1. About Us
Soniq Studio is a service provided by Pogo Kid Limited. Pogo Kid Limited is a Software Development company trading as Soniq Studio.
- Company number: 08184013
- ICO registration: ZB000768
Pogo Kid Limited acts as both a Data Controller and Data Processor under GDPR, depending on the data:
- As a Controller: We determine the purposes and means of processing your personal data (Customer Personal Data) such as account details, login credentials, and billing information.
- As a Processor: We process Student Personal Data on your behalf, with you as the Controller, following your documented instructions for the purpose of providing the Services.
As a Data Controller, we are responsible for implementing appropriate technical and organisational measures to ensure and demonstrate that our data processing activities comply with GDPR requirements. This includes ensuring lawful bases for processing, protecting your data rights, maintaining records of processing activities, and implementing
appropriate security measures.
This privacy notice outlines how we fulfil these responsibilities.
2. Scope
This Privacy Policy applies to Soniq Studio’s processing of your personal data as the platform provider. It explains how Pogo Kid Limited collects, uses, stores, and protects personal data when you use Soniq Studio services.
This policy does not cover:
- The relationship between you (our Customer) and your Students or Responsible Adults
- How you process Student Personal Data for which you are the Controller
- Your own privacy notices or communications with your Students or Responsible Adults
As outlined in Section 1, Soniq Studio acts as:
- Controller for your personal data
- Processor for Student Personal Data — processing it on your behalf, with you as the Controller, under your instructions
You remain responsible for ensuring your own processing of Student Personal Data complies with applicable data protection laws, including providing Students and Responsible Adults with appropriate privacy information.
Sections 4 onwards are written for you, our Customer. If you are a student or a parent who has been sent a link by a teacher, Section 3 is written for you.
3. For students and parents
Your music teacher uses Soniq Studio to run their teaching. If they have sent you a link to see your lessons or your invoices, this section is for you, the rest of this policy is written for the teacher.
3.1 Who is responsible for what
Your teacher decides what information to keep about you: your name, your contact details, your lessons, notes about them, messages, and any images they upload. Your teacher is the Data Controller for that information. Soniq Studio stores and displays it on their instructions, as their Processor.
Soniq Studio is the Controller for one narrower thing, the technical information created when you open one of their links, described below.
To see, correct or delete the information your teacher holds about you, ask your teacher or their organisation. We cannot make those changes ourselves. We do help teachers respond to requests, and if you write to us by mistake we will tell you who to contact.
3.2 When you open a contact portal link
A contact portal link is a private web address your teacher generates for you. You do not need a Soniq Studio account to use it, the link expires, and your teacher can revoke it at any time. Depending on which link they issued, it shows either your upcoming lessons, or your lessons together with your invoices, payment history and Direct Debit status.
When you open it, we process:
| What | Why | Our lawful basis |
|---|---|---|
| Your IP address, browser and device type | Keeping the service secure, preventing abuse, diagnosing errors | Legitimate interest (Art. 6(1)(f)) |
| The time the link was opened | Security monitoring | Legitimate interest (Art. 6(1)(f)) |
We have assessed this in our Legitimate Interest Assessment, and you can object to it, see below.
Your browser also stores a small amount of information on your device so the page works. It is strictly necessary to show you the page you asked for, so we do not ask for consent (Section 9). Clearing your browser’s site data removes it.
3.3 Paying an invoice
If you follow a link from your teacher to pay an invoice, you are taken to GoCardless to set up or confirm a payment. GoCardless receives your name, contact details and bank account details, and acts as an independent Data Controller for that information. It uses it for its own regulatory purposes, such as fraud prevention and anti-money-laundering checks. Soniq Studio does not receive or store your bank details; we hold only a reference to what GoCardless creates, so your teacher can see whether it is active. What GoCardless does with your information is covered by its own terms and privacy notice at gocardless.com/legal.
3.4 What we never do
- No advertising, marketing or tracking cookies, and no ads.
- We do not sell or rent your information, or share it with anyone for their own purposes.
- We do not use your information, or anything your teacher writes about you, to train AI or machine-learning models.
