Sotto
Last updated: 2026-05-15
Sotto is built on the premise that anonymity is not a setting — it is the architecture. This policy explains precisely what data we collect, why we collect it, who processes it, and what rights you have over it.
We collect only what is necessary to operate the platform safely and legally:
Your real name, email, and verified identity are never disclosed to other users. Every user is represented by a stable opaque identifier ("n° ID") that cannot be reverse-engineered to your personal data without Sotto's direct cooperation with a competent legal authority.
No public profiles exist on Sotto. Counterparties in a transaction only know your n° ID, your bid or ask amount, and the outcome of authentication. Nothing else.
Sotto employees with access to linked identity data are subject to strict need-to-know policies, access logging, and contractual confidentiality obligations.
All processors are bound by Data Processing Agreements (DPAs) meeting applicable legal standards. Processor agreements are available on request from our DPO.
KYC identity records are retained for a minimum of 5 years following account closure, in compliance with AML obligations under Turkish Banking Regulation, EU AMLD6, and UAE AML Federal Decree Law No. 20 of 2018.
Transaction records are retained for 7 years for tax and regulatory purposes. Chat and concierge communications are retained for 3 years.
Account data not required for compliance is deleted within 90 days of account closure. Backups are purged on a rolling 30-day cycle.
Subject to applicable law, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure of data no longer required for legal retention; request portability of your data in a machine-readable format; object to processing based on legitimate interests; and withdraw consent where processing is based on consent.
Rights requests can be submitted via your account settings or by email to our DPO. We respond within 30 days (GDPR/KVKK) or 45 days (UAE PDP). Erasure requests may be partially declined where retention is required by law.
Sotto uses only session cookies required for authentication and security. No advertising, tracking, or third-party cookies are set.
Analytics are handled by Plausible, which operates without cookies and without cross-site tracking. Plausible data is anonymised at collection and cannot be linked back to an individual.
For all privacy-related matters, rights requests, and DPA requests, contact our Data Protection Officer:
Use the form below to submit a data access, export, rectification, or erasure request. Signing in is required so we can verify your identity and act only on requests for your own data. We respond within 30 days.