EEA और यूनाइटेड किंगडम पूरक

    प्रारंभिक संस्करण, कानूनी समीक्षा में

    संस्करण 0.9.0

    यह दस्तावेज़ अभी हिंदी में अनुवादित नहीं है। इसे अंग्रेज़ी में दिखाया गया है; अनुवाद उपलब्ध होने तक अंग्रेज़ी पाठ ही बाध्यकारी है।

    Table of contents

    1. Scope and precedence
    2. Who we are, and our representatives
    3. Legal bases
    4. Special categories of data
    5. Children and the age of digital consent
    6. Your rights
    7. Automated decisions (Art. 22)
    8. International transfers
    9. Complaints to authorities
    10. Consumer rights
    11. Digital Services Act
    12. AI Act transparency
    13. Business customers: Data Act switching
    14. Language

    1. Scope and precedence

    1.1. This Supplement applies to you if you are in a member state of the EEA (the EU, Iceland, Liechtenstein and Norway) or in the United Kingdom.

    1.2. It supplements the Privacy Policy, the Terms of Service and the other documents of the SonhoLab Legal Center. It does not repeat them.

    1.3. If this Supplement conflicts with any other SonhoLab document, this Supplement prevails for you. "GDPR" means Regulation (EU) 2016/679 and, for the UK, the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 (DUAA).

    1.4. Nothing in the Terms of Service or in any other document excludes or limits rights that cannot be excluded or limited under the law that applies to you.

    2. Who we are, and our representatives

    2.1. Controller. L. M. PEREZ MONTANA, trade name SonhoLab, CNPJ 61.620.014/0001-00, Rua Fausto Cabral, 871, Casa A, Vicente Pinzon, Fortaleza-CE, 60181-227, Brazil. Email contacto@sonholab.com. Phone +55 85 99412-2292.

    2.2. Data protection officer. Our data protection officer (encarregado under Brazilian law) is reachable at contacto@sonholab.com.

    2.3. EU representative (GDPR Art. 27). SonhoLab is appointing a representative in the European Union, established in Ireland. Until the appointment is published, you and any EU supervisory authority can contact us at contacto@sonholab.com on any data protection matter.

    2.4. UK representative (UK GDPR Art. 27). SonhoLab does not currently direct its services to the United Kingdom and has no UK representative. If it starts to do so, it will appoint one and list it here. If you are in the UK, you keep all your rights under the UK GDPR, and you and the Information Commissioner's Office (ICO) can contact us directly at contacto@sonholab.com.

    2.5. Our roles. We are the controller for our website, central registration, accounts, billing, support, marketing, free tools and consumer apps. When a business customer loads personal data into a System, the customer is the controller and we are its processor under the Data Processing Addendum (DPA). If your data is in a customer's System, contact that organization first; we forward requests we receive and help it answer.

    3.1. We process your personal data as controller on these bases (GDPR Art. 6). Data categories and retention periods are in the Privacy Policy and the Data Retention Schedule.

    PurposeLegal basis
    Create and run your account; central registration; provide the Systems you selectContract (Art. 6(1)(b))
    Billing and paymentContract (Art. 6(1)(b))
    Keep invoices and tax records required by Brazilian lawLegitimate interest in complying with the law of the country where we are established (Art. 6(1)(f)). Brazilian law is not EU or member state law, so Art. 6(1)(c) does not apply.
    Keep access logs required by Brazilian law (Marco Civil art. 15)Legitimate interest in complying with that law and in keeping our services secure (Art. 6(1)(f))
    Security, fraud and abuse prevention; rate limitingLegitimate interest in protecting our users and services (Art. 6(1)(f)). In the UK, the recognized legitimate interests for security and crime prevention may apply.
    Support tickets and service messagesContract (Art. 6(1)(b))
    Marketing emailsConsent (Art. 6(1)(a)); for existing customers, marketing of similar services under ePrivacy Art. 13(2) and PECR, with an opt-out in every message
    Website analytics and other non-essential cookiesConsent (ePrivacy Art. 5(3); Art. 6(1)(a)). See the Cookie Policy.
    AI features you use in our consumer appsContract (Art. 6(1)(b))
    Hades voice samples and voice modelsExplicit consent of the voice owner (Arts. 6(1)(a) and 9(2)(a))
    Legal acceptance and consent records; legal claimsLegitimate interest in proving compliance and defending claims (Art. 6(1)(f)); Art. 9(2)(f) for special category data

    3.2. Legitimate interests. Where we rely on legitimate interests, we have balanced them against your rights and freedoms. You can ask the data protection officer for more information about the balancing test.

