Privacy Policy
What personal data Audiobly handles, why, on what legal basis, who it goes to, how long we keep it, and what you can ask us to do about it.
Audiobly OÜ (“Audiobly”, “we”, “us”) is a company registered in Estonia (registry code 17550070), with its registered office at Ahtri 12, Tallinn 15551, Estonia.
This policy covers our website (audiobly.com), the Audiobly platform and its API, the public registration and delegate pages we host on behalf of event organisers, and our sales and support communications.
Two things are worth reading before anything else.
01Who this policy is for
| If you are… | Read especially |
|---|---|
| A user of the Audiobly platform — an organiser, editor, analyst or administrator at a customer organisation | §§ 3.1, 4, 9, 10, 11 |
| A website visitor, or someone who contacts us about the product | §§ 3.1, 4, 10, 13 |
| An event attendee, delegate, speaker or sponsor contact whose data reached us through an organiser | §§ 2, 3.2, 5, 6, 7, 8, 12 |
02Our two roles: controller and processor
Audiobly acts in two distinct capacities, and your rights differ depending on which one applies.
Controller for the data we decide the purposes of ourselves: platform user accounts and authentication, billing and account administration, our website, our marketing and sales contacts, support enquiries, and the security and operational logs we keep to run the service safely.
Processor for everything our customers put into the platform or generate with it: event audio and video, transcripts and their edits, speaker and attendee rosters, registration and ticketing records, analyses, generated content and reports. Our customer — the event organiser or media owner — is the controller of that data. We process it only on their documented instructions, under a data processing agreement, and for no independent purpose of our own.
Where we act as a processor, the organiser’s own privacy notice governs why your data was collected and how it is used. We can act on a request about that data only where the organiser instructs us to, or where the law requires us to act directly. We will always pass your request on to them and tell you we have done so.
03What personal data we process
3.1 As controller Controller
| Category | Examples | Where it comes from |
|---|---|---|
| Account and identity data | Name, work email address, organisation, role and permissions, password (stored only as an Argon2id hash), password-change history | You, or an administrator at your organisation |
| Authentication and session data | Session records, refresh-token identifiers, IP address and browser user-agent at sign-in, sign-in timestamps, failed-attempt counters, API key identifiers | Generated when you use the service |
| Support and communications data | Messages you send us, the contents of enquiries, transactional email delivery records | You |
| Billing and commercial data | Contracted plan, usage volumes, invoicing contacts, payment references | You and our payment providers |
| Website and operational data | Pages requested, request identifiers, error and job logs, timing and diagnostic data | Generated automatically when you use the site or platform |
| Sales and marketing data | Business contact details of prospective customers, correspondence, publicly available company information | You, your employer’s website, public business sources |
3.2 As processor, on behalf of an event organiser Processor
What we hold depends on which service an organiser takes, and the difference is significant. Most organisers take the content service only: we receive recordings and the information needed to attribute what was said — speakers, sessions and, at most, a delegate list of names, job titles and employers. For those organisers we never process registrations, orders or payment data, because we do not run their registration. Where an organiser also takes the registration and ticketing service — the public registration and delegate pages we host — the last three categories below additionally apply. The rows are marked accordingly.
| Category | Examples |
|---|---|
| Recorded content | Event and session audio, video, and — where the organiser connects a conferencing or streaming source — live captured or streamed audio |
| Transcripts and derived text | Verbatim transcripts, speaker-diarised segments, timestamps, editorial corrections and suggestions, glossary and terminology matches, extracted quotes |
| Analyses and generated assets | Topics, themes, named entities, sentiment (overall, per speaker and over time), summaries, articles, and branded PDF reports |
| Speaker and participant data | Names, honorifics, job titles, employers, biographies, session roles, photographs and links supplied by the organiser or published by the speaker |
| Attendee and delegate data — registration service only, except a delegate list | Name, email address, phone number, employer, job title, delegate type, country, dietary or accessibility notes and other free-text answers, marketing and lead-sharing consent flags, registration source and campaign attribution |
| Registration, ticketing and access data — registration service only | Orders, ticket types, promotional codes, invitation codes, payment references and amounts, session registrations, check-in and attendance records. None of this arises for an organiser who does not take the registration and ticketing service |
| Contact graph data | A deduplicated cross-event record of a person within that organiser’s tenant, and the employer profile it resolves to |
| Integration and connection data | Credentials for conferencing and capture providers the organiser connects (encrypted at rest), and data imported from registration, CRM or agenda systems the organiser chooses to connect |
We do not ask organisers for special-category data — health, religion, political opinion, biometric or similar — and the platform has no feature that requires it. Free-text fields, though, can contain it: a dietary note, an accessibility request, or something said out loud in a session. Where that happens we process it only as part of the content the organiser gave us, on their instructions and legal basis, and our redaction controls (§ 5) apply.
