Skip to content

Privacy Policy

Last updated: 2026-06-17

This Privacy Policy describes how Holophonix Remote Control (the "App") and its documentation website at hrc.tonlab.fr (the "Website") collect, use and protect personal data when you install and use the App, or when you contact us through the Website.

It is written to comply with the EU General Data Protection Regulation (GDPR) and to satisfy a reasonable level of transparency for users located in the United States (CCPA-aligned good practices). The App is intended for professional audio operators ("front-of-house engineers", "stage managers"), distributed worldwide as a public beta.

1. Data controller

Holophonix Remote Control is published by TonLab, the trading name of Achille Decoussé (auto-entrepreneur), registered in France under SIRET 10251863600018.

  • Contact: hrc@tonlab.fr
  • Jurisdiction: France

You can use this email for any question related to this policy or to exercise the rights described in section 7.

2. Data we collect

The App is designed to keep all show-critical data on your device. We only send data outside your device if you have explicitly enabled diagnostics through Settings → Diagnostics → Help improve Holophonix Remote. The opt-in is OFF by default.

2.1 Local-only data (never sent to us)

The following data stays on your machine, in the App's project files (.hrc), automation files and local preferences. We never receive it.

  • Project names, cue names, automation names, channel names and any other free-text label you type
  • Cue snapshots (positions, mixer state, MIDI mappings, custom OSC actions)
  • Network configuration (Holophonix IP, backup IP, ports, WebSocket address)
  • Background images, channel customization, layout configuration
  • Connection mode, MIDI device list, Stream Deck profiles

2.2 Crash reports (Sentry, opt-in)

When you enable diagnostics, the App uses Sentry to send crash reports so we can detect and fix bugs. Each crash event contains:

  • Device type and operating system version (e.g. macOS 15.5, iPad)
  • App version and build number (e.g. v0.7.0-beta)
  • Crash stack trace, with absolute file paths anonymized (/Users/<name>/... becomes /Users/<redacted>/...)
  • A short trail of the last application events ("breadcrumbs"), limited to a fixed list maintained by us: cue recall, cue go, automation play/stop, project switch, connection mode change, connection lost, failover switch, MIDI device change, OSC error, What's New fetch failure
  • Bug report text and email if you voluntarily submit one through Settings → Diagnostics → Report a bug

Before any event leaves your device, an automatic filter strips:

  • User home paths (/Users/<name> and equivalents on Windows / Linux)
  • Local IP addresses (RFC 1918 / CGNAT / APIPA ranges and .local / .lan hostnames)
  • Project file names (*.hrc becomes <project>.hrc)

We never attach free-text identifiers (cue names, project names) to breadcrumb data.

Note: the bug report free-text field is the only mechanism through which user-typed content can leave your device. If you include identifying information, it will be transmitted as-is and retained for the standard 90 days. You are responsible for the content of bug reports you choose to submit.

2.3 Anonymous usage events (PostHog, opt-in)

When you enable diagnostics, the App also uses PostHog to count anonymous usage events. This helps us understand which features are used and prioritize roadmap work. Events sent are limited to the following list, with the following properties:

Event Properties
app.boot boot time in ms
screen.viewed screen name (e.g. cues, mixer)
cue.recalled cue index, total cues, trigger flag
cue.go_pressed cue index, total cues
cue.created total cues after creation
automation.played automation type (xy, mixer, midi, osc)
automation.created automation type (xy, mixer, midi, osc)
project.switched (no name attached)
connection.mode_set mode (standalone, server, client)
midi.device_connected total device count

Every event is also tagged with the following session-wide properties: app version, operating system, current connection mode, Holophonix firmware version (if known). The same privacy filter as Sentry strips paths, IPs, hostnames and project file names before sending.

We never send user-typed strings (cue names, project names, channel names) as properties.

2.4 What we never collect

  • Names, postal addresses, phone numbers
  • Audio content, microphone signals, network packets sent to or from the Holophonix processor
  • IP addresses of users (Sentry / PostHog see the request source IP at the network level but we do not store or look at it; both providers are configured EU-cloud)
  • Cookies, web beacons, fingerprinting or third-party web analytics — neither the App nor the Website use them (the Website's only data collection is the contact form you choose to submit, see section 2.6)

2.5 Show mode

When the App is in Show mode (live performance), all PostHog event capture and property updates are suppressed in real time. Crash reporting via Sentry remains active so a crash during a show can still be diagnosed.

