Privacy Policy
Effective date: June 22, 2026 · Last updated: June 22, 2026
1. Who We Are
Zapys is a meeting-recording product operated by SoftImply OÜ (registry code: 16776329), a company registered in Estonia. SoftImply OÜ is the data controller for the personal data described in this policy. Zapys records meetings, stores audio and video recordings, produces transcripts, identifies speakers, and lets recordings be shared inside and outside your organization.
- Company
- SoftImply OÜ
- Registry code
- 16776329
- Address
- Sepapaja tn 6, 15551 Tallinn, Estonia
- Jurisdiction
- Estonia, EU (GDPR applies)
- privacy@softimply.tech
2. Information We Collect
Because Zapys records meetings, the data we process is more sensitive than for a typical web service. We collect and process:
- Meeting audio and video recordings — the full audio and video captured by the recording bot when it joins a Microsoft Teams, Google Meet, or Zoom call, or media files you upload. Recordings may contain the voices, faces, names, screen shares, and anything else said or shown by every participant in the meeting.
- Transcripts — machine-generated text transcripts of recordings, including speaker labels, timestamps, and any words spoken during the meeting.
- Voiceprints / speaker embeddings (biometric data) — to attribute spoken segments to a speaker, Zapys derives numerical voiceprints (speaker embeddings) from meeting audio. When used to uniquely identify a natural person, these are biometric data and a special category of personal data under Article 9 of the GDPR. See section 4 for the legal basis and consent we rely on to process them.
- Calendar data — when you connect a Microsoft or Google calendar, we read your events (titles, descriptions, times, organizer and attendee details, and meeting join links) to detect upcoming meetings and automatically schedule recordings. We do not modify your calendar.
- Account data — name, email address, authentication identifiers (Microsoft Entra ID sign-in or a password hash), role, and access status.
- Sharing and access data — share links you create, the recipients you grant access to, guest (external) accounts you invite, and access/audit metadata.
- Technical data — IP address, timestamps, and operational logs, collected for security and to operate the service.
3. Whose Data Appears in Recordings
A recording captures everyone present in the meeting, not only the Zapys user who scheduled it. The people whose personal data we process therefore include:
- All meeting participants — staff and any third parties (clients, candidates, partners) on the call, whether or not they hold a Zapys account.
- Public share-link recipients — anyone who opens a tokenized public share link can watch the recording without signing in. Anyone who creates such a link is responsible for sharing it only with people entitled to view the recording.
- External testers and guests — people outside your organization who are invited as guest accounts or testers and can view recordings specifically shared with them. Their access is limited to the recordings assigned to them.
Consent to record. The user who initiates a recording is responsible for ensuring that all participants are informed that the meeting is being recorded and that any consent required by applicable law (including for recording and for processing biometric voiceprints) has been obtained before recording begins. See our Terms of Service for acceptable-use rules on recording others.
4. Legal Basis for Processing
As a controller established in the European Union, we process personal data under the GDPR on the following bases:
- Contract / legitimate interest (Art. 6(1)(b) and (f)) — recording, storing, transcribing, and sharing meetings to operate the service for your organization and to keep an accurate record of business meetings.
- Explicit consent for biometric data (Art. 9(2)(a)) — voiceprints / speaker embeddings are special-category biometric data. Where Zapys uses them to uniquely identify a speaker, we rely on the explicit consent of the individuals concerned, obtained before recording, as the lawful basis under Article 9(2)(a). Speaker recognition can be disabled for an organization or recording; where no valid consent exists, Zapys must not be used to generate identifying voiceprints.
- Consent for calendar access (Art. 6(1)(a)) — you explicitly authorize calendar access through Microsoft or Google OAuth, and you can revoke it at any time by disconnecting the calendar.
- Legal obligation (Art. 6(1)(c)) — where we must retain or disclose data to comply with the law.
You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. For a full description of your rights and how to exercise them, see our GDPR Data Processing Policy.
5. How We Use Recordings, Transcripts and Voiceprints
- Producing playable recordings in your library.
- Generating transcripts and making them searchable across your organization's recordings.
- Diarizing speech and, where enabled and consented to, matching speakers to known voiceprints to label who said what.
- Tracking meeting goals and questions and surfacing them against the transcript.
- Sharing recordings with the people and link recipients you choose.
- Operating, securing, and improving the service.
We do not sell personal data, and we do not use recordings, transcripts, or voiceprints for advertising.
6. Service Providers and Sub-processors
We share data only with sub-processors who help us run the service, under contractual confidentiality and security obligations:
- Hosting and storage — application servers and the recording library run on EU-based infrastructure (Hetzner in Germany/Finland); recordings are stored in Microsoft Azure Blob Storage and metadata in a managed PostgreSQL database.
- Recording bot (Attendee) — a self-hosted bot service that joins meetings on your behalf to capture audio and video.
- Transcription and speaker recognition providers — audio is sent to RunPod-hosted transcription and diarization models to produce transcripts and voiceprints. RunPod processes audio as our processor and does not use it for its own purposes.
- Microsoft and Google — calendar and meeting-platform integrations and, where configured, Microsoft Entra ID for sign-in.
Where a sub-processor is located outside the European Economic Area, transfers are protected under GDPR Chapter V (the EU-US Data Privacy Framework and/or Standard Contractual Clauses).
7. Retention and Deletion
Recordings, transcripts, and the derived data described above are retained only as long as needed to provide the service:
- Recordings — retained for the period configured by your organization, after which they are automatically deleted by a scheduled retention job. Share links can be set to expire and can be revoked at any time, which ends access for public and guest recipients.
- Transcripts — retained alongside their recording and deleted with it.
- Voiceprints / speaker embeddings — retained only for as long as speaker recognition is enabled and consent is in place; they are deleted when speaker recognition is turned off for the individual or organization, or on request.
- Calendar data — event data is refreshed from the connected calendar and removed when you disconnect the calendar.
You may request deletion of a specific recording, transcript, or voiceprint at any time by contacting privacy@softimply.tech. Deletion removes the media from storage and the associated records from our database.
8. Data Security
- All data is transmitted over HTTPS with TLS 1.2 or higher.
- Recordings are stored in private Azure Blob Storage containers with no public access; playback uses short-lived, signed URLs.
- Access to the application is gated by Microsoft Entra ID or password sign-in and a role-based permission model; guests are confined to recordings explicitly shared with them.
- Provider credentials are stored encrypted at rest.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your Rights
Under the GDPR you have the rights of access, rectification, erasure, restriction, data portability, objection, and to withdraw consent. You may also lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at www.aki.ee. To exercise any right, email privacy@softimply.tech; we respond within 30 days. Full detail is in our GDPR Data Processing Policy.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be posted on this page with an updated effective date.
See also: Terms of Service · GDPR Data Processing Policy