Privacy Policy
(Last updated: 15.09.2026 – Version 2.0)
wespond UG (haftungsbeschränkt) (hereinafter: "we", "us", "Jamie") welcomes your visit to our website www.meetjamie.ai (hereinafter: "Website"), our web app app.meetjamie.ai (hereinafter: "Web App") and our mobile application (hereinafter: "Mobile App"; Web App and Mobile App together: "the App"). Below you will find the information on how we process your personal data, as required by Articles 13 and 14 of the General Data Protection Regulation (GDPR).
Our principle is to collect only what we need and to process this information solely to provide you with the service you expect.
1. General
1.1. Controller
The controller for the processing of personal data described in this privacy policy within the meaning of the GDPR is:
wespond UG (haftungsbeschränkt)
Alte Kölner Straße 25a
51503 Rösrath
Germany
Email: privacy@meetjamie.ai
1.2. Data Protection Officer
Our appointed Data Protection Officer is:
Kertos GmbH
Briennerstraße 41
80333 Munich
Germany
Email: dsb@kertos.io
1.3. Our two roles: controller and processor
Jamie is an AI meeting assistant that records, transcribes and summarises meetings. Depending on the data concerned, we act in one of two roles:
- As controller we process the data described in this privacy policy: data of visitors to our Website, account and contact data of our users, billing and support data, usage data of the App and data we process for our own marketing.
- As processor we process the content our customers create with Jamie – meeting recordings, transcripts, summaries and, if activated, speaker profiles – on behalf of and according to the instructions of the customer whose organisation uses Jamie. That customer is the controller of this content and is responsible for informing meeting participants. The details of this processing – subject matter, categories of data and data subjects, retention, security measures and the complete list of the service providers involved (subprocessors) – are set out in our Data Processing Agreement (hereinafter: "DPA"), which forms part of our contract with every customer.
All external service providers we use are listed by name, with their purpose, location and transfer safeguard, in section 6: the subprocessors that process App data and meeting content on our behalf in section 6.1, which is identical to Annex 2 of the DPA, and the providers used only for our Website in section 6.2. The text of this privacy policy describes providers by their function only.
1.4. Recipients of personal data
Within our company, only those individuals who need your personal data for the respective purposes have access to it. Your personal data will only be disclosed to external recipients if we are legally entitled to do so or if you have consented. The recipients fall into the following categories:
- Processors: External service providers who process data on our behalf and only according to our instructions, who are carefully selected and bound by data processing agreements pursuant to Article 28 GDPR. These are, in particular, providers of hosting and cloud infrastructure, databases, speech recognition and AI models, authentication, e-mail and push notifications, customer support, product analytics, error monitoring, consent management and – for the Website – analytics and advertising. All of them are listed by name in section 6.
- Public authorities: Authorities and state institutions, such as tax authorities, prosecutors or courts, to whom we must transmit personal data, e.g. to fulfil legal obligations or to safeguard legitimate interests.
- Other recipients only with your consent, for example when you connect a third-party account (see section 3.5).
1.5. International data transfers
We mainly process your data within the European Union (EU) and the European Economic Area (EEA). Some of our service providers are located, or have parent companies, outside the EEA in so-called "third countries", in particular in the United States and the United Kingdom. The GDPR imposes strict requirements on the transfer of personal data to third countries. Before we engage a service provider in a third country, we review its level of data protection, and every service provider must conclude a data processing agreement with us. According to Art. 44 et seq. GDPR, personal data is transferred only if at least one of the following conditions is met:
- The European Commission has determined that the third country ensures an adequate level of protection (Art. 45 GDPR), e.g. the United Kingdom, or – for companies certified under the EU-U.S. Data Privacy Framework (DPF) – the United States.
- Standard contractual clauses of the European Commission have been included in our contract with the recipient (Art. 46 GDPR), including any additional measures if necessary.
- Other appropriate safeguards are provided according to Art. 46 GDPR, or in exceptional cases a derogation according to Art. 49 GDPR applies.
