Privacy Policy
Effective: 26 April 2026 · Last updated: 26 April 2026
- 1. Introduction
- 2. Information we collect
- 3. Lawful bases for processing
- 4. How we use your information
- 5. How we share your information
- 6. Data retention
- 7. International data transfers
- 8. Your rights under GDPR
- 9. Cookies and tracking
- 10. Security measures
- 11. Children's privacy
- 12. Changes to this policy
- 13. Contact us
1. Introduction
Sonara Media AS (“Sonara”, “we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and safeguard personal data when you visit our website, sign up for our services, or use our platform.
This policy applies to information collected through our marketing website (sonaramedia.no), our application (app.sonaramedia.no), and any related services, sales activities, marketing campaigns, or events.
We are based in Oslo, Norway, and we comply with the European Union General Data Protection Regulation (GDPR), the Norwegian Personal Data Act, and applicable data protection laws in jurisdictions where our customers are located.
2. Information we collect
2.1 Information you provide directly
When you visit our website, request a demo, sign up for a trial, or subscribe to a paid plan, we collect information you provide such as:
- Identity information: name, email address, telephone number, job title, employer.
- Account credentials: hashed passwords or OAuth tokens.
- Billing information: company name, billing address, VAT number. Payment card details are handled by our payment processor (Stripe) and are not stored on our systems.
- Communications you send to us: support tickets, sales inquiries, feedback.
2.2 Information collected automatically
When you use our website or platform, we automatically collect certain technical information, including IP address, browser type and version, device type, operating system, pages visited, referrer URL, time and date of access, and session identifiers. This is collected through cookies and similar technologies (see Section 9).
2.3 Customer Data (data processed on behalf of our customers)
When our customers use the Sonara platform to manage their own sales and marketing operations, they may upload, generate, or process personal data about their own prospects and contacts. This is referred to as “Customer Data”.
Customer Data may include information such as names, email addresses, phone numbers, job titles, employer information, public profile data (e.g. LinkedIn), website data, conversation histories, and other information our customers choose to process. With respect to Customer Data, our customers are the “data controllers” and Sonara is the “data processor”. We process Customer Data only on instructions from our customers and in accordance with our Data Processing Agreement.
3. Lawful bases for processing
Under the GDPR, we process personal data on the following lawful bases:
- Performance of a contract — to provide the services you have signed up for, manage your account, and process payments.
- Legitimate interests — to operate, secure, and improve our services; to communicate with users about service updates; to prevent fraud and abuse.
- Consent — for non-essential cookies, marketing communications outside an existing customer relationship, and other situations where consent is required by law.
- Legal obligations — to comply with tax, accounting, and other legal requirements.
4. How we use your information
We use the information we collect for the following purposes:
- Providing, maintaining, and improving the Sonara platform and related services.
- Processing payments and managing subscriptions.
- Sending you account-related communications, security notices, and transactional emails.
- Providing customer support and responding to inquiries.
- Sending marketing communications, where you have opted in or where permitted by law (you can opt out at any time).
- Analysing usage patterns to improve our products and develop new features.
- Detecting, preventing, and investigating fraud, security incidents, or violations of our Terms of Service.
- Complying with legal obligations and enforcing our rights.
6. Data retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Typical retention periods include:
- Account information: for the duration of the account, plus up to six (6) years after closure for tax and legal record-keeping.
- Usage data: up to 24 months.
- Marketing data: until you opt out or otherwise withdraw consent.
- Customer Data: per the customer’s configured retention settings; deleted within 30 days of account termination unless required by law.
- Backups: up to 30 days after primary deletion.
7. International data transfers
Some of our sub-processors are located outside the European Economic Area (EEA), including the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs) and supplementary measures where required, to ensure the protection of your personal data.
8. Your rights under GDPR
If you are located in the EEA, the United Kingdom, or another jurisdiction with similar laws, you have the following rights regarding your personal data:
- Right of access — to request a copy of the personal data we hold about you.
- Right of rectification — to correct inaccurate or incomplete data.
- Right of erasure — to request deletion of your data, subject to legal retention requirements.
- Right to restrict processing — to limit how we process your data in certain circumstances.
- Right to data portability — to receive your data in a structured, commonly used, machine-readable format.
- Right to object — to object to processing based on legitimate interests, including direct marketing.
- Right to withdraw consent — where processing is based on consent.
- Right to lodge a complaint — with the Norwegian Data Protection Authority (Datatilsynet) or your local supervisory authority.
To exercise any of these rights, contact us at the address in Section 13. We will respond within 30 days.
10. Security measures
We implement appropriate technical and organisational measures to protect personal data, including:
- Encryption in transit (TLS 1.2+).
- Encryption at rest for sensitive data (AES-256).
- Role-based access controls and audit logging.
- Regular security reviews and dependency updates.
- Incident response procedures.
No system is perfectly secure. In the event of a data breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours where required by law.
11. Children’s privacy
Our services are intended for business use and are not directed at children under 16. We do not knowingly collect personal data from children under 16. If we learn that we have collected such data, we will delete it promptly.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered users at least 30 days before they take effect. Continued use of our services after the effective date of changes constitutes acceptance of the updated policy.
13. Contact us
For questions, requests to exercise your rights, or any other privacy-related concern, please contact us:
Norwegian residents can also contact the Norwegian Data Protection Authority (Datatilsynet) at www.datatilsynet.no.
This Privacy Policy is provided as a starting point and should be reviewed by qualified legal counsel before being relied upon for any specific transaction or relationship. It does not constitute legal advice.
