Privacy Policy
Last updated: March 1, 2026
This Privacy Policy describes how SonexLabs ("we", "our", or "us") collects, uses, stores, and protects information when you use the SonexLabs platform. We are committed to responsible data handling and to compliance with applicable privacy and data protection regulations across the jurisdictions in which we operate, including the General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, India's Digital Personal Data Protection Act (DPDPA), the California Consumer Privacy Act (CCPA), and other regional frameworks.
1. Who We Are and How to Contact Us
SonexLabs operates the platform and is the data controller for personal data collected through account registration, platform usage, and direct communications. For any privacy enquiry, data subject request, or complaint, contact us at: support@sonexlabs.com
2. Data We Collect
We collect and process the following categories of data:
- Account data: Name, email address, organisation name, and authentication credentials provided at registration.
- Billing data: Wallet top-up history and invoice records. Payment card details are processed exclusively by our payment providers and are never stored by SonexLabs.
- Usage and log data: Feature usage, API request metadata, session data, IP address, browser type, and timestamps generated when you use the platform.
- Telephony metadata: Call records including call duration, connection status, campaign identifiers, and timestamps. Audio recordings of calls are only stored if you have explicitly enabled call recording within your account settings.
- Agent configuration data: Call scripts, agent configurations, voice settings, and workflow logic that you create and save on the platform.
- AI interaction data: Inputs and outputs generated during AI-powered calls, where retained according to your account settings. This data is not used to train or improve our AI models without your explicit written consent.
- Communication data: Emails and messages you send to our support or sales team.
3. How We Use Your Data
We use your data to:
- Create and manage your account and provide platform access;
- Process wallet transactions and generate invoices;
- Operate, monitor, and improve platform performance and reliability;
- Provide customer support and respond to your enquiries;
- Enforce our Terms of Use and protect the security of the platform;
- Comply with legal obligations and respond to lawful regulatory requests;
- Send you service-related communications including security alerts and platform updates.
We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes.
4. AI and Generative AI Data Practices
SonexLabs uses AI systems to power voice agent calls on behalf of our customers. These systems process spoken audio, generate natural language responses, and manage conversation flows. The following commitments apply to how we handle data within these AI systems:
- No model training on customer data: We do not use your call content, scripts, voice recordings, or personal data to train, fine-tune, or evaluate our AI models unless you have provided explicit written consent to do so.
- Data minimisation: AI systems process only the data necessary to conduct and complete the specific call task configured by you.
- Transparency obligations: Where required by the EU AI Act, TCPA, or equivalent local regulations, you are responsible as the deploying party for disclosing to call recipients that they are speaking with an AI. Our Terms of Use require this of all customers.
- Human oversight: SonexLabs provides tools for you to monitor AI agent outputs and review call transcripts. For high-stakes use cases, you are responsible for implementing appropriate human review processes.
- EU AI Act compliance: Our voice AI systems are designed with the risk classification framework of the EU AI Act in mind. We maintain documentation of our AI system capabilities, intended use cases, and technical limitations, and we cooperate with customers and regulators on compliance matters.
5. Your Customers' Data (Controller and Processor)
When you use SonexLabs to make calls to individuals, the personal data of those individuals is processed by SonexLabs on your behalf. In this context:
- You are the data controller for your end users' personal data;
- SonexLabs acts as a data processor and processes this data only as instructed by you.
You are responsible for ensuring that you have a lawful basis for processing your end users' data and that you have obtained all required consents before initiating calls. Enterprise customers requiring a formal Data Processing Agreement (DPA) should contact support@sonexlabs.com.
6. Legal Bases for Processing (GDPR and UK GDPR)
Where GDPR or the UK GDPR applies, we rely on the following legal bases:
- Contract performance: Processing necessary to deliver the platform services you have agreed to receive;
- Legitimate interests: Security monitoring, fraud prevention, platform performance analysis, and improving the reliability of our service, where these do not override your rights;
- Legal obligation: Where processing is required to comply with applicable law or respond to a regulatory authority;
- Consent: For optional communications such as product news and marketing updates, where we seek your explicit opt-in.
7. Sharing Your Data
We may share data with the following categories of third parties, only to the extent necessary:
- Infrastructure providers: Cloud and hosting providers that operate the technical infrastructure of the platform, bound by confidentiality and data processing agreements;
- Payment processors: To handle wallet top-up transactions securely;
- Analytics and monitoring tools: For platform reliability, error tracking, and performance diagnostics, using anonymised or pseudonymised data where possible;
- Regulators and law enforcement: Where we are legally required to disclose data in response to a court order, regulatory request, or legal process.
We do not share your data with advertisers, data brokers, or any third party for commercial profiling purposes.
8. International Data Transfers
Your data may be stored or processed in countries outside your jurisdiction. Where data is transferred from the European Economic Area (EEA), the UK, or other regions with data transfer restrictions, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA), or other mechanisms approved by the relevant supervisory authority.
9. Data Retention
We retain your account and usage data for as long as your account is active and for a reasonable period thereafter, as required for legal, audit, or contractual purposes. Call metadata and AI interaction records are retained according to your account configuration and applicable legal requirements. You can request deletion of your data at any time, subject to our obligations under applicable law.
10. Security
We implement technical and organisational security measures designed to protect your data against unauthorised access, disclosure, loss, or destruction. These measures include encryption of data in transit and at rest, access controls and authentication requirements, audit logging, and regular security reviews. While we take security seriously, no system can guarantee absolute protection. We will notify you of any material data breach affecting your personal data in accordance with applicable law.
11. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate or outdated data;
- Request erasure of your data, subject to legal retention obligations;
- Object to or restrict certain processing of your data;
- Receive a portable copy of your data in a machine-readable format;
- Withdraw consent at any time where processing is based on consent.
California residents have additional rights under the CCPA, including the right to know what personal information we collect and sell. We do not sell personal information.
To exercise any of these rights, email us at support@sonexlabs.com. We will respond within the timeframe required by applicable law (30 days under GDPR, 45 days under CCPA).
12. Cookies and Tracking
The platform uses strictly necessary cookies to maintain your session and authenticate your access. We do not use third-party advertising cookies or cross-site behavioural tracking technologies. Where we use analytics tools, they are configured to anonymise data and comply with applicable law. You can manage cookie preferences through your browser settings.
13. Children's Privacy
The platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently done so, we will delete it promptly.
14. Updates to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a clear notice within the platform, with at least 14 days notice before such changes take effect. Your continued use of the platform after the effective date constitutes acceptance of the revised policy.
15. Supervisory Authority
If you are located in the EU or UK and believe we have not addressed a privacy concern to your satisfaction, you have the right to lodge a complaint with your local data protection supervisory authority. In the EU, you can find your authority at edpb.europa.eu. In the UK, the relevant authority is the Information Commissioner's Office (ICO) at ico.org.uk.
16. Contact
For all privacy-related enquiries, requests, or complaints: support@sonexlabs.com