What Sookly is
Sookly is an early-stage clinic communication SaaS that helps clinics and other connected businesses manage enquiries from channels such as LINE Official Account, Facebook Messenger, Instagram messaging (including Instagram Direct), and website chat in one workflow. LinkedIn messaging and related LinkedIn APIs are on the product roadmap; Sookly maintains a LinkedIn developer application associated with the Sookly LinkedIn Company Page for that purpose.
This policy covers visitors to sookly.co, people who contact us, waitlist registrants, and clinic or business teams that use or evaluate Sookly. When a business uses Sookly to manage patient or customer conversations, that business remains responsible for its own privacy notices and lawful use of those messages.
Roles under Thailand PDPA and similar laws
For website visitors, waitlist registrants, and people who contact Sookly directly, Sookly generally acts as the data controller for that information.
For patient or customer messages and related conversation data inside a connected clinic workspace, the clinic or business is typically the data controller. Sookly acts as a service provider / data processor, processing that data on the clinic’s instructions to provide the inbox and workflow features.
Clinics remain responsible for their own privacy notices, lawful bases, consents, and patient communications under Thailand’s Personal Data Protection Act (PDPA) and any other applicable law.
Information we collect
We may collect contact details such as name, email address, phone or LINE contact, clinic or business name, website, role, and information you submit through forms or email.
When clinics or other businesses use Sookly, the service may process workspace information, staff account details, channel connection details, conversation metadata, message content, tags, notes, assignments, and support requests.
We may also collect technical information such as IP address, device type, browser, approximate location, pages visited, timestamps, and usage logs needed to operate and secure the website and service.
How information is used
We use information to respond to enquiries, process waitlist registrations, operate the Sookly inbox, support customer accounts, improve reliability, investigate issues, and communicate product or service updates.
We may use aggregated or de-identified information to understand website usage, improve content, and make the product more useful for clinic teams.
Sookly does not sell personal information.
When we share information
We share information with service providers and subprocessors that help us run sookly.co and Sookly (see Service providers and subprocessors), and with connected platforms when a clinic connects a channel (for example to send or receive messages).
We may disclose information if required by law, regulation, legal process, or to protect the rights, safety, or security of Sookly, our customers, or others. If Sookly is involved in a merger, acquisition, or asset transfer, information may transfer under appropriate safeguards and notice where required.
Staff of a connected clinic can see conversation and workspace data according to the permissions that clinic configures.
Facebook Messenger and Instagram messages
When a clinic or other business connects its Facebook Page and/or Instagram professional account to Sookly, we process Facebook Messenger and Instagram messages (and related conversation metadata) for that connected business so the business can receive, organise, reply to, assign, and follow up on customer enquiries in Sookly.
This processing is done on behalf of the connected business to provide the messaging inbox and related workflow features they request. Message content may include names, contact details, appointment or service questions, and other information customers choose to send.
Connected businesses remain responsible for telling their customers how messaging is handled, obtaining any required consents or opt-ins before proactive outreach, honouring blocks and opt-outs, and complying with Meta Platform Terms, Meta Business Tools Terms, Meta Developer Policies (including Messenger and Instagram messaging rules), and applicable privacy law. That includes Meta’s standard messaging window and any allowed tags (such as Human Agent for genuine human follow-up) — not using tags or automation to send spam or unapproved promotional messages.
Meta’s minimum privacy-policy expectations for developers: https://developers.facebook.com/docs/development/terms-and-policies/privacy-policy/
Messenger Platform and Instagram Messaging API policy overview: https://developers.facebook.com/docs/messenger-platform/policy/
Customers who messaged a business should contact that business first for message-content requests; contact privacy@sookly.co for questions about Sookly’s role as the service provider.
LINE Official Account messages
When a clinic or other business connects its LINE Official Account to Sookly, we process LINE messages and related metadata for that connected business so the business can manage enquiries in Sookly.
This processing is done on behalf of the connected business. Connected businesses must comply with LINE’s applicable terms and the LINE User Data Policy when using LINE APIs or Official Account messaging features with Sookly.
Conversation message content needed to run the clinic inbox may be stored longer than 24 hours so the business can reply and follow up; by connecting LINE to Sookly, the business is notifying end users through its own notices (and this policy) that such storage may occur. Friend lists and group membership metadata from LINE must not be retained beyond LINE’s User Data Policy limits (including the 24-hour limit on friend/group information where it applies).
Workspace admins can disconnect LINE at any time and request deletion of linked conversation data. End customers who messaged a connected business should contact that business first, or follow https://www.sookly.co/data-deletion and email privacy@sookly.co.
LINE User Data Policy: https://terms2.line.me/LINE_Developers_user_data_policy
LINE Developers Agreement: https://terms2.line.me/LINE_Developers_Agreement_202501
LINE Official Account Guideline (Thailand): https://terms2.line.me/official_account_guideline_th
LINE Official Account Terms of Use (Thailand): https://terms2.line.me/official_account_terms_th
Website chat and embeddable widget
When a business embeds Sookly website chat on its site, we process chat messages, session identifiers, and related technical data so the business can receive and reply to enquiries in Sookly.