Which of these safeguards applies to which provider is stated per provider in section 6. You can obtain a copy of the applicable safeguards from us at the contact address in section 1.1.
1.6. Storage duration
Unless a specific retention period is stated in the sections below, we delete or block personal data as soon as the purpose of storage ceases to apply. Storage beyond that point takes place only if provided for by European or national law, in particular commercial and tax retention obligations (currently six to ten years for accounting-relevant data). Blocking or deletion also takes place when a statutory retention period expires, unless further storage is necessary for the conclusion or fulfilment of a contract.
1.7. Data security
We are committed to treating your personal data confidentially. To prevent manipulation, loss or misuse of your data stored with us, we take extensive technical and organisational security measures, which are regularly reviewed and adapted to technological progress. All connections to our Website and App are encrypted in transit; data stored in our databases and on your device (in the Mobile App: authentication tokens and user IDs, stored in the operating system's keychain or keystore) is encrypted at rest. The measures we commit to towards our customers are documented in Annex 3 of the DPA.
We inform you that due to the structure of the internet, it is possible that data protection regulations and the above-mentioned security measures may not be observed by other persons or institutions outside our area of responsibility. In particular, unencrypted data – for example, when transmitted by e-mail – can be viewed by third parties. We have no technical influence on this.
1.8. Artificial intelligence, automated decision-making and model training
Jamie uses artificial intelligence (speech recognition and large language models) to transcribe meetings, identify speakers and generate summaries. This is a tool for documentation; we do not use it to make decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR.
We do not use personal data – in particular no meeting content – to develop, improve, train, retrain or fine-tune artificial intelligence or machine learning models, neither our own nor those of our providers. This also applies to any data obtained through the Google Workspace APIs or other third-party accounts you connect (see section 3.5).
1.9. Obligation to provide data
You are not legally obliged to provide personal data to us. To conclude and perform a contract with you, however, we need the data marked as necessary during registration (in particular your name and e-mail address). Without it, we cannot provide the App to you. All other data is provided voluntarily, and processing that is based on your consent can be stopped by withdrawing that consent at any time.
2. Website (www.meetjamie.ai)
This section applies to visitors of our marketing website. We are the controller for all processing described here.
2.1. Provision of the Website and log files
When you access our Website, we collect personal data that your browser automatically transmits to our server. This information is temporarily stored in a so-called log file. The following information is collected without your intervention and stored until its automatic deletion:
- IP address of the requesting computer,
- date and time of access,
- name and URL of the retrieved file,
- website from which access is made (referrer URL),
- the browser used and, if applicable, the operating system of your computer as well as the name of your access provider.
We process this data to ensure a smooth connection to and comfortable use of the Website and for IT security purposes. Article 6(1)(f) GDPR serves as the legal basis; our legitimate interest lies in the secure and functional operation of the Website. Log files are deleted as soon as they are no longer required for these purposes, at the latest after 30 days, unless a security incident requires longer retention. The collection of this data is essential for the operation of the Website, so there is no possibility to object.
2.2. Hosting and content delivery
The Website is hosted by an external website platform provider whose servers are located in the United States; the log data described in section 2.1 is transferred to this provider to deliver the Website to you. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in the provision of the technical infrastructure, as otherwise it would not be possible to operate the Website.
Fonts on the Website are loaded from the servers of an external font provider. When you visit the Website, your browser transmits your IP address, the referrer URL and browser information to that provider, typically to a server in the United States. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in the uniform and fast presentation of the Website.
Both providers, their locations and the applicable transfer safeguards are listed in section 6.1.2.
2.3. Cookies and consent
We use cookies and similar technologies (device fingerprinting, local storage, so-called "universal IDs"; below collectively "cookies") on our Website. Technically necessary cookies – for example to store your language or your consent decision – are used on the basis of § 25(2) TDDDG and Article 6(1)(f) GDPR, as we have a legitimate interest in the user-friendly presentation of our Website. All other cookies, in particular for analytics and advertising (section 2.4), are only set if you have given your consent via our consent banner; the legal bases are then § 25(1) TDDDG and Article 6(1)(a) GDPR. You can withdraw or change your consent at any time via the "Cookie settings" link in the footer of the Website, with effect for the future.
