sonarsense.io

Privacy Policy

Effective Date: September 2, 2026

1. General Provisions

This Privacy Policy (hereinafter referred to as the 'Policy') describes the procedure for collecting, processing, and protecting the personal data of users of the sonarsense.io platform (hereinafter referred to as the 'Service'), provided by SONAR Limited Liability Company (LLC 'SONAR', hereinafter referred to as the 'Operator').

This policy is developed in accordance with Federal Law No. 152-FZ of 27.07.2006 "On Personal Data" (as amended by changes effective 30.05.2025 and 01.09.2025), the Civil Code of the Russian Federation (Art. 152.1, 152.2), the Constitution of the Russian Federation (Art. 23, 24), and other regulatory acts of the Russian Federation regarding personal data.

2. Operator Information

  • Name:SONAR LLC
  • Tax ID: 3666278212
  • OGRN: 1263600003952
  • Address:394054, Voronezh, Shishkova St., 142, apt. 77
  • Registration number in the Register of Operators Processing Personal Data: 36-26-044855 (Roskomnadzor Order No. 51 of April 16, 2026, processing start date: May 1, 2026)
  • Data Controller: support@sonarsense.io
  • Website: sonarsense.io

3. What data do we collect

While using the Service, we process the following categories of data:

3.1. Account data

  • First and last name (when authorizing via Yandex ID)
  • Email address
  • Yandex ID

3.2. Call data

  • Telephone conversation audio recordings
  • Phone numbers of call participants
  • Date, time, and duration of the call
  • Call direction (incoming/outgoing)

3.3. Analysis results

  • Transcript (conversation text)
  • Assessment of sentiment and conflict signals from the transcript
  • Sales Quality Index (SQI)
  • Client profile and recommendations

3.4. Technical data

  • IP address, browser type, operating system
  • Cookie data
  • Actions in the Service interface (to improve the user experience)

3.5. Sonar Assistant data (desktop application)

  • Audio stream from computer microphone (User's voice and potentially other participants' voices within microphone range)
  • Audio stream of computer system sound when the option is enabled (voices of interlocutors from any telephony/video conferencing software)
  • Screenshots of the primary monitor when the “Screenshots” option is enabled
  • Meeting metadata: identifier, time, duration, title, description
  • Client technical data: app version, operating system, session ID

Voice data is considered biometric if used to establish a person's identity (Art. 11, 152-FZ). Sonar Assistant does not use voice for identification. A full description of categories, sources, purposes, and retention periods is provided in Sonar Assistant Policy.

3.6. Demo request and feedback data

  • Name, phone number, and, if provided, email address
  • Company, field of activity, and comment text, if specified
  • Submission page and standard UTM tags for the advertising campaign

3.7. Article subscription data

  • Email address
  • Consent page and time of consent
  • Status of the subscription, delivery, unsubscription, or email blocking by the email provider

4. Legal grounds for processing

Personal data processing is carried out on the following grounds (Art. 6 of 152-FZ):

  • Contract execution(clause 5, part 1, article 6) — processing of account data, audio recordings, and analysis results necessary to provide the Service within the scope of Terms of Use. Registration for the Service constitutes acceptance of the public offer agreement; data is processed for the purpose of performing that agreement.
  • Operator’s legitimate interest(clause 7, part 1, article 6) — technical data necessary to ensure the security and functionality of the Service, and mandatory authentication cookies.
  • Subject consent(clause 1, part 1, article 6) — analytical cookies (consent via the cookie banner), as well as informational and promotional emails about new articles and updates. Consent to receive emails is given through a separate action in the subscription form and may be withdrawn via the link in each email or by contacting the Operator, in accordance with part 1 of article 18 of Federal Law No. 38-FZ of March 13, 2006, “On Advertising.”
  • Written consent for processing biometric personal data (part 1, article 11 of 152-FZ), if voice is used to establish identity in a separate scenario. Such consent is documented in a separate document Consent to processing of biometric personal data in accordance with Part 1, Art. 9 of Federal Law No. 152-FZ (as amended on 09/01/2025).
  • Data subject’s consent to the cross-border transfer of personal data (part 4, article 12 of 152-FZ) — for transferring data to foreign countries that do not ensure adequate protection (USA, China). This is documented in a separate document Consent to cross-border data transfer.

