in a public profile, post, message, assignment, or AI prompt unless it is necessary and you are authorized to share it.

    2.2. Data collected through use of the Services

    • Usage data, including pages and content viewed, searches, clicks, feature use, course activity, recommendations opened or dismissed, interactions, session dates and duration, referring pages, and navigation patterns.
    • Device and technical data, including IP address, device type, operating system, browser, language, app version, identifiers, approximate location inferred from IP address, and diagnostic or crash data.
    • Cookies and similar technologies used for authentication, preferences, security, analytics, performance, and, if introduced and permitted, marketing. Our Cookie Policy and consent controls will provide more detail.
    • Communication metadata, such as sender, recipient, date, time, delivery status, and whether a notification or message was opened or acted upon, where the feature and applicable settings allow.

    We will ask for permission before collecting precise device location, accessing a microphone, camera, contacts, calendar, or similar device resource. The Services should not collect those data unless the relevant feature has been implemented and permission is enabled.

    2.3. Data from other people and organizations

    • Enterprise customers, schools, employers, sponsors, or program partners may provide account, eligibility, enrollment, or participation data when they arrange access to the Services.
    • Experts, coaches, assessors, recruiters, employers, investors, mentors, and other participants may provide feedback, evaluations, opportunity requirements, application status, or information about interactions with you.
    • Integration providers may provide data when you choose to connect another service to Sohaara. The consent screen should identify the data requested and the purpose.
    • Public and licensed sources may provide professional, business, event, job, funding, or market information used to populate the Services or support recommendations. Where required, we will identify the source or provide notice.
    • Other Members may mention you, upload content involving you, recommend you, or invite you to connect. They are responsible for having authority to share personal data they provide about others.

    2.4. Data we infer or generate

    We may derive information from the data described above, such as likely interests, skill gaps, readiness indicators, preferred opportunities, recommended people or resources, language preference, risk signals, and engagement patterns. These inferences help personalize the Services, but they can be incomplete or wrong. Members should be able to correct relevant source information and provide feedback on recommendations.

    3. How we use personal data

    3.1. Provide and personalize the Services

    • Create and administer accounts, profiles, subscriptions, enrollments, and certificates.
    • Deliver learning, assessments, coaching, community features, messages, events, tools, and customer support.
    • Personalize dashboards, content, skills guidance, readiness pathways, and recommendations.
    • Recommend jobs, clients, funding, events, tools, knowledge, experts, peers, partners, and other connections that may be relevant.
    • Enable Members and organizations to find and communicate with each other according to visibility controls and the context of the feature.
    • Process transactions, maintain business records, and enforce applicable program or subscription terms.

    3.2. Soha AI and automated recommendations

    Soha uses account, profile, activity, readiness, preference, and interaction data to answer questions, retrieve relevant information, explain options, personalize guidance, and surface potential opportunities. Depending on the feature, Soha may use speech, search, hosting, or analytics providers acting under contract.

    AI output may be inaccurate, incomplete, outdated, or inappropriate for your circumstances. Soha does not make final hiring, admission, licensing, credit, investment, immigration, medical, or other legally significant decisions. Unless a specific feature expressly says otherwise, recommendations and readiness indicators are guidance, not guarantees, professional advice, or proof that you qualify for an opportunity.

    Sohaara will not use private Member content or private AI conversations to train a general-purpose AI model unless the Member is given clear notice and any choice required by law. We may use limited interactions to operate, secure, evaluate, and improve the Services, including through human review by authorized personnel or contractors when necessary and subject to confidentiality controls. Where feasible, evaluation data should be de-identified or minimized.

    3.3. Communications and marketing

    We use contact and preference data to send service messages, security alerts, program information, reminders, recommendations, invitations, and support responses. We may also send promotional communications about Sohaara services or relevant partner opportunities where permitted. You can opt out of promotional email or similar marketing, but you cannot opt out of essential account, transaction, security, or legal notices.

    3.4. Safety, integrity, support, and legal compliance

    We use data to authenticate users, protect accounts, prevent fraud and abuse, moderate content, enforce our terms, investigate suspected violations, respond to complaints, debug the Services, comply with law, and protect the rights, safety, and property of Sohaara, our users, and others.

    3.5. Analytics, research, and service development

    We analyze use of the Services to understand performance, improve usability and recommendations, develop features, assess program effectiveness, and identify workforce and business trends. We may create and share aggregated or de-identified statistics that do not reasonably identify an individual. We do not attempt to re-identify de-identified data, except to test whether de-identification measures work where permitted by law.

    4. Legal bases for processing

    Where applicable law requires a legal basis, we process personal data based on one or more of the following: performance of our contract with you; our legitimate interests or those of another party, balanced against your rights; your consent; compliance with a legal obligation; and protection of vital interests or other grounds permitted by law.

    Typical legitimate interests include operating and improving the Services, personalizing relevant professional guidance, securing the platform, preventing fraud, communicating about the Services, and understanding service performance. Where we rely on consent, you may withdraw it at any time without affecting processing already performed. Some processing is necessary to provide a requested service; if you do not provide the required data, we may be unable to provide that service.