To obtain, store and document your consent we use a consent management platform. It records your consent decision, its time and the version of the banner you saw, and stores this for one year from your last decision or until you change your preferences, whichever is earlier (Article 6(1)(c) GDPR in conjunction with § 25 TDDDG, and Article 6(1)(f) GDPR). The complete and current list of the cookies used on the Website, including provider, purpose and storage duration, is available at any time in the cookie declaration of the consent banner. It is maintained there so that it always reflects the current state of the Website.
You can also configure your browser to accept only certain cookies or no cookies at all, or to delete stored cookies; please use your browser's help menu for the configuration options. We would like to point out that you may no longer be able to use all functions of the Website if you disable cookies.
2.4. Analytics and advertising on the Website
We use analytics and advertising tools to continuously optimise our Website, to measure the reach of our online offer and to display and evaluate advertising. All of them are used only after your explicit consent in the consent banner (Article 6(1)(a) GDPR and § 25(1) TDDDG). You can withdraw your consent at any time in the consent banner; this does not affect the lawfulness of the previous processing.
Each of these tools processes your IP address, information about your browser and device, the pages you visit and your interactions with the Website and with our advertisements, and the provider may link this information to your account with that provider (e.g. a Facebook, Instagram, LinkedIn or Google account) if you have one. The providers use this information on our behalf to evaluate your use of the Website, compile reports on website activity and measure conversions from advertisements, and – in the case of the advertising networks – also for their own advertising purposes. The data is generally transmitted to servers in the United States; the applicable safeguard is stated per provider in section 6.
The tools currently in use fall into two groups:
- Tag management and web analytics: a tag manager that loads and controls the other tags on the Website, and a web analytics service that measures visits, pages and events with cookies and similar methods. The IP address transmitted by your browser is not merged with other data of the analytics provider. User- and event-level analytics data is retained for 14 months; we retain reports only in aggregated form.
- Advertising and conversion measurement: tracking pixels and tags of the social and search advertising networks on which we advertise, used to measure the effectiveness of our advertisements (conversion tracking) and to display targeted advertising to interested users on those networks.
The providers, with links to their privacy policies, are listed in section 6.1.2. The cookies they set, with their storage duration, are listed in the cookie declaration of the consent banner.
2.5. Contact and demo booking
If you contact us by e-mail or via a form on the Website, we process the personal data you provide (e.g. name, e-mail address, company, content of your message) solely to process and respond to your request. The legal basis is our legitimate interest in communicating with you (Article 6(1)(f) GDPR) or – if your inquiry relates to the initiation or fulfilment of a contract – Article 6(1)(b) GDPR. Your data is retained as long as necessary to process your request and thereafter only as far as commercial or tax retention obligations require.
If you book a demo or a meeting with us via a booking link, the appointment is scheduled with an external scheduling service, which processes your name, e-mail address, the selected time and any notes you enter; the provider and its location are listed in section 6.1.1. The legal basis is Article 6(1)(b) GDPR (pre-contractual measures at your request).
3. Web App and Mobile App
This section applies to users of the App. We are the controller for the processing described here – your account, your use of the App and our communication with you. For meeting content processed on behalf of a customer organisation, section 1.3 and the DPA apply.
3.1. Registration and account
To use the App you need a user account. For registration we process your name, your e-mail address and either a password or the identifier of the single sign-on provider you choose (e.g. Google or Microsoft). If you are invited into a workspace of your organisation, we additionally process your role in that workspace. We use an external authentication service to verify your identity and manage sessions; the provider is listed in section 6.1. The legal basis is Article 6(1)(b) GDPR (performance of the contract). Account data is deleted when you delete your account or when the contract with your organisation ends, unless statutory retention obligations apply.
