1. Who we are
Sonproof, Inc. ("Sonproof", "we", "us") operates the Sonproof platform and website (the "Service") - an independent music-rights protection service that detects unauthorised uses of sound recordings and musical compositions across digital platforms and, on instruction from rights holders, carries out claims, monetisation requests, takedown notices and related enforcement procedures.
For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), Sonproof is the controller of personal data we collect through our website and in the course of running our own business, and a processor of personal data contained in catalog and rights documentation that our clients upload to the platform.
Incorporated in Delaware, United States
privacy@sonproof.com
Where required, our representative in the EU and the UK and our Data Protection Officer can be reached through privacy@sonproof.com.
2. What personal data we collect
2.1 Data you give us
- Account and contact data - name, business email, phone, job title, company, billing contact, and login credentials when you request a demo, create an account, or contact us.
- Rights and catalog documentation - names of writers, performers, producers and rights holders; contractual documents; Letters of Authorisation; ISRC, ISWC, UPC and split data; and the audio recordings themselves. These may contain personal data of third parties (for example, songwriters), which you are responsible for being entitled to share with us.
- Communications - emails, support tickets, meeting notes and the content of forms you submit.
2.2 Data we collect when you use the Service
- Usage and device data - IP address, browser and device type, pages viewed, actions taken in the dashboard, timestamps and referring URLs. We use strictly necessary and (with consent) analytics cookies; see Section 8.
- Audit logs - every action taken in a client account (detections reviewed, claims approved, notices sent, disputes handled) together with the user who took it and when. These logs are a core part of the Service and are retained for evidentiary purposes.
2.3 Data we collect from third parties and public platforms
To provide the Service we scan publicly available content on video, social, streaming, download, live-streaming and other digital platforms. In doing so we collect platform-level data about uploads that match our clients' catalogs: channel or account names, public display names, URLs, upload dates, view counts, and the matched audio or video itself. Some of this information constitutes personal data of the uploader (an "Uploader"). We process it for the legitimate interests of our clients and of Sonproof in identifying and enforcing intellectual-property rights (GDPR Art. 6(1)(f)) and, where a notice is sent, to comply with the legal requirements of the relevant notice-and-action regime.
When an Uploader submits a counter-notice or dispute, we collect the personal data they provide in that submission (name, address, contact details, statement, and - for US DMCA counter-notices - consent to jurisdiction). See the Counter-Notice Policy.
3. Why we use personal data and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Providing the Service to clients, including detection, human review, evidence packaging and enforcement actions | Account data, catalog and rights data, platform data about Uploaders, audit logs | Contract (Art. 6(1)(b)) with clients; legitimate interests (Art. 6(1)(f)) in IP enforcement for Uploader data |
| Sending claims, takedown notices and counter-notice forwarding in compliance with law | Rights holder contact data, Uploader data, notice content | Legal obligation (Art. 6(1)(c)) where a statute prescribes notice content; otherwise legitimate interests |
| Security, fraud prevention, abuse detection and audit | Usage data, audit logs | Legitimate interests |
| Billing, accounting and tax | Billing and contact data | Contract; legal obligation |
| Marketing to business contacts (demo follow-ups, product updates) | Contact data | Legitimate interests; consent where required by local law (you can opt out at any time) |
| Analytics and product improvement | Usage data (cookies) | Consent |
| Establishing, exercising or defending legal claims | Any of the above | Legitimate interests; legal obligation |
We do not use personal data to make decisions about individuals that produce legal or similarly significant effects solely by automated means. Every enforcement action is reviewed and approved by a trained human before it is sent. Automated matching scores inform, but do not make, enforcement decisions.
4. How we share personal data
- Platforms. When we send a claim, monetisation request, takedown notice or counter-notice, we transmit the information the platform's process requires - which under the DMCA and similar laws typically includes the name and contact details of the complaining rights holder or its authorised agent, and may be forwarded by the platform to the Uploader.
- Our clients. Clients see the detections, evidence packages and enforcement history relating to their own catalog, including Uploader platform data relevant to each case.
- Service providers acting on our instructions under data-processing agreements: cloud hosting, audio fingerprinting infrastructure, email delivery, CRM, analytics, payment processing and customer support tools. A current list of our sub-processors is available on request from privacy@sonproof.com.
- Professional advisers, regulators, courts and law enforcement where required by law, to respond to lawful requests, or to protect the rights, property or safety of Sonproof, our clients or others.
- Corporate transactions. If Sonproof is involved in a merger, acquisition or asset sale, personal data may be transferred as part of that transaction, subject to this Policy.
We do not sell personal data, and we do not share it with third parties for their own marketing.
5. International transfers
Sonproof is headquartered in the United States and uses service providers in the US, the EU and the UK. Where personal data originating in the EEA, UK or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum or IDTA), supplemented where necessary by additional safeguards. Copies are available on request.
6. How long we keep personal data
| Data | Retention |
|---|---|
| Client account data | Life of the contract plus 6 years (limitation periods and tax law) |
| Catalog audio and rights documentation | Life of the contract; deleted or returned within 90 days of termination unless required to defend a pending claim |
| Enforcement case files, evidence packages and audit logs | 7 years from case closure, because these may be required to defend claims of misrepresentation (e.g. 17 U.S.C. §512(f)) or to respond to disputes |
| Uploader platform data for matches that are reviewed and not acted upon | Deleted or de-identified within 12 months of the last review |
| Counter-notice and dispute submissions | 7 years from resolution |
| Marketing contact data | Until you opt out, or 24 months after last interaction |
| Website analytics | Up to 26 months (aggregated thereafter) |
7. Your rights
Depending on where you are, you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to our processing (including to processing based on legitimate interests), to data portability, and to withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with a supervisory authority - in the EU, the authority in your member state; in the UK, the Information Commissioner's Office.
If you are an Uploader whose content was the subject of an enforcement action, you can exercise these rights by writing to privacy@sonproof.com. Note that we may be required to retain some data to document a notice that has already been sent, to process a counter-notice, or to defend a legal claim; where we rely on an exemption we will tell you.
California residents have rights under the CCPA/CPRA to know, delete, correct, and opt out of "sale" or "sharing" of personal information, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined in the CPRA. To exercise your rights, email privacy@sonproof.com. We will verify your identity before acting on a request.
We respond to verified requests within one month (GDPR) or 45 days (CCPA), extendable where the law permits.
8. Cookies and similar technologies
Our website uses strictly necessary cookies (session, security, preference) that do not require consent, and - only with your consent - analytics cookies to understand how the site is used. We do not use advertising cookies. You can change your choices at any time via the cookie settings link in the footer. The platform dashboard uses only cookies that are necessary to keep you signed in and secure.
9. Security
We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2+) and at rest, role-based access control, single sign-on and multi-factor authentication for client accounts, segregated client environments, logging and monitoring, vendor due diligence, and regular security reviews. Catalog audio is stored in access-controlled storage and is never made publicly accessible. No system is perfectly secure; if we become aware of a personal-data breach that is likely to result in a risk to individuals we will notify the relevant supervisory authority and affected persons as required by law.
10. Children
The Service is designed for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact privacy@sonproof.com and we will delete it.
11. Changes to this Policy
We may update this Policy from time to time. We will post the new version here with a revised "Last updated" date and, for material changes, notify clients by email or in-product notice at least 30 days before they take effect.
12. Contact
Questions, requests and complaints: privacy@sonproof.com, or by post to the address in Section 1. EU/UK representative and DPO: reachable via privacy@sonproof.com.