Legal

Privacy policy

Last updated: 20 July 2026

This policy describes how the Sona service (mobile application and sona-app.xyz website), published by BeBranded, collects and processes personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act. Sona does not sell any data and uses no advertising trackers.

1Data controller

The data controller is BeBranded, a French simplified joint-stock company (SAS) with a share capital of €10,000, registered with the Bobigny Trade and Companies Register under number 984 530 212, with its registered office at 34 avenue Chanzy, 93250 Villemomble, France.

For any question about your data: privacy@sona-app.xyz.

2Data we collect

We apply the principle of minimisation: we only collect what is necessary for the Service to work.

Account
Email address, password (stored as a hash, never in clear text), name or nickname, profile picture if you add one. Depending on your sign-in method: phone number (SMS code sign-in) or the technical identifier and email address provided by Apple or Google.
Use of the Service
Favourited events and venues, venues, artists and companies you follow, recent searches (stored on your device), display and language preferences.
Cultural venues
For manager accounts: name and professional contact details of the contact person, associated venue(s), published content.
Location
Approximate device location, only if you grant location access, in order to show nearby events. The permission can be revoked at any time in your system settings.
Notifications
Technical notification identifier (push token) if you enable notifications.
Technical data
IP address, device type, operating system and app version, API access logs and error (crash) reports, for security and troubleshooting purposes.
Newsletter and contact
Email address and message content when you subscribe to the newsletter or write to us.

We do not collect any special-category data within the meaning of Article 9 GDPR and carry out no advertising profiling.

3Purposes and legal bases

Providing the Service (account, favourites, follows, event listings)
Performance of the contract formed by the terms of use (Art. 6(1)(b) GDPR)
Authentication and account security (including one-time SMS codes)
Performance of the contract and legitimate interest in securing the Service (Art. 6(1)(b) and 6(1)(f))
Showing nearby events
Consent, through the system location permission (Art. 6(1)(a))
Push notifications
Consent (Art. 6(1)(a))
Newsletter and Service updates
Consent (Art. 6(1)(a)), withdrawable at any time
Technical usage measurement, troubleshooting, abuse prevention
Legitimate interest in maintaining a reliable and secure service (Art. 6(1)(f))
Moderation of published content and handling of reports
Legitimate interest and compliance with legal obligations (Art. 6(1)(f) and 6(1)(c))
Accounting and legal obligations
Legal obligation (Art. 6(1)(c))

4Recipients and processors

Your data is accessible only to authorised staff at BeBranded and to the following technical providers, which act as processors and are bound by an agreement compliant with Article 28 GDPR:

Cloudflare, Inc.
Hosting of the website and API, and network delivery (processing within the European Union)
Supabase, Inc.
Database and file storage, infrastructure located in the European Union (“eu” region)
Resend, Inc.
Sending of transactional emails (password reset, address verification, invitations, newsletter)
Twilio Inc.
Sending of sign-in codes by SMS
Functional Software, Inc. (Sentry)
Technical monitoring and error reporting
Apple Inc. / Google LLC
App distribution, Sign in with Apple or Google, delivery of push notifications

We neither sell nor rent your data. It may be disclosed to the competent authorities where required by law.

Cultural venues have no access to the list of users who follow them by name; they only receive aggregated statistics.

5Transfers outside the European Union

The Service hosting and the database are located within the European Union. Some processors (Cloudflare, Sentry, Twilio, Resend, Apple, Google) are established in the United States or may access data from there for support purposes.

These transfers are governed by the European Commission's standard contractual clauses and, where applicable, by the provider's certification under the EU–US Data Privacy Framework, supplemented by technical measures (encryption in transit and at rest).

6Retention periods

Account and associated data
For as long as the account exists, then deletion or anonymisation within 30 days of its deletion
Inactive account
Deleted after 3 years without sign-in, following prior notice by email
Technical and security logs
12 months maximum
Error reports
90 days
Newsletter subscription
Until consent is withdrawn, then 3 years maximum from the last contact
Contact requests and reports
3 years from the last exchange
Accounting records
10 years (legal obligation)

7Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw your consent at any time and to issue directives regarding the fate of your data after your death.

You may exercise these rights directly in the app (editing your profile, deleting your account, managing notifications and location) or by writing to privacy@sona-app.xyz. We respond within one month, extendable by two months for complex requests. Proof of identity may be requested in the event of reasonable doubt.

You may also lodge a complaint with the French data protection authority, the CNIL (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr), or with the supervisory authority of your country of residence.

8Security

We implement appropriate technical and organisational measures: encryption in transit (HTTPS), encryption at rest, passwords stored as salted hashes, restricted and logged access to data, database-level privilege separation, error monitoring and regular backups.

No client application accesses the database directly: every request goes through our API, the single point where authorisation rules are enforced.

In the event of a data breach likely to result in a high risk to your rights, you will be informed in accordance with Articles 33 and 34 GDPR.

9Cookies and trackers

The sona-app.xyz website uses no advertising cookies and no third-party analytics trackers. Only strictly necessary local storage is used, in particular to remember your chosen display language; it requires no prior consent.

The mobile application embeds no advertising SDK and performs no tracking across other apps or websites. No tracking permission (App Tracking Transparency) is requested.

10Third-party links and websites

The Service links to the official websites of cultural venues and their ticketing providers, in particular through the “Book” button. Once on those sites, you are subject to their own privacy policies, over which BeBranded has no control.

Outbound links may carry an attribution parameter indicating that the visit comes from Sona; it contains no data that identifies you.

11Minors

The Service is not intended for people under 15 and we do not knowingly collect their data. If you become aware that an account has been created by a child under 15, write to privacy@sona-app.xyz: the account and associated data will be deleted.

12Changes to this policy

This policy may be updated to reflect legal or functional developments. The date of the latest update appears at the top of the page, and any material change will be signalled in the app or by email.

13Contact

BeBranded — 34 avenue Chanzy, 93250 Villemomble, France. Phone: +33 1 89 70 89 35. Personal data: privacy@sona-app.xyz. General enquiries: contact@sona-app.xyz.