We take privacy seriously and design our products to need as little of your data as possible. This page explains, in plain language, what we collect, why, and how to control it.
Tona Digital is a privately held company based in the Netherlands, registered with the Kamer van Koophandel. For privacy-related requests, contact privacy@tonadigital.com.
We collect three categories of data:
Under the GDPR, we rely on the following legal bases:
We host on EU infrastructure by default (Amsterdam, Frankfurt and London). We do not sell, rent, or share your data with third parties for marketing. We never train our models on your data without an explicit, separately signed agreement.
Under the GDPR, you have the right to access, correct, port, restrict, or delete your data, and to object to processing. To exercise any of these rights, email privacy@tonadigital.com. We will respond within 30 days.
You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
We use a minimal set of cookies:
We do not use third-party advertising trackers, Facebook Pixel, Google Analytics, or similar.
All traffic is forced over TLS 1.3. Passwords are hashed with Argon2id. Customer data is encrypted at rest with AES-256. We run quarterly security reviews and welcome responsible disclosure at security@tonadigital.com.
We may update this policy as our products evolve. When we do, we will update the "last updated" date above and email all account holders 30 days before significant changes take effect.
For any privacy question, please write to privacy@tonadigital.com. We read every message.