    3.3. Contract and statutory requirements. Data marked as required at sign-up is needed to create your account and provide the service. Without it we cannot provide the service. You are not under a statutory obligation to give us data.

    3.4. Withdrawing consent. You can withdraw consent at any time, as easily as you gave it. Withdrawal does not affect processing done before it.

    4. Special categories of data

    4.1. As controller, we process special categories of data (Art. 9) only in Hades:

    • Voice. We treat voice samples and voice models as special category data, and process them only with the explicit consent of the voice owner, given separately from the Terms of Service. When the voice owner withdraws consent, the voice is removed for everyone (the user who created it and all other users) and the source audio and voice model are deleted from all our systems automatically. Hades is not currently offered to the public; access is limited to invited testers.
    • Shared voice library. A voice is added to the shared library only if the voice owner opts in. For users in the EEA, a voice is available in the library only if the voice owner gave explicit consent to that sharing.
    • Conversations can reveal health or other sensitive information. We use it only to provide the conversation you request and to run the crisis protocol.
    • The rules for voices, memorials and deceased persons are in the Hades Addendum: Voice, Biometrics, Memorials and Companion AI. The GDPR does not apply to deceased persons (Recital 27), but national rules may, and the data of living people in recordings is fully protected.

    4.2. As processor, our Systems may hold special category data that customers load (for example, patient data in Clínicas). The customer chooses the legal basis, for example Art. 9(2)(h) for healthcare. See the Health Data Addendum (Clínicas).

    5.1. Our consumer apps are not for children. Hades and SonhoLab Poker are for adults (18+).

    5.2. Verita. In Verita, the school is the controller. It chooses the legal basis and, where consent is needed, obtains it from parents. See the Children and Student Data Addendum (Verita).

    5.3. Art. 8 ages. Where consent is the legal basis for an information society service offered directly to a child, the child must be at least 16, or the lower age set by the child's country. Below that age, a person with parental responsibility must give or authorize consent, and we make reasonable efforts to verify it (Art. 8(2)).

    Age of digital consentCountries
    13Belgium, Denmark, Estonia, Finland, Latvia, Malta, Portugal, Sweden; Iceland, Norway
    13United Kingdom (Data Protection Act 2018, s. 9)
    14Austria, Bulgaria, Cyprus, Italy, Lithuania, Spain
    15Czechia, France, Greece, Slovenia
    16Croatia, Germany, Hungary, Ireland, Luxembourg, Netherlands, Poland, Romania, Slovakia; Liechtenstein

    5.4. Country notes.

    • Spain: a draft law would raise the age to 16. If it enters into force, the new age applies.
    • Italy: children under 14 need parental consent to access AI technologies (Law 132/2025).
    • United Kingdom: where a service is likely to be accessed by children, we follow the ICO's Age Appropriate Design Code, including high-privacy defaults, geolocation off and profiling off by default.

    6. Your rights

    6.1. You have the right to:

    • access your data and receive a copy (Art. 15);
    • correct inaccurate or incomplete data (Art. 16);
    • erase your data (Art. 17);
    • restrict processing (Art. 18);
    • port the data you gave us, in a structured, machine-readable format (Art. 20). Data export is always available in your account, on every plan;
    • withdraw consent at any time (Art. 7(3));
    • not be subject to certain automated decisions (Art. 22; section 7).

    6.2. How to ask. Write to contacto@sonholab.com, or use the tools in your account. The procedure is in Your Privacy Rights and How to Exercise Them.

    6.3. Deadlines. We answer within 1 month of receiving your request. For complex or numerous requests, we can extend by up to 2 more months; if we do, we tell you within the first month and explain why (Art. 12(3)). If we do not act on a request, we tell you why and how to complain (Art. 12(4)).

    6.4. Free of charge. Requests are free. We may charge a reasonable fee or refuse only if a request is manifestly unfounded or excessive (Art. 12(5)).

    6.5. Identity. If we have reasonable doubts about your identity, we may ask for the minimum information needed to confirm it.

    6.6. UK subject access. In the UK, we carry out reasonable and proportionate searches. If we need you to clarify your request, the time limit pauses until you do.

