Privacy Policy
This policy explains what personal data Sonela handles, why we handle it, who else sees it and what you can ask us to do about it. It is written in plain language on purpose, the same as our terms — where something carries a real consequence, it says so in the same sentence rather than in a schedule somewhere else.
1. Who we are, and what this covers
"Sonela", "we" and "us" mean the operator of the Sonela service. This policy covers this website, the dashboard at app.sonela.ai, and the assistant our customers embed in their own applications. It sits alongside the terms of service, which govern the service itself.
Sonela is operated from Albania and is currently in early access with no paid subscriptions. The full company registration details — legal entity name, registration number and registered address — are published on this page before the service accepts payment.
Privacy questions, and any request under section 10, go to hello@sonela.ai. A person reads it.
2. The two roles we play
We are the controller for the people who use Sonela directly: whoever opens a workspace and anyone they invite into it. That covers account details, billing records, messages you send us and our server logs — everything in section 3 that is about you rather than about your business.
We are a processor for the personal data that lives in your own systems and reaches the assistant while it answers a question, and for the written material you upload to ground it. You are the controller of that data and we act on your instructions, as section 5 of the terms sets out. The relationship is written up in the data processing agreement, which forms part of the terms once you are on a paid plan.
If you are an end user of a customer's application rather than a Sonela customer yourself, that customer decides what happens to your data and your request goes to them. When they ask us to act on it, we act.
3. What we collect
- Account details. Your email address, a display name if you give one, and your password stored only as a hash. We also record when the account was created and which workspace it belongs to.
- Sign-in and security records. Your two-factor settings, and a short label for each browser you allow to skip the second factor. We write that label ourselves from what the browser reports; the raw header is not kept.
- Workspace configuration. The workspace name, the plan it is on, the schema you approved, the business context you wrote, and the written material you upload to ground the assistant. An AI provider key you supply is encrypted at rest and decrypted only in memory to serve a request; no API we expose returns it.
- Usage records. One row per question, holding counts, timings and token totals. There is no column in it for the text of a question, an answer, or the query behind either.
- Billing records. The plan you are on, and the customer and subscription references Paddle gives us. Card details are entered on Paddle's own checkout and are held by Paddle.
- What you send us. The contact form takes an email address, a message, and one file if you choose to attach one. Anything you email us is the same.
- Server logs. Every request on the web carries the caller's IP address, and each one appears in ordinary server logs alongside the time and the URL requested.
4. What we do not collect
Some of these are the reason to choose the product, so each one is scoped to the thing it describes rather than claimed broadly.
- This website is static pages. It sets no cookies, stores nothing in your browser, loads nothing from anyone else's servers, and runs no analytics — see section 11.
- Questions and the rows that answer them pass through our service, and reach one AI provider. They are not written to our storage.
- Chat transcripts are held in the end user's browser for the length of the conversation. We keep none.
- Our usage records store counts, timings and token totals — never the text of a question, an answer, or a query.
- We do not train any model on your data, and we do not use it to improve the service for anyone else.
- We do not sell personal data, we do not share it for advertising, and we build no profile of anyone who reads this site.
- We do not ask for special category data — health, beliefs, biometrics — and no feature of the product needs any. Where your own data holds such information it stays yours, and you stay its controller.
5. Why we use it, and our lawful basis
- To run the service for you — answering questions, holding your configuration, keeping your workspace working. Our contract with you.
- To bill you and keep our books — our contract with you, and a legal obligation for the accounting records themselves.
- To keep the service secure and stop abuse — quotas, rate limits and the server logs in section 3. Our legitimate interest in a service that stays up and is not misused, which we think you share.
- To answer what you send us — our legitimate interest in replying, and steps taken at your request before any contract exists.
- To send you email about your workspace — confirming your address, resetting a password, telling you a trial has ended. Our contract with you.
- To meet a legal obligation where one applies to us.
Where we ever rely on your consent for something, you can withdraw it at any time, and withdrawing it does not make what happened before unlawful.
None of that involves deciding anything about you by automated means, and we do not profile you. The assistant composes answers with an AI model, but it is a tool you point at your own data to get an answer, not a judgement we make about a person: the decisions that follow are yours, which is what section 6 of the terms says at more length.
6. Who else handles it
We use a small number of providers to run the service, and each one receives only what its job needs.
- Cloud hosting. This site, our API and the database behind it run on a commercial cloud platform.
- Email delivery. An email provider sends the messages the product sends you, and the messages we send in reply to you.
- Payments. Paddle, acting as merchant of record. Your invoice comes from them, and what you pay with is entered on their checkout rather than ours.
- The AI provider, which depends on whose key runs your plan. On a plan where you bring your own key, your questions, the rows that answer them and the written material you uploaded to ground the assistant all reach the provider you chose, under your own agreement with them. On a plan where we supply the key, those same three reach the provider we contract with, under our agreement, on a model we pick — and trials always run this way. Either way that is the one AI provider your data reaches; we do not send it on to a second one.
