This policy explains how Soras Corporation LTD ("we", "us") handles personal data when you visit our websites, create an Enthyma account, or use the Service. It covers the EU and UK General Data Protection Regulations (GDPR and UK GDPR), the California Consumer Privacy Act as amended (CCPA/CPRA) and the other laws named below.
1. Who we are and how to reach us
- Controller: Soras Corporation LTD, to be confirmed, Ukraine, company number to be confirmed.
- Privacy contact: help@sorascorp.com. General support: help@sorascorp.com.
- Our representative in the EU (Article 27 GDPR): to be confirmed.
- Our representative in the UK (Article 27 UK GDPR): to be confirmed.
2. Our roles
2.1 Controller. We decide how account, security and billing-relationship data is used, so we are its controller.
2.2 Processor. Our customers upload or connect audience evidence (reviews, comments, interview notes, public posts) and create content with it ("Customer Data"). We process Customer Data only on the customer's instructions under our Data Processing Addendum. If your data is in a customer's workspace (for example, you were interviewed or your public post was analysed), please contact that customer; we will help them respond.
2.3 Paddle. When paid plans are available, Paddle.com acts as our reseller and Merchant of Record. Paddle is an independent controller of the payment and tax data it collects; see Paddle's privacy notice.
3. What we collect
| Category | Examples | Source | Required? |
|---|---|---|---|
| Account data | Email address, name, password hash, interface language, time zone, company country and (at checkout) company name | You, or your sign-in provider (Google, GitHub or Apple) when you choose it | Needed to create and run an account (contractual) |
| Sign-in provider data | Your provider account id, name, avatar and whether the provider verified your email | Google, GitHub or Apple | Only if you use that sign-in |
| Acceptance evidence | Which document versions you accepted, the statement shown, time, locale, a keyed hash of your IP address, your browser's user agent | Generated when you accept | Needed to prove the agreement (legal obligation and defence of claims) |
| Security data | Sign-in events, audit records, keyed hashes of IP addresses, raw IP addresses in rate limiting | Generated by the Service | Needed for security |
| Usage events | Which product features were used, without content | Generated by the Service | Optional: you can switch them off |
| Support data | Messages you send to support | You | Only if you contact us |
| Billing data we store | Paddle customer and subscription ids, plan, status and renewal dates. We never receive card numbers | Paddle | Needed for paid plans |
| Share-page visitors | A keyed hash of the visitor's IP address and the time a share link was opened | Generated when a shared page is opened | Used to count opens |
We determine your country from what you enter at registration; payment details at checkout may also show a country, and we record where each value came from.
4. Why we use it and our legal bases
| Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|
| Creating and running your account, providing the Service, support | Performance of a contract (Art. 6(1)(b)) |
| Keeping records of acceptances, handling legal claims, tax and accounting | Legal obligation (Art. 6(1)(c)) and legitimate interests in defending claims (Art. 6(1)(f)) |
| Security, fraud prevention, abuse handling, rate limiting | Legitimate interests (Art. 6(1)(f)) |
| First-party product analytics without content | Legitimate interests (Art. 6(1)(f)); you can opt out in Account settings |
| Service emails (verification, security, legal notices, exports) | Performance of a contract and legal obligation |
| Marketing email | Only with your consent (Art. 6(1)(a)); we send none today |
Your right to object (Article 21). Where we rely on legitimate interests, you can object at any time on grounds relating to your situation. Write to help@sorascorp.com or switch off usage events in Account settings.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you.
5. Who receives personal data
5.1 Sub-processors. We use service providers to host and run the Service. The current list, with locations, transfer mechanisms and retention at each provider, is at Sub-processors. It includes Oracle Cloud Infrastructure (hosting and backups), Cloudflare (network and secure tunnel), Resend (email delivery), and AI inference providers such as Ollama Cloud and Groq. We only send data to an AI provider that has committed not to train on it.