    7. Automated decisions (Art. 22)

    7.1. You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects on you or similarly significantly affects you, unless an exception in Art. 22(2) applies. Where one applies, you can obtain human review, express your view and contest the decision.

    7.2. As controller, SonhoLab does not suspend or terminate accounts by automated means alone (Terms of Service, Section 13.3). Automated tools such as rate limits can block a specific request, not your account.

    7.3. In the UK, Arts. 22A to 22D UK GDPR apply, with the same safeguards: information about the decision, the right to make representations, human intervention and the right to contest.

    7.4. Where a customer uses automated features in a System (for example, a valuation estimate), the customer is the controller and answers the request. We help it.

    8. International transfers

    8.1. Hosting in the EU. Our primary hosting is Hetzner Online GmbH, in Helsinki, Finland, with Hetzner's automated server backups in Finland.

    8.2. Brazil. SonhoLab is established in Brazil, and our staff access data from Brazil. An off-site backup copy, encrypted before it leaves the server, is stored on equipment operated by SonhoLab in Brazil.

    • EEA: the European Commission has recognized Brazil as adequate (Commission Implementing Decision (EU) 2026/179; GDPR Art. 45).
    • UK: the UK has not recognized Brazil as adequate. For transfers from the UK to SonhoLab in Brazil we use the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU standard contractual clauses. For business customers, these are part of the DPA.

    8.3. United States. Some subprocessors are in the US (for example Stripe, Meta, Google for push notifications and analytics, and OpenAI for our own website chat and support desk). AI providers that a business customer connects with its own key are that customer's vendors, and the customer arranges those transfers. For our own transfers:

    • where the recipient is certified under the EU-US Data Privacy Framework (Decision (EU) 2023/1795), or its UK Extension, we rely on it; and
    • in every case, we also sign the EU standard contractual clauses of 2021 (Module 2 when we are controller, Module 3 when we are processor), with the UK Addendum for UK data, and we assess the transfer.

    8.4. Other countries. Our subprocessors and the safeguard for each are listed in Subprocessors and International Transfers.

    8.5. Copy of the safeguards. You can ask for a copy of the safeguards we use at contacto@sonholab.com. We may redact commercial terms.

    9. Complaints to authorities

    9.1. EEA. You can complain to the supervisory authority of the member state where you live, where you work, or where you think an infringement happened (Art. 77). The European Data Protection Board lists all national authorities.

    9.2. UK: our complaints procedure. Before going to the ICO, you can complain to us about how we use your data (Data Protection Act 2018, s. 164A):

    • write to contacto@sonholab.com, with the subject "Privacy request";
    • we acknowledge your complaint within 30 days;
    • we investigate without undue delay and keep you informed;
    • we tell you the outcome and your right to go to the ICO.

    9.3. UK: the ICO. You can complain to the Information Commissioner's Office at any time: https://ico.org.uk.

    10. Consumer rights

    This section applies if you buy from us as a consumer. It prevails over the Terms of Service.

    10.1. Right of withdrawal: 14 days. You can withdraw from a contract concluded online within 14 days without giving a reason (EU Consumer Rights Directive Art. 9; UK Consumer Contracts Regulations 2013). The period starts on the day the contract is concluded.

    10.2. How to withdraw. You can withdraw at any time during the withdrawal period by any clear statement sent to contacto@sonholab.com, for example the model statement below. We send an acknowledgment of receipt on a durable medium (email) without undue delay.

    10.3. Model statement. You can use this text: "I hereby give notice that I withdraw from my contract for [plan or item], ordered on [date], account email [email]."

    10.4. Refund. We refund all payments within 14 days of receiving your withdrawal, using the same payment method.

    10.5. Services that start at once. If you ask us to start a paid plan during the withdrawal period and then withdraw, you pay only a proportionate amount for the service provided until you withdrew.

    10.6. Digital content (for example, virtual chips). You lose the right to withdraw from digital content only if all three conditions are met: you expressly asked us to begin performance during the withdrawal period, you acknowledged that you would lose the right, and we confirmed this on a durable medium. If any condition is missing, you keep the right.

    10.7. App store purchases. If you bought through Google Play or the Apple App Store, the store handles withdrawal and refunds under its terms.

    10.8. Conformity of digital content and services. Our digital content and services must conform to the contract and to the objective requirements of the law, including necessary security updates (Digital Content Directive 2019/770; UK Consumer Rights Act 2015, Part 1, Chapter 3). If they do not, you can ask us to bring them into conformity, or get a price reduction or end the contract. These rights cannot be excluded.

