Skip to content
Soras Corp Tech
Products Enthyma Legal Contact us
Part of Soras Corp
Englishen Deutschde Españoles Françaisfr Italianoit 日本語ja Polskipl Português (Brasil)pt Русскийru Українськаuk
Contact us

Privacy Policy

Documents for Enthyma, operated by Soras Corporation LTD.

Drafts under legal review

These documents are working drafts prepared for review by counsel and are not yet in force. The English version governs.

On this page
  1. 1. Who we are and how to reach us
  2. 2. Our roles
  3. 3. What we collect
  4. 4. Why we use it and our legal bases
  5. 5. Who receives personal data
  6. 6. International transfers
  7. 7. How long we keep data
  8. 8. Your rights
  9. 9. California residents
  10. 10. Other jurisdictions
  11. 11. If your public post was analysed
  12. 12. Children
  13. 13. Security
  14. 14. Cookies
  15. 15. Changes
All legal documents

This policy explains how Soras Corporation LTD ("we", "us") handles personal data when you visit our websites, create an Enthyma account, or use the Service. It covers the EU and UK General Data Protection Regulations (GDPR and UK GDPR), the California Consumer Privacy Act as amended (CCPA/CPRA) and the other laws named below.

1. Who we are and how to reach us

  • Controller: Soras Corporation LTD, to be confirmed, Ukraine, company number to be confirmed.
  • Privacy contact: help@sorascorp.com. General support: help@sorascorp.com.
  • Our representative in the EU (Article 27 GDPR): to be confirmed.
  • Our representative in the UK (Article 27 UK GDPR): to be confirmed.

2. Our roles

2.1 Controller. We decide how account, security and billing-relationship data is used, so we are its controller.

2.2 Processor. Our customers upload or connect audience evidence (reviews, comments, interview notes, public posts) and create content with it ("Customer Data"). We process Customer Data only on the customer's instructions under our Data Processing Addendum. If your data is in a customer's workspace (for example, you were interviewed or your public post was analysed), please contact that customer; we will help them respond.

2.3 Paddle. When paid plans are available, Paddle.com acts as our reseller and Merchant of Record. Paddle is an independent controller of the payment and tax data it collects; see Paddle's privacy notice.

3. What we collect

CategoryExamplesSourceRequired?
Account dataEmail address, name, password hash, interface language, time zone, company country and (at checkout) company nameYou, or your sign-in provider (Google, GitHub or Apple) when you choose itNeeded to create and run an account (contractual)
Sign-in provider dataYour provider account id, name, avatar and whether the provider verified your emailGoogle, GitHub or AppleOnly if you use that sign-in
Acceptance evidenceWhich document versions you accepted, the statement shown, time, locale, a keyed hash of your IP address, your browser's user agentGenerated when you acceptNeeded to prove the agreement (legal obligation and defence of claims)
Security dataSign-in events, audit records, keyed hashes of IP addresses, raw IP addresses in rate limitingGenerated by the ServiceNeeded for security
Usage eventsWhich product features were used, without contentGenerated by the ServiceOptional: you can switch them off
Support dataMessages you send to supportYouOnly if you contact us
Billing data we storePaddle customer and subscription ids, plan, status and renewal dates. We never receive card numbersPaddleNeeded for paid plans
Share-page visitorsA keyed hash of the visitor's IP address and the time a share link was openedGenerated when a shared page is openedUsed to count opens

We determine your country from what you enter at registration; payment details at checkout may also show a country, and we record where each value came from.

4. Why we use it and our legal bases

PurposeLegal basis (GDPR / UK GDPR)
Creating and running your account, providing the Service, supportPerformance of a contract (Art. 6(1)(b))
Keeping records of acceptances, handling legal claims, tax and accountingLegal obligation (Art. 6(1)(c)) and legitimate interests in defending claims (Art. 6(1)(f))
Security, fraud prevention, abuse handling, rate limitingLegitimate interests (Art. 6(1)(f))
First-party product analytics without contentLegitimate interests (Art. 6(1)(f)); you can opt out in Account settings
Service emails (verification, security, legal notices, exports)Performance of a contract and legal obligation
Marketing emailOnly with your consent (Art. 6(1)(a)); we send none today

Your right to object (Article 21). Where we rely on legitimate interests, you can object at any time on grounds relating to your situation. Write to help@sorascorp.com or switch off usage events in Account settings.

We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you.

5. Who receives personal data

5.1 Sub-processors. We use service providers to host and run the Service. The current list, with locations, transfer mechanisms and retention at each provider, is at Sub-processors. It includes Oracle Cloud Infrastructure (hosting and backups), Cloudflare (network and secure tunnel), Resend (email delivery), and AI inference providers such as Ollama Cloud and Groq. We only send data to an AI provider that has committed not to train on it.