3.2. Provision of the App and technical infrastructure
When you use the App, your browser or device automatically transmits data that we store in log files: your IP address, date and time of access, the retrieved resource, the referrer URL, browser type and version, operating system and, in the Mobile App, the device model, the app version and the language setting. We process this data to ensure a smooth connection and comfortable use of the App and for IT security purposes (Article 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of the App). Log data is deleted after 30 days at the latest, unless a security incident requires longer retention.
The App runs on cloud infrastructure of external providers: hosting and compute platforms, a content delivery network with DDoS protection, managed databases and a log and error monitoring service. Our production data is stored in data centres in the European Union. For exceptional cases in which a provider based outside the EEA accesses data, e.g. for support or maintenance, standard contractual clauses or the EU-U.S. Data Privacy Framework apply. All infrastructure providers, their locations and the applicable transfer safeguard are listed in section 6.1. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in the provision of the technical infrastructure, as it would otherwise be impossible to operate the App.
3.3. Meeting recordings, transcripts and summaries
The core function of Jamie is to record a meeting, convert the audio into a transcript and generate a structured summary. When you start a recording, the audio is captured on your device and transmitted to our servers, where it is transcribed by an AI-based speech recognition service. The transcript is then analysed by large language models to identify important points and create the summary. The audio recording is deleted as soon as the transcription is complete. Transcripts, summaries and meeting metadata (title, time and date, participants where available, calendar information if you connected your calendar) are stored in an EU-based database until you delete them or your account is closed. The AI providers involved process the data in data centres in the European Union; they are listed in section 6.1.
If you or your organisation activate the optional "Speaker Memory" function, we create and store voice profiles (voice embeddings) of speakers in order to recognise them in future meetings. These are biometric data within the meaning of Art. 9(1) GDPR and are processed only on the basis of explicit consent (Art. 9(2)(a) GDPR) – your own, and for other participants the consent obtained by the organisation using Jamie. Voice profiles are deleted when you deactivate the function or delete the respective speaker.
Meeting content may incidentally contain special categories of personal data if such topics are discussed in a meeting; we do not deliberately evaluate them for such information. Where you use Jamie on behalf of your organisation, your organisation is the controller of this content and this processing takes place under the DPA. Where you use Jamie for your own purposes, the legal basis is Article 6(1)(b) GDPR (performance of the contract with you). In both cases, you are responsible for informing the other participants of a meeting that it is being recorded, as required by the laws applicable to you.
3.4. Customer data and "Speaker Memory" on behalf of our customers
When the "Speaker Memory" function is used within a customer organisation, we process personal data of meeting participants exclusively on behalf of and according to the instructions of our customer. The respective customer is responsible for this processing; its data protection information contains the relevant details, including any necessary consents.
3.5. Connected accounts and integrations
You can connect third-party accounts to the App, for example your Google or Microsoft calendar to detect upcoming meetings, or note-taking and CRM tools to export summaries. When you connect an account, we access only the data required for the respective function (e.g. calendar entries with title, time and participants) and only for as long as the connection exists. The legal basis is Article 6(1)(b) GDPR, and, for the technical access to your device or account, your consent under § 25(1) TDDDG, which you give when authorising the connection and can withdraw at any time by disconnecting the account. For some integrations we use an integration platform provider that relays data between the App and the third-party service; it is listed in section 6.1.
No use of Workspace APIs for AI/ML training. In connection with the use of Google Workspace and the associated APIs, we clarify that we do not use personal data or other user data obtained through these APIs to develop, improve or train artificial intelligence (AI) or machine learning (ML) models. In particular, no storage, analysis or other processing of content provided via Workspace services (e.g. Gmail, Google Calendar, Google Drive) is carried out for these purposes. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your relationship with the provider of a connected account is governed solely by your agreement with that provider.
3.6. Notifications and e-mails
We send you transactional messages that are necessary for the use of the App – for example confirmations, invitations, notifications that a summary is ready and important service or security information – by e-mail and, in the Mobile App, by push notification. For this we process your e-mail address, your user ID, the time and content of the message and technical delivery data. The legal basis is Article 6(1)(b) GDPR. Push notifications are sent only if you have enabled them in your device settings.
