Back

GDPR Data Processing Policy

Effective date: June 22, 2026 · Last updated: June 22, 2026

1. Data Controller

SoftImply OÜ (registry code: 16776329), a company registered in Estonia, is the data controller responsible for processing the personal data handled by Zapys as described in this policy and in our Privacy Policy.

Company
SoftImply OÜ
Registry code
16776329
Address
Sepapaja tn 6, 15551 Tallinn, Estonia
Jurisdiction
Estonia, EU (GDPR applies)
Email
privacy@softimply.tech

2. Categories of Personal Data

Zapys processes the following categories of personal data:

  • Meeting recordings (audio and video) of all participants in recorded meetings.
  • Transcripts of those recordings, including speaker labels and timestamps.
  • Biometric data — voiceprints / speaker embeddings derived from meeting audio to identify speakers. This is a special category of personal data under Article 9 of the GDPR.
  • Calendar data — events, attendees, and meeting links from connected Microsoft and Google calendars.
  • Account and access data — name, email, role, share links, guest invitations, and audit metadata.
  • Technical data — IP address, timestamps, and operational logs.

3. Legal Basis for Processing

  • Art. 6(1)(b) / (f) — performance of the service and our legitimate interest in keeping an accurate record of business meetings.
  • Art. 9(2)(a) — explicit consent for biometric data — voiceprints used to uniquely identify a speaker are processed only on the explicit consent of the individuals concerned, obtained before recording. Where consent is not available, speaker recognition must be disabled.
  • Art. 6(1)(a) — consent — for connecting and reading a calendar, revocable at any time by disconnecting it.
  • Art. 6(1)(c) — legal obligation — where retention or disclosure is required by law.

4. Data Storage and Security

Application servers and the recording library run on EU-based infrastructure (Hetzner). Recordings are stored in private Microsoft Azure Blob Storage containers and metadata in a managed PostgreSQL database. We apply the following measures:

  • HTTPS / TLS 1.2+ for all data in transit.
  • Private storage containers; playback via short-lived signed URLs.
  • Role-based access control; guests are limited to recordings shared with them.
  • Provider credentials encrypted at rest.

5. Data Retention and Deletion

  • Recordings and transcripts — retained for the period configured by your organization, then deleted automatically by a scheduled retention job.
  • Voiceprints / speaker embeddings — retained only while speaker recognition is enabled with consent in place; deleted when it is disabled or on request.
  • Calendar data — removed when you disconnect the calendar.
  • Share access — public links can expire or be revoked, ending access for public and guest recipients.

You may request deletion of specific recordings, transcripts, or voiceprints by emailing privacy@softimply.tech.

6. Recipients and International Transfers

We do not sell personal data. Data is shared with sub-processors who help operate the service:

  • Hetzner — EU hosting (Germany/Finland).
  • Microsoft Azure — recording storage; and Microsoft Entra ID for sign-in where configured.
  • Microsoft and Google — calendar and meeting-platform integrations.
  • Transcription and speaker-recognition providers — RunPod-hosted transcription and diarization models, processing audio as our processor.
  • Attendee (self-hosted bot) — joins meetings to capture audio and video.

Where a recipient is outside the European Economic Area, transfers rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses under GDPR Chapter V.

7. Your Rights Under GDPR

  • Access (Art. 15) — a copy of your personal data.
  • Rectification (Art. 16) — correction of inaccurate data.
  • Erasure (Art. 17) — deletion of your personal data, including recordings and voiceprints.
  • Restriction (Art. 18) — limit how we use your data.
  • Portability (Art. 20) — your data in a machine-readable format.
  • Objection (Art. 21) — object to processing based on legitimate interests.
  • Withdraw consent (Art. 7(3)) — including consent for biometric voiceprint processing, at any time.

To exercise any right, email privacy@softimply.tech. We respond within 30 days.

8. Supervisory Authority

If you believe your data protection rights have been violated, you may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon):

Authority
Andmekaitse Inspektsioon
Website
www.aki.ee
Email
info@aki.ee

9. Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. Changes will be posted on this page with an updated date.