This Privacy Policy (the "Policy") regulates how ReVoice AI AB (the "Company," "we," "us") collects, processes, stores, and protects personal data in connection with the provision of the AI-based meeting assistant ReVoice (the "Service").
Processing of personal data is conducted in strict accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the "GDPR") and other applicable national data protection legislation.
1. Data Controller and Contact Information
ReVoice AI AB (org.nr 559505-0849) is the Data Controller for the processing operations where the Company determines the purposes and means of the processing.
- Company Name: ReVoice AI AB
- Registration number: 559505-0849
- Registered address: Katthögsvägen 66-76, 244 91 Kävlinge, Sweden
2. Regulatory Roles under GDPR
- 2.1 The Company as Data Controller The Company acts as an independent Data Controller for processing related to the Service’s infrastructure, administration, and commercial operations. This includes:
- Management of user accounts, authentication, and user profiles.
- Management of subscriptions, payment flows, and billing.
- Operational security, logging, technical troubleshooting, and proactive prevention of misuse.
- Direct communication with registered users and operation of the website (including necessary cookies).
- 2.2 The Company as Data Processor When a legal entity or organization (the "Customer") uses the Service to process meeting content (such as recording, transcription, summarization, text analysis, and document management), the Company acts as a Data Processor on the instructions of the Customer.
In these cases, the Customer is the Data Controller and is responsible for ensuring that:
- A valid legal basis exists under Article 6 of the GDPR for the processing of meeting data.
- All meeting participants have received adequate information (Articles 13 and 14 of the GDPR).
- Recording and transcription are permitted.
The Company’s obligations as a Data Processor are regulated in a separate Data Processing Agreement ("DPA").
- 2.3 Shared Meeting Sessions Between Organizations When two or more Customer organizations attend the same meeting and each uses the Service, a single meeting assistant may be used to capture the meeting only once. Each organization nonetheless receives and processes its own separate copy of the resulting transcript within its own workspace, as an independent Data Controller of that copy. Meeting data is never shared or commingled between the participating organizations: each organization’s notes, AI-generated summaries, preparation, and internal knowledge remain within its own workspace, and only the raw transcript of the meeting the participant attended is made available to their organization. The Company acts as an independent Data Processor for each organization under its respective DPA.
3. Categories of Personal Data Processed
The Company processes the following categories of personal data:
- Administrative and Account Data: Name, e-mail address, password (stored in hashed form), profile settings, language preferences, workspace affiliation, and role.
- Technical and Security Data: IP address, device information, browser type, session data, login history, error reports, and security logs.
- Meeting Metadata: Meeting titles, timestamps, meeting links, platform information (e.g., Zoom, Microsoft Teams, Google Meet), and participant lists.
- Audio, Video, and Text Data: Audio and video recordings, screen sharing data, real-time transcriptions, final transcripts, speaker labels, and edited text versions.
- AI-generated Data: Summaries, action items, decision history, conversation analysis, sentiment analysis, data from AI chat (Live Assistant/Live Coach), and structured relationship data (knowledge graphs).
- Documentation (Company Knowledge): Uploaded files, extracted text, metadata, and associated vector representations (embeddings).
- Integration Data (Third-party): Calendar events, CRM/ERP metadata, and encrypted OAuth tokens (access/refresh tokens) upon user activation.
- Financial Data: Subscription status, customer ID at payment provider, and billing documentation. Credit card details are processed directly by a PCI-DSS-certified payment provider and are not stored by the Company.