In addition, we inform existing users by e-mail about new features and product updates. The legal basis is your consent (Article 6(1)(a) GDPR) or, for existing customers and similar own services, Article 6(1)(f) GDPR in conjunction with § 7(3) UWG. Every such e-mail contains an unsubscribe link; you can object to this use at any time without incurring costs other than the transmission costs according to basic rates. For the delivery of e-mails and push notifications we use external providers, which process the data above on our behalf; they are listed in section 6.1. Whether and when you open an e-mail and which links you click is recorded only for marketing e-mails and only with your consent.
3.7. Customer support
If you contact our support via the App, by e-mail or via the chat on our Website, we process your name, e-mail address, the content of your request and, where necessary to solve your problem, technical information about your account and the affected meetings. The legal basis is Article 6(1)(b) GDPR, or Article 6(1)(f) GDPR where your request does not concern a contract with you; our legitimate interest lies in providing efficient customer service. Support conversations are managed in a customer support platform hosted in the United Kingdom and the EEA and are retained for three years after the request has been closed, unless a longer retention is required by law. The provider is listed in section 6.1.
3.8. Product analytics and error monitoring
To understand how the App is used and to identify errors, we use a product analytics service and an application monitoring service, both hosted in the European Union.
- Product analytics records events such as screen views, sign-in and onboarding events, the start and end of recordings and the use of individual features, together with your user ID, IP address, device and browser information and session duration. We use this data to improve the usability and performance of the App. Where the technology used is not strictly necessary for providing the App, we use it only with your consent (Article 6(1)(a) GDPR and § 25(1) TDDDG), which you give in the App and can withdraw at any time in the App's privacy settings or via the consent banner. Session replays are enabled only with your consent.
- Error monitoring collects error and crash reports (including stack traces), performance metrics such as load and response times, device and platform details and the affected URL and time. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in the stability and security of the App. Error data is retained for 90 days and performance data for 30 days.
Both providers are listed in section 6.1.
3.9. Cookies in the Web App
The Web App uses cookies and local storage that are technically necessary to keep you signed in, to secure the session against attacks and to store your settings (§ 25(2) TDDDG, Article 6(1)(b) and (f) GDPR). Analytics cookies are used only with your consent as described in section 3.8. The current list of cookies, with provider, purpose and duration, is available in the cookie declaration of the consent banner of the Web App.
3.10. Payments and subscriptions
If you take out a paid subscription, we process the data required for invoicing: name, company, billing address, VAT number where applicable, the selected plan and the payment status. The payment itself is processed by our payment service provider or – for subscriptions taken out in the Mobile App – by the Apple App Store or Google Play; we do not receive your full payment card details. The legal basis is Article 6(1)(b) GDPR and, for retaining invoices, Article 6(1)(c) GDPR in conjunction with commercial and tax law. In the Mobile App we use a paywall service to display and manage subscription offers; it is listed in section 6.1.
3.11. Mobile App: app stores, device permissions and updates
App stores. When downloading the Mobile App, the necessary information is transmitted to the app store (Apple App Store or Google Play), in particular your username, e-mail address, customer account number, download time, payment information and unique device identifier. The app store also independently collects various data and provides analysis results. We have no influence on this data processing and are not responsible for it. We only process these data as far as it is necessary for downloading the Mobile App to your device.
Device permissions. Certain features of the Mobile App require access to specific interfaces and data on your device. Depending on your operating system, this may require your explicit consent (§ 25(1) TDDDG). Below, we explain which permissions the Mobile App may request and for what features they are necessary. You can adjust permission settings at any time in your device's system settings.
- Notifications/push notifications: Authorisation is required for the use of push services. For some devices, this is enabled by default for all apps.
- Camera: Authorisation is required for the app to use your device's camera to scan QR codes. The app will only access the camera when you select the corresponding function in the app.
