GDPR Compliance

GDPR Compliance

How All Note AI complies with the EU General Data Protection Regulation to protect your personal data.

Last updated: July 23, 2026

1

Our Commitment to GDPR

All Note AI is fully committed to complying with the General Data Protection Regulation (GDPR). As a meeting transcription and AI note-taking platform, we understand the sensitivity of the data we process and take our obligations seriously.

  • Data Controller: All Note AI (operated by Dictalogic) acts as the data controller for account and billing data, and as a data processor for meeting content processed on behalf of our customers
  • Legal Basis: We process personal data based on contractual necessity (to provide our services), legitimate interest (to improve our platform), and consent (for marketing communications)
  • Transparency: We are transparent about what data we collect, why we collect it, how we use it, and how long we retain it
  • Accountability: We maintain records of our data processing activities and can demonstrate compliance upon request
2

Data We Process

In providing our meeting transcription and AI note-taking services, we process the following categories of personal data:

  • Account Information: Name, email address, organization name, and billing details provided during registration
  • Meeting Content: Audio recordings, transcriptions, AI-generated summaries, and screenshots captured during meetings you choose to record
  • Calendar Data: Meeting titles, times, and participant information from connected calendars (Google, Microsoft, Zoom) used for auto-join scheduling
  • Usage Data: Information about how you interact with our platform, including feature usage and session data
  • Technical Data: IP addresses, browser type, device information, and cookies necessary for platform functionality

We only process data that is necessary for the purposes described. We do not collect or process special category data (e.g., health, biometric, or political data) unless incidentally present in meeting recordings.

3

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights which we fully support:

  • Right of Access (Article 15): You can request a copy of all personal data we hold about you. We will respond within 30 days
  • Right to Rectification (Article 16): You can request correction of any inaccurate or incomplete personal data
  • Right to Erasure (Article 17): You can request deletion of your personal data. You can delete recordings, transcriptions, and summaries directly from your dashboard, or request full account deletion
  • Right to Restrict Processing (Article 18): You can request that we limit how we process your data in certain circumstances
  • Right to Data Portability (Article 20): You can request your data in a structured, machine-readable format. We support export of transcriptions and meeting data
  • Right to Object (Article 21): You can object to processing based on legitimate interest, including direct marketing
  • Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time without affecting prior processing

To exercise any of these rights, contact us at privacy@allnote.ai. We will respond within 30 days as required by GDPR.

4

Data Security Measures

We implement robust technical and organizational measures to protect your personal data as required by Article 32 of the GDPR:

  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher
  • Encryption at Rest: All stored data — including recordings, transcriptions, and personal information — is encrypted using AES-256
  • Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA), and the principle of least privilege for all internal systems
  • Network Security: Virtual private clouds, firewalls, network segmentation, and DDoS protection
  • Monitoring: 24/7 monitoring of systems and logs for anomalous activity with defined incident escalation paths
  • Regular Testing: Annual penetration testing by third-party security firms, continuous vulnerability scanning, and security audits

For full details, see our Security Policy.

5

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Meeting Content: Recordings, transcriptions, and summaries are retained for as long as your account is active. You can delete any content at any time from your dashboard
  • Account Data: Retained for the duration of your account plus a reasonable period for legal and audit purposes (typically 90 days after account deletion)
  • Audio Files: Raw audio files are automatically deleted after transcription processing is complete, unless you choose to retain them
  • Usage Logs: Technical and usage logs are retained for up to 12 months for security monitoring and product improvement
  • Account Deletion: When you delete your account, all personal data is permanently erased within 30 days, except where retention is required by law
6

International Data Transfers

All Note AI primarily processes data within the European Economic Area (EEA). Where data is transferred outside the EEA, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): We use EU-approved Standard Contractual Clauses for transfers to third-party processors outside the EEA
  • Adequacy Decisions: Where applicable, we transfer data to countries that the European Commission has recognized as providing adequate data protection
  • Transfer Impact Assessments: We conduct assessments to evaluate the data protection landscape of recipient countries
  • Sub-Processor Oversight: All sub-processors handling EU personal data are contractually bound to GDPR-equivalent protections
7