4. Purposes and Legal Basis for Processing
| Purpose | Category of Data | Legal Basis (GDPR) |
|---|
| Provision of the Service (Account and administration) | Account and administrative data. | Contract (Art. 6.1.b) |
| Meeting processing (for account holders/customers) | Meeting, integration, audio/video, and AI data. | Contract (Art. 6.1.b) |
| Meeting processing (for external participants) | Meeting, audio/video, and AI data. | Customer's responsibility (See section 2.2) |
| Financial administration | Financial data, account data. | Contract (Art. 6.1.b) |
| Security and operational stability | Technical data, security logs. | Legitimate Interest (Art. 6.1.f) |
| Product development and communication | Usage statistics, technical data, system logs. | Legitimate Interest (Art. 6.1.f) |
| Regulatory compliance | Financial data, transaction history. | Legal Obligation (Art. 6.1.c) |
| Third-party integrations | Calendar data, tokens. | Consent (Art. 6.1.a) |
Important clarification: The Company does not sell personal data to third parties, does not share meeting content with advertisers, and does not use the Customer's specific meeting content or documents to train general AI models for external purposes.
5. Transparent Information for Meeting Participants
When ReVoice joins a virtual meeting as a digital bot or assistant, participants shall be notified. The Service is configured to provide an automatic message in the chat or corresponding interface:
- Swedish: "Hej, jag är Matilda från ReVoice. Jag deltar som AI-mötesassistent för att spela in/transkribera mötet och skapa AI-stödda anteckningar. Information om personuppgiftsbehandling finns på https://re-voice.io/privacy"
- English: "Hi, I’m Matilda from ReVoice. I’m joining as an AI meeting assistant to record/transcribe this meeting and create AI-assisted notes. Privacy information is available at https://re-voice.io/privacy"
This notification constitutes an information measure and does not replace the Customer's obligation to ensure that there is a legal basis for the recording itself.
6. Profiling and Automated Decision-Making
The Service applies advanced algorithms and AI for transcription, sentiment analysis, and summarization. These processes do not constitute automated decision-making that produces legal effects or similarly significantly affects the data subject within the meaning of Article 22 of the GDPR. AI-generated content should be considered decision support and should be verified manually by the User.
7. Recipients of Personal Data and Sub-processors
To provide the Service, the Company engages suppliers and sub-processors ("Sub-processors"). These act under strict written data processing agreements and include suppliers in areas such as server operations and cloud hosting, database management, specialized API suppliers for text-to-speech, speech-to-text, LLM models, and payment intermediaries. A complete and updated list of authorized Sub-processors is provided to corporate customers upon request in accordance with the applicable DPA.
8. Third-Country Transfers (Outside EU/EEA)
In the event that personal data is transferred to, or made accessible from, a country outside the EU/EEA (e.g., the USA), the Company ensures that the transfer relies on a legal basis and that an adequate level of protection is maintained. This is achieved through:
- Adequacy decisions issued by the European Commission (Article 45 GDPR), or;
- Standard Contractual Clauses (SCCs) approved by the European Commission (Article 46 GDPR), supplemented by encryption in transit and at rest, access restrictions, and other relevant security measures.
9. Storage and Retention (Retention Period)
Personal data is stored only for the period required to fulfill the purposes for which it was collected, or as long as required by law or applicable customer agreements.
- Account Data: Stored during the contract period (active account) and deleted or anonymized upon termination of the agreement, subject to statutory limitation periods.
- Meeting Data (Recordings, transcripts, AI data): Conversation records that belong to a workspace on the free plan, and conversation records that belong to no workspace and are owned by a User on the free plan, are automatically marked for deletion thirty (30) days after creation and are permanently erased from the Company's databases and object storage within a further thirty (30) days; erasure is processed in batches and may take correspondingly longer where large volumes are involved. That automatic deletion does not apply to records held in a workspace on a paid plan, even where the User who owns them is on the free plan. On paid plans, conversation records are retained until deleted by the User, until the User's account is deleted, or until a retention period configured by the workspace administrator expires; separate retention periods for recordings, transcripts and uploaded documents apply only where a workspace administrator has configured them. Deleting a workspace purges the associated recordings and other media from object storage but does not delete the conversation records themselves, which are detached from the workspace and retained. Data deleted by the User is removed from the Service immediately and permanently erased within thirty (30) days, subject to the same batch processing. Calendar entries created from a connected calendar are not covered by an automatic retention period; see section 10.1.