3.5 Who to ask
| If you want to | Contact |
|---|---|
| See, correct or delete what your teacher holds: your details, lessons, notes, messages, invoices | Your teacher or their organisation |
| Stop receiving links or emails from your teacher | Your teacher or their organisation |
| Ask about the technical data we collect when you open a link, or object to it | privacy@soniq.studio |
| Complain about how Soniq Studio has handled your information | complaints@soniq.studio, then the ICO at ico.org.uk |
If you are not sure who to ask, write to privacy@soniq.studio and we will point you in the right direction.
3.6 If you are under 18
If you are under 13 in the UK, or under 16 in most EU countries, a parent, guardian or carer needs to agree before your teacher keeps information about you. That is your teacher’s responsibility rather than ours, and a parent or guardian can ask them about it at any time. Write to us at privacy@soniq.studio if your parent or guardian would rather start with us.
4. What personal information will be collected and why?
The data and information will be collected both directly and indirectly by signing up, and through using the Services. As a Processor, Student Personal Data is processed on your behalf, with you as the Controller, for the purpose of providing the Services.
You are able to make changes to your data by using the application and the Account sections or by contacting us directly.
4.1 Account & profile
| Data | Purpose | Lawful Basis |
|---|---|---|
| Full name | Account identification and personalisation | Contract (Art. 6(1)(b)) |
| Email address | Authentication, service communications, account recovery | Contract (Art. 6(1)(b)) |
| Profile handle | Unique identifier for public profile pages | Contract (Art. 6(1)(b)) |
| Business/organisation name and address | Display name for your business or organisation on lessons, invoices and tax compliance | Contract (Art. 6(1)(b)) |
| Student/parent contact name and optional email | Manage your student and parent contacts for scheduling and billing | Processed on your behalf as Processor — you determine the lawful basis (see Section 1 & 2) |
| Subscription plan details | Manage your Soniq Studio subscription | Contract (Art. 6(1)(b)) |
4.2 Invoicing & Payments
| Data | Purpose | Lawful Basis |
|---|---|---|
| Payment provider details (Stripe, GoCardless customer IDs) | Process payments through integrated providers | Contract (Art. 6(1)(b)) |
| Payment amounts and transaction data | Record and track payment history | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for the retention period in Section 5 |
4.3 Messages & Communication
| Data | Purpose | Lawful Basis |
|---|---|---|
| Message content | Internal messaging between you and your contacts | Contract (Art. 6(1)(b)) |
4.4 System & Usage
| Data | Purpose | Lawful Basis |
|---|---|---|
| Profile preferences | Personalise your experience and remember settings | Legitimate interest (Art. 6(1)(f)) |
| Audit log of any access to sensitive resources | Security monitoring and compliance | Legitimate interest (Art. 6(1)(f)) |
| Device and connection data (IP address, browser and device type) | Security monitoring, abuse prevention, and diagnosing server errors | Legitimate interest (Art. 6(1)(f)) |
We process usage data, audit logs, and device/connection data under Legitimate Interest (Article 6(1)(f) UK GDPR). A Legitimate Interest Assessment (LIA) has been conducted to ensure our interests do not override your rights and freedoms. The assessment confirms that:
- Purpose: Security monitoring, abuse prevention, service improvement
- Necessity: No less intrusive method achieves these purposes
- Balancing: Our interests do not outweigh your rights, given appropriate safeguards (e.g., data minimisation, retention limits)
See Legitimate Interest Assessment for the full assessment.
4.5 Special Category Data
We do not intentionally collect or process special categories of Personal Data as defined in Article 9 UK GDPR, including:
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Genetic or biometric data
- Health data
- Sexual orientation or sex life
If such data is inadvertently included in free-text fields (e.g., lesson notes, messages), you should avoid entering it. We do not rely on explicit consent (Article 9(2)(a)) or substantial public interest (Article 9(2)(g)) for processing special category data.
4.6 Children’s Data
Where a Student is under 13 (UK) or under 16 (EU), we rely on you (the Customer) to obtain explicit consent from their Responsible Adult before processing their Personal Data. This is in accordance with:
- UK GDPR Article 8 (parental consent for information society services)
- DPA 2018 Section 9 (UK implementation)
You must ensure you have verified parental consent before inputting any Student Personal Data for minors.
