Privacy Policy
This privacy notice for Sonesse Ltd ("Company," "we," "us," or "our") describes how and why we might collect, store, use, and/or share ("process") your information when you use our services ("Services"), such as when you:
- Visit our website at https://www.sonesse.ai, or any website of ours that links to this privacy notice
- Interact with a Sonesse conversational demo agent
- Engage with us in other related ways, including any sales, marketing, or events
Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions, contact us at privacy@sonesse.ai.
Summary of Key Points
This summary provides key points from our privacy notice. You can find more detail on any topic using the table of contents below.
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us, the choices you make, and the features you use.
Do we process sensitive personal information? We do not process special category data. Voice interactions with our demo agents are processed in memory to operate the Service and are not retained as recordings unless you are told otherwise.
Do we receive information from third parties? We do not receive personal information from third parties.
How do we process your information? To provide, improve, and administer our Services, communicate with you, ensure security and prevent fraud, and comply with law. We process your information only when we have a valid legal reason to do so.
When and with whom do we share information? We may share information in specific situations with specific third-party processors, described in Section 4.
What are your rights? Under UK GDPR you have rights over your personal information. See Section 8.
How do you exercise your rights? Email privacy@sonesse.ai. We act on requests in accordance with applicable data protection law.
Table of Contents
- What information do we collect?
- How do we process your information?
- What legal bases do we rely on?
- When and with whom do we share your information?
- Do we use cookies and tracking technologies?
- How long do we keep your information?
- How do we keep your information safe?
- What are your privacy rights?
- Do we collect information from minors?
- Controls for Do-Not-Track features
- International data transfers
- Do we make updates to this notice?
- How can you contact us?
1. What Information Do We Collect?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide when you register on the Services, express interest in our products, participate in activities on the Services, or otherwise contact us. This may include:
- Names
- Email addresses
- Passwords
- Lead information you submit through a demo agent (where a capture form is enabled)
Information automatically collected
In Short: Some information — such as your IP address and browser/device characteristics — is collected automatically when you visit our Services.
We automatically collect certain information when you visit, use, or navigate the Services. This may include your IP address, browser and device characteristics, operating system, language preferences, referring URLs, country, and information about how and when you use our Services. This is primarily needed to maintain the security and operation of our Services and for internal analytics.
Voice interaction data
In Short: Voice input to our demo agents is processed to operate the Service.
When you interact with a Sonesse conversational demo agent, your speech is processed in real time to generate responses. Voice data is processed in memory to deliver the Service and is not stored as a permanent recording unless expressly stated at the point of collection.
2. How Do We Process Your Information?
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.
- To facilitate account creation and authentication and otherwise manage user accounts.
- To deliver and facilitate delivery of Services to the user.
- To respond to user inquiries and offer support.
- To improve our Services through analytics and performance monitoring.
- To comply with our legal obligations.
3. What Legal Bases Do We Rely On?
In Short: We only process your personal information when we have a valid legal basis to do so under UK GDPR.
- Consent. Where you have given us permission to use your information for a specific purpose (e.g. marketing). You can withdraw consent at any time.
- Performance of a contract. Where necessary to fulfil our contractual obligations to you, including providing the Services.
- Legitimate interests. For platform security, fraud prevention, and analytics, provided these are not overridden by your rights.
- Legal obligations. Where necessary to comply with law, cooperate with regulators, or defend our legal rights.
4. When and With Whom Do We Share Your Information?
In Short: We share information only with the sub-processors needed to run the Services, each under a written data-processing contract.
We share personal information with the following categories of sub-processors, which corresponds to the list in Annex 3 of our Data Processing Agreement. Entries marked [to confirm] will name the specific provider; we keep this list current and give notice of material changes.
- ElevenLabs, Inc. — AI voice synthesis (United States) — elevenlabs.io/privacy
- AI language model provider [to confirm] — conversational AI / text generation
- Hosting & infrastructure [to confirm] — application hosting and storage
- Transactional email [to confirm] — account and service emails
- Analytics [to confirm] — product usage analytics
- Payment processor [to confirm] — billing and payments
Only providers that process personal data are listed above. We may also share or transfer your information in connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business.