- Professional advisers under a duty of confidence, and anyone a court or the law obliges us to tell.
Ask us and we will name the current provider in any of those categories. Once the data processing agreement in section 2 exists, it carries that list.
7. Where it goes
Sonela is operated from Albania, which is outside the EEA and the UK, and the providers in section 6 operate internationally. So personal data may be handled outside the country you are in.
That is two transfers rather than one, and they are covered separately. Personal data you give us directly — your account details, your workspace configuration, what you write to us — reaches us in Albania because that is where the service you signed up to is run from. For the personal data we handle on your behalf as a processor, the safeguard is the European Commission's standard contractual clauses, which the data processing agreement carries between you and us and which, like the registration details in section 1, is published before the service accepts payment.
Personal data reaching one of the providers in section 6 is covered by the safeguard in our agreement with that provider: the same standard contractual clauses, or that provider's own approved transfer mechanism. The data processing agreement sets this out provider by provider.
8. How long we keep it
- Account and workspace configuration — for as long as the workspace exists. You may ask us to export your configuration or delete your workspace at any time by emailing hello@sonela.ai, and we will action it. Deleting a workspace removes its configuration and any key it held.
- Usage counters — retained in aggregate for billing and accounting records, including after the workspace they came from is deleted.
- A paused trial workspace — if you do not choose a plan, we may delete it after 90 days, with notice first.
- Messages sent through the contact form — stored with us while we answer you, then deleted automatically a fixed period after the request is closed, whether it was closed by an answer or by our giving up on delivering it. A file you attached does not survive the pipeline that forwards it, whether or not the forward succeeds; the privacy note on the terms page is the statement of record for what this website sends.
- Server logs — kept on the rolling retention our hosting platform applies, for as long as they are useful in serving the site and looking into a security or abuse problem, and read for nothing else.
- Billing and accounting records — for as long as tax and company law require them, which is longer than any of the above.
9. How we keep it safe
- Everything travels over HTTPS, on this site and in the product.
- Passwords are stored as hashes. A token that lets a browser skip your second factor is stored as a hash of itself and expires on a fixed date rather than being extended by use. You can turn two-factor sign-in on from your dashboard.
- An AI provider key you supply is encrypted at rest and decrypted only in memory to serve a request.
- Every question is bound on our server to the workspace that asked it, and the read-only validation described on the security one-pager runs before a query is executed. That page names the file behind each layer, so you can check it rather than take our word.
No system is perfect. If a breach affects your personal data we will tell you, and the relevant authority, where the law requires it — and we would rather tell you early than tidily.
10. Your rights
If you are in the UK or the EEA the law gives you the rights below over personal data we hold as controller. We honour them wherever you are, because running two standards is how one of them slips.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of anything wrong or incomplete.
- Erasure — deletion, where we have no overriding reason or legal duty to keep it.
- Restriction — a pause on our use of it while something is disputed.
- Portability — the data you gave us, in a machine-readable form, sent to you or to someone you name.
- Objection — to any use we base on a legitimate interest, and at any time to direct marketing.
- Complaint — to the data protection supervisory authority in your country, whether or not you raise it with us first.
Write to hello@sonela.ai and we will answer within one month, or tell you honestly that a request will take longer and why. There is no fee. We may ask you to confirm who you are before we hand over personal data, and we will not use that as a way to delay you.
11. Cookies
This website is static pages. It sets no cookies, stores nothing in your browser, loads nothing from anyone else's servers and runs no analytics, so there is nothing to consent to and no banner asked you. You can check that in your browser's developer tools, on this tab, right now. What the site does fetch — and the one request that carries anything you typed — is set out in the privacy note on the terms page.
The dashboard at app.sonela.ai has to keep you signed in, so while you are using it, it holds your session in your browser. That is strictly necessary for a service you asked for, and it is used for nothing else. The embedded assistant keeps a conversation in the page's own memory for as long as that page is open, and it ends when the page does.
12. Children
Sonela is a tool for businesses. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to hello@sonela.ai and we will delete it.
13. Changes to this policy
We may update this policy as the product changes. For a material change we will give at least 30 days' notice by email to the address on your account and update the version and date at the top of this page. Everything else — corrections, clearer wording — takes effect when the date changes.
14. Contact
Questions about this policy, a request under section 10, or a concern about how we handle personal data: hello@sonela.ai. We answer. If our answer does not satisfy you, you can take it to the data protection supervisory authority in your country.
Checkable, or it is not a commitment.
If a sentence here is unclear, that is a defect in the writing and we would like to know. This policy stands with the terms of service, which govern the service, the refund policy, which covers what you pay for it, and the security one-pager, which names the file behind every claim it makes.