Legal

Privacy policy

How SONALAB collects, uses and safeguards your personal data. Prepared in accordance with GDPR, UK GDPR, Swiss nDSG and the German BDSG.

Last reviewed: September 7, 2026

1. Controller

SONALAB GmbH August-Bebel-Str. 26-53 14482 Potsdam, Germany Email: contact@sonalab.eu

This policy covers our website at sonalab.eu and all subdomains, our Voice AI platform and plugins, and related marketing. It applies under the GDPR (EEA), UK GDPR, and the Swiss nDSG.

2. What Data We Process

Data you provide:

  • Contact data: email address, phone number, postal address
  • Account data: username (email), password (stored encrypted)
  • Payment information: billing address, card details (processed by Stripe; we never see or store full card numbers)
  • Usage data: uploaded audio files, transcripts, project metadata, editing decisions
  • Communication data: support tickets, contact preferences

Sensitive data (Art. 9 GDPR): payment information and voice recordings, processed only to perform the contract (Art. 6(1)(b) GDPR).

Automatically collected: server and application log files (Art. 6(1)(f) GDPR): IP address, browser type, OS, referrer, hostname, timestamp, requested resources. Retained for 14 days unless a security incident requires keeping specific entries longer. We do not use tracking technologies.

3. Purposes and Legal Bases

PurposeLegal basis (GDPR)
Account creation and managementArt. 6(1)(b): contract performance
Provision of ServicesArt. 6(1)(b): contract performance
Payment processingArt. 6(1)(b): contract performance
Customer supportArt. 6(1)(b): contract performance
Administrative noticesArt. 6(1)(b): contract performance
Marketing communicationsArt. 6(1)(a): consent (opt-in only)
IT security and fraud preventionArt. 6(1)(f): legitimate interest
Legal obligationsArt. 6(1)(c): statutory retention

You may withdraw consent at any time by emailing contact@sonalab.eu. Prior processing remains lawful.

4. Recipients and Transfers

We work with processors under GDPR-compliant DPAs (Art. 28 GDPR):

ProviderPurposeLocationSafeguards
Hetzner Online GmbHWeb hosting, cloud storage for AI models and audio filesGermany / EUGDPR-compliant, ISO 27001
Lyceum TechnologyEU-based AI model hostingEUGDPR-compliant
Stripe Payments Europe, Ltd.Payment processing (subscriptions, checkout, card storage)Ireland / EUGDPR-compliant DPA; transfers to Stripe, Inc. (US) safeguarded by the EU-U.S. Data Privacy Framework and SCCs (Art. 46 GDPR)

Service data (audio, transcripts, voice models) is processed within the EU/EEA only and is not transferred to third countries. Payment data is handled by Stripe; where Stripe transfers data to the US, it does so under the EU-U.S. Data Privacy Framework and SCCs (Art. 46(2)(c) GDPR). We never see or store your full card details. We do not sell, rent, or share your data for third-party marketing.

5. Cookies

The public website sets no cookies. The signed-in web interface uses only strictly necessary session cookies from our self-hosted Keycloak (AUTH_SESSION_ID, KEYCLOAK_SESSION, KC_RESTART) under Art. 6(1)(f) GDPR, technical necessity.

6. AI Processing

Our Voice AI performs automatic transcription, machine translation, text-to-speech, voice cloning, and speech-to-speech translation. Inputs are processed only to deliver the Service.

  • EU hosting only; on-premise available for enterprise clients
  • By default, your data is NOT used to train our AI models
  • No automated individual decisions with legal effect (Art. 22 GDPR)

7. Data Retention

DataRetentionBasis
Account dataUntil account deletion, plus backup rotationArt. 6(1)(b)
Projects & transcriptsUntil you delete them, or the account is deletedArt. 6(1)(b)
Uploaded source audioWith your project until you delete it or the account is deletedArt. 6(1)(b)
Rendered audioRemoved 15 minutes after a render completes; voice-design previews after 24 hoursArt. 6(1)(b)
Voice clone filesUntil account deletion, plus backup rotationArt. 6(1)(b)
Watermark provenance recordsIndefinitely; required to keep SONA Verify checks workingArt. 6(1)(f)
Invoices / accounting records10 yearsArt. 6(1)(c): § 147 AO, § 257 HGB
Server and application logs14 daysArt. 6(1)(f)

Card and payment data is not stored by us; it is processed and held by our payment provider. Encrypted database backups rotate out after 14 days (daily copies), 70 days (weekly copies) and 12 months (monthly copies); deleted records can therefore persist in backups for up to 12 months.

8. Your Rights

You have the right to:

  • Access (Art. 15): request a copy of your data and its processing details
  • Rectification (Art. 16): correct inaccurate data
  • Erasure / "right to be forgotten" (Art. 17): subject to statutory retention exceptions
  • Restriction (Art. 18)
  • Portability (Art. 20): receive your data in JSON/CSV
  • Object (Art. 21) to processing based on legitimate interest or direct marketing
  • Withdraw consent (Art. 7(3)) at any time
  • Complain to a supervisory authority (Art. 77)

Competent authority (Berlin): Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstraße 219, 10969 Berlin, mailbox@datenschutz-berlin.de.

To exercise your rights, email contact@sonalab.eu. We respond within one month (Art. 12(3) GDPR) and may ask you to verify your identity.

9. Security

All transmissions are TLS-encrypted; passwords are hashed (Argon2); access follows need-to-know; breaches are notified within 72 hours (Art. 33 GDPR).

10. Controller or Processor

Where you use the Services on behalf of your organization, your company is the controller and SONALAB acts as a processor (Art. 28 GDPR); a DPA is executed on request. Plugins transmit data encrypted to our EU servers; we do not access your DAW project files, only the audio you explicitly upload.


Last reviewed: September 7, 2026. Prepared in accordance with GDPR, UK GDPR, Swiss nDSG, and the German BDSG.