Last updated: 30 July 2026

Who we are

Sonar Development (“we”, “us”, “our”) operates the website at https://sonardevelopment.com. For the personal data described in this policy, we act as the data controller.

You can contact us about this policy or about your personal data by email at .

The personal data we collect

We collect the information you choose to submit through the contact, project-brief and newsletter forms on this website. We do not collect more than we need for the purpose shown beside each form.

Contact form

  • Name (required) - used to identify you and address our reply.
  • Email address (required) - used to reply to your enquiry and to send you a confirmation that we received it.
  • Business name (optional) - used for business context.
  • Telephone number (optional) - used to call you back if you prefer a call to email.
  • Location (required) - the town or area your business serves, used to advise on coverage and travel.
  • Existing website address (optional) - used to look at what you already have before we reply.
  • Service and package selections (service required) - which of our services or packages you are asking about, used to categorise and route your enquiry.
  • Approximate budget and preferred start date (both optional) - used to recommend the right starting point.
  • Project details (required) - the free-text content of your enquiry. Because this is free text, it may contain whatever personal data you choose to include.
  • The page on this website your enquiry started from (recorded automatically when you arrive via a package button) - used to understand which service you were reading about.
  • Consent - a tick confirming you agree to us storing these details to respond to your enquiry. The checkbox is not ticked by default.

Project-brief form

  • Name and email address (email required) - used to identify you and reply.
  • Company (optional) - used for business context.
  • What you need (required) - the type of project, so we understand what to build.
  • Your goal (required) - a free-text description of what the project should achieve. Because this is free text, it may contain whatever personal data you choose to include.
  • Additional information (optional) - any other free-text context you choose to share.
  • Consent - a tick confirming you agree to us storing the brief to assess and respond to your project. The checkbox is not ticked by default.

Newsletter form

  • Email address (required) - used only to send the Sonar Letter after you confirm the address.
  • Consent - an unticked checkbox recording that you asked for occasional email updates and may unsubscribe at any time.
  • Confirmation status and timestamps - used to operate double opt-in and prove that the address was confirmed.
  • Hashed confirmation and unsubscribe tokens - used to secure each preference link. The usable token is not stored.
  • Source, hashed IP address and truncated browser User-Agent - used for consent provenance, rate limiting and abuse prevention.

Signing up does not add you to the active audience immediately. We send a 24-hour confirmation link, and only a completed confirmation activates the subscription. Every newsletter email includes an unsubscribe link.

Data we generate when you submit a form

When the website's database is enabled, submitting a form also creates the following technical data, used for security and record-keeping rather than collected from you directly:

  • A salted SHA-256 hash of your IP address. We never store your raw IP address. The hash is used for rate limiting, abuse prevention, and to record the provenance of your consent.
  • Your browser's User-Agent string, truncated to 300 characters, kept for diagnostics and abuse context.
  • A consent record storing the exact consent wording shown to you, the form type, the hashed IP and a timestamp.
  • A reference code generated for your submission so it can be tracked. The code itself is not personal data but is linked to your record.
  • Operational email-delivery logs (recipient address, subject, template, status and any error) recording that a notification or confirmation email was sent.

Both forms also include a hidden anti-spam field. If it is filled in - which only automated bots do - the submission is silently discarded and never stored.

We do not intentionally collect special-category data (such as data about health, race, religion or political views). Please avoid including such information in free-text fields unless it is necessary.

Separately, we hold credentials for internal staff who administer this website (name, email, role and a hashed password). This data is never collected from public visitors and is not shown publicly.

Client portal

If you are a client of Sonar with access to the client portal (at /portal), we process a small amount of personal data to run it. Sonar is the data controller for these portal records.

  • Your name and email address - set up by us from your engagement so we can identify your account and email you a secure, single-use sign-in link. The portal has no password.
  • Your project records - project name, live URL, hosting arrangement, your release history and the documents we make available to you (for example your handover agreement, invoices, a credentials note and brand assets).
  • Sign-in and download logs - an audit record of portal sign-ins, sign-in-link requests and file downloads, each storing the action, a salted SHA-256 hash of your IP address (never the raw address), your truncated browser User-Agent and a timestamp. We use these for security, integrity and support.
  • Account and invitation records - your portal account is created by us and activated by you from a single-use invitation link. We store the dates the invitation was sent and accepted, the date the account was activated, the date you last signed in, and any company name, phone number or billing address you supply when activating. Invitation and sign-in links are stored only as SHA-256 hashes, never in a form that could be used to sign in as you.
  • Your acceptance of the portal terms and privacy notice - the date you accepted and the version of each document in force at that moment, so we can show what you agreed to.

The source code and documents delivered through the portal are yours. We store them so you can download them; we do not use their contents for any other purpose.

How we use your personal data, and our legal bases

Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we must have a lawful basis for each use of your personal data. We rely on the following:

  • Consent (UK GDPR Article 6(1)(a)) - our primary basis for storing and using details submitted through the public forms. Consent checkboxes are not ticked by default, and we store the exact wording you agreed to. Newsletter email is sent only after double opt-in confirmation.
  • Steps prior to a contract (UK GDPR Article 6(1)(b)) - where processing your project brief is necessary to take steps, at your request, before potentially entering into a contract with you.
  • Legitimate interests (UK GDPR Article 6(1)(f)) - for security and abuse prevention (such as hashed-IP rate limiting, the hidden anti-spam field, CAPTCHA verification where enabled, and audit logging) and for responding to and managing inbound business enquiries.

