1. Controller
SONALAB GmbH August-Bebel-Str. 26-53 14482 Potsdam, Germany Email: contact@sonalab.eu
This policy covers our website at sonalab.eu and all subdomains, our Voice AI platform and plugins, and related marketing. It applies under the GDPR (EEA), UK GDPR, and the Swiss nDSG.
2. What Data We Process
Data you provide:
- Contact data: email address, phone number, postal address
- Account data: username (email), password (stored encrypted)
- Payment information: billing address, card details (processed by Stripe; we never see or store full card numbers)
- Usage data: uploaded audio files, transcripts, project metadata, editing decisions
- Communication data: support tickets, contact preferences
Sensitive data (Art. 9 GDPR): payment information and voice recordings, processed only to perform the contract (Art. 6(1)(b) GDPR).
Automatically collected: server and application log files (Art. 6(1)(f) GDPR): IP address, browser type, OS, referrer, hostname, timestamp, requested resources. Retained for 14 days unless a security incident requires keeping specific entries longer. We do not use tracking technologies.
3. Purposes and Legal Bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Account creation and management | Art. 6(1)(b): contract performance |
| Provision of Services | Art. 6(1)(b): contract performance |
| Payment processing | Art. 6(1)(b): contract performance |
| Customer support | Art. 6(1)(b): contract performance |
| Administrative notices | Art. 6(1)(b): contract performance |
| Marketing communications | Art. 6(1)(a): consent (opt-in only) |
| IT security and fraud prevention | Art. 6(1)(f): legitimate interest |
| Legal obligations | Art. 6(1)(c): statutory retention |
You may withdraw consent at any time by emailing contact@sonalab.eu. Prior processing remains lawful.
4. Recipients and Transfers
We work with processors under GDPR-compliant DPAs (Art. 28 GDPR):
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Hetzner Online GmbH | Web hosting, cloud storage for AI models and audio files | Germany / EU | GDPR-compliant, ISO 27001 |
| Lyceum Technology | EU-based AI model hosting | EU | GDPR-compliant |
| Stripe Payments Europe, Ltd. | Payment processing (subscriptions, checkout, card storage) | Ireland / EU | GDPR-compliant DPA; transfers to Stripe, Inc. (US) safeguarded by the EU-U.S. Data Privacy Framework and SCCs (Art. 46 GDPR) |
Service data (audio, transcripts, voice models) is processed within the EU/EEA only and is not transferred to third countries. Payment data is handled by Stripe; where Stripe transfers data to the US, it does so under the EU-U.S. Data Privacy Framework and SCCs (Art. 46(2)(c) GDPR). We never see or store your full card details. We do not sell, rent, or share your data for third-party marketing.
5. Cookies
The public website sets no cookies. The signed-in web interface uses only strictly necessary session cookies from our self-hosted Keycloak (AUTH_SESSION_ID, KEYCLOAK_SESSION, KC_RESTART) under Art. 6(1)(f) GDPR, technical necessity.
6. AI Processing
Our Voice AI performs automatic transcription, machine translation, text-to-speech, voice cloning, and speech-to-speech translation. Inputs are processed only to deliver the Service.
- EU hosting only; on-premise available for enterprise clients
- By default, your data is NOT used to train our AI models
- No automated individual decisions with legal effect (Art. 22 GDPR)
7. Data Retention
| Data | Retention | Basis |
|---|---|---|
| Account data | Until account deletion, plus backup rotation | Art. 6(1)(b) |
| Projects & transcripts | Until you delete them, or the account is deleted | Art. 6(1)(b) |
| Uploaded source audio | With your project until you delete it or the account is deleted | Art. 6(1)(b) |
| Rendered audio | Removed 15 minutes after a render completes; voice-design previews after 24 hours | Art. 6(1)(b) |
| Voice clone files | Until account deletion, plus backup rotation | Art. 6(1)(b) |
| Watermark provenance records | Indefinitely; required to keep SONA Verify checks working | Art. 6(1)(f) |
| Invoices / accounting records | 10 years | Art. 6(1)(c): § 147 AO, § 257 HGB |
| Server and application logs | 14 days | Art. 6(1)(f) |
Card and payment data is not stored by us; it is processed and held by our payment provider. Encrypted database backups rotate out after 14 days (daily copies), 70 days (weekly copies) and 12 months (monthly copies); deleted records can therefore persist in backups for up to 12 months.
8. Your Rights
You have the right to:
- Access (Art. 15): request a copy of your data and its processing details
- Rectification (Art. 16): correct inaccurate data
- Erasure / "right to be forgotten" (Art. 17): subject to statutory retention exceptions
- Restriction (Art. 18)
- Portability (Art. 20): receive your data in JSON/CSV
- Object (Art. 21) to processing based on legitimate interest or direct marketing
- Withdraw consent (Art. 7(3)) at any time
- Complain to a supervisory authority (Art. 77)
Competent authority (Berlin): Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstraße 219, 10969 Berlin, mailbox@datenschutz-berlin.de.
To exercise your rights, email contact@sonalab.eu. We respond within one month (Art. 12(3) GDPR) and may ask you to verify your identity.
9. Security
All transmissions are TLS-encrypted; passwords are hashed (Argon2); access follows need-to-know; breaches are notified within 72 hours (Art. 33 GDPR).
10. Controller or Processor
Where you use the Services on behalf of your organization, your company is the controller and SONALAB acts as a processor (Art. 28 GDPR); a DPA is executed on request. Plugins transmit data encrypted to our EU servers; we do not access your DAW project files, only the audio you explicitly upload.
Last reviewed: September 7, 2026. Prepared in accordance with GDPR, UK GDPR, Swiss nDSG, and the German BDSG.