- Microphone: Authorisation is required for the use of your device's microphone to enable audio recording and processing. This access is only requested and used if you actively use the recording functionality (e.g. when starting a meeting or audio note). The specific purpose is to allow high-quality audio capture, real-time audio monitoring and background audio processing where supported by your device. To ensure uninterrupted recording, the app may process audio data in the background while you are using other functions of your device.
- Network access: This permission enables the app to transfer data over your device's internet connection, e.g. to send your recordings to our servers.
- Access to device storage: The app may store or access files (such as audio recordings or meeting metadata) in its own app-specific storage; access to unrelated files or general device storage is not possible.
We do not process your device's IMEI, IMSI, phone number or MAC address, and the Mobile App does not contain advertising networks. The analytics and error-monitoring SDKs described in section 3.8 may process a device identifier assigned by the operating system; where this is not strictly necessary, it is used only with your consent, which you can withdraw in the app's privacy settings.
Expo Updates. The Mobile App uses Expo Updates to provide secure over-the-air updates. This allows us to deliver new features and important security patches directly to your device. When checking for updates, your device transmits the app version, platform and a request identifier. The processing is based on our legitimate interest in maintaining the security and up-to-date operation of the app (Article 6(1)(f) GDPR) or, if technically necessary, on contract performance (Article 6(1)(b) GDPR).
4. Rights of the data subject
With regard to your personal data, you have the following legal rights towards us:
- Right of access (Art. 15 GDPR): You have the right to request confirmation as to whether we are processing personal data concerning you. If this is the case, you have the right to access this personal data and further information, such as the processing purposes, the recipients and the planned duration of storage or the criteria for determining the duration.
- Right to rectification (Art. 16 GDPR): You have the right to request the rectification of inaccurate data without undue delay. Considering the purposes of the processing, you have the right to request the completion of incomplete data.
- Right to erasure (Art. 17 GDPR): You have the right to request erasure if the processing is not necessary. This is the case, for example, if your data is no longer needed for the original purposes, if you have withdrawn your consent, or if the data has been processed unlawfully.
- Right to restriction of processing (Art. 18 GDPR): You have the right to request the restriction of processing, for example if you believe that the personal data is inaccurate.
- Right to data portability (Art. 20 GDPR): You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format.
- Right to object (Art. 21 GDPR): You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you that is based on Article 6(1)(f) GDPR. In the case of direct marketing, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
- Right to withdraw consent (Art. 7(3) GDPR): You can withdraw your consent to the processing of your personal data at any time with effect for the future. This does not affect the lawfulness of the processing carried out up to the withdrawal.
To exercise your rights, contact us at privacy@meetjamie.ai. Where we process meeting content on behalf of a customer organisation (section 1.3), we will forward your request to that organisation, which is responsible for answering it.
Notwithstanding these rights, you have the right to lodge a complaint with a supervisory authority at any time if you believe that the processing of your personal data violates data protection regulations. The supervisory authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, <https://www.ldi.nrw.de>.
5. Changes to this privacy policy
We update this privacy policy when our services, the providers we use or the legal requirements change. The current version is always available at <https://www.meetjamie.ai/privacy-policy>. Changes to our service providers are reflected in section 6 and, for subprocessors, in Annex 2 of the DPA; customers are informed of changes to subprocessors as set out in the DPA.
Version history
Date | Version | Reason |
|---|---|---|
20.03.2025 | 1.0 | First version of the revised data protection notice in the new format |
27.05.2025 | 1.1 | Updating the DSE with the processing of the web application |
03.09.2025 | 1.2 | Updating the DSE with the new processing of the web application |
15.09.2026 | 2.0 | Restructured by role (controller/processor); service providers for App data and meeting content referenced via the DPA subprocessor list instead of being repeated; cookie lists moved to the consent banner; corrections of outdated provider details; new sections on AI, automated decision-making and the obligation to provide data |
6. Service providers
This section lists every external service provider that processes personal data for us. It is the only place in this privacy policy where providers are named; the sections above describe them by function only.