5.2 Paddle, as an independent controller, for paid plans.

5.3 YouTube API Services. When a customer connects YouTube, the Service uses YouTube API Services to read public comments. By using those features you also agree to the YouTube Terms of Service (https://www.youtube.com/t/terms), and the Google Privacy Policy (https://policies.google.com/privacy) applies. You can revoke the Service's access through the Google security settings page (https://security.google.com/settings/security/permissions). Search queries sent to YouTube consist of the keywords the customer enters.

5.4 Authorities where the law requires, and professional advisers under confidentiality.

We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising.

6. International transfers

We host the Service in to be confirmed. Some sub-processors, including AI inference and email providers, process data outside the European Economic Area and the UK, for example in the United States. Where we transfer personal data out of the EEA or UK, we rely on an adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified), or on the European Commission's Standard Contractual Clauses and the UK Addendum. You can ask for a copy of the relevant safeguards at help@sorascorp.com.

7. How long we keep data

DataHow long
Account dataWhile the account exists, plus 30 days
Security and audit records365 days
IP addressesStored only as keyed hashes; raw addresses in rate limiting for 24 hours
Product usage events13 months
Server logs14 days
Acceptance evidenceWhile the account exists, plus 6 years
Data exports7 days
Erasure records (to re-apply erasures after a restore)37 days
Background job records7 days
Backups and previous object versions30 days, rolling
Customer DataAs configured per workspace; deleted within 30 days after the account ends
YouTube API dataRefreshed or deleted within 30 days
Legal notice delivery records3 years
Records of privacy requests6 years

When you delete your account there is a grace period of 7 days in which you can change your mind; after that we erase your account and workspaces.

AI inference providers process prompts only to return a response. Their retention of prompts, if any, is shown for each provider on the Sub-processors page.

8. Your rights

Depending on where you live, you can ask to access, correct, delete, restrict or port your personal data, object to processing, and withdraw consent. Most of this is self-service in Account › Privacy and data: download your data, see your agreements, and delete your account. You can also write to help@sorascorp.com. We answer within one month (extendable by two months for complex requests, with notice).

You have the right to lodge a complaint with a data protection authority, in particular in the country where you live or work or where an alleged infringement occurred. In the UK this is the Information Commissioner's Office.

9. California residents

This section is our notice at collection under the CCPA/CPRA. We collect the categories listed in section 3 for the purposes in section 4, and keep them for the periods in section 7. We do not sell or share personal information, and we honour Global Privacy Control signals as an opt-out. You have the right to know, delete and correct personal information, and to limit the use of sensitive personal information (we do not use it for purposes that would require this). You can use an authorised agent; we may ask the agent for proof of authority and verify your identity. We will not discriminate against you for exercising your rights.

10. Other jurisdictions

  • Brazil (LGPD). You can contact our data protection contact at help@sorascorp.com and complain to the ANPD. We follow ANPD Resolution 19/2024 for international transfers.
  • Japan (APPI). Transfers to third parties abroad are made with the safeguards APPI requires; you can ask us about the recipient country's system.
  • Switzerland (FADP). Transfers rely on adequacy or the Standard Contractual Clauses as amended for Swiss law.
  • Québec (Law 25). Our privacy contact is responsible for the protection of personal information.

11. If your public post was analysed

Customers can analyse public comments and posts about their category. The Service stores the text, a pseudonymised author handle, the date and a link to the original. It does not build profiles of individual authors. To object or ask for deletion, contact the customer who collected it; if you do not know who that is, write to help@sorascorp.com with a link to the post and we will help locate it and pass your request on.

12. Children

The Service is for business use by people aged 18 or over. We do not knowingly collect data about children.

13. Security

We use encryption in transit, per-workspace isolation enforced in the database, encryption of stored connector credentials, keyed hashing of IP addresses, least-privilege access, audited administration with multi-factor authentication, and encrypted off-site backups. See the Data Processing Addendum for details.

14. Cookies

We use only necessary and preference cookies; see the Cookie notice.

15. Changes

We will tell you about material changes by email and in the Service before they apply. The "Last updated" date and version history show every change.

Soras Corp Tech

The technology division of the international Soras Corp holding. We build AI products for business.

Products

Enthyma Enthyma pricing Open the Enthyma app

Company

About Careers Contact Soras Corp

Legal

Privacy policy Terms of service Data processing All documents
© 2026 Soras Corp Tech. All rights reserved. Part of the Soras Corp holding. sorascorp.com