- Google Integration Data and OAuth Tokens: OAuth access and refresh tokens for Google Calendar and Google Drive are stored encrypted for as long as the integration remains connected. They are deleted from the Company's database when the User disconnects the integration or deletes the account. A single Google grant covers both Google Calendar and Google Drive. Revocation of that grant with Google is requested when an integration is disconnected, except that it is not requested when Google Drive is disconnected while a Google Calendar connection remains; see section 10.1 for the full description, including what happens to a still-connected Drive integration when Google Calendar is disconnected. Account deletion does not revoke the grant, and the User can revoke it at https://myaccount.google.com/permissions. Calendar entries created from synchronized events (event title, scheduled times, meeting link, Google's event identifier and iCalUID) are not covered by an automatic retention period and are not deleted by disconnecting the integration; they are deleted when the meeting is deleted or on request. For each summary the Service writes to Google Drive, the Company retains a delivery record containing the Drive file identifier, the meeting title and the first two hundred (200) characters of the summary. That record is attached to the Google Drive integration and not to the meeting, so it is not deleted when the meeting or the conversation record is deleted, nor by any automatic retention period; it is deleted when the User disconnects the Google Drive integration or deletes the account. Deletion before the end of these periods may be requested at any time via privacy@re-voice.io.
- Technical and Audit Logs: Webhook logs, cron logs and system metrics are deleted after ninety (90) days. Audit log entries are deleted after ninety (90) days, except entries recording security and compliance events, such as administrative actions, data protection requests, single sign-on events, membership changes and deletions, which are retained indefinitely as evidence. Records of registration attempts are deleted after one hundred and eighty (180) days. Completed data deletion requests are deleted thirty (30) days after completion. Separately from these, the Service writes technical application logs, which may contain calendar event titles and meeting links; those logs are held by the Company's hosting provider, are used only to operate and debug the Service, are not part of the User's account data, and are not used for any other purpose.
- Accounting Records: Stored for seven (7) years in accordance with the Swedish Accounting Act (1999:1078).
- Backups: Deleted data may remain in encrypted backups for a limited cycle before permanent overwriting occurs.
10. Specific Terms for Third-Party Platforms
- 10.1 Google API Services ReVoice's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. That policy is available at https://developers.google.com/terms/api-services-user-data-policy.
- Scopes requested: when the User connects a Google account, the Company requests only openid, email and profile (to sign the User in with Google), read-only access to Google Calendar events (https://www.googleapis.com/auth/calendar.events.readonly), and per-file access to Google Drive (https://www.googleapis.com/auth/drive.file).
- Data received from Google Calendar: the Company reads events from the User's primary calendar only, within a window from twenty-four (24) hours in the past to thirty (30) days ahead, retrieving up to fifty (50) events per page and no more than five hundred (500) events per synchronization. Each event may contain title, description, start and end time, location, conference link (Google Meet), event status, iCalUID, and the attendee list with names, email addresses and RSVP status. The Company never creates, modifies or deletes Google Calendar events.
- Data received from Google Drive: the Company reads no file content of any kind. The only read the Service performs is a metadata search that returns the identifier and name of the folder the Service itself created, so that new documents can be filed into it. The Service uses the drive.file scope solely to create and manage files that it has itself created.
- Use: calendar data is used to display the User's upcoming meetings, to let the User select a meeting, to connect the ReVoice meeting assistant to the correct Zoom, Google Meet or Microsoft Teams link, to attribute speech in a transcript to the correct participant, and to answer the User's own questions about their meetings and schedule. Google Drive access is used solely to create a folder called ReVoice Meeting Summaries and to write one Google document per meeting summary to the destination the User has selected; no recordings and no raw transcripts are written to Drive.