Sub-Processors

We use a limited number of sub-processors to deliver our services. Each sub-processor is carefully vetted and bound by data processing agreements:

  • Cloud Infrastructure: Microsoft Azure — hosting, storage, and compute services (EU and US regions)
  • Speech-to-Text: Deepgram, Azure Cognitive Services — real-time audio transcription (data processed in transit, not retained by providers)
  • AI Processing: OpenAI, Anthropic — AI-generated summaries and action items (data not used for model training)
  • Email Services: For transactional emails and notifications
  • Payment Processing: Stripe — payment and billing (PCI DSS compliant, Stripe acts as independent controller for payment data)

We maintain a current list of sub-processors and will notify customers of any material changes. Your continued use of the service after notification constitutes acceptance of the updated sub-processor list.

8

Data Processing Agreements

We provide Data Processing Agreements (DPAs) as required by Article 28 of the GDPR:

  • Enterprise DPAs: Available for enterprise and business customers upon request
  • Standard DPA: Our standard DPA covers the nature and purpose of processing, data categories, retention periods, and security measures
  • Sub-Processor Agreements: We maintain DPAs with all our sub-processors ensuring GDPR-equivalent protections
  • Audit Rights: Our DPA grants customers the right to audit our compliance, either directly or through a qualified third-party auditor

To request a DPA, contact us at privacy@allnote.ai.

9

Data Breach Notification

In accordance with Articles 33 and 34 of the GDPR, we have established a robust breach notification process:

  • Detection: Continuous monitoring and automated alerting to detect potential data breaches promptly
  • Internal Response: Documented incident response plan with defined roles, severity classification, and escalation paths
  • Authority Notification: We will notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, where required
  • Customer Notification: We will notify affected customers without undue delay when a breach is likely to result in a high risk to their rights and freedoms
  • Documentation: All breaches are documented with details of the nature, effects, and remedial actions taken
10

AI Processing & Meeting Data

As a meeting transcription platform, we take special care with how AI processes your meeting data:

  • Purpose Limitation: Meeting data is processed solely to provide transcription, summaries, and action items as requested by you
  • No Model Training: Your meeting data is never used to train AI models — neither ours nor any third party's
  • Isolated Processing: Meeting audio is processed in isolated, ephemeral environments with no cross-customer data access
  • Data Minimization: We only process the data necessary to deliver the requested features
  • Customer Control: You have full control to delete any recording, transcription, or AI-generated content at any time
  • No Automated Decision-Making: We do not use personal data for automated decision-making or profiling that produces legal effects
11

Privacy by Design & Default

In accordance with Article 25 of the GDPR, we embed data protection into our product from the ground up:

  • Data Minimization: We collect and process only the minimum data necessary for each feature
  • Default Privacy Settings: New accounts are configured with privacy-protective defaults — you opt in to sharing, not out
  • Tenant Isolation: Each customer's data is logically isolated in separate database schemas, ensuring no cross-tenant data access
  • Secure Deletion: When data is deleted, it is permanently removed from primary storage and backups within the documented retention period
  • Pseudonymization: Where possible, we use pseudonymization techniques to reduce the identifiability of personal data in processing
12

Supervisory Authority & Contact

If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority:

  • Your Local Authority: You may contact the data protection authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement
  • Our Contact: Before filing a complaint, we encourage you to contact us first so we can address your concern directly

Data Protection Contact:

We are committed to resolving any data protection concerns promptly and transparently. For more information about our overall privacy practices, see our Privacy Policy.

Questions about GDPR?

If you have any questions about our GDPR compliance, wish to exercise your data protection rights, or need a Data Processing Agreement, please contact our privacy team.