04Why we process personal data, and our legal basis
Where we are a controller:
| Purpose | Legal basis |
|---|---|
| Providing the platform to our customer and the people it authorises to use it | Performance of a contract (Art. 6(1)(b)), or our legitimate interest in serving our customer where you are that customer’s staff member (Art. 6(1)(f)) |
| Authenticating users, protecting accounts, rate limiting, detecting and preventing abuse | Legitimate interests (Art. 6(1)(f)) — running a secure service |
| Support, service notifications and administration | Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) |
| Operating, monitoring, debugging and improving the service | Legitimate interests (Art. 6(1)(f)) — a working, reliable product |
| Billing, accounting, tax and corporate records | Legal obligation (Art. 6(1)(c)) and contract (Art. 6(1)(b)) |
| Business-to-business marketing to prospective customers | Legitimate interests (Art. 6(1)(f)), or consent where local law requires it. You can object or unsubscribe at any time |
| Responding to legal claims, regulators and lawful requests | Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) |
Where we are a processor, the organiser is responsible for identifying the legal basis for collecting and using event content, attendee data and recordings, and for giving participants notice — including notice that a session is being recorded and transcribed. Our contract requires them to have that basis in place before sending us the data.
05Audio, video and transcripts
This is the heart of what Audiobly does, so we set it out precisely.
What we receive. Audio and video files that an organiser uploads, or that we capture from a conferencing or streaming source the organiser connects. A recording of a conference session typically contains the voices of speakers, moderators and, where there is audience participation, attendees.
What we do with it. We store the media, convert speech to text using a specialist speech recognition service, separate speakers, clean the transcript, apply the organiser’s terminology, run automated personal-data detection over it, make it available to reviewers for correction, and then generate analyses, summaries, articles and reports from the approved text.
Automated detection and redaction. Before a transcript reaches a human reviewer, an automated detection pass runs over it. By default it redacts email addresses, telephone numbers, payment card numbers, bank account numbers (IBAN), national identifiers and IP addresses, replacing each with a placeholder such as [EMAIL] — and flags person and organisation names for a human decision rather than removing them, since a conference transcript in which every speaker’s name has been deleted is useless to the customer who commissioned it. Each organiser can tighten or relax this policy per category, and can require human review before a transcript proceeds. Our redaction audit log records what category was redacted and where, as a salted hash and a placeholder; it never stores the removed text itself.
Who can read a transcript. Users the organiser has authorised in their own tenant, and — where the organiser has engaged us for editorial review — Audiobly editorial staff assigned to that event. Access to transcripts and audio by editorial staff is logged. Tenants are isolated from one another in the database at the row level, so one customer’s staff cannot reach another customer’s content.
06Artificial intelligence
Audiobly uses machine learning and large language models to do the work the product exists to do. You should know exactly where.
Where AI is used: converting speech to text and separating speakers; detecting personal data in transcripts; suggesting corrections to a transcript; extracting topics, themes, entities, sentiment and quotes; classifying job titles into seniority and function; drafting summaries, articles and report narratives; matching a company name to its website and building an employer profile.
Where AI is not used: we do not use AI to make decisions about individuals that produce legal effects or similarly significant effects on them (see § 7). We do not use it to infer special categories of data about participants.
Accuracy. Speech recognition and language models make mistakes. Transcripts, analyses and generated reports may contain errors, including misattributed speech. That is why the platform is built around a human review and approval step, and why nothing is presented as a verbatim record until a person has approved it. If a transcript or report says something inaccurate about you, you have a right to have it corrected — see §§ 11 and 12.
07Profiling and automated decision-making
The platform derives scores and classifications about people and companies from event data: a seniority and function classification from a job title, a per-attendee relevance score for a session, an aggregate measure of how well an audience matched the content, a company-level loyalty or churn-risk indicator, and buyer–seller matching between attendee interest and sponsor offerings. These are deterministic calculations over data the organiser already holds, presented to the organiser as analysis.
