Privacy and Cookie Policy

Last updated: 29 April 2026

This Privacy and Cookie Policy ("Policy") describes how Bajara S.r.l. ("SongyBird", "we", "us" or "our") collects, uses, discloses and protects your personal data when you use the SongyBird platform, websites, mobile applications and related services (collectively, the "Service"). It is issued in accordance with Regulation (EU) 2016/679 ("GDPR"), the Italian Personal Data Protection Code (Legislative Decree no. 196/2003 as amended by Legislative Decree no. 101/2018) and Directive 2002/58/EC ("ePrivacy Directive").

1. Data Controller

The Data Controller is:
Bajara S.r.l.
Registered office: Via Sandro Pertini 25 - 42017, Novellara (RE), Italia
VAT / Tax code: IT03013870351
Email: [email protected]
Website: songybird.com

For any privacy-related request, including the exercise of your rights, you may contact us at [email protected].

2. Definitions

  • Personal Data: any information relating to an identified or identifiable natural person.
  • Processing: any operation performed on Personal Data (collection, storage, use, disclosure, deletion, etc.).
  • Data Subject: the natural person to whom the Personal Data relate (i.e., you).
  • Controller: the entity that determines the purposes and means of the Processing.
  • Processor: the entity that processes Personal Data on behalf of the Controller.
  • Chirp: an asynchronous video message recorded and shared through the Service.
  • Nest: a real-time group video chat room provided through the Service.

3. Categories of Personal Data We Collect

We collect the following categories of Personal Data:

3.1 Data you provide directly

  • Account data: name, email address, username (auto-generated), password (stored only as a salted hash), email verification status.
  • Billing data (Pro / paid plans only): first name, last name, telephone number, billing address (street, city, state/province, postal code, country), Italian tax code (Codice Fiscale), VAT number (Partita IVA), PEC address, SDI recipient code.
  • Payment data: payment instrument details are collected and processed directly by our payment provider Stripe; we receive and store only a Stripe customer identifier, subscription identifier, plan, billing period, subscription status and invoice history.
  • User-generated content: Chirp video recordings (webcam stream, optional screen-share stream), audio, comments, text messages exchanged in Nest rooms and any files you choose to attach.
  • Communications: the content of any messages or support requests you send to us.

3.2 Data collected automatically

  • Technical data: IP address (recorded against Chirp views for abuse-prevention and analytics), browser type and version, operating system, device identifiers, language preference, time zone.
  • Usage data: pages visited, features used, Chirp views and timestamps, session duration, error logs.
  • Authentication tokens: Laravel Sanctum personal access tokens stored client-side in your browser's localStorage; short-lived JWT-style tokens (15 minutes) for WebRTC socket connections.
  • Cookies and similar technologies: see Section 12 below.

3.3 Data we do not collect

  • We do not knowingly collect special categories of data (Art. 9 GDPR) such as data revealing racial/ethnic origin, political opinions, religious beliefs, health, sexual orientation, biometric or genetic data. Please do not transmit such data through Chirps or Nests.
  • We do not currently use third-party analytics, advertising or tracking services (e.g., Google Analytics, Meta Pixel, Hotjar).

4. Purposes and Legal Bases of Processing

PurposeCategories of dataLegal basis (Art. 6 GDPR)
Creating and managing your account, providing the Service (Chirps, Nests, profile) Account data, user-generated content, technical data (b) Performance of the contract
Processing payments and managing subscriptions Billing data, payment data (b) Performance of the contract; (c) legal obligations (accounting, tax)
Issuing invoices and complying with Italian/EU tax law Billing data, tax identifiers (c) Legal obligation
Sending transactional emails (verification, password reset, billing notifications) Account data, billing data (b) Performance of the contract
Security, fraud prevention, abuse moderation, blocking disposable email addresses Account data, technical data, IP address (f) Legitimate interest in maintaining a safe Service
Diagnosing technical issues and improving the Service Technical data, usage data, error logs (f) Legitimate interest in operating and improving the Service
Responding to your requests and exercise of rights Account data, communications (c) Legal obligation; (f) legitimate interest
Marketing communications (where activated) Email address, name (a) Consent — withdrawable at any time
Defence of legal claims All categories as needed (f) Legitimate interest

5. Sources of Data

We collect data directly from you when you register, complete your profile, subscribe, record content or contact us. Some technical data is collected automatically by your browser or device when you interact with the Service. We do not purchase Personal Data from third-party data brokers.

6. Recipients and Categories of Recipients

Your Personal Data may be shared with the following categories of recipients, acting as Data Processors or autonomous Controllers:

  • Cloud hosting and storage providers: servers hosting the Service and storing user-generated content (videos, files).
  • Stripe Payments Europe, Ltd. (Ireland) — payment processing and subscription management. Privacy policy: stripe.com/privacy.
  • Transactional email providers (e.g., Amazon SES, Postmark, Resend or SMTP — depending on configuration).
  • Real-time media providers: our own MediaSoup SFU and Socket.IO infrastructure for WebRTC streaming; no third-party media providers receive your video streams.
  • Professional advisors: accountants, auditors, legal counsel, bound by confidentiality.
  • Public authorities: where disclosure is required by law (e.g., court order, tax authority).
  • Acquirers: in case of merger, acquisition or sale of assets, with prior notice to you.

We do not sell or rent your Personal Data to third parties for advertising purposes.