2.6 Contact form (Website)

The documentation Website provides a contact form so you can reach us (support, bug reports, general enquiries). When you submit it, we collect:

  • the name you enter,
  • your email address,
  • the message you write,
  • standard technical metadata attached to the request by the web server (timestamp, source IP address, user-agent), kept only in short-lived server access logs.

This data is transmitted to and handled on TonLab's own self-hosted mail server (hrc.tonlab.fr). It is not processed by any third-party form or email provider, and is used solely to read and reply to your message.

We rely on your explicit consent (GDPR Article 6 (1) (a)) for all opt-in diagnostics. The consent is collected through the first-launch Help improve Holophonix Remote dialog and is revocable at any moment from Settings → Diagnostics.

For the Website contact form (section 2.6), we process the name, email and message you submit on the basis of taking steps at your request and our legitimate interest in answering you (GDPR Article 6 (1) (b) and (f)).

Local-only data (section 2.1) never leaves your device, so no legal basis is required.

4. Retention

Data Retention
Crash reports (Sentry) 90 days (Sentry tenant default)
Anonymous usage events (PostHog) 1 year (PostHog tenant default)
Contact-form messages (name, email, message) Kept while we handle your request, then deleted — at most 12 months.
Web-server access logs (timestamp, IP, user-agent) Rotated within 30 days.
Local files on your device (.hrc, automations, preferences) Until you delete them. The App never deletes them on its own.

After the retention window, Sentry and PostHog automatically purge the events from their servers.

5. Recipients

  • Sentry GmbH (Functional Software Ireland Ltd., EU cloud) — crash reports
  • PostHog Inc. (EU cloud region) — anonymous usage events
  • App stores (Apple App Store, Google Play Store, Microsoft Store) — at install / update time, the stores see the standard install metadata they collect from every app. Their handling is governed by their own privacy policies.

Contact-form data (section 2.6) is handled only on our own self-hosted server; it is not sent to any third-party recipient. We never sell or share data with advertising networks.

6. Transfers outside the EU

None. Sentry and PostHog are configured to use their EU cloud regions. No data is sent to the United States or any other non-EU country through our pipelines.

If you install the App from a non-EU app store, the store itself may process install metadata in its own jurisdiction — refer to the store's privacy policy.

7. Your GDPR rights

You can exercise the following rights at any time by sending an email to hrc@tonlab.fr:

  • Access — request a copy of the data we hold linked to your installation (in practice: Sentry / PostHog events tagged with the installation id, which is anonymous)
  • Rectification — request that inaccurate data be corrected
  • Erasure ("right to be forgotten") — request deletion. Because events are anonymous, we will erase by purging events that match the install id you provide (visible in Settings → Diagnostics → Diagnostics ID)
  • Restriction — request that processing be paused
  • Objection — withdraw consent. You can also disable diagnostics with one tap in Settings → Diagnostics; the toggle takes effect at the next app start
  • Portability — request an export in a machine-readable format

We will reply within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the French data protection authority, the CNIL.

8. Cookies and web tracking

Neither the App nor the documentation Website use cookies, web beacons, fingerprinting or third-party web analytics. The Website is served from a self-hosted server which, like any web server, keeps short-lived access logs (timestamp, source IP, user-agent) for security and troubleshooting — rotated within 30 days and never used to profile visitors. The only personal data the Website collects is what you choose to submit through the contact form (section 2.6).

9. Minors

The App is intended for adult audio professionals and is not specifically directed at users under 16. We do not knowingly collect data from minors. If you believe a minor has used the App and produced diagnostics events, contact us at hrc@tonlab.fr and we will purge them.

10. Changes to this policy

The date at the top of this document reflects the last revision. Significant changes are shipped together with new App releases and highlighted in the in-app "What's New" popup.

Continued use of the App after a revision constitutes acceptance of the new policy.