In practice, we use the data to identify you, reply to your enquiry, assess and scope a potential project, operate newsletter subscriptions you explicitly request, send relevant confirmations, and protect the website and our records from abuse.

Who we share your personal data with

We do not sell your personal data. We share it only with service providers who process it on our behalf (our processors) so that this website can function. Depending on how the site is configured, these may include:

  • Our hosting platform and content delivery network, Vercel Inc., which handles all request traffic to the site, provides HTTPS, and serves the site from a global edge network.
  • Our email infrastructure, Microsoft 365, which operates the studio mailbox that receives and answers your enquiry.
  • A transactional email provider, used to deliver the notification email to the studio and the confirmation email to you when one is enabled. The studio notification includes the details you submitted.
  • A database host, which stores the records described above when the website's database is enabled.
  • Cloudflare Turnstile, used to check that public form submissions are human without placing the address on the newsletter audience.

We keep this list current: if we change or add a processor that handles your personal data, we update this policy first. You can ask us at any time which specific providers are active by emailing .

Some optional services exist in the website but are not active by default and do not currently receive any personal data: file/object storage (no file uploads are collected today), web analytics (none is loaded by default), and error monitoring. If we enable any of these, we will update this policy first.

We may also disclose personal data where required by law or to establish, exercise or defend legal claims.

International transfers

Some of our processors may store or process personal data outside the United Kingdom - for example, our hosting platform operates a global content delivery network with infrastructure in the United States and elsewhere. Where that happens, we ensure an appropriate safeguard is in place, such as a UK adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, relying on the processor's published data-processing terms.

How long we keep your personal data

We operate a retention schedule so that personal data is not kept longer than necessary. A scheduled process permanently removes records once they pass their retention period, and you can ask us to erase your data sooner (see Your rights).

Some data is also cleared on a purely operational basis: expired staff login sessions, expired client-portal sessions, used sign-in and password-reset tokens and short-lived rate-limiting entries are removed continuously.

Our current retention periods are: enquiry and brief records, 24 months after the last update; consent records, kept as proof of consent and removed within 6 years once no longer tied to an active enquiry; unconfirmed newsletter requests, 30 days; unsubscribed newsletter records, 30 days; internal audit logs, 12 months; client-portal sign-in and download logs, 12 months; email-delivery logs, 6 months; expired or used portal invitation links, removed continuously once spent. Active newsletter subscriptions remain until you unsubscribe. Client-portal accounts, projects, releases and documents are kept for the life of your engagement and removed on request or when the engagement ends. If we change these periods, we will update this policy.

Your rights

Under UK GDPR and the Data Protection Act 2018 you have the following rights in relation to your personal data:

  • The right to be informed - explained by this policy.
  • The right of access - to a copy of the personal data we hold about you.
  • The right to rectification - to have inaccurate personal data corrected.
  • The right to erasure - to ask us to permanently delete your personal data. On request we delete, in a single transaction, your enquiry and brief records, the related consent records, the inbound and internal email-delivery logs that reference you, and lead-related audit entries. We may keep a limited record only where the law allows or requires it, for example to establish or defend legal claims.
  • The right to restrict processing - to ask us to limit how we use your data.
  • The right to data portability - where processing is based on consent or a contract and carried out by automated means.
  • The right to object - to processing based on our legitimate interests.
  • The right to withdraw consent - at any time, without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, contact us at . Newsletter consent can also be withdrawn immediately using the unsubscribe link in any newsletter email. We honour erasure and withdrawal-of-consent requests by permanently deleting the records associated with your email address. We respond to rights requests within one calendar month, as UK GDPR requires, and where a request is made about data tied to an email address we will verify the request by corresponding with that address before acting on it.

Complaints

If you have a concern about how we handle your personal data, please contact us first at so we can try to resolve it.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection, at ico.org.uk.

Cookies

For public visitors browsing the site, no cookies are set by default. Two strictly necessary authentication cookies are set only after someone signs in: sonar_session for the internal staff admin area, and sonar_portal for a client signing in to the client portal. Neither is set for ordinary public browsing. In both cases only a hashed version of the session token is stored on our side; both are HttpOnly, use SameSite=Lax and are marked Secure in production.

No analytics or marketing cookies are set by default, and no third-party tracking scripts are loaded. For full details, please see our Cookie Policy.

How we protect your personal data

We take the security of your personal data seriously and apply a range of technical measures, including:

  • Server-side validation of all form input (required fields, length limits, email format and a strict consent check).
  • A hidden anti-spam field and rate limiting to reduce abuse, plus a swappable CAPTCHA verification step where enabled.
  • Storing IP addresses only as salted SHA-256 hashes, never in raw form, and truncating browser User-Agent strings.
  • Storing staff passwords only as hashes, with account-lockout protections.
  • Protecting internal studio accounts with mandatory two-factor authentication. The authenticator secret is held encrypted, never in plain text, and single-use recovery codes are stored only as keyed hashes.
  • Opaque, hashed session tokens with a short lifetime, and audit logging of administrative actions.
  • An append-only record of the exact consent wording you agreed to, with a timestamp.
  • Strict security headers, including a nonce-based Content Security Policy, and enforced HTTPS in production.
  • Fail-closed configuration checks that refuse to run the production site with unsafe settings.

Changes to this policy

We may update this policy from time to time, for example if we enable new services or change our processors. When we do, we will revise the “Last updated” date at the top of this page. Significant changes will be made clear.

Contact

For any question about this policy or your personal data, email us at .