The business remains the controller for those visitor conversations and should disclose chat use in its own notices where required. Cookies and similar technologies used by the widget and sookly.co are described in our Cookie Policy at https://www.sookly.co/cookie-policy . Clinics that embed the widget are also responsible for their own website cookie notices for third-party technologies on their pages.
LinkedIn developer app and LinkedIn messages
Sookly registers and maintains a LinkedIn developer application associated with the Sookly LinkedIn Company Page (https://www.linkedin.com/company/117234458). The privacy policy URL provided to LinkedIn for that application is this Privacy Policy (https://www.sookly.co/privacy).
Until a LinkedIn messaging or related LinkedIn API channel is enabled for a workspace, Sookly does not process LinkedIn member message content or LinkedIn member profile data on behalf of that workspace through the LinkedIn APIs.
When a clinic or other business connects LinkedIn to Sookly (for example LinkedIn messaging or other LinkedIn APIs we enable), we process LinkedIn conversation content, member identifiers, and related metadata for that connected business so the business can receive, organise, reply to, assign, and follow up on enquiries in Sookly. That processing is done on behalf of the connected business as a service provider / data processor.
We do not sell LinkedIn member or message data. We do not use LinkedIn data to build advertising profiles, and we do not transfer LinkedIn data to advertising networks, data brokers, or similar monetisation services. LinkedIn data is used only to provide the requested Sookly features to the connected business, to secure and operate the service, and to comply with law.
Connected businesses remain responsible for telling their customers and LinkedIn members how messaging is handled, obtaining any required consents or opt-ins before proactive outreach, honouring blocks and opt-outs, and complying with the LinkedIn API Terms of Use, LinkedIn User Agreement, LinkedIn Privacy Policy, LinkedIn developer policies, and applicable privacy law (including Thailand’s PDPA).
Workspace admins can disconnect LinkedIn when the channel is available and request deletion of linked conversation and connection data by emailing privacy@sookly.co or following https://www.sookly.co/data-deletion. End customers or LinkedIn members who messaged a connected business should contact that business first; they may also email privacy@sookly.co.
LinkedIn API Terms of Use: https://www.linkedin.com/legal/l/api-terms-of-use
LinkedIn Privacy Policy: https://www.linkedin.com/legal/privacy-policy
LinkedIn User Agreement: https://www.linkedin.com/legal/user-agreement
Clinic and customer message data
Clinic and business message data may include patient or customer enquiries from connected channels (including LINE, Facebook Messenger, Instagram, and LinkedIn when enabled), appointment-related details, staff replies, AI-assisted drafts, summaries, and handoff notes.
Some enquiries may include health-related or other sensitive personal data that customers voluntarily send. Connected businesses should minimise unnecessary sensitive data in channels, configure staff access carefully, and ensure their own notices and lawful bases cover that processing. Sookly is not a medical record system.
Sookly is designed to support teams with faster replies and clearer handoff, but connected businesses remain responsible for what they send to patients or customers, how they configure the service, and whether they need consent or additional notices for their own operations.
AI-assisted processing
Sookly may use AI systems in the subcategory of third-party hosted large language model / generative AI inference (API-style providers) to draft replies, summarise conversations, suggest routing or tags, or support other workflow features. Message or workspace content may be sent to those providers solely to return the requested model output for the connected business.
AI outputs are assistive only. Clinics should review AI-assisted content before sending it where the message may affect care, pricing, booking decisions, sensitive information, or customer expectations.
We do not sell personal information. We do not use clinic message content to build a public AI model of our own. Inference providers process content only as needed to deliver the requested feature under our instructions and their terms; we will name the production AI vendor (and summarise any training-use restrictions in their enterprise terms) in this policy when that vendor is fixed for Sookly.
Cookies and analytics
We may use cookies, local storage, and similar technologies on sookly.co, the Sookly dashboard, and the embeddable chat widget to keep the service working, remember preferences such as language or theme, improve security, understand website usage, and improve our services.
Strictly necessary cookies support security, sessions, routing, and remembering cookie choices. Optional analytics, performance, or marketing cookies are used only where enabled and, where required, after you use the cookie or consent controls on the website.
You can manage non-essential cookies through those controls where available, or through your browser settings. Blocking all cookies may affect login, preferences, and chat sessions. Full categories, third-party notes, and control options are in our Cookie Policy at https://www.sookly.co/cookie-policy .
Service providers and subprocessors
To operate sookly.co and the Sookly service we use trusted providers that process information only as needed to provide their services to us. Current core providers include: Vercel (hosting and deployment), Supabase (database and related backend services), and Resend (transactional and waitlist email).
Provider privacy information (for reference): Vercel https://vercel.com/legal/privacy-policy ; Supabase https://supabase.com/privacy ; Resend https://resend.com/legal/privacy-policy . Those policies describe how each provider handles data when acting for their customers; Sookly remains responsible for choosing and instructing providers as described in this policy.