- Transfers: calendar data, including attendee names and email addresses, is transmitted to a large language model inference provider (OpenAI, or Microsoft Azure OpenAI where configured), and is used there for inference only. Separately, where the ReVoice meeting assistant joins a meeting, the meeting link taken from the calendar event is transmitted to the Company's meeting-bot provider so that the assistant can join that meeting; the only other personal data sent with the link are the assistant's display name, the meeting owner's own display name and any custom vocabulary the User has configured, which are passed as hints to improve speech recognition. No calendar event title, description, location or attendee list is transmitted to that provider. No other AI sub-processor receives Google Calendar data, and no speech-to-text or text-to-speech provider receives it. Inference is configured against these providers' European endpoints; any transfer outside the EU/EEA is governed by section 8 above. Calendar data is also held by the Company's cloud hosting, database and backup providers as part of operating the Service. Writing a summary to Google Drive is itself a transfer of meeting data into the User's own Google account, and occurs only where the User has configured that destination and the workspace's external sharing policy permits it.
- Limitations on use: the Company does not sell information received from Google APIs, does not use it for advertising or to build advertising profiles, and does not permit any human to read it except with the User's explicit consent, to the extent necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized. Information received from Google APIs is under no circumstances used to train, retrain, fine-tune or otherwise optimize general AI or machine learning models, whether by the Company or by any sub-processor.
- Protection: all transfers occur over encrypted connections (TLS). Google OAuth access and refresh tokens, and the titles of meetings and calendar events stored by the Service, are encrypted at rest in the Company's database. Other calendar-derived fields, including the snapshot of attendee names, email addresses and RSVP statuses, are stored without field-level encryption in an access-controlled database. Access to a meeting record is limited to the User who owns it, to the members of the workspace it belongs to, and to anyone the User has shared the record with; where a record belongs to no workspace, members of a channel the User has shared it into can also read it. Modification is further restricted by role. Additional technical and organizational measures are described in section 14 below.
- What is stored: for calendar events that contain a recognized Zoom, Google Meet or Microsoft Teams link, the Company stores the event title, start and end time, the meeting link, Google's event identifier and iCalUID, and a snapshot of up to fifty (50) attendees (name, email address and RSVP status). Event descriptions and locations are processed in memory only, in order to detect a meeting link, and are not stored. For operational and troubleshooting purposes the titles and meeting links of synchronized calendar events, including events that are discarded because they contain no recognized meeting link, are written to the Company's technical application logs. Those logs are held by the Company's hosting provider, are used only to operate and debug the Service, are not part of the User's account data, and are not used for any other purpose.
- Retention and deletion: a synchronized calendar event creates two records, a calendar entry (event title, Google's event identifier, iCalUID, scheduled times and the meeting link) and a conversation record (title and the attendee snapshot, together with any later recording, transcript and summary). Conversation records that belong to a workspace on the free plan, and conversation records that belong to no workspace and are owned by a User on the free plan, are automatically marked for deletion thirty (30) days after creation and are permanently erased from the Company's databases and object storage within a further thirty (30) days; erasure is processed in batches and may take correspondingly longer where large volumes are involved. That automatic deletion does not apply to records held in a workspace on a paid plan, even where the User who owns them is on the free plan, and it does not apply to any workspace whose administrator has configured a retention period, which governs those records instead. On paid plans, conversation records are retained until the User deletes them, until the User's account is deleted, or until a retention period configured by the workspace administrator expires. Deleting a workspace does not delete the conversation records held in it: the associated recordings and other media are purged from object storage, but the records themselves are detached from the workspace and retained, and are then deleted by the User, by deletion of the owning account, or on request. Calendar entries are not covered by any automatic retention period; they are deleted when the User deletes the meeting, and otherwise on request to privacy@re-voice.io. When the User deletes a conversation, or requests deletion at privacy@re-voice.io, the record is removed from the Service immediately and permanently erased from the Company's databases and object storage within thirty (30) days; where an erasure operation against external storage fails it is retried automatically up to ten (10) times, after which it is flagged for manual completion. Deleting the account erases the User's conversation records, transcripts, participant records and the calendar attendee snapshot; calendar entries are not linked to a user account and may remain in the database after account deletion, without attendee data but containing the event title, Google's event identifier, iCalUID, scheduled times and the meeting link, and are erased on request to privacy@re-voice.io. Self-service account deletion cannot be completed while the User owns a company or owns a workspace that has other members; ownership must be transferred first.