5. Do We Use Cookies and Tracking Technologies?
In Short: We may use cookies and similar technologies to collect and store information.
We use cookies and similar tracking technologies to access or store information, support security, and analyse usage. You can set your browser to remove or reject cookies; this may affect certain features of the Services. Where required, we obtain your consent before setting non-essential cookies.
6. How Long Do We Keep Your Information?
In Short: We keep your information only as long as necessary.
We retain personal information for as long as your subscription is active. Following termination, we make Customer Data available for export on request for 30 days and then delete or anonymise it within 90 days, unless a longer retention period is required or permitted by law (such as tax or accounting requirements). This mirrors the deletion commitments in our Data Processing Agreement.
7. How Do We Keep Your Information Safe?
In Short: We aim to protect your information through appropriate technical and organisational measures.
We have implemented appropriate technical and organisational security measures designed to protect your personal information. However, no transmission over the internet or storage technology can be guaranteed 100% secure, so we cannot guarantee that unauthorised third parties will never defeat our security. You access the Services at your own risk and should do so within a secure environment.
8. What Are Your Privacy Rights?
In Short: Under UK GDPR you have rights of access, rectification, erasure, restriction, portability, and objection.
You have the right to:
- Request access to and obtain a copy of your personal information
- Request rectification or erasure
- Restrict the processing of your information
- Request data portability
- Object to processing based on legitimate interests
- Withdraw consent at any time where processing is based on consent
To exercise any right, email privacy@sonesse.ai. We will consider and act upon any request in accordance with applicable data protection laws. If you believe we are unlawfully processing your information, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Withdrawing your consent
If we are relying on your consent to process your personal information, you have the right to withdraw it at any time by contacting us. However, this will not affect the lawfulness of processing before withdrawal, nor processing conducted on other lawful grounds.
Opting out of marketing communications
You can unsubscribe from our marketing communications at any time by clicking the unsubscribe link in our emails or contacting us. We may still send you service-related messages necessary for the administration of your account.
Account information
To review, change, or terminate your account, log in to your account settings or contact us. On request to terminate, we will deactivate or delete your account, though we may retain some information to prevent fraud, troubleshoot problems, assist investigations, enforce our terms, and comply with legal requirements.
9. Do We Collect Information From Minors?
In Short: We do not knowingly collect data from or market to children under 18.
We do not knowingly solicit data from or market to children under 18 years of age. By using the Services, you represent that you are at least 18, or that you are the parent or guardian of a minor and consent to their use of the Services. If we learn that personal information from users under 18 has been collected, we will deactivate the account and take reasonable measures to delete such data. If you become aware of any data we may have collected from children under 18, contact us at privacy@sonesse.ai.
Controls for Do-Not-Track Features
Most web browsers and some operating systems include a Do-Not-Track ("DNT") feature you can activate to signal your privacy preference. No uniform technology standard for recognising DNT signals has been finalised. As such, we do not currently respond to DNT browser signals. If a standard is adopted that we must follow, we will inform you in a revised version of this notice.
10. International Data Transfers
In Short: Some of our processors are located outside the UK.
Some of our sub-processors (such as ElevenLabs, and our AI language model provider once confirmed) are based in the United States or other countries outside the UK. Where personal information is transferred outside the UK to a country without UK adequacy status, we rely on appropriate safeguards, such as the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses together with the UK Addendum.
11. Do We Make Updates to This Notice?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this privacy notice from time to time. The updated version will be indicated by an updated "Last updated" date and will be effective as soon as it is accessible. We encourage you to review this notice frequently.
12. How Can You Contact Us?
Sonesse Ltd
Company number: 17119432
Incorporated: 26 March 2026
Registered address: 20 Wenlock Road, London, England, N1 7GU
Email: privacy@sonesse.ai