These providers may process data in regions outside Thailand (including the United States and other regions where they operate). Where personal data is transferred internationally, we rely on appropriate contractual and organisational safeguards required by applicable law, including Thailand’s PDPA cross-border transfer rules where they apply.
Connected communication channels such as LINE, Meta products (Facebook Messenger and Instagram), LinkedIn (when enabled), and other supported platforms, are governed by their own terms and privacy practices. Businesses should review those platform requirements before connecting channels.
Roadmap and future channels
Sookly may add messaging or social channels over time (for example TikTok messaging, Telegram, WeChat, X, or Reddit). LinkedIn is covered separately under LinkedIn developer app and LinkedIn messages — the developer app may exist before messaging is enabled in workspaces. Until a channel is enabled for your workspace, we do not process that channel’s message data for you.
When a future channel is connected, we will process its messages on behalf of the connected business under the same controller/processor model described above, and the business must comply with that platform’s terms, developer policies, and privacy requirements. Reference terms for planned platforms include X Developer Agreement (https://developer.x.com/en/developer-terms/agreement), WeChat / Weixin platform terms (https://developers.weixin.qq.com/miniprogram/en/product/service), and Reddit Developer Terms (https://www.redditinc.com/policies/developer-terms).
This policy and our Terms of Use will be updated when new channels go live if additional disclosures are required.
Waitlist and email communications
When you join the Sookly waitlist or contact us, we use your email (and related details you submit) to confirm registration, answer questions, and send practical launch or product updates related to Sookly.
Transactional messages such as waitlist confirmation may be sent automatically. Marketing-style updates about launch readiness are sent only in connection with your registration interest; you can ask us to stop by replying to the email, emailing privacy@sookly.co, or requesting deletion at https://www.sookly.co/data-deletion .
We do not sell waitlist emails. Email delivery uses Resend as described under Service providers and subprocessors.
Children
Sookly’s website and service are directed to clinics and businesses, not to children. We do not knowingly collect personal information from children for our own marketing. Connected businesses are responsible for how they handle messages that may involve minors under applicable law (including Meta, LINE, and LinkedIn rules where relevant).
User data deletion
Workspace admins can disconnect LINE, Facebook Messenger, Instagram, and LinkedIn (when enabled) channels in Sookly and request deletion of linked conversation and connection data.
Step-by-step instructions — including how to email privacy@sookly.co to wipe linked messaging data — are published at https://www.sookly.co/data-deletion.
End customers who messaged a connected business should contact that business first; they may also email privacy@sookly.co and we may need the business to authorise deletion of message content held for their workspace.
Data retention
We keep information for as long as reasonably needed to provide the website or service, support customers, maintain records, resolve disputes, and meet legal or operational requirements.
Waitlist and website contact records are kept while your interest remains relevant and until you ask us to delete them, or until we close inactive registrations under our operational practices.
Clinic workspace and conversation data retention may depend on the clinic’s subscription, configuration, legal needs, and deletion requests. Some logs and backups may remain for a limited period after deletion for security or continuity reasons.
Platform-specific limits also apply — for example LINE friend/group metadata limits described under LINE Official Account messages.
Security and incidents
We use reasonable technical and organisational safeguards designed to protect information from unauthorised access, loss, misuse, or alteration.
No online service can guarantee absolute security. Clinics should also manage staff permissions, connected channels, passwords, and internal procedures carefully.
If we become aware of a personal data incident affecting data we process as a processor for a clinic, we will notify that clinic without undue delay so they can meet controller duties (including PDPA expectations to assess and, where required, notify the PDPC and affected people — often within about 72 hours of becoming aware for controllers). If the incident affects data we control (such as waitlist records), we will investigate and notify as required by applicable law.
User rights and contact
Depending on your location and relationship with Sookly or a clinic using Sookly, you may have rights to request access, correction, deletion, restriction, objection, or other privacy-related actions under PDPA or other applicable law.
If your message was sent to a clinic or business using Sookly, please contact that organisation first where appropriate. For questions about this policy or Sookly’s handling of information — including LINE, Facebook Messenger, Instagram, and LinkedIn message processing for connected businesses — contact privacy@sookly.co.
To disconnect channels or request deletion of linked data, follow https://www.sookly.co/data-deletion.
This privacy policy is published at https://www.sookly.co/privacy and https://www.sookly.co/en/privacy-policy (Thai: https://www.sookly.co/th/privacy-policy).
Related documents: Terms of Use https://www.sookly.co/terms-of-use , Cookie Policy https://www.sookly.co/cookie-policy , and Data deletion instructions https://www.sookly.co/data-deletion .
Changes to this policy
We may update this Privacy Policy as the website, service, channels, providers, or legal requirements change. The “Last updated” date at the end of this page will change when we post a revision.
If changes are material, we will take reasonable steps to notify customers or highlight the update on sookly.co. Continued use of the website or service after an update means you acknowledge the revised policy, to the extent allowed by law.
Last updated
24 July 2026