- Disconnection and revocation: Google Calendar and Google Drive are separate integrations and are disconnected separately, but a single Google grant covers both surfaces, so revoking it affects both. When the User disconnects one of them, the tokens stored for that integration are deleted from the Company's database and the Company requests revocation of the Google grant, with one exception: revocation is not requested when the Google Drive integration is disconnected while a Google Calendar connection remains, so that the calendar connection is not broken. Disconnecting Google Calendar always requests revocation, which also invalidates a Google Drive integration that is still connected; that integration's record and its stored tokens remain in the Company's database until the User disconnects it or deletes the account. Revocation is requested on a best-effort basis, and a failed request does not prevent deletion of the tokens held by the Company. Deleting the account removes the stored tokens from the Company's database but does not by itself revoke the grant at Google; the User can revoke it at any time at https://myaccount.google.com/permissions. Disconnecting an integration stops further retrieval of data but does not delete records already created from calendar events; those follow the retention and deletion rules stated above.
- 10.2 Microsoft Services When integrating Microsoft services (e.g., Outlook or Teams), profile data and calendar information are processed exclusively to identify, schedule, and connect the Service to relevant meeting instances upon the user's request.
11. Special Categories of Personal Data (Sensitive Data)
Voice recognition and voiceprints. When voice recognition is enabled for a workspace, ReVoice creates a voiceprint - a mathematical representation of a person's voice characteristics - from meeting audio and uses it to recognise and label recurring speakers across meetings. A voiceprint is biometric data processed for the purpose of uniquely identifying a person, which is a special category of personal data under Article 9 of the GDPR. This feature is controlled by a workspace setting and is not active unless a workspace administrator enables it. Where ReVoice acts as a Data Processor for meeting content, the Customer (as Data Controller) is responsible for establishing a valid Article 9(2) condition - typically the explicit consent of the speakers - before enabling it. A workspace can disable voice recognition and have its voiceprints deleted at any time by contacting privacy@re-voice.io.
Apart from voiceprints, the Service is not otherwise intended for the processing of special-category data. Since meeting conversations may naturally contain such information, it remains the Customer's responsibility, as Data Controller, to ensure an appropriate legal basis and safeguards are in place before applying the Service to sensitive meeting contexts.
12. Children’s Privacy
The Service is not directed to, and is not intended for, persons under the age of eighteen (18). The Company does not knowingly collect personal data from minors. If it comes to our attention that personal data regarding a minor has been collected without proper parental consent, the Company will promptly take steps to permanently delete it.
13. Rights of the Data Subject
You as a data subject have the right to request access, rectification, erasure, restriction, data portability, and to object to processing or withdraw consent regarding the Company (when the Company acts as Data Controller). Contact privacy@re-voice.io to exercise your rights. You also have the right to lodge a complaint with the competent supervisory authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
14. Technical and Organizational Security Measures
The Company implements and maintains appropriate technical and organizational security measures to ensure a level of security proportionate to the risk (Article 32 GDPR). These include:
- Transport encryption (TLS/SSL) and encryption of sensitive tokens at rest.
- Strict authorization controls, Role-Based Access Control (RBAC), and network isolation of production environments.
- Systematic logging, vulnerability analyses, rate-limiting, and proactive protection mechanisms against automated incidents.
- Established routines for the handling and reporting of personal data breaches.
15. Changes to this Policy
The Company reserves the right to unilaterally revise this Policy. In the event of material changes that affect the rights or obligations of data subjects, the Company will notify this in advance. The updated Policy applies from the date specified in the Policy. If a change requires consent or other action, the Company will obtain this where necessary.