Sotero, Inc.
Sotero Privacy Policy
Introduction
Effective date: August 10, 2026
This privacy policy (“Policy”) describes how Sotero, Inc. (“Sotero”) collects, uses, and shares personal information of consumer users of Sotero websites (the “Sites”) or any products or services available on or through the Sites. Sotero is the sole owner of information collected on the Sites or through your use of Sotero products and services. We will not sell, share, or rent this information in ways different from what is disclosed in this Policy.
Sotero respects your privacy and is committed to protecting your personal data in line with the General Data Protection Regulation—Regulation (EU) 2016/679 (GDPR). This Policy explains how we look after your personal data when you interact with us, including when you visit our Sites, and describes your rights in relation to your personal data.
What Is Personal Data and Who Is Responsible for It?
Personal data is any information about an identifiable individual. Sotero is responsible for personal data we collect from you and, along with our distributors, resellers, dealers, and other sales channels, for how we handle personal data collected from Sotero sales partners.
Data Collected and Its Use
Sotero allows you to voluntarily provide contact information through our website and when purchasing or redeeming offers or registering products purchased from authorized retailers. Information we may collect includes your name, email address, phone number, and past purchases. We do not collect or store credit card information.
If you contact us, we may keep a record of the communication to help resolve issues. We may also receive contact details or other information about you from publicly and commercially available sources and combine it with other information received from or about you. Information from third-party sources is used in accordance with this Policy.
When you create or use a Sotero account, authenticate through an identity provider, accept a software license, or download Sotero software, we collect account and authentication information, event timestamps, IP address, browser or client user-agent, an internal request identifier, license-acceptance records, and installer version, operating-system, architecture, filename, download result, and download activity. We use this information to authenticate users, secure accounts, prevent fraud and abuse, document license acceptance, authorize and troubleshoot downloads, operate the service, and respond to support, legal, or privacy requests.
We never store your plaintext password. We may check a new or reset manual-account password against known data breaches through the Pwned Passwords service from Have I Been Pwned. When this advisory feature is enabled, the browser computes a one-way SHA-1 hash and sends only its first five characters for a privacy-preserving range lookup; neither the password nor its complete hash is disclosed to that service. A match displays a warning but does not prevent you from choosing the password. Accepted passwords are stored only as Argon2id hashes.
If you affirmatively select the optional product-contact preference, we may combine your account information with login, license-acceptance, installer version, operating-system, architecture, and download history to understand current product use and identify individuals or groups who may benefit from a feedback request or relevant product communication. Raw IP addresses, user-agent strings, and internal request identifiers are excluded from the product-outreach profile. We do not use this optional profile to make decisions that produce legal or similarly significant effects.
Product outreach is optional and is not required to create an account, accept a EULA, use social sign-in, or download eligible software. You may withdraw or restore this preference in Account Settings or by contacting privacy@sotero.ai. Withdrawal applies to future outreach and does not affect account-security, legal, transactional, or requested-service communications.
Information submitted to a blog, bulletin board, or similar public communication area may be read, collected, or used by others. We use administrative, technical, and physical safeguards to protect personal data, but no Internet transmission can be guaranteed to be entirely secure.
Authentication via Google or Microsoft
If you sign in with Google or Microsoft, we never receive or store your third-party account password. We request only the minimum identity scopes needed to sign you in: from Google, your email address; from Microsoft, your email address and basic profile (name). We do not request or store a profile picture, and we do not request access to your files, mail, contacts, or calendar. After your Sotero session is established, the provider access and refresh tokens are discarded; we do not retain long-lived tokens for either provider.
The data categories involved are your name, email address, and the provider account identifier used to link sign-ins to your Sotero account, together with the login-event and security information described above.
If you are located in the European Economic Area, the United Kingdom, or Canada, our basis for this processing depends on context: performance of a contract to establish and secure the account you requested; legitimate interests in fraud prevention and platform security; and, where applicable under PIPEDA or U.S. state law, the consent reflected by your choice to continue with that identity provider. Section “International Transfers” describes the safeguards that apply when this data is processed in the United States.