6.1. Subprocessors (identical to Annex 2 of the DPA)
The following providers process personal data of App users and meeting content on our behalf. This list is identical to Annex 2 of our Data Processing Agreement and is maintained together with it; customers are informed of changes as set out in the DPA.
Subprocessor (Name & Address) | Purpose of Service | Server Location | Data Transfer to Third Countries (Legal Basis) |
|---|---|---|---|
Better Stack, Inc., 651 N Broad St., Suite 206, Middletown, DE 19709, USA | Observability platform for uptime monitoring, incident management, and log aggregation. | European Union | Processing and storage take place in the EU. For exceptional cases (e.g., access from the United States), SCCs (Art. 46 GDPR). |
Clay Labs Inc., 119 N 11th Street, 3C, Brooklyn, NY 11249, USA | Data enrichment and outbound automation platform for building prospect lists from multiple data sources. | United States | Processing and storage take place in the United States. SCCs (Art. 46 GDPR). |
Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA | Content delivery network (CDN) and edge platform for DNS, DDoS protection, and web security. | European Union | Processing and storage take place in the EU. For exceptional cases (e.g., access from the United States), SCCs (Art. 46 GDPR). |
Google Cloud Platform (Google Cloud EMEA Limited), 70 Sir John Rogerson's Quay, Dublin 2, Ireland | Cloud computing platform providing infrastructure, platform, and machine learning services (IaaS/PaaS). | European Union | Processing and storage take place in the EU. For exceptional cases (e.g., access from the United States), EU-US DPF (Art. 45 GDPR) and additionally SCCs (Art. 46 GDPR). |
Google Workspace (Google Cloud EMEA Limited), 70 Sir John Rogerson's Quay, Dublin 2, Ireland | Productivity and collaboration suite providing email, calendar, documents, storage, and video conferencing. | Global (EU data regions configurable) | Data may be processed globally unless EU data regions are enabled. For transfers to the United States, EU-US DPF (Art. 45 GDPR) and additionally SCCs (Art. 46 GDPR) under the Cloud Data Processing Addendum. |
Astrodon Corporation (Loops), 9450 SW Gemini Dr, PMB 22902, Beaverton, OR 97008, USA | Email marketing platform for SaaS companies for sending campaigns, sequences, and transactional email. | United States | Processing and storage take place in the United States. EU-US DPF (Art. 45 GDPR) and additionally SCCs (Art. 46 GDPR). |
Modal Labs, Inc., 233 Spring Street, Floor 11, New York, NY 10013, USA | Serverless compute platform for running Python workloads such as AI inference and batch jobs in the cloud. | European Union | Processing and storage take place in the EU. For exceptional cases (e.g., access from the United States), SCCs (Art. 46 GDPR). |
OneSignal, Inc., 201 S. B Street, Suite 200, San Mateo, CA 94401, USA | Customer engagement platform for sending push notifications, in-app messages, email, and SMS across web and mobile apps. | European Union (Netherlands) | Processing and storage take place in the EU (Netherlands). For exceptional cases (e.g., access from the United States), EU-US DPF (Art. 45 GDPR) and additionally SCCs (Art. 46 GDPR). |
Forge Technology, Inc. (Paragon), 10900 Wilshire Blvd, Suite 440, Los Angeles, CA 90024, USA | Embedded integration platform (iPaaS) for shipping native third-party integrations inside a SaaS product. | European Union | Processing and storage take place in the EU. For exceptional cases (e.g., access from the United States), SCCs (Art. 46 GDPR). |
Not Just Tickets Ltd (Plain), 3rd Floor, 1 Ashley Road, Altrincham, Cheshire, WA14 2DT, United Kingdom | Customer support platform for B2B companies with shared inbox and API-first workflows. | United Kingdom / EEA | Processing and storage take place in the UK and EEA. UK Adequacy Decision (Art. 45 GDPR); SCCs (Art. 46 GDPR) for onward transfers to US sub-processors. |
