1. Controller and Contact
The controller responsible for data processing on this website is:
SONALAB GmbH August-Bebel-Str. 26-53 14482 Potsdam, Germany
Represented by the partners: Alexander Wolf and Sören Hübner
Email: contact@sonalab.eu Phone: +49 152 05644686 Website: https://sonalab.eu
Data Protection Officer: A data protection officer has not yet been appointed, as the legal requirements under Art. 37 GDPR and § 38 BDSG are not met.
VAT Identification Number: Will be added once issued.
2. Scope
This privacy policy applies to the processing of personal data in connection with our services ("Services"):
- Our website at sonalab.eu and all associated subdomains
- Our Voice AI platform for professional media production workflows (dialogue replacement, dubbing, voiceover)
- Our web application and plugins for common editing software (e.g., AVID ProTools, Steinberg Nuendo)
- Marketing activities and events related to our Services
This policy applies to users residing in the European Economic Area (EEA), the United Kingdom (UK), and Switzerland under the GDPR, UK GDPR, and Swiss Federal Act on Data Protection (nDSG).
3. Summary of Key Points
What personal data do we process? Data you provide when visiting our website, using our Services, or contacting us (email, name, payment data, audio files).
Do we process sensitive data? Yes — financial data for payments, and voice recordings which may qualify as biometric data. Only processed with your consent or for contract performance.
Do we receive data from third parties? No.
How do we process your data? To provide, improve, and manage our Services; for communication; fraud prevention; and to comply with legal obligations.
When and with whom do we share your data? Only with third parties necessary for providing our Services (e.g., cloud hosting) or when required by law.
Your rights. Access, rectification, deletion, restriction, portability, objection — depending on your location.
Exercise your rights. Email contact@sonalab.eu. We respond within 30 days under the GDPR.
4. What Information Do We Collect?
4.1 Data You Provide
- Contact data: email address, phone number, postal address
- Account data: username (email), password (stored encrypted)
- Payment information: billing address, card details (via third-party providers)
- Usage data: uploaded audio files, transcripts, project metadata, editing decisions
- Communication data: support tickets, contact preferences
Sensitive data (Art. 9 GDPR): payment information and voice recordings — processed only to perform the contract (Art. 6(1)(b) GDPR).
4.2 Automatically Collected Data
Server log files (Art. 6(1)(f) GDPR): IP (anonymized after session), browser type, OS, referrer, hostname, timestamp, requested resources. Retained for 7 days unless a security incident applies.
We currently do not use cookies or tracking technologies on this public website.
4.3 Data from Minors
We do not target persons under 18 and do not knowingly collect their data.
5. How Do We Process Your Data?
| Purpose | Legal basis (GDPR) |
|---|---|
| Account creation and management | Art. 6(1)(b) — contract performance |
| Provision of Services | Art. 6(1)(b) — contract performance |
| Payment processing | Art. 6(1)(b) — contract performance |
| Customer support | Art. 6(1)(b) — contract performance |
| Administrative notices | Art. 6(1)(b) — contract performance |
| Marketing and newsletters | Art. 6(1)(a) — consent (opt-in only) |
| IT security and fraud prevention | Art. 6(1)(f) — legitimate interest |
| Legal obligations | Art. 6(1)(c) — statutory retention |
You may withdraw consent at any time by emailing contact@sonalab.eu. Prior processing remains lawful.
6. Legal Bases for Processing (Art. 6 GDPR)
- 6(1)(a) Consent — you explicitly permit us (newsletter, marketing).
- 6(1)(b) Contract performance — necessary to deliver the Services.
- 6(1)(c) Legal obligation — e.g. HTTP access logs, tax law.
- 6(1)(f) Legitimate interest — e.g. IT security, fraud prevention. Balanced against your rights.
7. When and With Whom Do We Share Your Data?
We work with processors under GDPR-compliant DPAs (Art. 28 GDPR):
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Hetzner Online GmbH | Web hosting, cloud storage for AI models and audio files | Germany / EU | GDPR-compliant, ISO 27001 |
| Lyceum Technology | EU-based AI model hosting | EU | GDPR-compliant |
All processing happens within the EU/EEA. We do not transfer personal data to third countries. If that ever changes, we will use SCCs (Art. 46(2)(c) GDPR) and additional safeguards.