You control your authentication connections directly with the provider: Google Account Settings > Security > Third-party apps with account access; Microsoft Account Dashboard > Privacy > Apps and services that can access your data. Disconnecting a provider there will prevent sign-in through that method until you establish another one. You may also request access, correction, or deletion of this data as described in “Your Rights” below or at Account and Privacy Requests.
Data Integrity and Security
Sotero uses industry-standard security measures to protect against loss, misuse, or alteration of data in our systems. We use measures such as encryption when transmitting certain sensitive information, regularly review security policies as threats evolve, and monitor systems to support availability. Questions about security may be sent to privacy@sotero.ai.
Lawful Grounds for Using Personal Data
Lawful grounds on which we use personal data include legitimate interests such as:
- Understanding how customers use our products and services.
- Keeping our records up to date.
- Developing our products and services and growing our business.
Complaints and Contact
You may make a complaint to the supervisory authority for data-protection issues in your country. We would appreciate the opportunity to address your concerns first. Contact privacy@sotero.ai with privacy questions or concerns.
Technical and Aggregated Data
Sotero may collect technical information when you interact with our website, including browser name, computer type, operating system, Internet service provider, and similar information. Some technical information, such as an IP address or online identifier, may be personal data. We use technical information to secure, operate, optimize, and improve our services. We use aggregated or de-identified information for analytics only when it can no longer reasonably be associated with an individual.
Cookies and Similar Technologies
Sotero uses only essential cookies: to keep you signed in, protect your session, complete Google and Microsoft authentication redirects, protect state-changing requests, and authorize a requested download. These cookies are necessary for the service to function and are not used for advertising, cross-site tracking, or behavioral profiling. You may configure your browser to refuse cookies, but doing so may prevent sign-in or download features from working.
Some Sotero downloads or software may generate a computer ID during installation. This ID does not contain specific information about you or data on your computer.
We use Cloudflare Turnstile on account-registration and password-recovery forms to distinguish legitimate requests from automated abuse. Cloudflare may process limited device, browser, network, interaction, and IP-address information to provide this security service. Turnstile is used for security and fraud prevention, not by Sotero for advertising or product-outreach profiling.
If Sotero later adds analytics, advertising, or other non-essential tracking technologies, we will update this Policy and this section before enabling them, and will provide any consent mechanism required by applicable law.
Surveys and Responsive Requests
Participation in surveys or similar requests is voluntary. Requested information may include contact and demographic information. If you provide personal information about another person, we assume you have permission to do so. Survey information may be used to monitor or improve satisfaction with our Sites, products, or services.
Information Sharing and Disclosure
Sotero will not sell or rent personal data, except to successors in interest, without your consent. We may exchange account information with organizations for fraud protection and credit-risk reduction.
We share personal data when necessary to provide a requested product or service and with service providers that support activities such as hosting, database operations, email delivery, artifact distribution, bot and abuse prevention (including Cloudflare Turnstile), password-compromise screening, security, and professional advice. Service providers may process personal data only for specified purposes and according to our instructions.
We may disclose personal data in response to subpoenas, court orders, legal process, lawful public-authority requests, emergencies, or violations of usage guidelines. Information posted to public forums is not protected by this Policy. If Sotero is involved in a merger, acquisition, or asset sale, information may be shared with a successor while remaining subject to this Policy.
We require third parties to respect the security of personal data and treat it according to law.
International Transfers
Sotero, Inc. is based in the United States, and many service providers are outside the European Economic Area (EEA). Personal data may therefore be transferred outside the EEA. We seek to provide a similar degree of protection by using countries deemed adequate by the European Commission or approved contractual protections with service providers. Contact privacy@sotero.ai for information about transfer mechanisms.
Other Sites
Our Sites may link to external websites that Sotero does not control. Sotero is not responsible for their privacy practices or content. Review their privacy policies to understand how they use personal data.
