SonaPorta — Privacy policy

Applies to SonaPorta on Android phones, tablets and Wear OS watches, and to the SonaPorta desktop edition for Windows 11.

Who is responsible and how to contact us

Sonamont, Iterstrasse 3, B-4730 Raeren, Belgium. Business registration: 0817.863.814. VAT: BE0817863814. Privacy and support contact: sonamontmedia@gmail.com.

This notice covers SonaPorta on Android phones, tablets and Wear OS watches, the desktop edition for Windows 11, and related support correspondence. Sonamont handles messages addressed to it. Your telephone-system operator controls that system and its records; Sonamont cannot access or delete them through the app.

What the app does

SonaPorta sends a control signal to your configured SIP telephone system after you tap a gate. A separate login test checks your SIP credentials. There is no Sonamont app account, app backend, analytics, advertising, crash upload or AI service. The app does not record microphone audio or request access to contacts or location. The Windows edition works the same way and needs no Android device, Python installation, cloud account or microphone.

Google Play, Android and Wear OS may process purchase, installation or platform diagnostic data under their own terms. The app's absence of telemetry does not describe Google's independent processing. See Google's privacy policy: https://policies.google.com/privacy. Microsoft and the Microsoft Store may likewise process purchase, installation and platform diagnostic data for the Windows edition under their own terms: https://privacy.microsoft.com/privacystatement. An Android TV edition is not covered by this notice.

Data stored on your device

The app stores your SIP host, port, username and password, gate names, internal numbers, control codes, selected icons and button colors, timing and protocol options, setup progress and unfinished gate drafts. These settings are encrypted using Android facilities and a device-held key. Android cloud backup and device transfer are excluded by the app configuration. On Windows the same configuration is stored in the single file %LOCALAPPDATA%\SonaPorta\settings.dpapi, encrypted with Windows DPAPI for your Windows user account; no plaintext copy, export or backup is created.

These values are needed to configure and operate your installation. Without valid SIP credentials and a compatible target, the app cannot send the intended signal. You can read Help without entering credentials.

Data transmitted and recipients

SIP signaling sends usernames, source and destination network addresses, internal numbers, call metadata and password-derived authentication responses to the configured telephone system. Control codes are sent as RTP telephone events or SIP INFO, according to your settings. The system can specify a media endpoint that receives RTP. Hostname resolution uses the Wi-Fi network's DNS resolver.

On Android the app binds its sockets to Wi-Fi and does not require the entered host or negotiated media endpoint to be a private network address. On Windows it uses the operating system's own route to the address, over Ethernet or Wi-Fi, changes no adapter setting, and accepts only destinations that are or resolve to private IPv4 addresses. Your telephone-system operator, DNS provider and network infrastructure can therefore receive traffic. No app telemetry is sent to Sonamont.

SIP and RTP use unencrypted UDP, not TLS or SRTP. Encryption of saved settings and SIP digest authentication do not encrypt the network traffic. Use a trusted network and an installation you are authorized to control.

Diagnostics

The app keeps its latest 20 diagnostic lines in memory and also writes diagnostic messages to Android's local system log. The app filters SIP diagnostic text before displaying or logging it: recognized methods, status codes and timings are retained, while account identifiers, internal numbers, network addresses, control codes and remote reason phrases are omitted. The diagnostic screen also shows the app version and device model. Older builds and external diagnostic captures may still contain sensitive values. The app does not upload these logs. The in-app buffer ends with the app process; Android controls system-log retention separately. On Windows the diagnostic lines stay in memory only, are not written to any system log or file, and leave the app only when you click to copy them.

If you choose to send a screenshot or log to support, remove passwords, control codes and personal details first. Sending email is your separate action; viewing Help sends nothing.

Support, purposes and legal bases

When you email Sonamont, we receive your email address, message and any attachments you choose to send. We use them to answer your request and investigate the problem, not for unrelated marketing. Contract-related support relies on GDPR Article 6(1)(b). Other inquiries rely on Article 6(1)(f), our legitimate interest in answering inquiries and maintaining the app. Where a legal recordkeeping obligation applies, Article 6(1)(c) is the basis for keeping the relevant records.

Support correspondence is handled through Google Gmail and the sender's email services. These providers also process transmission and account data under their own terms. Processing can involve countries outside the European Economic Area; Google's privacy policy describes its processing and international-transfer arrangements: https://policies.google.com/privacy. Sonamont has no remote access to your device's settings. Do not send SIP passwords or gate control codes to support.

Retention and deletion

Saved settings remain on your device until edited, removed, the app's storage is cleared, or the app is uninstalled. A device reset also removes them. There is no Sonamont cloud backup from which to restore them. An individual gate can be deleted in Settings; that does not remove the SIP account saved for other gates. On Windows the settings file survives removal of the program folder; deleting %LOCALAPPDATA%\SonaPorta\settings.dpapi resets the app.

Uninstalling does not revoke the IP telephone account, delete telephone-system or DNS logs, or delete support email. Their operators manage those records. We keep support correspondence for as long as needed to deal with your request, follow up on the reported problem, and meet applicable recordkeeping obligations or establish, exercise or defend legal claims. When those purposes no longer apply, the correspondence is deleted. You may request deletion at sonamontmedia@gmail.com; if an exception requires retention, we explain it.

Your rights

Where applicable under the GDPR, you may request access, correction, erasure, restriction or portability of personal data Sonamont holds, and object to processing based on legitimate interests. Contact sonamontmedia@gmail.com. These rights have legal conditions and exceptions; Sonamont cannot retrieve or delete data held only on your device or in your telephone system.

You may complain to a data protection supervisory authority, including the Belgian Data Protection Authority or the authority where you live or work. The app does not carry out profiling or automated decisions with legal or similarly significant effects.

Website and changes

The standalone SonaPorta privacy and deletion pages contain no analytics scripts, third-party fonts, forms or embedded media. Fetching a page still sends technical request data, including an IP address, to the hosting infrastructure. Such server-side processing is separate from the app's operation. The website privacy notice describes website hosting and other website services: https://www.sonamont.com/?type=privacy&lang=en.

We update this notice when data handling changes. The date above identifies this version. This notice does not replace the privacy information supplied by your telephone-system operator, network providers, Google or Microsoft.