1. About Us

Soniq Studio is a service provided by Pogo Kid Limited. Pogo Kid Limited is a Software Development company trading as Soniq Studio.

  • Company number: 08184013
  • ICO registration: ZB000768

Pogo Kid Limited acts as both a Data Controller and Data Processor under GDPR, depending on the data:

  • As a Controller: We determine the purposes and means of processing your personal data (Customer Personal Data) such as account details, login credentials, and billing information.
  • As a Processor: We process Student Personal Data on your behalf, with you as the Controller, following your documented instructions for the purpose of providing the Services.

As a Data Controller, we are responsible for implementing appropriate technical and organisational measures to ensure and demonstrate that our data processing activities comply with GDPR requirements. This includes ensuring lawful bases for processing, protecting your data rights, maintaining records of processing activities, and implementing
appropriate security measures.

This privacy notice outlines how we fulfil these responsibilities.


2. Scope

This Privacy Policy applies to Soniq Studio’s processing of your personal data as the platform provider. It explains how Pogo Kid Limited collects, uses, stores, and protects personal data when you use Soniq Studio services.

This policy does not cover:

  • The relationship between you (our Customer) and your Students or Responsible Adults
  • How you process Student Personal Data for which you are the Controller
  • Your own privacy notices or communications with your Students or Responsible Adults

As outlined in Section 1, Soniq Studio acts as:

  • Controller for your personal data
  • Processor for Student Personal Data — processing it on your behalf, with you as the Controller, under your instructions

You remain responsible for ensuring your own processing of Student Personal Data complies with applicable data protection laws, including providing Students and Responsible Adults with appropriate privacy information.

Sections 4 onwards are written for you, our Customer. If you are a student or a parent who has been sent a link by a teacher, Section 3 is written for you.


3. For students and parents

Your music teacher uses Soniq Studio to run their teaching. If they have sent you a link to see your lessons or your invoices, this section is for you, the rest of this policy is written for the teacher.

3.1 Who is responsible for what

Your teacher decides what information to keep about you: your name, your contact details, your lessons, notes about them, messages, and any images they upload. Your teacher is the Data Controller for that information. Soniq Studio stores and displays it on their instructions, as their Processor.

Soniq Studio is the Controller for one narrower thing, the technical information created when you open one of their links, described below.

To see, correct or delete the information your teacher holds about you, ask your teacher or their organisation. We cannot make those changes ourselves. We do help teachers respond to requests, and if you write to us by mistake we will tell you who to contact.

A contact portal link is a private web address your teacher generates for you. You do not need a Soniq Studio account to use it, the link expires, and your teacher can revoke it at any time. Depending on which link they issued, it shows either your upcoming lessons, or your lessons together with your invoices, payment history and Direct Debit status.

When you open it, we process:

What Why Our lawful basis
Your IP address, browser and device type Keeping the service secure, preventing abuse, diagnosing errors Legitimate interest (Art. 6(1)(f))
The time the link was opened Security monitoring Legitimate interest (Art. 6(1)(f))

We have assessed this in our Legitimate Interest Assessment, and you can object to it, see below.

Your browser also stores a small amount of information on your device so the page works. It is strictly necessary to show you the page you asked for, so we do not ask for consent (Section 9). Clearing your browser’s site data removes it.

3.3 Paying an invoice

If you follow a link from your teacher to pay an invoice, you are taken to GoCardless to set up or confirm a payment. GoCardless receives your name, contact details and bank account details, and acts as an independent Data Controller for that information. It uses it for its own regulatory purposes, such as fraud prevention and anti-money-laundering checks. Soniq Studio does not receive or store your bank details; we hold only a reference to what GoCardless creates, so your teacher can see whether it is active. What GoCardless does with your information is covered by its own terms and privacy notice at gocardless.com/legal.

3.4 What we never do

  • No advertising, marketing or tracking cookies, and no ads.
  • We do not sell or rent your information, or share it with anyone for their own purposes.
  • We do not use your information, or anything your teacher writes about you, to train AI or machine-learning models.