Where an organiser has enabled sponsor lead sharing, an individual delegate’s contact details are released to a sponsor only where that delegate’s marketing consent is recorded as given. Delegates who did not opt in are represented at company level only, never individually.
08Who we share personal data with
We do not sell personal data. We do not share it for third-party advertising.
With the event organiser and those they authorise. As processor, we make event content and participant data available to the organiser’s own users, and — at their instruction — to sponsors and exhibitors through sponsor-facing views and to delegates through the delegate portal, subject to the consent gate described in § 7.
With service providers acting on our instructions. We use a small number of specialist providers to run the service. They act only on our documented instructions, under written contracts containing the protections required by Article 28 GDPR, and may not use the data for their own purposes.
| Category of provider | What they receive | Where processed | Transfer safeguard |
|---|---|---|---|
| Cloud infrastructure and object storage | All hosted platform data: databases, media files, generated assets | Finland and Germany (EU) | Not applicable — processed in the EU |
| Offsite backup provider | Encrypted backup copies of the databases and of stored media | Ireland (EU) | Not applicable — stored in the EU |
| Speech-to-text provider | Event audio and video, and the resulting transcript | European Economic Area | Not applicable — processed in the EEA |
| Large language model provider | Transcript text and analysis prompts | European Economic Area | Not applicable — processed in the EEA |
| Text embedding provider | Terminology and transcript-derived text fragments | European Economic Area | Not applicable — processed in the EEA |
| Transactional email provider | Recipient name and email address, and the content of account and service notifications | EEA / United States | Standard Contractual Clauses, and certification under the EU–US Data Privacy Framework where the provider holds it |
| Payment providers — registration service only | Order reference, amount, currency, and the payer details needed to take payment. Not engaged at all for organisers who do not take the registration and ticketing service | EEA / United Kingdom | Adequacy decision and/or Standard Contractual Clauses |
| Company and logo enrichment services | A company name or website domain — not participant personal data | EEA / United States | Standard Contractual Clauses where applicable |
We maintain a current list naming each of these providers. Customers receive it as part of their data processing agreement and are notified before we add a new one; anyone else may request it at privacy@audiobly.com.
With conferencing and business systems you connect. If an organiser connects a conferencing, registration, agenda or CRM system, data flows between that system and Audiobly as the organiser configures. Those systems are governed by their own privacy notices and, in most cases, by the organiser’s contract with them rather than ours.
With professional advisers, acquirers and authorities. We may disclose personal data to our auditors and legal advisers under confidentiality, to a buyer or successor in a merger or acquisition (with notice to affected customers), and to courts, regulators or law enforcement where we are legally required to. We assess every such request, disclose no more than is required, and notify the affected customer unless legally prohibited from doing so.
09International transfers
Our application servers and platform databases are hosted in Finland, our media and generated-asset storage in Germany, and our encrypted offsite backups in Ireland — all within the European Union. Speech recognition, language model generation and embedding are each carried out on EEA-hosted endpoints. Customer content does not leave the EEA for hosting, storage or processing.
Where you or your organisation are in the United Kingdom, personal data moving between the UK and the EEA in either direction travels under the adequacy decisions in force. The European Commission renewed its adequacy decisions for the United Kingdom on 19 December 2025, running to 27 December 2031, and the United Kingdom recognises the EEA as adequate, so no additional transfer mechanism is required for that leg.
Customer content is processed within the EEA. Recordings, transcripts, analyses and generated assets are processed and stored on infrastructure and provider endpoints inside the European Economic Area, and our agreements with each provider prohibit the use of customer content to train their models. The providers, what each receives and where each processes are listed in § 8.
Two limited categories sit outside that. Account and service email — the name and business email address of your own platform users, and the notification or password-reset link sent to them — is handled by a transactional email provider in the United States under the Standard Contractual Clauses and EU–US Data Privacy Framework. It carries no event content and no attendee or speaker data. Payment processing, where an organiser takes our registration and ticketing service, runs through the providers in § 8. Where personal data is transferred outside the EEA we rely on the Standard Contractual Clauses, supplemented by encryption in transit, contractual restrictions on retention and on model training, and a transfer risk assessment. You may request a summary of these safeguards at privacy@audiobly.com.
