In effect as of 18 July 2026.
This policy describes how Cohesium AI collects, uses and protects the personal data of users of the Tonael service (the API and the platform.tonael.com console), in accordance with the GDPR (Regulation (EU) 2016/679) and French Data Protection Act No. 78-17 of 6 January 1978, as amended.
1. Our Role: Controller and Processor
Cohesium AI, SASU, 888 Route de la Caille, 74350 Allonzier-la-Caille, France — SIREN 992 658 401. Contact: contact@tonael.com.
Cohesium AI plays two distinct roles, and this policy covers only the first:
- Controller — for the data we process for our own purposes: your account, authentication, billing, security and fraud prevention, and aggregate service statistics. That is what this policy describes.
- Processor — where you submit audio or lyrics relating to other people (for example your own end users' recordings), you are the controller and we act on your instructions. That processing is governed by our Data Processing Agreement, not by this policy.
If you only submit content relating to yourself, or content containing no personal data, the second role does not arise.
2. Data Protection Contact
Cohesium AI has not appointed a Data Protection Officer (DPO). For any question regarding your data or to exercise your rights, you may write to contact@tonael.com.
3. Data Collected, Purposes and Legal Bases
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Account creation and management, email verification, transactional communications | Performance of the contract (Art. 6.1.b) |
| Password hash (argon2id) | Secure authentication | Performance of the contract (Art. 6.1.b) |
| OAuth identifiers (Google / GitHub) if this method is chosen | Authentication | Performance of the contract (Art. 6.1.b) |
| IP address (sign-up and use) | Fraud prevention, prevention of service and free-tier abuse, security | Legitimate interest (Art. 6.1.f) |
| Session data | Maintaining the connection, security | Performance of the contract + legitimate interest |
| API usage data (volumes, minutes processed, technical logs) | Billing, support, security and service improvement | Performance of the contract (Art. 6.1.b) + legitimate interest (Art. 6.1.f) |
| Payment data (card) | Processing of payments and credit purchases | Performance of the contract (Art. 6.1.b) |
| Audio files and lyrics submitted for processing | Production of the lyrics/audio alignment (the service output) | Performance of the contract (Art. 6.1.b). Where you submit content relating to your own end users, you are the controller and Cohesium AI acts as your processor on your documented instructions (Art. 28) |
| Submitted content, where you have opted in | Training and evaluation of the Tonael models (optional programme, Section 4) | Consent (Art. 6.1.a), withdrawable at any time |
Payment data: card data is collected and processed directly by our payment provider Stripe. Cohesium AI does not store card numbers in clear text.
Sensitive data: the service is not intended to process special categories of data (Art. 9 GDPR). It is the user's responsibility not to submit lyrics or audio revealing such data without an appropriate legal basis.
4. Improvement and Training of the Models
By default, Cohesium AI does not use the content you submit (audio files, lyrics) to train its models. Content submitted for alignment is processed to deliver the result and deleted at the end of the retention period set out in Section 5. It is not retained in any training corpus.
Cohesium AI operates a separate, optional training programme which a customer may join explicitly. Participation is:
- Opt-in only — based on your consent (Art. 6.1.a and Art. 7 GDPR), given by a specific, unticked choice in your account. It is never bundled with acceptance of these terms or of the Terms of Sale.
- Withdrawable at any time (Art. 7.3 GDPR), from your account or by writing to contact@tonael.com. Withdrawal takes effect for the future; it does not affect the lawfulness of processing carried out beforehand.
- Conditional on your rights in the content — participation requires you to warrant that you hold the rights necessary to authorise this specific use, which is broader than the alignment itself.
- Without consequence if declined — refusing, or later withdrawing, has no effect whatsoever on your access to the service, its price, or its quality.
Where you act as a data controller and submit content relating to your own end users, this programme is available only within the framework of the data processing agreement between us, and on your documented instructions (Art. 28.3.a GDPR).
5. Retention Periods
| Category | Period |
|---|---|
| Account and associated data (email, password hash) | For the life of the account, then deleted or anonymized within 30 days of closure |
| Alignment results, audio files and lyrics submitted (for service delivery) | No longer accessible 24 hours after processing for hot jobs, 72 hours for batch jobs; erased from our storage servers within 72 hours |
| Job records and API usage logs (metadata: timestamps, duration, model, amount charged — not the audio or lyrics) | 90 days, then deleted |
| Content included in the optional training programme (opt-in only) | For as long as the consent is not withdrawn, and no longer than necessary for that purpose; removed from future training runs on withdrawal |
| Security logs / IP addresses | 12 months |
| Billing data and accounting records | 10 years (Article L.123-22 of the French Commercial Code) |
| Payment data | Retained by Stripe under its own policy |
6. Recipients and Processors
Your data is processed by Cohesium AI and by processors acting on its instructions, under data processing agreements (DPAs) compliant with Art. 28 GDPR:
| Processor / recipient | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | EU / United States |
| Brevo (formerly Sendinblue) | Transactional emails | EU (France) |
| Cloudflare R2 | Temporary storage of results / stems | European Union (bucket pinned to the EU jurisdiction) |
| Modal | GPU compute (alignment processing) | European Economic Area (workloads are region-pinned to the EEA) |
| Cohesium AI (self-hosted) | Platform hosting | EU (France) |
| Google / GitHub | OAuth authentication (if the user chooses this method) | United States |
Cohesium AI does not sell or rent your data. Data is disclosed only to the processors listed above, to authorities where required by law, and where applicable to advisers bound by professional secrecy.
7. Transfers Outside the European Union
The content you submit (audio and lyrics) does not leave the European Economic Area. GPU processing is region-pinned to the EEA and temporary result storage is pinned to the European Union jurisdiction.
Certain account-level processors may process data outside the European Union, in particular in the United States: Stripe (payments) and, where you choose that sign-in method, Google or GitHub (OAuth). Such transfers are governed by appropriate safeguards within the meaning of Articles 44 et seq. GDPR — the European Commission's Standard Contractual Clauses and/or the provider's participation in the EU-U.S. Data Privacy Framework.
8. Security
Cohesium AI implements appropriate technical and organizational measures: password hashing (argon2id), encryption of communications (HTTPS/TLS), access control, automatic expiry of results after 24 hours (72 hours for batch jobs) followed by erasure from storage within 72 hours, and anti-abuse measures. In the event of a data breach likely to result in a risk to your rights and freedoms, Cohesium AI will notify the CNIL within 72 hours and, where applicable, the data subjects concerned (Art. 33 and 34 GDPR).
9. Your Rights
Under the GDPR, you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21, to processing based on legitimate interest), the right to withdraw consent at any time (Art. 7.3, in particular for the optional training programme described in Section 4), and the right to set post-mortem directives (Art. 85 of the French Data Protection Act).
You may exercise these rights by writing to contact@tonael.com. Proof of identity may be requested in the event of reasonable doubt. A response is provided within one month (extendable by two months in complex cases).
10. Complaint to the CNIL
If, after contacting us, you consider that your rights are not respected, you may lodge a complaint with the CNIL (the French data protection authority): 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.
11. Changes
This policy may be updated. The applicable version is the one published on the website at the time of your use. In the event of a material change, notice will be provided via the platform or by email.