Sonar Distribution
Privacy Policy
This Policy explains which personal data Sonar Distribution (https://sonar-distribution.com) processes, why we do so, and what rights you have. It is written with the GDPR (EU/EEA), the California CCPA/CPRA, Russian Federal Law No. 152-FZ on Personal Data, and other applicable data-protection rules in mind.
1. Data controller
The controller of personal data is Sonar Distribution. Send privacy requests to [email protected] with the subject «Privacy». We will respond within the time required by applicable law (typically 30 days, with a possible extension for complex cases).
2. Data we process
- Account data: name or label name, email, password (hashed), country, interface language, role.
- Release data: audio, artwork, metadata, contributors, UPC/ISRC, moderation status, AI flags.
- Financial data: balances, credit history, withdrawal requests, and payout details you save.
- Support correspondence and attachments.
- Technical data: IP address, browser type, session cookies, security and API logs.
- Catalogue analytics: aggregated store reports on streams, territories, and revenue linked to your releases.
We do not ask for special-category data (health, biometrics, political opinions). Please do not send it to us on purpose.
3. Purposes and legal bases (GDPR)
- Contract (Art. 6(1)(b) GDPR): registration, distribution, the cabinet, payouts, support.
- Legal obligation (Art. 6(1)(c)): accounting and tax records, lawful authority requests.
- Legitimate interests (Art. 6(1)(f)): security, fraud prevention, improving the Service, defending our rights. You may object to processing based on legitimate interests.
- Consent (Art. 6(1)(a)): if we ever add optional analytics or marketing cookies, only after a separate consent that you can withdraw.
4. 152-FZ (Russian Federation)
If you are in Russia, processing is also based on Art. 6(1)(5) of 152-FZ (performance of a contract) and other applicable grounds. You may request information about processing, correction, blocking, or destruction, withdraw consent where processing relies on it, and complain to Roskomnadzor or a court.
5. CCPA/CPRA (California)
We do not sell or share personal information for money within the meaning of the CCPA. California residents may request information about collected data, deletion (subject to exceptions such as performing a contract and record-keeping), and freedom from discrimination for exercising these rights. Email [email protected].
6. Recipients and international transfers
Data may be disclosed to:
- digital stores — as needed for distribution and reporting;
- processors (hosting, email, file storage, payment services) under processing terms;
- public authorities — only when legally required;
- a successor if the Service is reorganised.
Stores and infrastructure may be outside your country, including countries without an EU adequacy decision. We then rely on contractual necessity, Standard Contractual Clauses (SCCs), and other lawful mechanisms. By uploading a release, you understand that files and metadata will be sent to the chosen stores worldwide.
7. Retention
- Account data — while the account is active and then for as long as needed for payouts, claims, and law (typically up to 5 years for financial records unless the law requires longer).
- Releases and distribution logs — while the release is live and a reasonable period after takedown.
- Security logs — a limited period sufficient to investigate incidents.
- Support correspondence — while needed to help you and defend our rights.
8. Your rights
Depending on applicable law, you may request access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and information about transfers. You may also lodge a complaint with a supervisory authority where you live, work, or where the alleged infringement occurred (in the EU, a GDPR authority; in Russia, Roskomnadzor).
We may ask you to verify your identity. Some data cannot be deleted while it is still needed for the contract, payouts, claims defence, or the law.
9. Children
The Service is not directed at anyone under 18. If we learn that a child created an account, we will delete it and related data except where the law requires us to keep it.
10. Security and automated decisions
We use organisational and technical measures: HTTPS, password hashing, staff access limits, and backups. No online service is perfectly secure.
We do not take solely automated decisions that produce legal effects (such as automated denial of rights). Release moderation involves the team.
11. Changes
We may update this Policy. The current version is always on this page with the effective date. For material changes we will notify you by email or in the cabinet where reasonable.