Skip to main content

Sorola privacy notice

Version and effective date: 2026-09, 2 September 2026

This controller-level notice covers Sorola.fi, sorola.fi, Soro.la, Webtools.sorola.fi and related Sorola services. Tool-specific notices supplement it with details about content handled by each tool.

1. Controller

Markus Pentti Matias Sorola, Finnish private trader operating the Soroltech service
Business ID: 3363620-8
Ruuhikoskenkatu 15 B 7, FI-24240 Salo, Finland
Telephone: +358 45 865 3436
Privacy and data-subject requests: contact.make@sorola.fi

No separate data protection officer has been appointed. The controller handles requests through the address above.

2. Data, purposes and legal bases

Sorola data categories, purposes and legal bases
CategoryData and purposeLegal basis and necessity
Accounts and securityUsername, salted password hash, role, invitation, session identifier/times and up to 240 characters of user-agent data; encrypted administrator TOTP secret, recovery-code hashes and 2FA security events.GDPR 6(1)(b), providing the requested account/login service; 6(1)(f), legitimate interest in preventing abuse. Credentials are necessary for an account; 2FA is optional.
Social comparisonFollower/following names from an export supplied by the user, platform and an encrypted follower snapshot. The export may contain data about other people.6(1)(b), performing the comparison/history requested by the user. The export is needed for the feature; history can be erased.
Public content and sharesShort-link destination/path/click count; paste content; guestbook name/message/reply; file or ciphertext, name, MIME type, size, expiry, download limit/count and SHA-256 key verifier. Sorola does not receive the raw encryption key.6(1)(b), providing the requested publication/share; 6(1)(f), service integrity and abuse prevention. The submitted content is necessary for the selected feature.
Feedback, abuse notices and reviewsFeedback type, subject, message, optional name/email and technical details; reported item, reason, details, reporter name/email, good-faith declaration, one-way receipt hash, status, public decision reason and private administrator note. A review or counter-notice contains the party's role, name, email, statement, declaration, status and decision reason.6(1)(f), improving/protecting the service and handling notices and reviews; 6(1)(c), applicable legal notice/authority duties. Feedback contact is optional. Name, email, statement and declaration are required for a content notice or review so it can be assessed and the decision communicated.
Requests and logsCloudflare and the server may process IP address, time, method, normalized path, status, referrer and browser/device information. Application logs intentionally omit queries, bodies, cookies, credentials and email. The Webtools IP feature returns the requester's IP/header values to that requester.6(1)(f), legitimate interest in delivery, security, diagnosis and monitoring. Network metadata is necessary to transmit a request.
Local browser toolsPassword generator, Base64, JSON, JWT, UUID and ExportView inputs stay in the browser and are not sent to Sorola. Ordinary page/network metadata is still processed under this notice.No Sorola server processing of the tool input; local processing follows the user's request.
Optional analyticsAfter acceptance, GTM-configured Plausible measurement may receive URL, title, referrer, browser/device and form/link/download event data. RUM reports only product, coarse page class, rounded Core Web Vitals and a capped error count.6(1)(a), consent. It is optional, refusal does not limit service, and it can be withdrawn using “Privacy settings”.

The QR tool sends QR content to api.qrserver.com to render an image. DNS/domain tools send the entered domain to public DNS resolvers. Do not enter unnecessary personal data in those tools.

3. Retention

Sorola retention periods and deletion criteria
DataRetention
Account, 2FA and social snapshotsFor the account lifetime, until deleted by the user or administrator. Account deletion cascades to sessions, 2FA and snapshots. Snapshots/history can be erased earlier.
Sessions/setupSessions default to 24 hours. Expired sessions and sessions revoked more than seven days earlier are purged hourly. Pending TOTP setup expires after ten minutes.
File sharesUser-selected 1–7 days or earlier download-limit completion, followed by hourly deletion. Incomplete encrypted uploads expire after two hours. Separately stored administrator files remain until deleted.
Links, pastes and guestbookUntil administrator deletion or the need ends. A disabled item may be retained during investigation/legal claims but is no longer publicly served.
Reports and reviewsOpen feedback remains while handled; closed feedback/bug reports are deleted after seven days. New/reviewing abuse notices remain through decision; actioned/rejected notices and their reviews/counter-notices are deleted 90 days after the notice's latest decision. De-identified abuse events are deleted after 30 days.
Logs and metricsApplication metrics use a rolling window up to 60 minutes. Container logs rotate by size (default: at most 30 compressed 10 MiB files per service), so calendar duration depends on traffic. A narrowly scoped legal/security hold may last longer.
AnalyticsThe browser choice lasts up to one year. Withdrawal removes accessible analytics cookies and blocks new requests. Provider-side retention follows the approved analytics/provider configuration; details and applicable safeguards are available from the controller.

4. Recipients and international transfers

Data is not sold. A transfer outside the EU/EEA uses an applicable European Commission adequacy decision (including the EU–US Data Privacy Framework where valid and applicable) or the Commission's Standard Contractual Clauses plus necessary supplementary measures. You may request a copy of the applicable safeguard.

5. Your rights

Depending on the processing and legal basis, you may request access, correction, erasure, restriction or portability, and object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing already lawfully performed.

Send a specific request to contact.make@sorola.fi. Identity is verified only as needed. A legal restriction, another person's rights or a legal claim may limit a request; any refusal will be explained.

You may complain to the Office of the Data Protection Ombudsman, PO Box 800, FI-00531 Helsinki, tietosuoja@om.fi, +358 29 566 6700.

6. Sources, automated decisions and changes

Data normally comes from you and your device's service requests. A social-media export or abuse notice may contain data about other people supplied by a user. Technical link data arises from service use.

Sorola performs no solely automated GDPR Article 22 decision or profiling with legal or similarly significant effects. Download limits, expiry, rate limits and bot checks are technical safeguards; administrators make content decisions.

Material changes receive a new policy version and reasonable notice before new processing starts.

7. Tool-specific layers

Optional site analytics

Sorola does not load Google Tag Manager, its configured Plausible tags or performance measurement before acceptance. After acceptance, processing follows the analytics row above. Refusal does not limit service, and the choice can be changed at any time using “Privacy settings”.

« Back to home page