Back to home
LEGAL

Privacy Policy

Effective: 26 April 2026 · Last updated: 7 September 2026

1. Introduction

Sonara Media AS (“Sonara”, “we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and safeguard personal data when you visit our website, sign up for our services, or use our platform.

This policy applies to information collected through our marketing website (sonara-media.com), our application (sonara-media.com), and any related services, sales activities, marketing campaigns, or events.

We are based in Oslo, Norway, and we comply with the European Union General Data Protection Regulation (GDPR), the Norwegian Personal Data Act, and applicable data protection laws in jurisdictions where our customers are located.

2. Information we collect

2.1 Information you provide directly

When you visit our website, request a demo, sign up, or subscribe to a paid plan, we collect information you provide such as:

  • Identity information: name, email address, telephone number, job title, employer.
  • Account credentials: hashed passwords or OAuth tokens.
  • Billing information: company name, billing address, VAT number. Payment card details are handled by our payment processor (Stripe) and are not stored on our systems.
  • Communications you send to us: support tickets, sales inquiries, feedback.

2.2 Information collected automatically

When you use our website or platform, we automatically collect certain technical information, including IP address, browser type and version, device type, operating system, pages visited, referrer URL, time and date of access, and session identifiers. This is collected through cookies and similar technologies (see Section 9).

2.3 Customer Data (data processed on behalf of our customers)

When our customers use the Sonara platform to manage their own sales and marketing operations, they may upload, generate, or process personal data about their own prospects and contacts. This is referred to as “Customer Data”.

Customer Data may include information such as names, email addresses, phone numbers, job titles, employer information, public profile data (e.g. LinkedIn), website data, conversation histories, and other information our customers choose to process. With respect to Customer Data, our customers are the “data controllers” and Sonara is the “data processor”. We process Customer Data only on instructions from our customers and in accordance with our Data Processing Agreement.

3. Lawful bases for processing

Under the GDPR, we process personal data on the following lawful bases:

  • Performance of a contract — to provide the services you have signed up for, manage your account, and process payments.
  • Legitimate interests — to operate, secure, and improve our services; to communicate with users about service updates; to prevent fraud and abuse.
  • Consent — for non-essential cookies, marketing communications outside an existing customer relationship, and other situations where consent is required by law.
  • Legal obligations — to comply with tax, accounting, and other legal requirements.

4. How we use your information

We use the information we collect for the following purposes:

  • Providing, maintaining, and improving the Sonara platform and related services.
  • Processing payments and managing subscriptions.
  • Sending you account-related communications, security notices, and transactional emails.
  • Providing customer support and responding to inquiries.
  • Sending marketing communications, where you have opted in or where permitted by law (you can opt out at any time).
  • Analysing usage patterns to improve our products and develop new features.
  • Detecting, preventing, and investigating fraud, security incidents, or violations of our Terms of Service.
  • Complying with legal obligations and enforcing our rights.

5. How we share your information

We do not sell your personal data. We share information with the following categories of recipients, only as necessary and under appropriate contractual safeguards:

5.1 Service providers (sub-processors)

We rely on trusted third-party service providers to deliver our services. Each is bound by data processing terms compatible with GDPR. Our primary sub-processors include:

  • Vercel — hosting and infrastructure
  • Supabase — database and authentication
  • Resend — transactional email delivery
  • Twilio — SMS and WhatsApp messaging
  • OpenAI and Anthropic — AI text processing (we never train on Customer Data)
  • Stripe — payment processing (when activated)
  • Google — Google Calendar (create and manage the meeting events you book), when authorised by the user.
  • Apollo, Crunchbase, BuiltWith, Phantombuster, BRREG — data enrichment, when activated by the customer
  • Serper, Bright Data, Meta Platforms (Ad Library), Google (PageSpeed) — company research on publicly available business data, when activated by the customer
  • HubSpot, Pipedrive — CRM integration, when authorised by the customer
  • Sentry — error tracking and monitoring

A complete, current list — including each provider’s purpose, the data it processes, and its location — is available on our Sub-processors page. We notify customers of material changes to sub-processors before they take effect.

5.2 Legal and regulatory disclosures

We may disclose information when required by law, valid legal process, or to protect the rights, property, or safety of Sonara, our users, or others.

5.3 Business transfers

In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred to the acquiring entity. We will notify you of any such transfer.

