Privacy Policy
Last updated: July 2026
Who We Are
Soneila is a background music service for coffee shops and similar venues, provided by Yutori Solutions Oy (business ID: 3601516-7), a company registered in Finland with its registered office at Hämeenkatu 14 C 32, 33100 Tampere, Finland.
Soneila streams purpose-built, AI-generated ambient music through a browser-based player. This privacy policy explains how we collect, use, and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR).
Our role under GDPR: Yutori Solutions Oy is the data controller for the personal data described in this policy. The player itself does not require your customers (the people in your venue) to identify themselves, and we do not collect personal data about them. The only personal data we process relates to the account holder who subscribes to and manages the service. For data protection inquiries, contact us at privacy@soneila.com.
What Data We Collect
We collect only the data needed to run the service and verify your access:
- Email address — provided when you sign in. We use magic links (a one-time sign-in link sent to your email), so we do not store passwords.
- Stripe customer and subscription identifiers — to verify that your subscription is active and which location(s) it covers. We never see or store your card details (see "Payments" below).
- Security logs — your IP address and access times are recorded in our server logs to detect and prevent abuse. Retained for 90 days.
- Playback preferences — anonymous, aggregated signals such as track "play", "skip", or "dislike" actions, used to understand aggregate usage and improve the catalogue (for example, removing unwanted tracks). These are not linked to an identifiable individual.
We do not collect names, postal addresses, or any special categories of personal data.
Why We Collect Your Data
- To authenticate you and send sign-in links
- To verify your subscription status and grant access to the player
- To enforce per-location licensing and one active stream per license
- To detect and prevent abuse, fraud, and unauthorised access
- To send service-related communications (sign-in links, billing and renewal notices)
- To maintain and improve the music catalogue and player experience
- To comply with our legal and accounting obligations
Legal Basis for Processing
We process your personal data on the following grounds under GDPR. Each purpose is linked to its specific legal basis:
| Purpose | Legal basis |
|---|---|
| Authenticating you and providing access to the player | Contract performance (Art. 6(1)(b)) |
| Verifying subscription status and enforcing per-location licensing | Contract performance (Art. 6(1)(b)) |
| Sending service-related communications (sign-in links, billing notices) | Contract performance (Art. 6(1)(b)) |
| Detecting abuse and ensuring service security | Legitimate interest (Art. 6(1)(f)) |
| Improving the catalogue and player through aggregated usage signals | Legitimate interest (Art. 6(1)(f)) |
| Retaining billing data and complying with accounting obligations | Legal obligation (Art. 6(1)(c)) |
| Sending marketing communications (if applicable) | Consent (Art. 6(1)(a)) |
Data Recipients and Processors
We share your personal data only with the service providers needed to operate Soneila, each acting on our behalf under GDPR-compliant Data Processing Agreements:
- Stripe — payment processing and subscription billing
- Postmark — delivery of service emails (sign-in links, billing notices)
- Cloudflare — content delivery network and audio storage (R2)
- Hetzner — server hosting within the EU
We do not sell your personal data. We may disclose data to legal or regulatory authorities where required by law.
How Long We Keep Your Data
- Account data (email, Stripe identifiers): retained while your subscription is active and deleted after it ends, subject to the billing-record exception below.
- Security logs (IP address, access times): deleted after 90 days.
- Billing records: retained as required by Finnish accounting law (Kirjanpitolaki).
After the applicable retention period, data is securely deleted or irreversibly anonymised.
Your Rights Under GDPR
As a data subject in the EU, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your personal data
- Data portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interests
- Restrict processing — request limitation of processing in certain circumstances
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing
- Lodge a complaint — with a supervisory authority (see below)
How to exercise your rights: Email privacy@soneila.com. We will verify your identity and respond within 30 days. If your request is complex, we may extend this by a further 60 days and will notify you within the original 30-day period. Your first request is free; we may charge a reasonable fee for manifestly unfounded or excessive requests.
Supervisory authority: You may lodge a complaint with the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), Lintulahdenkuja 4, 00530 Helsinki, Finland. Website: tietosuoja.fi.
Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. This includes encryption in transit and at rest, access controls, and regular security review.
Soneila's servers and audio are hosted within the European Economic Area (EEA). Some providers, including our payment processor Stripe, may process limited data outside the EEA as part of their global operations. Where data is transferred outside the EEA, we rely on appropriate safeguards such as EU Standard Contractual Clauses or European Commission adequacy decisions.
Cookies and Tracking Technologies
Soneila uses a minimal, privacy-first approach:
- Essential cookie: a single strictly necessary cookie — an encrypted sign-in session that keeps you logged in on this device for up to 6 months. This does not require consent.
- No tracking or advertising cookies.
We use a privacy-first, cookieless analytics service to understand aggregate traffic to our website, and server-side logging of IP addresses and access times for security purposes (retained for 90 days, not used for profiling).
Contact Us
If you have questions about this privacy policy or wish to exercise your data protection rights, contact us at privacy@soneila.com. You also have the right to lodge a complaint with your local data protection authority.