5. How long we keep your data
| Data Type | Retention Period | Justification |
|---|---|---|
| Payment and transaction records | 6 years from end of accounting period | Legal obligation (UK VAT/HMRC) |
| Account or customer records and information to demonstrate compliance | Duration of active account plus up to 1 year | Contract and compliance |
| Account and Customer data not necessary to demonstrate compliance | Duration of active account plus 30 days | Contract, reactivation |
| Application and server error logs, and performance traces | Up to 90 days | Legitimate interest (debugging) |
6. Who we share your data with
6.1 Service Providers (Sub-processors)
The providers below process data on our behalf as sub-processors. They handle both the platform account data we control (this policy) and, where applicable, the Student Personal Data we process on behalf of our Customers.
| Provider | Purpose | Data Processed | Location | Safeguards |
|---|---|---|---|---|
| Scaleway | Cloud hosting, transactional email, encrypted backups, security | All platform data | France (EU) | DPA in place |
| Grafana Cloud | Server log aggregation, performance traces, and audit logs | Server application logs and traces; audit/administrative event logs (may include IP addresses) | United Kingdom | DPA in place; see Section 7 |
| Cloudflare | Network infrastructure, reverse proxy, DNS, DDoS protection, origin IP masking | Connection metadata including IP addresses (not stored long-term by Soniq Studio, but processed by Cloudflare as a reverse proxy) | Cloudflare Inc., headquartered in San Francisco, US; metadata may be processed at Cloudflare data centres globally | Transfers covered by the EU-U.S. Data Privacy Framework (and its UK Extension) and Cloudflare’s Standard Contractual Clauses (cloudflare.com/cloudflare-customer-dpa) |
We do not use any third-party service for behavioural or product analytics, advertising, or tracking of user browsing behaviour, and we do not share visited URLs with any third party. Any usage measurement we perform is first-party: it runs on our own infrastructure, is limited to the usage and engagement data described in Section 4.4, and is never shared with anyone.
6.2 Payment providers
When you collect payments through Soniq Studio, the payment provider you have connected receives the personal data needed to process those payments. These providers act as independent Controllers for their own regulatory purposes — including anti-money-laundering checks, fraud prevention, and sanctions screening — and their own privacy notices govern that processing.
| Provider | Purpose | Location | Role |
|---|---|---|---|
| GoCardless | Direct Debit collection from your students | United Kingdom | Independent Controller for its own compliance purposes |
| Stripe | Card payment processing and subscription billing | European Union and United States | Independent Controller for its own compliance purposes |
6.3 No Sale or Sharing
We do not sell or rent personal data. Apart from the payment providers described in Section 6.2, we do not share personal data with third parties for their own purposes. We do not use account data for advertising or marketing.
6.4 Legal Requirements
We may disclose data where required by law, regulation, or court order.
7. International data transfers
All account data and Student Personal Data are stored in the EEA. One sub-processor, Cloudflare, processes connection metadata outside the UK and EEA; the mechanism is named below. The payment providers in Section 6.2 act as independent Controllers, not sub-processors, and their own notices govern their processing.
| Service | Location | Transfer mechanism |
|---|---|---|
| Scaleway (hosting, email, backups) | France (EU) | None required. Data remains in the EEA |
| Grafana Cloud (server logs, traces, audit logs) | United Kingdom | No transfer arises for UK GDPR purposes. For data within scope of EU GDPR we rely on the European Commission’s adequacy decision for the UK. |
| Cloudflare (network infrastructure, reverse proxy, DNS, DDoS) | US; metadata processed at data centres globally | Yes. Covered by the EU-U.S. Data Privacy Framework (and its UK Extension) and Cloudflare’s Standard Contractual Clauses |
Cloudflare, Inc. (headquartered in San Francisco, US) provides network infrastructure and reverse proxy services. Connection metadata including IP addresses may be processed at Cloudflare data centres globally as traffic is routed to Scaleway. These international transfers are covered by the EU-U.S. Data Privacy Framework and its UK Extension (Cloudflare is an active participant) and by Cloudflare’s Standard Contractual Clauses (cloudflare.com/cloudflare-customer-dpa).
8. Data Security
We implement appropriate technical and organisational measures including:
- Encryption in transit using TLS 1.2 or higher
- Encryption at rest: data volumes are encrypted using LUKS2 with AES-256 (XTS mode)
- Role-based access controls — a user’s access is scoped to the profile they belong to
- Platform administrators do not routinely access profile content
- A Content Security Policy is enforced in the browser to limit the effect of any content-injection attack
- Encrypted server backups (Scaleway)
9. Cookies and similar technologies
Soniq Studio uses only strictly necessary cookies. We do not use any advertising, marketing, or behavioural tracking cookies, and we do not display a cookie consent banner: everything we store on your device is strictly necessary to provide the service you have asked for, which is exempt from the consent requirement under ePrivacy/PECR regulations.