5.4 Google user data (Limited Use)

When you connect a Google account, Sonara requests only the scopes it needs for the one feature that uses Google:

  • Google Calendar (calendar.events, calendar.freebusy) — to read your availability and to create, update, or cancel the meeting events you book through Sonara.

Sonara’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not transfer it to third parties except as necessary to provide or improve the features you request, to comply with applicable law, or as part of a merger or acquisition. We do not use Google user data to develop, improve, or train generalised or non-personalised AI or machine-learning models.

6. Data retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Typical retention periods include:

  • Account information: for the duration of the account, plus up to six (6) years after closure for tax and legal record-keeping.
  • Usage data: up to 24 months.
  • Marketing data: until you opt out or otherwise withdraw consent.
  • Customer Data: per the customer’s configured retention settings; deleted within 30 days of account termination unless required by law.
  • Backups: up to 30 days after primary deletion.

7. International data transfers

Some of our sub-processors are located outside the European Economic Area (EEA), including the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs) and supplementary measures where required, to ensure the protection of your personal data.

8. Your rights under GDPR

If you are located in the EEA, the United Kingdom, or another jurisdiction with similar laws, you have the following rights regarding your personal data:

  • Right of access — to request a copy of the personal data we hold about you.
  • Right of rectification — to correct inaccurate or incomplete data.
  • Right of erasure — to request deletion of your data, subject to legal retention requirements.
  • Right to restrict processing — to limit how we process your data in certain circumstances.
  • Right to data portability — to receive your data in a structured, commonly used, machine-readable format.
  • Right to object — to object to processing based on legitimate interests, including direct marketing.
  • Right to withdraw consent — where processing is based on consent.
  • Right to lodge a complaint — with the Norwegian Data Protection Authority (Datatilsynet) or your local supervisory authority.

To exercise any of these rights, contact us at the address in Section 13. We will respond within 30 days.

9. Cookies and tracking

We keep this deliberately minimal. Nothing beyond what the service needs is set unless you agree to it:

  • Strictly necessary — authentication and session cookies that keep you signed in, and security tokens that protect your account. Without these the platform cannot function, so they are set without consent as permitted by law.
  • Functional — a single cookie remembering your language choice (English or Norwegian), and one remembering your answer to the cookie banner.
  • Analytics — consent only — on our public website (not inside the platform) we use Google Analytics to count visits and see which pages are read. These cookies are set only if you accept in the banner. Until you do, Google Analytics is loaded in a consent-denied mode that stores nothing on your device, and if you choose “Necessary only” it stays that way.
  • Marketing — consent only — also on our public website only, we use the Meta (Facebook) pixel to measure our advertising and to reach people who have shown interest in what we do. Unlike the analytics tag, the pixel is not loaded at all until you accept: if you choose “Necessary only”, no script is fetched, no request is made to Meta, and nothing is stored.

Both run on the public website only. What you do inside the platform once signed in is never sent to Google or to Meta — no analytics or advertising tag runs on any signed-in page. Google’s own advertising and personalisation features are turned off and IP addresses are anonymised. We do not sell personal data, and we do not upload customer lists or contact details to any advertising network.

You can change your mind at any time by clearing cookies for this site in your browser, which makes the banner appear again. Clearing cookies will also sign you out of the platform.

10. Security measures

We implement appropriate technical and organisational measures to protect personal data, including:

  • Encryption in transit (TLS 1.2+).
  • Encryption at rest for sensitive data (AES-256).
  • Role-based access controls and audit logging.
  • Regular security reviews and dependency updates.
  • Incident response procedures.

No system is perfectly secure. In the event of a data breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours where required by law.

11. Children’s privacy

Our services are intended for business use and are not directed at children under 16. We do not knowingly collect personal data from children under 16. If we learn that we have collected such data, we will delete it promptly.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered users at least 30 days before they take effect. Continued use of our services after the effective date of changes constitutes acceptance of the updated policy.

13. Contact us

For questions, requests to exercise your rights, or any other privacy-related concern, please contact us:

Sonara Media AS

Oslo, Norway

Email: fabian@sonara-media.com

General inquiries: fabian@sonara-media.com

Norwegian residents can also contact the Norwegian Data Protection Authority (Datatilsynet) at www.datatilsynet.no.

This Privacy Policy is provided as a starting point and should be reviewed by qualified legal counsel before being relied upon for any specific transaction or relationship. It does not constitute legal advice.