3.5 Who to ask

If you want to Contact
See, correct or delete what your teacher holds: your details, lessons, notes, messages, invoices Your teacher or their organisation
Stop receiving links or emails from your teacher Your teacher or their organisation
Ask about the technical data we collect when you open a link, or object to it privacy@soniq.studio
Complain about how Soniq Studio has handled your information complaints@soniq.studio, then the ICO at ico.org.uk

If you are not sure who to ask, write to privacy@soniq.studio and we will point you in the right direction.

3.6 If you are under 18

If you are under 13 in the UK, or under 16 in most EU countries, a parent, guardian or carer needs to agree before your teacher keeps information about you. That is your teacher’s responsibility rather than ours, and a parent or guardian can ask them about it at any time. Write to us at privacy@soniq.studio if your parent or guardian would rather start with us.


4. What personal information will be collected and why?

The data and information will be collected both directly and indirectly by signing up, and through using the Services. As a Processor, Student Personal Data is processed on your behalf, with you as the Controller, for the purpose of providing the Services.

You are able to make changes to your data by using the application and the Account sections or by contacting us directly.

4.1 Account & profile

Data Purpose Lawful Basis
Full name Account identification and personalisation Contract (Art. 6(1)(b))
Email address Authentication, service communications, account recovery Contract (Art. 6(1)(b))
Profile handle Unique identifier for public profile pages Contract (Art. 6(1)(b))
Business/organisation name and address Display name for your business or organisation on lessons, invoices and tax compliance Contract (Art. 6(1)(b))
Student/parent contact name and optional email Manage your student and parent contacts for scheduling and billing Processed on your behalf as Processor — you determine the lawful basis (see Section 1 & 2)
Subscription plan details Manage your Soniq Studio subscription Contract (Art. 6(1)(b))

4.2 Invoicing & Payments

Data Purpose Lawful Basis
Payment provider details (Stripe, GoCardless customer IDs) Process payments through integrated providers Contract (Art. 6(1)(b))
Payment amounts and transaction data Record and track payment history Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for the retention period in Section 5

4.3 Messages & Communication

Data Purpose Lawful Basis
Message content Internal messaging between you and your contacts Contract (Art. 6(1)(b))

4.4 System & Usage

Data Purpose Lawful Basis
Profile preferences Personalise your experience and remember settings Legitimate interest (Art. 6(1)(f))
Audit log of any access to sensitive resources Security monitoring and compliance Legitimate interest (Art. 6(1)(f))
Device and connection data (IP address, browser and device type) Security monitoring, abuse prevention, and diagnosing server errors Legitimate interest (Art. 6(1)(f))

We process usage data, audit logs, and device/connection data under Legitimate Interest (Article 6(1)(f) UK GDPR). A Legitimate Interest Assessment (LIA) has been conducted to ensure our interests do not override your rights and freedoms. The assessment confirms that:

  • Purpose: Security monitoring, abuse prevention, service improvement
  • Necessity: No less intrusive method achieves these purposes
  • Balancing: Our interests do not outweigh your rights, given appropriate safeguards (e.g., data minimisation, retention limits)

See Legitimate Interest Assessment for the full assessment.

4.5 Special Category Data

We do not intentionally collect or process special categories of Personal Data as defined in Article 9 UK GDPR, including:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic or biometric data
  • Health data
  • Sexual orientation or sex life

If such data is inadvertently included in free-text fields (e.g., lesson notes, messages), you should avoid entering it. We do not rely on explicit consent (Article 9(2)(a)) or substantial public interest (Article 9(2)(g)) for processing special category data.

4.6 Children’s Data

Where a Student is under 13 (UK) or under 16 (EU), we rely on you (the Customer) to obtain explicit consent from their Responsible Adult before processing their Personal Data. This is in accordance with:

  • UK GDPR Article 8 (parental consent for information society services)
  • DPA 2018 Section 9 (UK implementation)

You must ensure you have verified parental consent before inputting any Student Personal Data for minors.


