Skip to main content
Back to home

Privacy Policy

Last updated: 25 May 2026

1. Who we are

SonicBridge s. r. o.(“SonicBridge”, “we”, “us”) is the data controller responsible for your personal data.

  • Registered address: Karpatské námestie 7770/10A, 831 06 Bratislava – mestská časť Rača, Slovakia
  • IČO (company reg.): 57 588 694
  • Contact: legal@sonicbridge.io

This policy applies to all users of the SonicBridge platform (sonicbridge.io) and is governed by the EU General Data Protection Regulation (GDPR) and Act No. 18/2018 Coll. on the Protection of Personal Data (Slovakia).

2. Data we collect and why

Account data

Name, email address, password (hashed).
Legal basis: Performance of contract (Art. 6(1)(b) GDPR).

Profile data

Profile photo, biography, location, genre preferences, social media links, platform links.
Legal basis: Performance of contract / Legitimate interest in providing personalised matching.

Submitted music and content

Audio files, release metadata (title, artist, ISRC, release date, artwork), submission notes.
Legal basis: Performance of contract.

Payment and billing data

Billing name, billing address, VAT number (optional). Card data is handled exclusively by Stripe — we never see or store raw card numbers. We store a record of each transaction (amount, date, Stripe session ID) for invoicing and legal retention obligations.
Legal basis: Performance of contract; Legal obligation (Slovak tax law, 10-year retention).

Usage and technical data

Log data (IP address, browser type, pages visited, timestamps), error reports, performance metrics. Vercel Analytics collects anonymised, cookieless page-view statistics — no personal identification is possible.
Legal basis: Legitimate interest in platform security and improvement.

Communications

Messages you send to us (support requests, feedback).
Legal basis: Legitimate interest.

3. How we use your data

  • Operate the platform and deliver the core service (matching creators with tastemakers)
  • Process payments and generate compliant invoices
  • Generate your Track Protection certificates
  • Send transactional emails (submission confirmations, invoice delivery, review notifications)
  • Send marketing communications — only with your explicit consent, and you can unsubscribe at any time
  • Detect fraud, prevent abuse, and enforce our Terms of Service
  • Comply with Slovak and EU legal obligations (tax records, GDPR)

4. Third-party processors (sub-processors)

We share your data only with the following trusted service providers, solely to operate the platform. Each is bound by GDPR-compliant data processing agreements or Standard Contractual Clauses (SCCs) for transfers outside the EU.

  • Supabase Inc.
    Country
    USA (data stored EU-West)
    Purpose
    Database, user authentication, file storage
  • Mux, Inc.
    Country
    USA
    Purpose
    Audio and video processing and delivery
  • Stripe Payments Europe Limited
    Country
    Ireland (EU)
    Purpose
    Payment processing
  • Vercel Inc.
    Country
    USA (EU edge network)
    Purpose
    Hosting, serverless compute, anonymised analytics
  • Resend Inc.
    Country
    USA
    Purpose
    Transactional email delivery
  • Functional Software Inc. (Sentry)
    Country
    USA
    Purpose
    Error monitoring and crash reporting
  • SuperFaktúra s. r. o.
    Country
    Slovakia (EU)
    Purpose
    Invoice generation and VAT compliance

We do not sell personal data to third parties. We do not use data brokers or advertising networks.

5. International data transfers

Some sub-processors are based in the United States. Where data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission, or on the EU-US Data Privacy Framework where applicable. Supabase stores your data in an EU-West region by default.

6. How long we keep your data

  • Account and profile data: Until you delete your account, plus 30 days for recovery.
  • Submitted music and content: Until you delete it or close your account.
  • Payment records and invoices: 10 years from the date of transaction (Slovak tax law requirement).
  • Error logs and technical data: 90 days.
  • Marketing consent records: Until you withdraw consent plus 3 years.

7. Cookies

We use only strictly necessary cookies — specifically, session cookies set by Supabase to manage your authenticated session. No advertising, tracking, or third-party marketing cookies are used. Vercel Analytics is cookieless.

For full details, see our Cookie Policy.

8. Your GDPR rights

Under GDPR you have the following rights. To exercise any of them, email legal@sonicbridge.io. We will respond within 30 days.

  • Access (Art. 15): Obtain a copy of your personal data.
  • Rectification (Art. 16): Correct inaccurate or incomplete data.
  • Erasure (Art. 17): Request deletion of your data, subject to legal retention obligations.
  • Restriction (Art. 18): Limit how we process your data.
  • Portability (Art. 20): Receive your data in a machine-readable format.
  • Objection (Art. 21): Object to processing based on legitimate interest.
  • Withdraw consent: Where processing is consent-based, withdraw at any time without affecting prior processing.

You also have the right to lodge a complaint with the Slovak data protection authority: Úrad na ochranu osobných údajov SR, dataprotection.gov.sk.

9. Security

We implement appropriate technical and organisational measures to protect your data — including encryption in transit (TLS) and at rest, access controls, row-level security on our database, and regular security reviews. In the event of a data breach affecting your rights, we will notify you and the relevant supervisory authority in accordance with GDPR Article 33/34.

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email or a prominent notice on the platform at least 14 days before they take effect. The “Last updated” date at the top of this page always reflects the most recent version.

11. Contact

For any privacy-related questions or data subject requests, contact us at legal@sonicbridge.io.

See also: Legal notice (Imprint) · Cookie Policy

© 2026 SonicBridge s. r. o. · All rights reserved.