Sonra Privacy Policy

Last Updated: 29 September 2026

This policy explains how Sonra, Inc. ("Sonra", "we") handles personal information. Sonra, Inc. is a Delaware corporation, 2810 N Church St STE 90561, Wilmington, DE 19802, USA. Contact: support@sonrahq.com.

1. Two roles

2. What we collect

We don't knowingly collect sensitive categories of data (such as health data), and firms shouldn't put them in Sonra. Time-off entries should say "holiday" or "leave", not medical detail.

3. How we use it, and our legal basis (EU/UK GDPR)

We don't sell personal information, and we don't use advertising or tracking cookies.

4. Cookies

The Sonra app uses only the cookies needed to keep you signed in and keep the service secure. Our marketing website uses a privacy-focused analytics tool that doesn't set cookies to count visits and see which pages are used. When we send you a video walkthrough, our video tool records that it was viewed. We don't use advertising or cross-site tracking cookies.

5. Who we share it with

We don't sell personal information. We share it only with service providers who help us run Sonra, under contracts that require them to protect it and use it only on our instructions:

The providers that process Customer Content on behalf of our customers are listed by name on our subprocessors page. Customers are notified before we add a new one, as set out in our Data Processing Agreement.

We may also disclose information if the law requires it, to protect our rights or users' safety, or as part of a merger or sale of the business, in which case this policy continues to apply.

6. International transfers

Sonra, Inc. is a US company. If you are in the EU or UK, your information is transferred to the US and other countries. Where required, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum), or on a provider's certification under the EU–US Data Privacy Framework.

7. How long we keep it

8. Security

We use encryption in transit (HTTPS), continuous encrypted backups, and access controls, and we limit who at Sonra can access Customer Content to what's needed to run and support the service. Copies of production data used for troubleshooting are kept only on encrypted company computers. No service is perfectly secure. If a breach affects your information, we'll notify your firm, and where required the relevant authority, without undue delay.

9. Your rights

Depending on where you are, you can ask to access, correct, delete, or receive a copy of your personal information, object to or restrict how we use it, or withdraw consent. To stop outreach emails, reply "stop" or email support@sonrahq.com. For information your firm put in Sonra, contact your firm first; we'll support them. You can also complain to your data-protection authority: in Ireland the Data Protection Commission (dataprotection.ie), in the UK the ICO (ico.org.uk). California residents have similar rights under the CCPA, and we don't sell or share personal information for cross-context advertising.

10. Children

Sonra is a business tool and isn't meant for anyone under 18.

11. Changes

We'll post changes here and update the date above. If a change is significant, we'll tell account admins by email before it takes effect.