Skip to content
Soriela
How it worksProductSecurityAboutEventsBlog
Book a demoSee Soriela in action
See Soriela in actionBook a demo
Legal

Privacy Policy

This policy explains what personal data Soriela collects, why, on what legal basis, who else sees it, and the rights you have over it. It covers this website and the Soriela product.

Last updated 27 August 2026

  1. 1. Who is responsible for your data
  2. 2. What we collect
  3. 3. Why we use it, and on what legal basis
  4. 4. AI processing of project data
  5. 5. Cookies and similar technologies
  6. 6. Who else processes it
  7. 7. International transfers
  8. 8. How long we keep it
  9. 9. How we protect it
  10. 10. Your rights
  11. 11. Children
  12. 12. Changes to this policy
  13. 13. Contact

1. Who is responsible for your data

Soriela ("Soriela", "we") is the controller for the personal data described in this policy. You can reach us about anything on this page at info@soriela.com.

Where Soriela processes project data on behalf of a customer, the customer is the controller and Soriela acts as a processor under a data processing agreement. In that case the customer's own privacy notice governs how that data may be used, and this policy describes what we do as their processor.

2. What we collect

When you visit this website. Our hosting provider records standard server data — IP address, browser and device type, pages requested, and the time of the request — to serve the site and keep it secure. We do not run advertising or analytics trackers on this site.

When you contact us or book a demo. Your name, email address, company, anything you choose to write to us, and the time and date of the meeting you book.

When you use the Soriela product. Account data (name, work email, organisation, role and authentication data), usage and audit logs, and the project data Soriela reads from the sources your organisation connects — issues, plans, documents, messages, mail and calendar entries, and the names of the people involved in them. Soriela reads the sources your organisation chooses to connect, with the scopes it grants, and nothing else.

We do not seek special categories of personal data, and the product is not intended to be used to process them.

3. Why we use it, and on what legal basis

  • To provide the product and the website — performance of a contract (Art. 6(1)(b) GDPR), or our legitimate interest in operating our site (Art. 6(1)(f)).
  • To respond to enquiries and run demos — steps taken at your request before entering a contract (Art. 6(1)(b)), or legitimate interest (Art. 6(1)(f)).
  • To secure our systems, prevent abuse and keep audit logs — legitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)).
  • To send occasional product or event email — consent (Art. 6(1)(a)), withdrawable at any time using the link in the message or by writing to us.
  • To meet accounting, tax and other legal duties — legal obligation (Art. 6(1)(c)).

We do not sell personal data, and we do not use customer project data to train third-party or foundation models.

4. AI processing of project data

Soriela sends project content to large language models in order to produce summaries, risks, briefings and answers. Which models, and where they run, depends on the deployment your organisation chooses — see our security and deployment page.

Model providers used in our hosted service process this content as sub-processors on our instruction, under terms that prohibit using it to train their models. Outputs are linked back to the source they came from, so a person can always check what an answer was based on.

5. Cookies and similar technologies

This website uses only what is strictly necessary to serve the page and remember your session. We do not set advertising, profiling or analytics cookies on it, so no consent banner is required here. If that changes, this section changes first and we will ask for consent before setting any non-essential cookie.

Two things on this site load from third parties, and both see your IP address as a consequence: web fonts served by Google Fonts, and — only if you open the in-page product demo — an embedded frame from app.soriela.com.

The Soriela product itself uses strictly necessary cookies to keep you signed in. You can block cookies in your browser, but the product will not work without the necessary ones.

6. Who else processes it

We share personal data only with service providers who process it on our behalf, under contract, and only for the purposes above. These currently fall into the following categories:

  • cloud hosting and infrastructure;
  • email, calendar and office productivity;
  • large language model providers;
  • error monitoring and operational logging;
  • professional advisers, where they need it.

A current list of the named sub-processors for the hosted service is available on request at info@soriela.com. We may also disclose data where we are legally required to, and to a buyer in the context of a merger or acquisition — in which case this policy continues to apply to the data transferred.

7. International transfers

We are based in Europe and prefer processing within the European Economic Area. Where a provider processes data outside the EEA, we rely on an adequacy decision where one exists, and otherwise on the European Commission's Standard Contractual Clauses together with additional safeguards where they are needed. You can ask us for a copy of the mechanism used for a specific transfer.

8. How long we keep it

  • Enquiries and demo bookings — up to 24 months after our last exchange, unless you ask us to delete them sooner.
  • Customer account and project data — for the life of the agreement. On termination it is deleted or returned within the period set out in the agreement, normally 30 days, unless we must keep it longer by law.
  • Security and audit logs — a limited retention period proportionate to the purpose.
  • Invoices and accounting records — for the statutory retention period.

Disconnecting a source stops Soriela reading it. Deleting a project or an account removes the data Soriela derived from it, subject to backups expiring on their normal cycle.

9. How we protect it

Connections to your tools are scoped, and you can revoke them at any time from the source system or from Soriela. Data is encrypted in transit and at rest, access inside Soriela is limited to the people who need it, and administrative actions are logged. Single-tenant, self-hosted and air-gapped deployments are available so that project data need never leave your own environment — see the security page for what is offered today.

If a personal data breach occurs, we notify the supervisory authority and affected customers as required by Art. 33 and 34 GDPR.

10. Your rights

If you are in the EEA or the UK you have the right to:

  • access the personal data we hold about you, and receive a copy;
  • have inaccurate data corrected;
  • have data erased, where the grounds in Art. 17 apply;
  • restrict or object to processing based on legitimate interests;
  • receive data you gave us in a portable format;
  • withdraw consent at any time, without affecting processing already carried out;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects — Soriela's outputs are decision support for a person, not automated decisions of that kind.

Write to info@soriela.com and we will respond within one month. If Soriela holds your data on behalf of a customer, send your request to that customer and we will support them in answering it.

You can also complain to a supervisory authority — ours is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), and you may instead go to the authority where you live or work.

11. Children

Soriela is a business product. It is not directed at children and we do not knowingly collect data from anyone under 16.

12. Changes to this policy

We update this policy when what we do changes. The date at the top is the version in force. Where a change materially affects you, we will tell customers directly rather than relying on you to re-read the page.

13. Contact

Questions, requests and complaints about this policy: info@soriela.com.

Something here unclear, or you need our data processing agreement? info@soriela.com

Soriela

AI project intelligence across the tools your teams already use — one live view of progress, risks, blockers, ownership gaps and next steps.

LinkedIninfo@soriela.com

Product

  • How it works
  • Features
  • Integrations
  • Security

Company

  • About
  • Partners
  • Events
  • Blog

Get started

  • Book a demo
  • See Soriela in action

Legal

  • Privacy Policy
  • Terms of Use
© 2026 Soriela. All rights reserved.
Privacy PolicyTerms of UseRSS