Clearing your browser’s site data removes everything from your device.
Authentication Cookies
Soniq Studio uses Keycloak as its identity provider, which is hosted on our infrastructure. Keycloak sets strictly necessary cookies on our domain to manage authentication sessions. These cookies contain authentication tokens and session identifiers, and are essential for secure access to your account. They are classified as strictly necessary and do not require consent under ePrivacy/PECR regulations.
| Technology | Provider | Purpose | Consent required? |
|---|---|---|---|
| Keycloak Auth Session cookie | Soniq Studio | Maintains active authentication session | No |
| Keycloak Auth “Remember me” cookie | Soniq Studio Keycloak Auth | “Remember me” persistent login across browser sessions | No |
| Keycloak Auth flow state | Soniq Studio Keycloak Auth | Managing login state and authentication flow | No |
Browser / Client-Side Storage and Offline data
In addition to Keycloak’s authentication cookies, Soniq Studio stores data in your browser’s localStorage and IndexedDB for application functionality. This includes authentication state (managed via localStorage rather than cookies), user preferences, and offline data caching. No third-party tracking or analytics cookies are used.
| Technology | Provider | Purpose | Consent required? |
|---|---|---|---|
| localStorage | Browser | Stores debug flags, authentication state, device ID, feature flag overrides, dismissable UI keys, and metronome session history | No |
| sessionStorage | Browser | Stores a reload flag to prevent infinite reload loops when recovering from stale deploys | No |
| IndexedDB | Browser | Stores job queue data for offline processing and metadata including offline state version for database migrations | No |
| Origin Private File System | Browser | Stores a local copy of your profile’s data for offline access | No |
10. Automated decision-making, Artificial Intelligence and Machine Learning
Soniq Studio incorporates artificial intelligence and machine learning functionality to provide enhanced features, such as intelligent scheduling suggestions. All AI processing occurs exclusively on your device, your personal data never leaves your device for AI purposes, and we do not use your data to train any models.
10.1 Automated Processing under Article 22 GDPR
Under Article 22 of the UK/EU GDPR, you have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you.
Our AI features may generate automated suggestions based on your usage data (for example, recommended lesson times or scheduling optimisations). However, these are always presented as non-binding recommendations that require your explicit review and approval before any action is taken. You retain full control to accept, modify, override, or ignore these suggestions at any time.
Therefore, Soniq Studio does not carry out automated decision-making as defined in Article 22 (1) GDPR, because meaningful human intervention (yours) is always required before any decision or action takes effect.
11. Your rights
Under UK GDPR and EU GDPR, you have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data where no longer necessary or consent withdrawn (Art. 17)
- Restrict processing in certain circumstances (Art. 18)
- Data portability — receive your account data in a structured format (Art. 20)
- Object to processing based on legitimate interests (Art. 21)
To exercise any right, contact us at privacy@soniq.studio. We will respond within one calendar month.
Important: The rights above cover the personal data we hold about you as a Soniq Studio account holder.
As an account holder, you are the Controller of Student Personal Data, the information you enter about students and Responsible Adults, including lesson notes, messages and uploaded images.
Requests about that information should be directed to you. We can assist you in responding as your Processor, under clause 4 (Data protection) of our Terms & Conditions.
12. Right of complaint
If you are unhappy with how we handle your data:
Complaints: complaints@soniq.studio
UK Information Commissioner’s Office (ICO): www.ico.org.uk.
13. Changes to the policy
We reserve the right to make changes to this notice at any time to reflect updates to the law or changes to our data collection and security practices. We recommend that you review it regularly for your own knowledge and benefit.
| Version | Date | Change |
|---|---|---|
| 2026-09 | 3 Sep 2026 | Greater detail about the company, the purposes and lawful basis for each piece of data collected. New sections for greater transparency. Moved server-side error monitoring onto our own infrastructure in France and named the transfer mechanism for each remaining provider outside the EEA. Added payment providers as independent Controllers, and device and connection data. Added section for students and Responsible Adults who open a contact portal link, and renumbered the sections after it. |
| 2025-05 | 29 May 2025 | First published version |