5. How we process data

Call data processing includes the following stages:

  • Speech recognition (STT)— conversion of audio recording to text
  • Sentiment analysis— identification of doubts, objections, and conflict phrases from the transcript
  • AI analysis— sales quality assessment, recommendation generation using a language model (LLM)

Audio recordings are processed automatically on the Operator's servers located in the Russian Federation.

Form data is used to respond to inquiries, arrange product demonstrations, and evaluate lead sources. Data is first saved in the Operator’s secure database; a copy may then be sent to designated employees via Google Sheets and Telegram.

Subscription data is used to send new articles and important updates, record consent, delivery, and unsubscription. Emails are sent via the Unisender Go service.

Data Processing in Sonar Assistant:

  1. Audio capture and (optionally) screenshots are performed by the application on the User's device
  2. Audio streams are transmitted in real time to Soniox, Inc. (USA) for speech recognition (processed on servers in Germany).
  3. The received transcript is stored on the Operator's servers in the Russian Federation (Timeweb, Moscow)
  4. Upon the User’s request (by clicking a button in the application), the transcript and screenshot are transferred to OpenRouter, Inc. (USA) or backup providers Google LLC (USA) and DeepSeek AI (China) to generate an AI hint.
  5. The generated prompt is displayed in the app and stored on the Operator's servers in Russia.

6. Data retention periods

Retention periods are set for each data category:

  • Account data— for the duration of the account. Deleted within 30 days after account deletion.
  • Call audio recordings— deleted after completion of processing and generation of analysis results.
  • Analysis results(transcripts, scores, recommendations) — for the duration of the account. They are deleted within 30 days after the account is deleted.
  • Technical logs— stored for no more than 12 months.
  • Cookie data— for the duration of the cookie's lifetime (see section 9).
  • Demo and Feedback Requests— deleted within 24 hours after 180 days. The user can request data deletion by contacting the Operator using the contacts specified in this Policy.
  • Article subscription data— until consent is revoked. After unsubscribing, the address and refusal status are retained only to the extent necessary to prevent re-mailing without new consent.
  • Sonar Assistant audio stream— not stored on the Operator's servers or the User's device. Used only for real-time recognition and discarded immediately.
  • Sonar Assistant Screenshots— not stored on the Operator's servers. Transferred to AI providers once to generate a single prompt.
  • Meeting transcripts, AI suggestions, and Sonar Assistant meeting metadata — for the duration of the account; deleted within 30 days after account deletion.

7. Data protection

The Operator applies the following security measures:

  • Localization of processing results in the Russian Federation— storage of accounts, analysis results, transcripts, AI prompts, and metadata is carried out on servers in the Russian Federation (Moscow, provider Timeweb).
  • Cross-border transfer— separate processing stages (speech recognition, AI prompt generation) are performed by engaged processors outside the Russian Federation; see sections 8.2 and 8.3, as well as the Cross-border Data Transfer Consent /consent/cross-border. Notification of intent to carry out cross-border transfer has been submitted to Roskomnadzor and approved.
  • Connection encryption (TLS 1.2+) for all data transfers
  • Access control at the account and session level
  • Regular backups
  • Unauthorized access monitoring

8. Third-party services

8.1. Third-party services for sonarsense.io (web platform)

  • Yandex ID(YANDEX LLC, Russia) — user authentication. Transferred: first name, last name, email address, and Yandex ID.
  • Yandex SmartCaptcha(YANDEX LLC, Russia) — form protection. Transferred: IP address, browser and device information, and technical parameters.
  • OpenRouter, Inc.(USA) — LLM analysis of transcripts. Transferred: anonymized call transcripts.
  • PyAnnote AI(France) — diarization (speaker identification). Transferred: call audio recording.
  • T-Bank JSC(Russia) — subscription payment processing. Card details are transferred directly by the user to T-Bank's processing center (PCI DSS Level 1); the Service does not have access to them.
  • Telephony providers(Mango, UIS, Bitrix24, etc., Russia) — integrations. Transferred: call-related Webhook data.
  • Google Sheets(Google LLC, USA) — request tracking spreadsheet. Data provided by the user in the form, the submission page, and standard UTM tags are transferred.
  • Telegram Bot API(Telegram Messenger Inc.) — notification of responsible employees about a new request. Data provided by the user in the form and the submission page are transferred.
  • Unisender Go(Russia) — delivery of emails about new articles and updates, and tracking of delivery and unsubscribes. The email address and email content are transferred; delivery statuses are returned to the Operator.

