Privacy Policy

Last updated: August 28, 2026

This Privacy Policy explains how Bokili ("Bokili", "we", "us") collects, uses, shares and protects personal data when you visit our websites, create an account, or use the Bokili platform (the "Service"). It applies to individual learners, team administrators, prospects and website visitors.

1. Controller & contact

Bokili is the data controller for personal data processed about learners, administrators and visitors, except where Bokili acts as a processor on behalf of a Team plan customer (see section 3). You can reach us at hello@bokili.com for any privacy question or to exercise your rights.

2. Data we collect

  • Account data: name, work email, company, job role, language, password hash.
  • Learning data: missions completed, prompts submitted to training exercises, AI coach interactions, scores, badges, timestamps.
  • Billing data: plan, seat count, invoices, billing contact and address. Card details are collected and stored by our payment processor, not by Bokili.
  • Technical data: IP address, device and browser information, log data, cookie identifiers.
  • Communications: messages you send through our contact form, support requests, and marketing preferences.

3. Team plans: Bokili as processor

When a company subscribes to a Team plan, that company is the controller of its employees' account and learning data, and Bokili acts as a processor under its instructions. Team administrators can see aggregated analytics and activity for their organisation. A Data Processing Agreement (DPA) is available on request at hello@bokili.com.

4. How and why we use data

  • Provide, personalise, secure and improve the Service.
  • Adapt missions to the learner's role and domain.
  • Give administrators aggregated analytics on adoption and skill progress.
  • Process payments and manage subscriptions.
  • Respond to enquiries and provide support.
  • Send service communications and, with consent where required, marketing communications.
  • Detect, investigate and prevent fraud, abuse and security incidents.
  • Comply with legal obligations and enforce our Terms.

5. Legal bases (GDPR)

We process personal data under the following bases: (i) performance of a contract with you or your employer; (ii) our legitimate interests in operating, securing and improving the Service; (iii) compliance with legal obligations; and (iv) your consent, where required (e.g. certain cookies and marketing emails). You can withdraw consent at any time without affecting prior processing.

6. AI providers & prompt data

The AI coach and certain mission features use third‑party AI providers (such as OpenAI, Anthropic, Google and Microsoft). Prompts you submit as part of training are transmitted to the relevant provider for processing. We contractually require our AI providers not to use content submitted through our API integrations to train their public foundation models, and we do not use Customer Content to train public models ourselves. In line with Article 50 of the EU AI Act, we make clear that the coach and its feedback are AI systems producing AI‑generated output — see our Terms & Conditions for details.

7. Sharing & sub‑processors

We share personal data only with vetted sub‑processors that help us operate the Service, including cloud hosting, analytics, email delivery, customer support tooling, payment processing and AI inference. We do not sell personal data. A current list of sub‑processors is available on request.

8. International transfers

Some of our sub‑processors are located outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and, where applicable, supplementary measures.

9. Retention

We keep personal data only for as long as necessary for the purposes described above. Account and learning data are retained for the duration of your subscription and deleted or anonymised within a reasonable period after account closure, unless we are required to keep it longer to meet legal or accounting obligations. Billing records are typically retained for up to 10 years to comply with accounting law.

10. Security

We use industry‑standard technical and organisational measures, including encryption in transit, encryption at rest for sensitive data, role‑based access control, logging, regular reviews and vendor due diligence. No system is 100% secure; if we become aware of a breach affecting your personal data, we will notify you and the competent authorities as required by law.

11. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. You may also lodge a complaint with your local data protection authority (in France, the CNIL). To exercise these rights, contact hello@bokili.com. If you are an employee of a Team plan customer, please contact your employer first, as they control your training data.

12. Cookies

We use strictly necessary cookies to operate the Service (for example authentication) and, with your consent where required, analytics cookies to understand how the site is used. You can control cookies through your browser settings and, where offered, through our in‑product preferences.

13. Children

The Service is intended for professional use and is not directed to children. We do not knowingly collect data from children under 16. If you believe a child has provided personal data, contact us and we will delete it.

14. Changes

We may update this Privacy Policy from time to time. Material changes will be notified via email or in‑app notice. The "Last updated" date at the top of this page indicates when it was last revised.

15. Contact

Bokili — hello@bokili.com. Please include "Privacy" in the subject line to help us route your request.