Privacy and the protection of personal data

This notice explains why we process the personal data you send through our website, where we store it and what rights you have. It also covers what the BMS Desktop application keeps on your own computer and how the Sona Meeting Room application uses Google Calendar data.

Data controller

Your personal data is processed by Sona Otomasyon Taahhüt Sanayi ve Ticaret Ltd. Şti. as data controller. Address: Soğanlık Yeni, Muş Sk. Soyak Evreka Sitesi No: 8, A6 Blok Daire 12, 34880 Kartal / İstanbul, Türkiye.

Personal data processed

There are three forms on the site that collect personal data, and each asks only for what its own job requires. Dealer application form: company name, address, country, city; the contact person's name, role, phone and email address; field of work, years in business and number of completed projects; the systems you work with and the protocols you use, who does the programming, and optionally your experience and company website; the regions to be served and the target project type. Technical support form: full name, email, phone, country, city; your project, who you bought the product from, which Sona product you use and the problem itself. Sales support form: full name, email, phone, country, city; whether you already have an automation server, which side you are on and your question. In all three forms the IP address and browser information the request came from, and the moment you ticked the consent box, are also recorded.

Purpose of processing

This data is processed only to evaluate your request and to get in touch with you: to assess your application in the case of a dealership application, to point you to a dealer who will take care of the problem in the case of a technical support request, and to answer your question in the case of a sales support request. It is not used for any other purpose and is not added to a marketing list.

Legal basis

Your data is processed on the basis of your explicit consent. The consent box you tick when you send the form gives that consent. You may withdraw your consent at any time; in that case your form record is deleted.

Method of collection

Data is collected only through the three forms on the website, entered directly by you: the dealer application, technical support and sales support. No data is collected through any other channel.

Disclosure to third parties

Your form information is not transferred to third parties. Form data is stored on Sona's own server; no external form service, analytics tool or bot protection service is used. The one exception is a technical support request: when we point your request to a dealer who will take care of it, the information they need to solve the problem is shared with that dealer. We do this only when you have filled in the technical support form, and only for that purpose.

Retention period

Form records are kept for five years and deleted at the end of that period.

BMS Desktop application

The application stores the address and port of the automation server it connects to, the username and password for that server, the application PIN, the certificate fingerprints of the servers, the interface language you choose, your screen-saver settings and the step the setup wizard stopped at. This information stays on your own computer, in a single file protected by Windows DPAPI encryption. If you load your own image for the screen saver, a copy of that image is also kept in the application folder.

None of it is sent to Sona or to any third party. The application contains no analytics, telemetry or usage tracking; it needs no internet connection and reaches only your own server on your local network. Application logs are visible inside the application alone and are never exported. The temporary profile of the browser component the application uses is deleted every time the application opens and closes.

You can erase all of this at any time using the application’s “factory reset” function or by uninstalling the application.

Sona Meeting Room and Google Calendar data

Sona Meeting Room is a meeting-room application that runs on a building automation server. The user may connect the application to their own Google account with the “Connect with Google” button; the connection is made on Google's own sign-in and consent screens, and Sona never sees the password.

The application reads only the following data from Google: the account's calendar list and, for the selected room calendars, each event's title, start and end time, organizer, privacy flag, cancellation status and number of attendees; attendees' names and e-mail addresses are not read. This data is used solely to display the schedule on the room's door panel and to derive the room's occupied/free state for the automation system. When a user books, extends or ends a meeting from the panel, the application creates an event in the corresponding room calendar or changes its end time; no other calendar data is written.

The data stays on the customer's own device: the access token and at most eight days of event summaries are stored in the device's memory. They are not sent to Sona's servers or to third parties, are not used for advertising, are not sold and are not read by humans. When the Google account is removed from the application or the application is uninstalled, this data is deleted from the device; the user can also revoke access at any time from the “Third-party apps with account access” page of their Google account.

The connection to Google is encrypted (HTTPS/TLS). The access and refresh tokens are kept only on the customer's building automation server, which is reachable only from within the customer's own network through its password-protected administration interface. The application never displays or exports the tokens and does not include them in its backup files.

Sona Meeting Room's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Sona Meeting Room — Microsoft 365 and Exchange calendar data

Sona Meeting Room can connect to your organisation's Microsoft 365 or on-premises Exchange calendar in order to show meeting-room schedules on door panels. This section explains what data we access through that connection, what we use it for, where it is kept and how it is deleted.

With Microsoft 365 the connection is made by an administrator of your organisation: consent is granted once to the “Sona Meeting Room” application on Microsoft's own consent screen, and the permissions requested are Calendars.ReadWrite (read and write calendars) and Place.Read.All (read the room list). No user's password is entered into or seen by the application. With on-premises Exchange, your IT administrator creates a service account that is authorised only for room mailboxes; the server address, account name and password are entered on the application's settings screen.

The application accesses the following data: your organisation's display name (Microsoft 365 only; shown on the “connected” line of the settings screen), the room list with each room's name and email address (Microsoft 365 only, to make room selection easier) and the calendar events of only those mailboxes you have defined as rooms on the settings screen — title, start and end time, organiser's name, sensitivity flag, cancellation status, all-day flag and the number of attendees. Attendee names and email addresses are neither stored nor displayed; only a count is calculated. The title and organiser of events marked “Private” or “Confidential” are not shown on the panel. We do not access emails, contacts, files, or the calendars of mailboxes that have not been defined as rooms.

The data is used only to show the room's busy or free status and its daily or weekly schedule on the door panel, to write a booking made on the panel to the room calendar as a new event, and — with the “Extend” and “End” commands — to change only that event's end time. The application does not delete events and does not send invitations or emails. The data is not used for advertising, profiling, or training artificial-intelligence or machine-learning models.

All data is kept only on the automation server on your own premises; no calendar data, account information or password is sent to Sona's servers, shared with third parties or sold. The automation server connects to Microsoft 365 directly over HTTPS (TLS); the on-premises Exchange connection is made inside your own network over a TLS-encrypted channel with NTLM authentication, and the password is never sent over the network in clear text. For Microsoft 365 only your organisation's directory ID and a short-lived access token are kept on the automation server; for on-premises Exchange the server address, service-account name and password are kept. The access token and the password are never sent back to the settings screen, do not appear on panel screens and are not written to the application's backup file. The settings screen is password-protected. Event information is held only temporarily for display on the panel and is refreshed on every calendar read.

When you choose “Delete account” on the settings screen, the account information, the access token or password, the room definitions and the temporary event data are deleted from the automation server; uninstalling the application also deletes all of its data. You can revoke the Microsoft 365 consent at any time: Microsoft Entra admin centre → Enterprise applications → “Sona Meeting Room” → Delete. Your administrator may also restrict the application's access on the Microsoft side to room mailboxes only. For on-premises Exchange, disabling the service account or changing its password is enough to cut off access. Questions and deletion requests: [email protected]

Your rights

You have the right to learn whether your personal data is being processed; to request information about it if it has been processed; to learn the purpose of the processing and whether it is used in line with that purpose; to know the third parties to whom it has been transferred in Türkiye or abroad; to request that it be corrected if it has been processed incompletely or incorrectly; to request that it be erased or destroyed; to request that these actions be notified to the third parties to whom the data has been transferred; to object to a result reached against you through analysis carried out solely by automated systems; and to claim compensation if you suffer loss because of unlawful processing.

How to apply

You can send requests relating to the rights above to [email protected]. Your request is concluded within thirty days at the latest.