8.2. Third-party services for Sonar Assistant (desktop application)

  • Keycloakon auth.sonarsense.io — Operator's own infrastructure (RF). Transmitted: email, full name (if set), user ID.
  • Soniox, Inc.(USA, servers in Germany) — streaming speech-to-text (STT). Transferred: real-time audio stream. The recipient does not retain it in accordance with its policy.
  • Hetzner Online GmbH(Germany) — network egress proxy for connecting to Soniox. Transferred: encrypted network traffic (not decrypted by the proxying party).
  • OpenRouter, Inc.(USA) — generation of AI prompts. Transferred: transcript and, optionally, screenshot.
  • Google LLC (Gemini API)(USA) — backup AI provider. The same data as for OpenRouter is transferred.
  • DeepSeek AI(China) — backup AI provider (no vision capabilities). Transferred: transcript.
  • SONAR LLC (backend Timeweb)(Russia, Moscow) — primary storage for processing results. Transferred: transcript, metadata, and prompts.

8.3. Cross-border transfer of personal data

The Operator transfers personal data across borders to the following foreign countries:

StateProtection category according to the Roskomnadzor listGuarantorGoal
GermanyEnsures adequate protectionSoniox (Frankfurt), Hetzner Online GmbHSTT, network transport
USADoes not provide adequate protectionSoniox HQ, OpenRouter, GoogleSTT, LLM generation
ChinaDoes not provide adequate protectionDeepSeek AILLM generation (backup)

The notification of intent to conduct cross-border transfers has been submitted to Roskomnadzor and approved without restrictions. For transfers to countries that do not provide adequate protection, the Operator obtains the Data Subject's separate written consent in accordance with Part 4 of Article 12 of Federal Law No. 152-FZ (see Consent to cross-border data transfer).

8.4. Voice data

Voice data is recognized as biometric personal data when used for identity verification (Art. 11, 152-FZ). Sonar Assistant processes audio for speech recognition, does not use it for personal identification, and does not place it in the Unified Biometric System. If voice is used for identity verification in a specific scenario, written consent as required by law will be needed (see Consent to processing of biometric personal data).

Each third-party service processes data in accordance with its privacy policy. We transfer only the minimum necessary amount of data.

9. Cookies

As of May 30, 2025, cookies that can identify a user are considered personal data (420-FZ). The service uses the following cookie categories:

  • Mandatory (strictly necessary)— required for authorization and correct Service operation. Cannot be disabled. Legal basis: operator's legitimate interest. Term: session or up to 30 days.
  • Analytical— help improve the Service, collect anonymized usage statistics. Can be disabled via the cookie banner. Legal basis: user consent. Term: up to 12 months.

We do not use advertising or marketing cookies. Analytical cookie management is available through the banner on your first visit to the site.

10. User rights

In accordance with 152-FZ, you have the right to:

  • Get information about the processing of your personal data
  • Request data clarification, blocking, or deletion
  • Withdraw consent for personal data processing (for data processed based on consent)
  • Unsubscribe from marketing emails
  • Appeal the Operator's actions to Roskomnadzor

To exercise your rights, send a request to support@sonarsense.io. We will review the request within 10 business days.

Withdrawal of consent for marketing emails does not affect the ability to use the Service. Withdrawal of consent for the processing of data necessary for the execution of the contract is grounds for termination of services.

11. Policy Changes

The Operator may amend this Policy. The current version is always available at sonarsense.io/privacy. In case of significant changes, we will notify users through the Service interface or by email.

12. Applicable Law

This Policy is governed by the legislation of the Russian Federation, including Federal Law No. 152-FZ of 27.07.2006 'On Personal Data'. The supervisory authority is the Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor).

© 2026 sonarsense.io