7. International Data Transfers

Personal Data is primarily processed within the European Economic Area (EEA). Some of our processors (such as Stripe) may transfer data outside the EEA, including to the United States. In such cases, we rely on the safeguards required by Articles 44–49 GDPR, including:

  • European Commission adequacy decisions (e.g., EU–US Data Privacy Framework, where applicable);
  • Standard Contractual Clauses ("SCCs") approved by the European Commission;
  • Supplementary technical, organisational and contractual measures where required.

You may request a copy of the relevant safeguards at [email protected].

8. Data Retention

Data categoryRetention period
Account dataFor the entire duration of the account, plus up to 12 months after deletion for security and legal purposes.
User-generated content (Chirps, comments, Nest messages, files)Until you delete it or your account is closed; then permanently deleted within 30 days, save for backups which are rotated within 90 days.
Billing and invoice data10 years after the relevant tax year, as required by Italian and EU accounting/tax law.
Payment data (Stripe identifiers)For the duration of the contractual relationship, plus 10 years for accounting purposes.
Server and security logs (incl. IP addresses on Chirp views)Up to 12 months, unless required longer for security investigations.
Email communications and support ticketsUp to 24 months from the last interaction.
Marketing data (if consent given)Until consent is withdrawn, and in any case no longer than 24 months from the last interaction.

9. Security Measures

We adopt appropriate technical and organisational measures to protect your Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in accordance with Article 32 GDPR. These include, among others:

  • Passwords stored exclusively as salted bcrypt hashes — they are never visible to us in clear text;
  • HTTPS/TLS encryption for all data in transit;
  • Encrypted, short-lived tokens for WebRTC media connections;
  • Role-based access control and the principle of least privilege for staff;
  • Regular software updates, vulnerability patching and dependency monitoring;
  • Logical separation of production and development environments;
  • Regular backups with limited retention.

No system is 100% secure; in case of a personal data breach affecting your rights and freedoms, we will notify you and the supervisory authority as required by Articles 33–34 GDPR.

10. Your Rights

Under Articles 15 to 22 GDPR, you have the right to:

  • Access your Personal Data and obtain a copy (Art. 15);
  • Rectify inaccurate or incomplete data (Art. 16);
  • Erase your data ("right to be forgotten") (Art. 17);
  • Restrict the Processing in certain circumstances (Art. 18);
  • Data portability — receive your data in a structured, machine-readable format and transmit it to another controller (Art. 20);
  • Object to Processing based on legitimate interest, including profiling (Art. 21);
  • Withdraw consent at any time, without affecting the lawfulness of Processing carried out before withdrawal (Art. 7.3);
  • Not be subject to solely automated decisions producing legal or similarly significant effects (Art. 22).

To exercise your rights, write to [email protected]. We will reply within 30 days (extendable by 60 additional days where the request is complex). The exercise of your rights is free of charge unless requests are manifestly unfounded or excessive.

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali): www.garanteprivacy.it, or with the supervisory authority of your EU country of residence.

11. Account Deletion

You may delete your account at any time from your account settings or by writing to [email protected]. Deletion will remove your profile and user-generated content from the active Service within 30 days. Some data may be retained longer where required by law (see Section 8 — Retention).

12. Cookies and Similar Technologies

The Service uses cookies and similar technologies (localStorage, sessionStorage) for the purposes described below. Cookie consent is managed in accordance with the ePrivacy Directive and the guidelines of the Italian Garante (10 June 2021).

12.1 Cookies we use

Name / typePurposeDurationCategory
Session cookie (Laravel)Maintains your authenticated sessionSession / 120 minStrictly necessary
XSRF-TOKENCSRF protectionSessionStrictly necessary
localeStores your language preference30 daysFunctional / strictly necessary
Sanctum auth token (localStorage)Authenticates API requestsUntil logoutStrictly necessary
Socket token (localStorage / memory)Authorises WebRTC socket connections15 minutesStrictly necessary
Cookie-consent preferenceStores your cookie choices12 monthsStrictly necessary

12.2 Third-party cookies

The Service does not currently set marketing, profiling or third-party analytics cookies. Stripe may set strictly-necessary cookies on the checkout and customer portal pages it hosts; please refer to stripe.com/cookies-policy.

12.3 Managing cookies

Strictly-necessary cookies do not require consent. For any non-essential cookie, you may grant or withdraw your consent at any time through the cookie banner or your browser settings. Disabling strictly-necessary cookies may impair the functionality of the Service.

13. Children's Data

The Service is not directed to children. In Italy, the minimum age to consent to information-society services is 14 years (Art. 2-quinquies of the Italian Privacy Code). Outside Italy, the minimum age may range from 13 to 16 depending on the EU member state. By creating an account you confirm that you meet the minimum age in your country. If you become aware that a minor has provided us with Personal Data without valid parental consent, please contact [email protected] and we will delete the data without undue delay.

14. Automated Decision-Making and Profiling

We do not carry out solely automated decisions producing legal or similarly significant effects on you (Art. 22 GDPR). Limited automated checks are performed for security purposes (e.g., rejecting disposable email addresses, abuse-rate limiting); these do not constitute solely automated decision-making in the sense of Art. 22.

15. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices or in applicable law. The "Last updated" date at the top of this page indicates the date of the latest revision. Material changes will be notified through the Service or by email at least 15 days before they take effect.

16. Contact

For any question relating to this Policy or to the Processing of your Personal Data, write to:
Bajara S.r.l.
Via Sandro Pertini 25 - 42017, Novellara (RE), Italia
Email (privacy): [email protected]
Email (support): [email protected]