5.2 Paddle, as an independent controller, for paid plans.
5.3 YouTube API Services. When a customer connects YouTube, the Service uses YouTube API Services to read public comments. By using those features you also agree to the YouTube Terms of Service (https://www.youtube.com/t/terms), and the Google Privacy Policy (https://policies.google.com/privacy) applies. You can revoke the Service's access through the Google security settings page (https://security.google.com/settings/security/permissions). Search queries sent to YouTube consist of the keywords the customer enters.
5.4 Authorities where the law requires, and professional advisers under confidentiality.
We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising.
6. International transfers
We host the Service in to be confirmed. Some sub-processors, including AI inference and email providers, process data outside the European Economic Area and the UK, for example in the United States. Where we transfer personal data out of the EEA or UK, we rely on an adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified), or on the European Commission's Standard Contractual Clauses and the UK Addendum. You can ask for a copy of the relevant safeguards at help@sorascorp.com.
7. How long we keep data
| Data | How long |
|---|---|
| Account data | While the account exists, plus 30 days |
| Security and audit records | 365 days |
| IP addresses | Stored only as keyed hashes; raw addresses in rate limiting for 24 hours |
| Product usage events | 13 months |
| Server logs | 14 days |
| Acceptance evidence | While the account exists, plus 6 years |
| Data exports | 7 days |
| Erasure records (to re-apply erasures after a restore) | 37 days |
| Background job records | 7 days |
| Backups and previous object versions | 30 days, rolling |
| Customer Data | As configured per workspace; deleted within 30 days after the account ends |
| YouTube API data | Refreshed or deleted within 30 days |
| Legal notice delivery records | 3 years |
| Records of privacy requests | 6 years |
When you delete your account there is a grace period of 7 days in which you can change your mind; after that we erase your account and workspaces.
AI inference providers process prompts only to return a response. Their retention of prompts, if any, is shown for each provider on the Sub-processors page.
8. Your rights
Depending on where you live, you can ask to access, correct, delete, restrict or port your personal data, object to processing, and withdraw consent. Most of this is self-service in Account › Privacy and data: download your data, see your agreements, and delete your account. You can also write to help@sorascorp.com. We answer within one month (extendable by two months for complex requests, with notice).
You have the right to lodge a complaint with a data protection authority, in particular in the country where you live or work or where an alleged infringement occurred. In the UK this is the Information Commissioner's Office.
9. California residents
This section is our notice at collection under the CCPA/CPRA. We collect the categories listed in section 3 for the purposes in section 4, and keep them for the periods in section 7. We do not sell or share personal information, and we honour Global Privacy Control signals as an opt-out. You have the right to know, delete and correct personal information, and to limit the use of sensitive personal information (we do not use it for purposes that would require this). You can use an authorised agent; we may ask the agent for proof of authority and verify your identity. We will not discriminate against you for exercising your rights.
10. Other jurisdictions
- Brazil (LGPD). You can contact our data protection contact at help@sorascorp.com and complain to the ANPD. We follow ANPD Resolution 19/2024 for international transfers.
- Japan (APPI). Transfers to third parties abroad are made with the safeguards APPI requires; you can ask us about the recipient country's system.
- Switzerland (FADP). Transfers rely on adequacy or the Standard Contractual Clauses as amended for Swiss law.
- Québec (Law 25). Our privacy contact is responsible for the protection of personal information.
11. If your public post was analysed
Customers can analyse public comments and posts about their category. The Service stores the text, a pseudonymised author handle, the date and a link to the original. It does not build profiles of individual authors. To object or ask for deletion, contact the customer who collected it; if you do not know who that is, write to help@sorascorp.com with a link to the post and we will help locate it and pass your request on.
12. Children
The Service is for business use by people aged 18 or over. We do not knowingly collect data about children.
13. Security
We use encryption in transit, per-workspace isolation enforced in the database, encryption of stored connector credentials, keyed hashing of IP addresses, least-privilege access, audited administration with multi-factor authentication, and encrypted off-site backups. See the Data Processing Addendum for details.
14. Cookies
We use only necessary and preference cookies; see the Cookie notice.
15. Changes
We will tell you about material changes by email and in the Service before they apply. The "Last updated" date and version history show every change.