PlanetScale, Inc., 535 Mission Street, 14th Floor, San Francisco, CA 94105, USA | Managed database platform providing serverless MySQL and Postgres with branching workflows. | European Union | Processing and storage take place in the EU. For exceptional cases (e.g., access from the United States), EU-US DPF (Art. 45 GDPR) and additionally SCCs (Art. 46 GDPR). |
Functional Software, Inc. (d/b/a Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA | Application monitoring platform for error tracking, crash reporting, and performance tracing. | European Union | Processing and storage take place in the EU. For exceptional cases (e.g., access from the United States), SCCs (Art. 46 GDPR). |
Soniox Inc., 1045 Helm Lane, Foster City, CA 94404, USA | Speech recognition API for real-time and batch speech-to-text transcription. | European Union | Processing and storage of customer data take place exclusively in the EU. Limited system data (account metadata, operational logs, service telemetry) may be processed outside the EEA; where applicable, SCCs (Art. 46 GDPR). |
Nest 22, Inc. (d/b/a Superwall), 2093 Philadelphia Pike #5307, Claymont, DE 19703, USA | Paywall management platform for building, testing, and optimizing in-app subscription paywalls on mobile apps without shipping app updates. | United States | Processing and storage take place in the United States. SCCs (Art. 46 GDPR). |
turbopuffer Inc., 222 Queen Street, 10th Floor, Suite 1006, Ottawa, ON, Canada | Serverless vector and full-text search database built on object storage for retrieval and RAG workloads. | European Union (customer-selected region) | Processing and storage take place in the EU (customer-selected region). For exceptional cases (e.g., support access from Canada), SCCs (Art. 46 GDPR). |
WorkOS, Inc., 548 Market Street, PMB 86125, San Francisco, CA 94104, USA | Authentication and identity API platform for adding enterprise features like single sign-on (SSO) and SCIM to SaaS applications. | United States | Processing and storage take place in the United States. SCCs (Art. 46 GDPR). |
6.2. Other service providers (Website only)
The following providers process personal data of visitors to our Website (sections 2.2 to 2.4). They do not process App data or meeting content and are therefore not subprocessors within the meaning of the DPA.
Provider (name and address) | Purpose | Server location | Transfer to third countries (legal basis) | Privacy policy |
|---|---|---|---|---|
Webflow, Inc., 398 11th St., Floor 2, San Francisco, CA 94103, USA | Hosting of the Website | United States | EU-US DPF (Art. 45 GDPR) | https://webflow.com/legal/eu-privacy-policy |
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland / Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA | Google Fonts (web fonts); Google Tag Manager (tag management); Google Analytics 4 (web analytics) | United States | EU-US DPF (Art. 45 GDPR) and additionally SCCs (Art. 46 GDPR) | https://policies.google.com/privacy |
Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland | Meta Pixel (conversion measurement and advertising on Facebook and Instagram) | United States | EU-US DPF (Art. 45 GDPR) and additionally SCCs (Art. 46 GDPR) | https://www.facebook.com/about/privacy |
LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland / LinkedIn Corporation, 1000 W Maude Ave, Sunnyvale, CA 94085, USA | LinkedIn Insight Tag (conversion measurement and advertising on LinkedIn) | United States | EU-US DPF (Art. 45 GDPR) and additionally SCCs (Art. 46 GDPR) | https://www.linkedin.com/legal/privacy-policy |
Microsoft Ireland Operations Ltd., One Microsoft Place, Leopardstown, Dublin 18, Ireland / Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA | Microsoft Advertising (conversion measurement and advertising on Bing) | United States | EU-US DPF (Art. 45 GDPR) and additionally SCCs (Art. 46 GDPR) | https://privacy.microsoft.com/privacystatement |
Usercentrics A/S (Cookiebot), Havnegade 39, 1058 Copenhagen, Denmark | Consent management platform (cookie banner and cookie declaration) | European Union | Processing and storage take place in the EU. | https://www.cookiebot.com/en/privacy-policy/ |