5. How long we keep your data

Data Type Retention Period Justification
Payment and transaction records 6 years from end of accounting period Legal obligation (UK VAT/HMRC)
Account or customer records and information to demonstrate compliance Duration of active account plus up to 1 year Contract and compliance
Account and Customer data not necessary to demonstrate compliance Duration of active account plus 30 days Contract, reactivation
Application and server error logs, and performance traces Up to 90 days Legitimate interest (debugging)

6. Who we share your data with

6.1 Service Providers (Sub-processors)

The providers below process data on our behalf as sub-processors. They handle both the platform account data we control (this policy) and, where applicable, the Student Personal Data we process on behalf of our Customers.

Provider Purpose Data Processed Location Safeguards
Scaleway Cloud hosting, transactional email, encrypted backups, security All platform data France (EU) DPA in place
Grafana Cloud Server log aggregation, performance traces, and audit logs Server application logs and traces; audit/administrative event logs (may include IP addresses) United Kingdom DPA in place; see Section 7
Cloudflare Network infrastructure, reverse proxy, DNS, DDoS protection, origin IP masking Connection metadata including IP addresses (not stored long-term by Soniq Studio, but processed by Cloudflare as a reverse proxy) Cloudflare Inc., headquartered in San Francisco, US; metadata may be processed at Cloudflare data centres globally Transfers covered by the EU-U.S. Data Privacy Framework (and its UK Extension) and Cloudflare’s Standard Contractual Clauses (cloudflare.com/cloudflare-customer-dpa)

We do not use any third-party service for behavioural or product analytics, advertising, or tracking of user browsing behaviour, and we do not share visited URLs with any third party. Any usage measurement we perform is first-party: it runs on our own infrastructure, is limited to the usage and engagement data described in Section 4.4, and is never shared with anyone.

6.2 Payment providers

When you collect payments through Soniq Studio, the payment provider you have connected receives the personal data needed to process those payments. These providers act as independent Controllers for their own regulatory purposes — including anti-money-laundering checks, fraud prevention, and sanctions screening — and their own privacy notices govern that processing.

Provider Purpose Location Role
GoCardless Direct Debit collection from your students United Kingdom Independent Controller for its own compliance purposes
Stripe Card payment processing and subscription billing European Union and United States Independent Controller for its own compliance purposes

6.3 No Sale or Sharing

We do not sell or rent personal data. Apart from the payment providers described in Section 6.2, we do not share personal data with third parties for their own purposes. We do not use account data for advertising or marketing.

We may disclose data where required by law, regulation, or court order.


7. International data transfers

All account data and Student Personal Data are stored in the EEA. One sub-processor, Cloudflare, processes connection metadata outside the UK and EEA; the mechanism is named below. The payment providers in Section 6.2 act as independent Controllers, not sub-processors, and their own notices govern their processing.

Service Location Transfer mechanism
Scaleway (hosting, email, backups) France (EU) None required. Data remains in the EEA
Grafana Cloud (server logs, traces, audit logs) United Kingdom No transfer arises for UK GDPR purposes. For data within scope of EU GDPR we rely on the European Commission’s adequacy decision for the UK.
Cloudflare (network infrastructure, reverse proxy, DNS, DDoS) US; metadata processed at data centres globally Yes. Covered by the EU-U.S. Data Privacy Framework (and its UK Extension) and Cloudflare’s Standard Contractual Clauses

Cloudflare, Inc. (headquartered in San Francisco, US) provides network infrastructure and reverse proxy services. Connection metadata including IP addresses may be processed at Cloudflare data centres globally as traffic is routed to Scaleway. These international transfers are covered by the EU-U.S. Data Privacy Framework and its UK Extension (Cloudflare is an active participant) and by Cloudflare’s Standard Contractual Clauses (cloudflare.com/cloudflare-customer-dpa).


8. Data Security

We implement appropriate technical and organisational measures including:

  • Encryption in transit using TLS 1.2 or higher
  • Encryption at rest: data volumes are encrypted using LUKS2 with AES-256 (XTS mode)
  • Role-based access controls — a user’s access is scoped to the profile they belong to
  • Platform administrators do not routinely access profile content
  • A Content Security Policy is enforced in the browser to limit the effect of any content-injection attack
  • Encrypted server backups (Scaleway)

9. Cookies and similar technologies

Soniq Studio uses only strictly necessary cookies. We do not use any advertising, marketing, or behavioural tracking cookies, and we do not display a cookie consent banner: everything we store on your device is strictly necessary to provide the service you have asked for, which is exempt from the consent requirement under ePrivacy/PECR regulations.

