Privacy policy
This policy explains what personal information Sonortix Consulting LLC collects through sonortix.bond and our engagements, why we collect it, how long we keep it and the rights available to you. It was last reviewed on 15 September 2026.

Sonortix Consulting LLC, a Delaware limited liability company with its head office at 1 Congress Plaza, Suite 2140, Austin, TX 78701, United States, is the controller of personal information collected through sonortix.bond and through client engagements, except where an engagement letter names the client as controller. This policy describes what we collect, why, how long we keep it, who we share it with and the rights you can exercise. It applies to visitors to this website, to people who contact us, and to individuals whose information is processed in the course of an engagement.
Information we collect
We collect information in three ways. First, information you give us: your name, work email address, telephone number, employer and the content of your inquiry when you contact us, apply for a role or subscribe to our newsletter. Second, information collected automatically: our website loads no third-party analytics, so we collect only standard server logs retained by our hosting provider, which include IP address, request time and user agent, kept for security and troubleshooting. Third, information received in an engagement: business contact details and, where relevant to the work, workforce and operational data supplied by the client under a data processing agreement.
How we use information
We use personal information to respond to inquiries, deliver and administer engagements, issue invoices and manage payment, meet legal, tax and accounting obligations, protect the security of our systems, and send our newsletter where you have opted in. We do not use personal information for automated decision-making that produces legal or similarly significant effects, and we do not carry out profiling for advertising.
Legal bases for processing
Where the EU or UK GDPR applies, we rely on the following legal bases. Performance of a contract, where processing is necessary to deliver a service you or your employer has engaged us for. Legitimate interests, for responding to inquiries, securing our systems and administering our business, balanced against your rights. Consent, for our newsletter and for any non-essential browser storage, which you may withdraw at any time. Legal obligation, for tax, accounting and lawful requests from authorities. Where we rely solely on consent, refusing it will not prevent you from using the rest of the website.
Sharing and disclosure
We share personal information only with service providers who process it on our instructions, such as our email host, our customer relationship system, our accounting platform and our hosting provider, and only to the extent needed to run our business. We require those providers to protect the information and to process it only for our purposes. We may disclose information where required by law, court order or a lawful request from a public authority, or where necessary to protect the rights and safety of our firm, our clients or the public. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to know the categories and specific pieces of personal information we have collected, the sources, the business purposes and the categories of third parties with whom we share it; the right to request deletion; the right to request correction of inaccurate information; the right to opt out of the sale or sharing of personal information; the right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising these rights. We do not sell personal information and we do not share personal information for cross-context behavioural advertising, so there is no sale or sharing to opt out of. You may exercise these rights yourself or through an authorised agent who submits a request on your behalf with written permission. Submit requests to [email protected]. We will acknowledge receipt within ten business days and respond substantively within forty-five calendar days, extendable once by a further forty-five days where reasonably necessary, with notice to you.
Children's privacy
Our services are directed at business organisations and are not intended for children. We do not knowingly collect or solicit personal information from anyone under thirteen, consistent with the Children's Online Privacy Protection Act (COPPA). If we learn that we have inadvertently collected information from a child under thirteen, we will delete it promptly. If you believe a child has provided information to us, contact [email protected].
Retention
We keep information only as long as needed for the purpose it was collected. Inquiry and prospect records are retained for two years from last contact. Engagement records and related correspondence are retained for seven years following the end of the engagement, consistent with professional and accounting practice. Newsletter subscriptions are kept until you unsubscribe plus a suppression record. Server logs are retained for up to ninety days. Where a client agreement specifies a shorter or longer period, the agreement controls for engagement data.
Security
We use administrative, technical and physical safeguards appropriate to the sensitivity of the information. These include access controls limited to those who need it, encryption in transit, encryption at rest for client material, vendor due diligence and periodic access reviews. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; we will notify affected individuals and regulators where a breach is likely to result in a risk to their rights, as required by applicable law.
International transfers
We are based in the United States. Where we transfer EU or UK personal data to the United States, we rely on recognised transfer mechanisms such as the Standard Contractual Clauses or an adequacy decision, and we assess the protection available in the destination. Individuals in the EU or UK have the right to lodge a complaint with their local supervisory authority, and may contact our privacy lead directly first so that we can try to resolve the matter informally.
Your rights and how to use them
Depending on where you live, you may have the right to access, correct, delete or port personal information, to object to or restrict certain processing, to withdraw consent, and to complain to a supervisory authority. You can exercise these rights by emailing [email protected]. We may need to verify your identity before acting, and we will not charge a fee unless a request is manifestly unfounded or excessive. If we decline a request, we will explain why.
Changes and contact
We review this policy at least annually and will post material changes on this page with a revised effective date. The current version is effective 15 September 2026. Questions, requests and complaints should be sent to [email protected], or by post to Sonortix Consulting LLC, 1 Congress Plaza, Suite 2140, Austin, TX 78701, United States.