Sonra Privacy Policy
Last Updated: 29 September 2026
This policy explains how Sonra, Inc. ("Sonra", "we") handles personal information. Sonra, Inc. is a Delaware corporation, 2810 N Church St STE 90561, Wilmington, DE 19802, USA. Contact: support@sonrahq.com.
1. Two roles
- When a firm uses Sonra, the firm decides what information about its staff and projects goes into Sonra. For that information ("Customer Content") the firm is the controller and Sonra is its processor: we handle it only to run the service for that firm, as set out in our Terms of Service and Data Processing Agreement. Staff who want to access or correct their information should ask their firm first; we'll help the firm respond.
- For our own business (our website, customer accounts and billing, and contacting firms about Sonra) we are the controller, and this policy describes what we do.
2. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account details | Name, work email, firm name, role, login details | You or your firm when an account is created |
| Customer Content | Projects, fees and phase budgets, tasks and estimates, hours logged, hourly or position rates, time off and fee proposals, and names and emails of the people your firm adds | Your firm and its users |
| Billing | Firm name, billing contact, invoices, payment status. Card and bank details are handled by Stripe; we don't see or store full card numbers | You, via Stripe |
| Usage and device data | Log-ins, pages used, actions such as creating a task, IP address, browser type, error logs | Collected automatically when you use Sonra |
| Communications | Emails and call notes when you contact us, or when we talk about Sonra | You |
| Business contact information (prospects) | Name, job title, work email, firm name and public details about the firm (such as projects, awards and planning applications) | Public sources: firm websites, professional registers, planning records, and business-contact data providers |
We don't knowingly collect sensitive categories of data (such as health data), and firms shouldn't put them in Sonra. Time-off entries should say "holiday" or "leave", not medical detail.
3. How we use it, and our legal basis (EU/UK GDPR)
| Use | Legal basis |
|---|---|
| Providing Sonra: accounts, sign-in, the features your firm uses, support | Contract (our agreement with your firm) and, for Customer Content, your firm's instructions |
| Billing and collecting payment | Contract; legal obligation (tax and accounting records) |
| Security, preventing abuse, fixing errors | Legitimate interests (keeping the service safe and working) |
| Improving Sonra, including building Sonra's own forecasting models from aggregated, de-identified data | Legitimate interests. Only aggregated, de-identified data is used, as set out in our Terms of Service |
| Service emails (invites, password resets, reminders, notices about your account or these policies) | Contract; legitimate interests |
| Contacting firms about Sonra by email (B2B outreach) | Legitimate interests: telling firms about a product relevant to their work. Each email says how to opt out, and we stop contacting you as soon as you ask |
We don't sell personal information, and we don't use advertising or tracking cookies.
4. Cookies
The Sonra app uses only the cookies needed to keep you signed in and keep the service secure. Our marketing website uses a privacy-focused analytics tool that doesn't set cookies to count visits and see which pages are used. When we send you a video walkthrough, our video tool records that it was viewed. We don't use advertising or cross-site tracking cookies.
5. Who we share it with
We don't sell personal information. We share it only with service providers who help us run Sonra, under contracts that require them to protect it and use it only on our instructions:
- Hosting and backups: the servers and storage that run Sonra and keep backups of it
- Email delivery: sending account, invite and service emails, and our own business and support email
- Payment processing: billing firms for Sonra
- Content delivery: delivering parts of the app's code to your browser
- Website and video analytics: counting visits to our website and recording when a video walkthrough we sent has been viewed
- Sales research tools: finding and verifying business contact details, and researching publicly available information about firms (never used for Customer Content)
The providers that process Customer Content on behalf of our customers are listed by name on our subprocessors page. Customers are notified before we add a new one, as set out in our Data Processing Agreement.
We may also disclose information if the law requires it, to protect our rights or users' safety, or as part of a merger or sale of the business, in which case this policy continues to apply.
6. International transfers
Sonra, Inc. is a US company. If you are in the EU or UK, your information is transferred to the US and other countries. Where required, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum), or on a provider's certification under the EU–US Data Privacy Framework.
7. How long we keep it
- Customer Content: for as long as your firm's account is active. After an account ends, we delete it within 60 days of the firm's request. Backups are kept for a limited period (currently around a year) and then expire.
- Billing records: as long as tax and accounting law requires (typically up to 7 years).
- Outreach contacts: until you opt out (we then keep only what we need to not contact you again), or deleted if there has been no contact for 2 years.
- Server logs and monitoring data: up to 12 months.
8. Security
We use encryption in transit (HTTPS), continuous encrypted backups, and access controls, and we limit who at Sonra can access Customer Content to what's needed to run and support the service. Copies of production data used for troubleshooting are kept only on encrypted company computers. No service is perfectly secure. If a breach affects your information, we'll notify your firm, and where required the relevant authority, without undue delay.
9. Your rights
Depending on where you are, you can ask to access, correct, delete, or receive a copy of your personal information, object to or restrict how we use it, or withdraw consent. To stop outreach emails, reply "stop" or email support@sonrahq.com. For information your firm put in Sonra, contact your firm first; we'll support them. You can also complain to your data-protection authority: in Ireland the Data Protection Commission (dataprotection.ie), in the UK the ICO (ico.org.uk). California residents have similar rights under the CCPA, and we don't sell or share personal information for cross-context advertising.
10. Children
Sonra is a business tool and isn't meant for anyone under 18.
11. Changes
We'll post changes here and update the date above. If a change is significant, we'll tell account admins by email before it takes effect.