    5. How personal data is visible and disclosed

    5.1. Other users and the public

    Profile visibility, posts, comments, group activity, showcases, work status, and similar content are visible according to the feature’s settings and audience. Content you publish publicly may be viewed, copied, indexed, reshared, or stored by others outside Sohaara. Private messages are visible to participants and authorized service personnel only when access is necessary for support, safety, security, legal compliance, or a feature you request.

    5.2. Experts, opportunity providers, and counterparties

    When you apply, enroll, request an introduction, book a session, join an event, or otherwise choose to engage with an expert, coach, employer, recruiter, investor, client, partner, or other counterparty, we share the information reasonably needed to facilitate that interaction. The recipient may process information under its own privacy policy once it receives the data.

    5.3. Enterprise and sponsored accounts

    If an organization pays for or administers your access, it may receive information necessary to manage seats, eligibility, participation, billing, and agreed program outcomes. Sohaara will disclose in-product or contractually what administrators can see. Unless you choose to share it or a specific agreement lawfully requires it, enterprise administrators should not receive your private messages, private AI conversations, personal job searches, or activity unrelated to the sponsored service.

    5.4. Service providers

    We disclose personal data to vendors that provide hosting, databases, authentication, cybersecurity, communications, customer support, payments, analytics, content delivery, search, AI and speech processing, learning tools, and professional services. They may process data only for agreed purposes, subject to contractual and security obligations appropriate to their role.

    5.5. Legal reasons, safety, and corporate transactions

    We may disclose personal data when we reasonably believe disclosure is required by law or valid legal process; necessary to investigate or prevent fraud, security incidents, illegal activity, or harm; needed to enforce agreements or protect rights and safety; or connected to a merger, financing, reorganization, acquisition, insolvency, or sale of assets. A successor may use the data only consistently with this Policy unless it provides notice and obtains any consent required by law.

    5.6. No sale of personal data

    Sohaara does not sell personal data for money. If Sohaara later uses personal data for cross-context behavioral advertising, shares it in a way treated as a “sale” or “sharing” under applicable U.S. state law, or introduces targeted advertising, it will update this Policy and provide legally required opt-out controls before doing so.

    6. Your choices and rights

    Depending on where you live and subject to legal exceptions, you may have rights to access, know about, correct, delete, restrict, or object to processing of your personal data; receive certain data in a portable format; withdraw consent; opt out of certain marketing, targeted advertising, sale, sharing, or profiling; and appeal a decision concerning a privacy request. You may also have the right to lodge a complaint with a data protection authority.

    You may use available account settings or contact the privacy address listed above. We may need to verify your identity and authority before completing a request. An authorized agent may submit a request where permitted by law. We will not discriminate against you for exercising a privacy right. We may retain or decline to delete information where permitted or required for security, fraud prevention, legal compliance, dispute resolution, recordkeeping, or the rights of others.

    7. Data retention

    We retain personal data only as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain account and program records, satisfy legal and accounting requirements, resolve disputes, enforce agreements, prevent fraud and abuse, and protect security. Retention periods depend on the type of data, the sensitivity and risk, the service context, user expectations, legal requirements, and whether the purpose can be achieved through aggregation or de-identification.

    When an account is closed, we will remove or de-identify personal data within a reasonable period, subject to lawful retention. Information shared with other users may remain in their messages, copies, exports, or reshared content. Public search engines and third-party caches may take time to refresh.

    8. International data transfers

    Sohaara operates internationally and may process personal data in countries other than the country where it was collected, including the United States and countries where Sohaara entities, personnel, or service providers operate. Those countries may have different data protection laws. Where required, we use recognized transfer mechanisms and safeguards, such as contractual protections, adequacy decisions, consent, or regulatory authorization.

    9. Security

    We use technical, organizational, and administrative measures designed to protect personal data, including access controls, encryption in transit, monitoring, backups, vendor controls, and incident response practices appropriate to the Services. No system is completely secure, and we cannot guarantee that unauthorized access, loss, misuse, or alteration will never occur. You are responsible for protecting your credentials and notifying us if you suspect unauthorized account use.

    10. Children and minimum age

    The Services are not directed to individuals under 18, and we do not knowingly collect personal data from them. A higher minimum age may apply where required by local law. If we learn that we collected personal data from a child below the applicable age without valid authorization, we will take reasonable steps to delete it. A parent or guardian may contact us if they believe a child has provided personal data improperly.

    11. Sensitive data and healthcare programs

    Some readiness programs may involve professional licensing, accommodations, demographic questions, or other information that applicable law treats as sensitive. We collect sensitive data only when necessary, with appropriate notice and consent or another lawful basis. Sohaara’s healthcare readiness programs are educational and professional services; they are not clinical care. Users must not upload patient records or protected health information unless Sohaara has expressly authorized a secure workflow for that purpose.

    12. Third party services and links

    The Services may link to or integrate with websites, applications, payment providers, video platforms, credential providers, job sites, event organizers, and other third parties. Their privacy practices govern their own collection and use of data. Review their notices before providing information. Sohaara is not responsible for third-party services it does not control.

    13. Changes to this Policy

    We may update this Policy as the Services, technology, or law changes. We will post the updated Policy with a new effective date. If changes materially affect your rights or how we use personal data, we will provide additional notice through the Services, email, or another appropriate method before the changes take effect where required.

    14. Contact and complaints

    Questions, privacy requests, or complaints should be sent to the privacy contact information listed in the Publication information section.