We do not sell, rent, or share your data for third-party marketing.
8. Cookies
The public website sets no cookies. The signed-in web interface uses only strictly necessary session cookies from our self-hosted Keycloak (AUTH_SESSION_ID, KEYCLOAK_SESSION, KC_RESTART) — Art. 6(1)(f) GDPR, technical necessity.
9. Artificial Intelligence (AI) in Our Services
Our Voice AI performs: automatic transcription, machine translation, text-to-speech, voice cloning, and speech-to-speech translation. Inputs (audio, transcripts, metadata, editing signals) are processed only to deliver the Service.
- EU hosting only — Hetzner + Lyceum Technology (EU).
- On-premise available for enterprise clients — data never leaves your servers.
- No transfer to third countries.
- By default, your data is NOT used to train our AI models.
- No automated individual decisions with legal effect within the meaning of Art. 22 GDPR.
Uploaded audio and derived artefacts are deleted 72 hours after project completion.
10. Data Retention
| Data | Retention | Basis |
|---|---|---|
| Account data | Until account deletion + 3 months | Art. 6(1)(b) |
| Audio & projects | Project completion + 72 hours (or on request) | Art. 6(1)(b) |
| Payment / invoices | 10 years | Art. 6(1)(c) — § 147 AO, § 257 HGB |
| Support tickets | 3 years after closure | Art. 6(1)(f) |
| Newsletter consent | Until withdrawal | Art. 6(1)(a) |
| Server logs | 7 days | Art. 6(1)(f) |
Backups are permanently overwritten within a maximum of 90 days.
11. Your Data Protection Rights
You have the right to:
- Access (Art. 15) — request a copy of your data and its processing details
- Rectification (Art. 16) — correct inaccurate data
- Erasure / "right to be forgotten" (Art. 17) — subject to statutory retention exceptions
- Restriction (Art. 18)
- Portability (Art. 20) — receive your data in JSON/CSV
- Object (Art. 21) to processing based on legitimate interest or direct marketing
- Withdraw consent (Art. 7(3)) at any time
- Complain to a supervisory authority (Art. 77)
Competent authority (Berlin): Berliner Beauftragte für Datenschutz und Informationsfreiheit — Friedrichstraße 219, 10969 Berlin — mailbox@datenschutz-berlin.de.
We respond within 30 days (Art. 12(3) GDPR). We may ask you to verify your identity.
12. Data Security
Technical measures: SSL/TLS on all transmissions, Argon2 password hashing, restricted server access, regular patching.
Organizational measures: employee training, need-to-know access, DPIA for high-risk processing (Art. 35), incident response with 72-hour breach notification (Art. 33 GDPR).
13. Data Transfers
Processing location: European Union (Germany). No transfers to third countries currently. Any future transfer would be secured via SCCs, the EU-U.S. Data Privacy Framework where certified, and additional safeguards.
14. Changes to This Privacy Policy
We may update this policy. The "Last updated" date will reflect any changes. Material changes are announced by email or a prominent website notice.
15. Contact
Email: contact@sonalab.eu — Subject: "Data Protection Request [Your Name, Your Account Email]"
Post: SONALAB GmbH, August-Bebel-Str. 26-53, 14482 Potsdam, Germany
16. Additional Information
B2B / Enterprise: where you use the Services on behalf of your organization, your company is the controller and SONALAB acts as a processor (Art. 28 GDPR). A separate DPA is executed on request.
Plugin users (AVID, Steinberg, etc.): plugins transmit data encrypted to our EU servers. We do not access your DAW project files — only the audio you explicitly upload.
17. Definitions
- Personal data — information relating to an identified or identifiable natural person.
- Processing — any operation performed on personal data.
- Controller — SONALAB GmbH.
- Processor — service providers acting on our behalf.
- GDPR — Regulation (EU) 2016/679.
- EEA — European Economic Area.
Last reviewed: February 17, 2026. Prepared in accordance with GDPR, UK GDPR, Swiss nDSG, and the German BDSG.