Last updated · July 2026
Privacy Policy
This Privacy Policy describes how Sonar Genius ("Sonar Genius", "we", "us"), the legal entity operating the Sonar Genius service, collects, uses, and protects personal data. Sonar Genius helps client-facing teams surface requests, complaints, and risks from their client email.
1. Our role
For personal data processed to operate the service (account data, product telemetry, and support communications), Sonar Genius acts as the data controller. For customer email content and derived issues processed on behalf of a customer organization, Sonar Genius acts as a data processor and the customer is the controller. See our Data Processing Addendum.
2. Data we process
- Account data: name, work email, company, role.
- Email content: only messages exchanged with domains your administrator has added to the client allowlist. Internal mail and personal mail are filtered out at ingest and never stored.
- Derived data: structured issues, sentiment, account health, and audit logs generated from allowlisted client correspondence.
- Product telemetry: anonymized usage events for reliability and product improvement.
- Payment data: when you purchase a subscription, our reseller Paddle collects billing details (name, address, payment method, tax info) directly. We receive limited transaction metadata (order ID, plan, status) from Paddle — we do not receive or store full payment card details.
3. How we use it and legal bases
- Providing the service (detect and surface client signals, sync issues to your CRM) — performance of contract.
- Security, fraud prevention, and service reliability — legitimate interests.
- Billing and tax compliance — performance of contract and legal obligation.
- Product improvement and analytics — legitimate interests.
- Marketing communications — consent, which you may withdraw at any time.
We do not sell personal data and we do not use customer email content to train third-party foundation models.
4. Sub-processors and data sharing
We share personal data with the following categories of recipients:
- Infrastructure and AI providers (hosting, database, AI inference) under contractual data protection terms.
- Paddle.com — our Merchant of Record for payment processing, subscription management, tax compliance, and invoicing. Paddle processes billing and payment data as an independent controller under its own Privacy Policy.
- Professional advisers (legal, accounting) as needed.
- Authorities where required by law.
A current sub-processor list is available on request and via our DPA.
5. Retention
Email content is retained only as long as needed to produce and update issues, and is deleted on request or when access is revoked. Derived issues persist with your account until you delete them. Billing records are retained as required by applicable tax law.
6. Your rights
Subject to applicable law (including GDPR and CCPA), you may request access, correction, deletion, portability, restriction, or objection regarding your personal data, and you may withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority. Email privacy@sonargenius.com.
7. Security
Encryption in transit and at rest, least-privilege access, scoped read-only mailbox grants, and continuous monitoring. See our Security page.