Legal

Security

How Sorkol protects confidential customer, operational, and energy-platform data across our website, product, and support channels.

Effective Date

August 12, 2026

Last Updated

August 12, 2026

Security first

Energy operators, mini-grid teams, and utilities trust Sorkol with operational and customer information that powers billing, payments, token vending, logistics, and reporting.

Protecting that data has been a core product priority from day one.

When it comes to data protection, Sorkol prioritizes the privacy and security of personal and business information processed through our Services. As the entity controlling information about your customers and operations, you remain the owner of that data — at no stage of collection, storage, or retrieval does customer operational data belong to anyone except you or your organization, except as needed to deliver the Services under our agreements.

Our principles

In short: We do not sell customer data for advertising. We do not extract confidential customer or end-user data for unrelated commercial purposes. We encrypt data where appropriate. We access customer data only to provide, support, secure, and improve the Services — or as required by law.

  • Sorkol acts as a service provider and data processor for customer operational data handled inside the platform, based on customer instructions and applicable product configuration.
  • Customers retain ownership of their business content and customer records uploaded to or generated in the Services.
  • We do not rent or sell personally identifying customer or end-user data to third parties for marketing.

Encryption

Web traffic to sorkol.com and authenticated product access is protected with modern TLS encryption (industry-standard HTTPS / TLS with strong cipher suites).

Sensitive credentials and secrets are never stored in plain text in application databases.

Where our hosting and infrastructure providers support it, data is encrypted in transit and at rest.

We continually review our security posture as part of product, operations, and compliance hardening.

Data storage and retention

Customer account data and service records are retained for as long as needed to operate the platform, fulfill contractual obligations, resolve disputes, enforce agreements, and meet legal or regulatory requirements.

Customer organizations own their business data within the product. We do not examine operational histories for advertising purposes — retention exists to maintain reliability, support, auditability, and product functionality.

Important caveats

  • Certain jurisdictions may require mandatory retention periods even after a deletion request.
  • If an account is compromised or data is deleted, residual copies may remain in encrypted backups for a limited recovery window (typically up to 90 days) before rotation completes.
  • We may introduce region-specific retention controls and irreversible deletion options as the platform matures.
  • If an account is closed, data is purged or anonymized on a regular cycle once contractual and legally required retention periods have elapsed.

Access and controls

Access to production systems and customer data is limited to authorized Sorkol personnel who need it to provide support, maintain reliability, investigate incidents, or fulfill contractual or legal duties.

We disclose operationally necessary information only to employees, contractors, and affiliated service providers that need to know it to process it on Sorkol’s behalf and that are bound by confidentiality obligations.

Sorkol does not rent or sell potentially personally identifying information gathered through the Services for third-party advertising.

Customers are responsible for configuring role-based access within their organization, protecting credentials, and reviewing user permissions regularly.

Infrastructure

We leverage trusted cloud hosting, connectivity, and security partners that provide physical, network, and platform safeguards.

Architecture prioritizes separation of environments, least-privilege access, monitoring, and backup/recovery capabilities appropriate for multi-tenant SaaS used by energy operators.

Third-party providers used to deliver core Services (for example hosting, email delivery, payment rails, or communications) are selected with reliability and security in mind and engaged under appropriate commercial and data-processing terms.

Compliance

Sorkol designs and operates the Services with regard to applicable privacy and data-protection expectations for customers in Nigeria, the United Kingdom, and other markets we serve.

  • Privacy practices described in our Privacy Policy
  • Alignment with GDPR / UK GDPR principles where they apply (lawful basis, purpose limitation, security of processing, and data subject rights support)
  • NDPR (Nigeria Data Protection Regulation) considerations for Nigerian operations
  • Contractual confidentiality and data-processing terms with customers and key processors
  • Ongoing review of vendor and sub-processor security commitments

Reporting a vulnerability

If you believe you have found a security issue affecting sorkol.com, the Sorkol platform, APIs, or related services, please report it responsibly.

We appreciate coordinated disclosure, will acknowledge valid reports, and will work to assess and remediate issues promptly.

Please do not publicly disclose vulnerability details until we have confirmed a fix or provided guidance.

Security Email
security@sorkol.com
General Enquiries
sales@sorkol.com

Related documents

For full privacy and contractual terms, review the documents below. Together they describe how we collect, use, protect, and process information across the website and platform.

Contact

Questions about this Security page or our security practices can be directed to:

Company
Sorkol
Security Email
security@sorkol.com

Nigeria Office

FCT Abuja, Nigeria

Business Hours

Monday - Friday8:00 AM - 6:00 PM
Saturday9:00 AM - 3:00 PM
SundayClosed