Skip to content
Sondero
All Agents About us Blog
Book a Strategy Call Book a Strategy Call
Explore all our EnginesAI Engines to enhance your entire GTM
Outbound EngineFor Outreach & Sequences Inbound EngineFor Lead Capture & Scoring Deal EngineFor Pipeline & Deal flow Demand EngineFor Content & Brand Voice CS EngineFor Renewals & Expansion RevOps EngineFor Reporting & Forecasts
Explore all our Engines Outbound Engine Inbound Engine Deal Engine Demand Engine CS Engine RevOps Engine
All Agents About us Blog
Book a Strategy Call Book a Strategy Call
EN · DE
Legal
DE EN

Privacy Policy

As of July 2026 · Cediro Consulting GmbH, trading as Sondero

Contents

01Controller02Overview of processing03Legal bases04Hosting and content delivery05Transfers to third countries06Processing on our website07Cookies and consent management08Contacting us09Processors10Retention period11Your rights12Right to lodge a complaint13SSL/TLS encryption14Changes15Language of this policy

01Controller

Cediro Consulting GmbH
Heinrichs bei Weitra 18/1/3, 3962 Unserfrau-Altweitra, Austria
Email: [email protected]
Phone: +43 664 1345512

Cediro Consulting GmbH operates the website sondero.ai under the brand name „Sondero“.

02Overview of processing

We process personal data only to the extent necessary to provide a functioning website along with our content and services.

Processing takes place only with your consent or where a legal basis permits it.

03Legal bases

  • Art. 6(1)(a) GDPR (consent)
  • Art. 6(1)(b) GDPR (contract or pre-contractual measures)
  • Art. 6(1)(f) GDPR (legitimate interest)

04Hosting and content delivery

Hosting via Cloudflare Pages. Our website is hosted by Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA) on its Cloudflare Pages platform and delivered through Cloudflare’s content delivery network. In doing so, Cloudflare processes the connection data technically required for delivery and mitigates attacks against the website. The legal basis is Art. 6(1)(f) GDPR (secure and efficient provision of our online offering). On transfers to the USA, see section 05.

When you access our website, the following data is processed automatically:

  • Browser type and version
  • Operating system
  • Referrer URL
  • Hostname of the accessing device
  • Time of the request
  • IP address

Server log files are generally deleted after 7–14 days unless a security-related analysis makes longer retention necessary.

05Transfers to third countries

Some of the providers listed below are based in the USA. Where a provider is certified under the EU-US Data Privacy Framework, the transfer takes place on the basis of an adequacy decision pursuant to Art. 45 GDPR. Otherwise the transfer takes place on the basis of standard contractual clauses pursuant to Art. 46(2)(c) GDPR.

This concerns in particular Cloudflare (hosting and CDN), Cal.com and — when the booking calendar is loaded — Google (appointment booking) and Loops (newsletter delivery). Cal.com bases the transfer on standard contractual clauses pursuant to Art. 46(2)(c) GDPR. Despite these safeguards, access to the transferred data by US authorities cannot be entirely ruled out.

06Processing on our website

Forms and enquiries (HubSpot)

We use HubSpot (HubSpot Ireland Ltd.) for our forms and enquiries. We process first and last name, business email address, and optionally company and phone number. The basis is Art. 6(1)(b) GDPR (pre-contractual measures) and, where you opt in to the newsletter, Art. 6(1)(a) GDPR.

Appointment booking (Cal.com)

On the Strategy Call page we embed the booking calendar of Cal.com, Inc. (USA) as an iframe. The calendar does not load automatically: at first you see only a placeholder, and the connection — which transfers your IP address to Cal.com, to Google (which serves the host’s profile picture) and to Sentry (Cal.com’s error diagnostics, USA) — is established only when you actively load it. Cal.com also stores display and session settings in your browser’s local storage (see section 07). When you book, Cal.com processes your name, email address, time zone and the answers you provide. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures). On transfers to the USA, see section 05.

Newsletter (double opt-in, Loops)

Our newsletter is sent via Loops, Inc. Sign-up uses the double opt-in procedure. We store the time of sign-up and the IP address. Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw at any time using the unsubscribe link.

