Sonak Media Ltd ("we", "us", "our") is a company registered in England and Wales. We operate the website sonakmedia.com and provide business automation products and services.
This privacy policy explains what personal data we collect when you visit our website or use our services, how we use it, who we share it with, and what rights you have over your data.
We are the data controller for the personal data described in this policy. If you have questions about how we handle your data, you can contact us at privacy@sonakmedia.com.
Information We Collect
Data you provide directly
When you fill in a form on our website, you may provide us with:
- Contact form: your name, email address, enquiry type, and message
All form fields marked as optional are clearly labelled. You are not required to provide optional information.
Data collected automatically
When you visit our website, we may automatically collect:
- Your IP address
- Browser type and version
- Operating system
- Pages you visit and how long you spend on them
- The website that referred you to us
- Date and time of your visit
This data is collected through standard web analytics and server logs.
Data from third parties
We do not currently purchase or receive personal data about you from third-party sources. If this changes, we will update this policy accordingly.
How We Use Your Information
We use the personal data we collect to:
- Respond to your enquiries submitted through our contact form
- Send you relevant follow-up communications about your enquiry
- Improve our website and services based on how visitors use the site
- Maintain the security and performance of our website
- Comply with legal and regulatory obligations
We will not use your data for purposes unrelated to those described above without your consent.
Lawful Basis for Processing
Under the UK GDPR and EU GDPR, we must have a lawful basis for processing your personal data. We rely on the following bases:
Consent
When you submit a form on our website, you consent to us processing the data you provide for the purpose described on that form. You can withdraw your consent at any time by contacting us.
Legitimate interests
We have a legitimate interest in responding to enquiries, improving our services, and communicating with prospective clients about our offerings. We balance these interests against your rights and freedoms.
Contract performance
Where you become a client, we process your data as necessary to deliver the services you have engaged us to provide.
Legal obligation
We may process your data where required to comply with applicable laws, regulations, or legal proceedings.
Data Sharing and Third Parties
We do not sell, rent, or trade your personal data to anyone.
To operate our website and deliver our services, we use the following third-party sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database โ stores form submissions and client data | EU |
| Resend | Transactional email delivery | US |
| Vercel | Website hosting, may log IP addresses | US |
| Stripe | Payment processing for client billing | US |
Each of these providers has their own privacy policy and data processing agreements in place. We only share the minimum data necessary for each provider to perform its function.
We may also disclose your data if required by law, regulation, or court order.
International Data Transfers
Sonak Media is based in the United Kingdom. Some of our sub-processors (Resend, Vercel, and Stripe) are based in the United States. This means your personal data may be transferred outside the UK and the European Economic Area (EEA).
Where we transfer data internationally, we ensure appropriate safeguards are in place, including:
- UK adequacy decisions: we rely on adequacy decisions made by the UK Secretary of State where available
- Standard Contractual Clauses (SCCs): where no adequacy decision exists, we use SCCs approved by the UK Information Commissioner's Office (ICO) and/or the European Commission
- EU-US Data Privacy Framework: where applicable, our US-based processors participate in the EU-US Data Privacy Framework
You can request a copy of the safeguards we use by contacting us at privacy@sonakmedia.com.
Data Retention
We keep your data only for as long as we need it. Our retention periods are:
- Form submissions (contact enquiries): retained for 24 months from submission, unless you request earlier deletion
- Analytics data: retained for 26 months
- Client data (for active service agreements): retained for the duration of the service agreement plus 6 months after termination
After the retention period expires, we securely delete or anonymise the data. If you would like your data deleted sooner, please contact us.
Your Rights
UK and EU GDPR rights
If you are in the UK or EEA, you have the following rights over your personal data:
- Right of access: request a copy of the personal data we hold about you
- Right to rectification: ask us to correct inaccurate or incomplete data
- Right to erasure: ask us to delete your personal data
- Right to restriction: ask us to limit how we process your data
- Right to data portability: request your data in a structured, commonly used format
- Right to object: object to processing based on legitimate interests or direct marketing
- Rights related to automated decision-making: you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects
California (CCPA) rights
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA):
- Right to know: request details about the categories and specific pieces of personal information we have collected about you
- Right to delete: request deletion of your personal information
- Right to opt-out of sale: we do not sell your personal information, so this right does not currently apply
- Right to non-discrimination: we will not treat you differently for exercising your privacy rights
How to exercise your rights
To exercise any of these rights, email us at privacy@sonakmedia.com. We will respond within 30 days (UK/EU GDPR) or 45 days (CCPA). We may ask you to verify your identity before processing your request.
Cookies
Cookies are small text files stored on your device when you visit a website.
Essential cookies
We use essential cookies that are strictly necessary for the website to function. These do not require your consent.
Analytics cookies
We may use analytics cookies to understand how visitors use our website (such as which pages are most popular and how visitors navigate the site). These cookies collect anonymised, aggregated data.
Managing cookies
You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. However, blocking essential cookies may affect how the website works.
We do not use advertising or tracking cookies on the public website.
Children's Privacy
Our website and services are designed for businesses and are not intended for children.
We do not knowingly collect personal data from anyone under the age of 16 (UK and EU) or under the age of 13 (US, in accordance with COPPA โ the Children's Online Privacy Protection Act).
If you believe we have inadvertently collected data from a child, please contact us at privacy@sonakmedia.com and we will delete it promptly.
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
If we make material changes, we will update the "Last updated" date at the top of this page. For significant changes that affect how we process your data, we will make reasonable efforts to notify you (for example, by posting a notice on our website or emailing you if we have your contact details).
We encourage you to review this policy periodically.
Contact Us
If you have any questions about this privacy policy or how we handle your data, please contact us:
- Email: privacy@sonakmedia.com
- Company: Sonak Media Ltd
- Registered in: England and Wales, United Kingdom
Complaints
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with a supervisory authority:
- UK: Information Commissioner's Office (ICO) โ ico.org.uk
- EU: your local data protection authority (DPA) in the EU member state where you reside
We would appreciate the chance to address your concerns before you approach a regulator, so please contact us first.