How Long We Keep Personal Data
We retain personal data only as long as necessary for the purposes for which it was collected, including legal, accounting, reporting, security, fraud-prevention, dispute-resolution, and software-license audit requirements. Raw IP addresses, user-agent strings, and internal request identifiers associated with account creation, login, consent, EULA acceptance, and downloads are normally removed after 90 days. They may be retained longer when reasonably necessary to investigate an active security incident, prevent fraud, comply with law, or establish, exercise, or defend legal claims.
When a public Sotero account is deleted, credentials and active sessions are removed and the account is marked deleted. Limited account identity and associated license, consent, login, and download history may be retained for applicable legal, security, fraud-prevention, dispute-resolution, and license-audit periods. A later registration creates a separate account.
In some circumstances, you may ask us to delete data. We may also anonymize data so it can no longer be associated with you and use that information for research or statistical purposes.
Your Rights
Depending on applicable law, you may have the following rights. Contact privacy@sotero.ai or visit our Account and Privacy Requests page to make a request.
- Access: request a copy of personal data we hold and check that it is processed lawfully.
- Correction: ask us to correct incomplete or inaccurate personal data.
- Erasure: ask us to delete personal data where no continuing lawful reason requires processing. We may be unable to comply for specific legal reasons.
- Objection: object to processing based on legitimate interests or for direct marketing.
- Restriction: ask us to suspend processing in circumstances provided by law.
- Transfer: request eligible automated personal data in a structured, commonly used, machine-readable format.
- Withdraw consent: withdraw consent at any time without affecting processing performed before withdrawal.
You ordinarily will not pay a fee to exercise these rights. We may charge a reasonable fee or decline requests that are clearly unfounded, repetitive, or excessive. We may request information needed to confirm your identity and clarify or expedite a request.
Additional Choices and Response Time
In addition to the rights listed above, we provide an opt-out or opt-in choice before sharing data with third parties other than our agents, or before using it for a purpose other than the purpose for which it was collected or subsequently authorized. To limit use and disclosure, contact privacy@sotero.ai. EU and Swiss individuals may request access, correction, amendment, or deletion of inaccurate information. We respond within a reasonable timeframe.
Acceptance of This Policy
This Policy provides notice of our data practices; it does not treat use of the Sites as consent where applicable law requires a separate affirmative choice. We request consent separately for optional product outreach and other activities that require it. We may change this Policy and will post material changes on our Sites with an updated effective date or other notice where required.
Children’s Privacy
We do not allow children under 13 to register and do not knowingly collect or solicit their personal information. No child under 13 should provide personal information through a Site. If we learn that we collected such information, we will terminate the account and communications and delete the information. Contact privacy@sotero.ai if you believe we have information about a child under 13. Minors aged 13 and over should use the Sites only with appropriate adult supervision.
California Notices
This section addresses California’s direct-marketing disclosure law specifically; the CCPA-specific rights below are separate and additional. California residents who provided personal data may request information identifying third parties to whom personal data was disclosed during the preceding year for direct-marketing purposes and the categories disclosed. Requests may be sent once per calendar year to privacy@sotero.ai.
Additional Information for California Residents
This section applies when Sotero acts as a “business” under the California Consumer Privacy Act (CCPA). CCPA rights are not absolute, and requests may be declined where permitted by law. Depending on applicable law, California residents may request:
- Categories of personal information collected and their sources.
- Business or commercial purposes for collection, use, sharing, or sale.
- Categories of third parties with whom information is shared.
- Information disclosed for a business purpose or sold and the recipient categories.
- Access to personal information collected about them.
- Deletion of eligible personal information.
- Opt-out of sales or sharing where those terms apply under California law.
- Freedom from unlawful discrimination for exercising privacy rights.
Exercise California rights by contacting privacy@sotero.ai. We may need to confirm residency and identity. An authorized agent may submit a request when sufficient authorization and identification are provided. We cannot process a request without enough detail to understand and respond to it.
Contact Information
Questions or comments about this Policy may be sent to privacy@sotero.ai or mailed to Sotero, Inc., 1500 District Ave, Burlington, Massachusetts 01803, USA.