Company logo in the booking confirmation (Brandfetch, icon.horse)

After you book a Strategy Call, we show your company’s logo. We look it up by the domain of your email address through Brandfetch; if that fails, through icon.horse as a fallback. Your IP address is transmitted to the respective provider in the process. Neither is a processor — both are independent recipients. Legal basis: Art. 6(1)(f) GDPR (recognising your company in the confirmation). The logos in our articles are served from our own server and transmit nothing to third parties. If you would rather we did not look it up, a short note to [email protected] is enough.

Fonts

Every font used on this website is served from our own server. There is no connection to Google Fonts or any other external font provider, and no data is transmitted to third parties for this purpose.

07Cookies and consent management

This website itself sets no cookies for analytics, marketing or tracking purposes and embeds no web analytics. Technically necessary cookies are set on the basis of § 165(3) Austrian Telecommunications Act (TKG 2021), as they are required to deliver a service you have expressly requested; this includes storing your consent choice.

We do not load consent-requiring external services unprompted. A self-hosted consent tool lets you control which categories you allow; nothing requiring consent is loaded without it. The booking calendar on the Strategy Call page uses a two-click solution and loads only after you actively agree (see section 06). You can change or withdraw your consent at any time via “Cookie settings” in the footer.

The specific cookies and local storage used are:

  • cc_cookie — stores your consent choice. First-party, 6-month lifetime.
  • cc_calcom — remembers that you loaded the Cal.com calendar. First-party.
  • __cf_bm, __Secure-next-auth.csrf-token, __Secure-next-auth.callback-url — set by Cal.com once you load the calendar (bot protection, session, CSRF protection).
  • loops-form-timestamp — prevents duplicate submissions of the newsletter form. First-party, local storage.
  • nextauth.message, timeOption.is24hClock — session and display settings stored in local storage by Cal.com once you load the calendar.

08Contacting us

If you contact us, we process:

  • Name
  • Email address
  • Content of the enquiry

Legal basis: Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR. The data is deleted as soon as it is no longer required.

09Processors

We use the following service providers. Data processing agreements pursuant to Art. 28 GDPR are in place with all of them:

  • Cloudflare, Inc. (USA) — website hosting and content delivery
  • HubSpot Ireland Ltd. (Ireland) — CRM and forms
  • Cal.com, Inc. (USA) — appointment booking on the Strategy Call page
  • Loops, Inc. (USA) — delivery of our newsletter and transactional emails

The following receive data as independent controllers rather than as processors: Brandfetch and icon.horse (company logo in the booking confirmation, see section 06) and Sentry (error diagnostics inside the Cal.com calendar). No Art. 28 GDPR agreement exists with them, nor would one apply to this processing.

10Retention period

Personal data is stored only for as long as it is required for the respective processing purpose. Statutory retention periods (for example under the Austrian Federal Fiscal Code, BAO) can be up to 7 years.

11Your rights

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR)
  • Withdrawal of consent (Art. 7(3) GDPR)

Withdrawal does not affect the lawfulness of processing carried out up to that point.

12Right to lodge a complaint

Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
Barichgasse 40-42, 1030 Vienna, Austria
Email: [email protected]
Website: dsb.gv.at

13SSL/TLS encryption

This website uses SSL/TLS encryption.

14Changes

We reserve the right to amend this privacy policy.

15Language of this policy

This is a translation provided for convenience. The German version is the legally binding one; in case of discrepancies, the German text prevails.

One free 45-min strategy session

Your stack deserves AI

Your people keep working exactly as they do. The AI just does the heavy lifting. We show you how in an hour.

Book a Strategy Call Book a Strategy Call Get your AI Readiness Report Get your AI Readiness Report
Sondero

AI that runs in the background so your best people stay in the foreground.

The 60-Second AI Leverage

One high-leverage AI idea in your inbox each week.

You’re in — check your inbox to confirm.

Something went wrong — please try again.

[email protected] n8n Partner

PAGES

HomeSkillsAll EnginesAll AgentsManifesto

RESOURCES

BlogGlossaryBuild vs buy AIAI Readiness ReportStyleguide

ENGINES

DemandInboundOutboundDealCustomer SuccessRevOps

INFORMATION

ContactPrivacyTerms
GDPR Compliant Made in Germany © 2026 Sondero Imprint
Strategy Call

See where AI pays off first.

You leave with a one-page map of where agents take over the manual work, built on the stack you already run.

EU-hosted GDPR-ready Live in ~2 weeks
Book a strategy call Book a strategy call