    10.9. Changes to a service. We change a paid digital service only for a valid reason set out in the Terms of Service and at no extra cost to you. If a change negatively affects your access or use beyond a minor extent, we tell you in advance on a durable medium, and you can end the contract free of charge within 30 days (DCD Art. 19).

    10.10. After termination. You can retrieve your content free of charge, in a commonly used format, within a reasonable time. Export is available for 30 days after termination.

    10.11. Liability. Nothing in our documents excludes or limits our liability for death or personal injury caused by negligence, for fraud, for gross negligence or willful misconduct, or for any liability that your law does not allow us to exclude. We never exclude all liability to consumers.

    10.12. Applicable law and courts. Brazilian law governs our contracts, but you keep the protection of the mandatory rules of the country where you live (Rome I Regulation Art. 6(2)). You can bring proceedings in the courts of the country where you live, and we can only sue you there (Brussels Ia Regulation Arts. 17-19). In the UK, you can bring proceedings in the courts of England and Wales, Scotland or Northern Ireland, depending on where you live. The US arbitration clause and class-action waiver in the Terms of Service do not apply to you.

    10.13. Out-of-court dispute resolution. The EU Online Dispute Resolution platform was discontinued in July 2025. SonhoLab is not obliged to take part, and does not take part, in dispute resolution proceedings before an alternative dispute resolution body.

    11. Digital Services Act

    11.1. Scope. Some of our services store information that users provide, and some make user content available to other users (for example, the Hades shared voice library). The Digital Services Act (Regulation (EU) 2022/2065) applies to those services. SonhoLab is a micro enterprise.

    11.2. Point of contact for authorities (Art. 11) and for users (Art. 12). Email contacto@sonholab.com. You can write in English, Portuguese or Spanish. A person reads every message; the channel is not solely automated.

    11.3. Legal representative (Art. 13). SonhoLab is appointing a legal representative in the European Union (Ireland). Until the appointment is published, authorities and users can contact contacto@sonholab.com.

    11.4. Notice and action (Arts. 16-17). You can report illegal content through the procedure in Copyright and Content Removal Policy. We confirm receipt, decide in a timely and diligent way, and tell you the result. If we restrict a user's content or account, we send that user a statement of reasons. Content rules and moderation are in the Acceptable Use Policy.

    12. AI Act transparency

    12.1. Under the AI Act (Regulation (EU) 2024/1689, Art. 50):

    • our AI assistants tell you at the start that you are interacting with an AI system;
    • synthetic audio, such as Hades voices, is labeled as AI-generated and marked in a machine-readable way;
    • a cloned voice of a real person is disclosed as artificially generated.

    12.2. The details, including the AI providers we use and our no-training commitments, are in the AI Transparency Notice.

    12.3. Mobile app vulnerabilities. For our mobile apps, we report actively exploited vulnerabilities and severe incidents to ENISA within the deadlines of the Cyber Resilience Act. See Security and Incident Response.

    13. Business customers: Data Act switching

    13.1. If you are a business customer in the EU, the switching rules of the Data Act (Regulation (EU) 2023/2854, Chapter VI) apply to our Systems:

    • you can end your contract and switch to another provider, or move your data to your own infrastructure, with notice of no more than 2 months;
    • after the notice period, we give you a transition period of up to 30 days to export your data;
    • you can export your data, in a structured, commonly used, machine-readable format, at any time in your account;
    • we do not charge switching or data egress fees.

    13.2. These rules prevail over any conflicting term of the Terms of Service or the DPA.

    13.3. Consumer rights in section 10 do not apply to business customers.

    14. Language

    14.1. The master text of our legal documents is in English. Where the law of your country requires information in your language, the version in that language prevails for you.


    Version 0.9.0 (preliminary) · Effective 26 September 2026 · © L. M. PEREZ MONTANA (SonhoLab), CNPJ 61.620.014/0001-00. This version is under legal review; we will notify material changes as described in these documents.

    प्रारंभिक संस्करण, कानूनी समीक्षा में

    संस्करण 0.9.0

    इस पाठ का SHA-256 फ़िंगरप्रिंट: eaef61f9fcedaa98da007ac6f9267686b79dc6a86b5fe9ac59b4367cf867c758

    कानूनी केंद्र पर वापस जाएँ