10How long we keep personal data
| Data | Retention |
|---|---|
| Event content processed as a processor — media, transcripts, analyses, rosters, registrations | For the period the organiser configures on their account, 365 days from creation by default, after which the event, its associated records and its stored files are permanently deleted. Deletion at the organiser’s instruction happens on request, ahead of that period. |
| Data export files generated on request | 7 days, then automatically expired |
| Platform user accounts and authentication records | For the life of the account. Sign-in sessions expire after 30 days of inactivity, access tokens after 15 minutes, password-reset links after 60 minutes |
| Support correspondence | For the duration of the customer relationship and a reasonable period afterwards for reference and dispute handling |
| Billing, invoicing and accounting records | As required by Estonian accounting and tax law — generally 7 years |
| Security, audit and operational logs | For as long as needed to investigate incidents, meet audit obligations and keep the service reliable |
| Marketing contact data for prospective customers | Until you object or unsubscribe, and reviewed periodically for continued relevance |
When a customer’s contract ends, we return or delete the personal data we hold as processor in accordance with that contract, and we record the deletion so it can be evidenced. Deleting an event removes its database records and its stored media and generated files together.
11Security
We protect personal data with measures appropriate to its sensitivity, including:
- Tenant isolation enforced in the database. Row-level security policies constrain every query to the tenant it belongs to, so a customer’s data cannot be reached from another customer’s session, independent of application logic.
- Role-based access control across the platform, with permissions granted per organisation and per role, and platform-staff access separated from customer administration.
- Encryption in transit for all traffic to and between our services, and encryption at rest for stored third-party credentials.
- Argon2id password hashing, password-reuse prevention, throttling and lockout on repeated failed sign-ins, short-lived access tokens with server-side revocable sessions, and refresh tokens held only in HTTP-only, Secure, SameSite=Strict cookies scoped to the authentication endpoints.
- Automated personal-data redaction in the transcript pipeline (§ 5), with an audit log that stores hashes rather than the redacted text.
- Access logging for editorial access to transcripts and audio.
- Backups and restore testing for the databases and object storage that hold customer content.
No system is perfectly secure. If we become aware of a personal data breach we will notify the affected customer without undue delay and in any event within the period our contract requires, and notify the supervisory authority and affected individuals where the law requires it. To report a vulnerability or a suspected breach, write to privacy@audiobly.com.
Note that brand assets — logos and similar images uploaded for report branding — are served from a public URL so they can be embedded in generated documents. Do not upload personal photographs or confidential images as brand assets.
12Your rights
Under the GDPR you have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing (including objecting to direct marketing at any time, and to processing based on legitimate interests), to data portability, and to withdraw consent where processing relies on it. Withdrawal does not affect processing already carried out.
How to exercise them. Email privacy@audiobly.com. We will respond within one month, and will tell you if we need to extend that by up to two further months because a request is complex. We do not charge a fee unless a request is manifestly unfounded or excessive. We may ask for information to confirm your identity, and we will use it only for that purpose.
Complaints. You can complain to us first — we would like the chance to put things right — and you have the right to complain to a supervisory authority. Ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee). You may also complain to the authority in your own country of residence or work.
13Cookies and similar technologies
The Audiobly application uses strictly necessary cookies only: a single HTTP-only refresh-token cookie, scoped to the authentication endpoints, that keeps you signed in. Your access token is held in browser memory and is discarded when the tab closes. We do not use advertising cookies, cross-site tracking, web beacons or third-party analytics on the platform, so no consent banner is required for it.
Public registration and delegate pages we host on behalf of an organiser record how a registration was referred — campaign attribution — where the organiser has configured it. That information forms part of the registration record the organiser controls.
If we later introduce optional analytics, we will ask for your consent first and update this policy before doing so.
14Children
Audiobly is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. Where an organiser’s event admits participants under 16, that organiser is responsible for obtaining any parental consent required. If you believe we hold data about a child, tell us at privacy@audiobly.com and we will delete it or refer it to the responsible organiser.
15Changes to this policy
We review this policy regularly. When we make a material change we will update the date at the top, publish the new version, and notify platform administrators by email or in-app notice before it takes effect. Continued use of the service after a change takes effect means the updated policy applies.
16How to contact us
Privacy enquiries, data subject requests and security reports: privacy@audiobly.com.
Audiobly OÜ · Ahtri 12, Tallinn 15551, Estonia · Registry code 17550070
Andmekaitse Inspektsioon · Tatari 39, 10134 Tallinn, Estonia · www.aki.ee