Clearing your browser’s site data removes everything from your device.

Authentication Cookies

Soniq Studio uses Keycloak as its identity provider, which is hosted on our infrastructure. Keycloak sets strictly necessary cookies on our domain to manage authentication sessions. These cookies contain authentication tokens and session identifiers, and are essential for secure access to your account. They are classified as strictly necessary and do not require consent under ePrivacy/PECR regulations.

Technology Provider Purpose Consent required?
Keycloak Auth Session cookie Soniq Studio Maintains active authentication session No
Keycloak Auth “Remember me” cookie Soniq Studio Keycloak Auth “Remember me” persistent login across browser sessions No
Keycloak Auth flow state Soniq Studio Keycloak Auth Managing login state and authentication flow No

Browser / Client-Side Storage and Offline data

In addition to Keycloak’s authentication cookies, Soniq Studio stores data in your browser’s localStorage and IndexedDB for application functionality. This includes authentication state (managed via localStorage rather than cookies), user preferences, and offline data caching. No third-party tracking or analytics cookies are used.

Technology Provider Purpose Consent required?
localStorage Browser Stores debug flags, authentication state, device ID, feature flag overrides, dismissable UI keys, and metronome session history No
sessionStorage Browser Stores a reload flag to prevent infinite reload loops when recovering from stale deploys No
IndexedDB Browser Stores job queue data for offline processing and metadata including offline state version for database migrations No
Origin Private File System Browser Stores a local copy of your profile’s data for offline access No

10. Automated decision-making, Artificial Intelligence and Machine Learning

Soniq Studio incorporates artificial intelligence and machine learning functionality to provide enhanced features, such as intelligent scheduling suggestions. All AI processing occurs exclusively on your device, your personal data never leaves your device for AI purposes, and we do not use your data to train any models.

10.1 Automated Processing under Article 22 GDPR

Under Article 22 of the UK/EU GDPR, you have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you.

Our AI features may generate automated suggestions based on your usage data (for example, recommended lesson times or scheduling optimisations). However, these are always presented as non-binding recommendations that require your explicit review and approval before any action is taken. You retain full control to accept, modify, override, or ignore these suggestions at any time.

Therefore, Soniq Studio does not carry out automated decision-making as defined in Article 22 (1) GDPR, because meaningful human intervention (yours) is always required before any decision or action takes effect.


11. Your rights

Under UK GDPR and EU GDPR, you have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data where no longer necessary or consent withdrawn (Art. 17)
  • Restrict processing in certain circumstances (Art. 18)
  • Data portability — receive your account data in a structured format (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)

To exercise any right, contact us at privacy@soniq.studio. We will respond within one calendar month.

Important: The rights above cover the personal data we hold about you as a Soniq Studio account holder.

As an account holder, you are the Controller of Student Personal Data, the information you enter about students and Responsible Adults, including lesson notes, messages and uploaded images.

Requests about that information should be directed to you. We can assist you in responding as your Processor, under clause 4 (Data protection) of our Terms & Conditions.

12. Right of complaint

If you are unhappy with how we handle your data:

Complaints: complaints@soniq.studio

UK Information Commissioner’s Office (ICO): www.ico.org.uk.


13. Changes to the policy

We reserve the right to make changes to this notice at any time to reflect updates to the law or changes to our data collection and security practices. We recommend that you review it regularly for your own knowledge and benefit.

Version Date Change
2026-09 3 Sep 2026 Greater detail about the company, the purposes and lawful basis for each piece of data collected. New sections for greater transparency. Moved server-side error monitoring onto our own infrastructure in France and named the transfer mechanism for each remaining provider outside the EEA. Added payment providers as independent Controllers, and device and connection data. Added section for students and Responsible Adults who open a contact portal link, and renumbered the sections after it.
2025-05 29 May 2025 First published version