Skip to content
Audiobly OÜ · Legal

Privacy Policy

What personal data Audiobly handles, why, on what legal basis, who it goes to, how long we keep it, and what you can ask us to do about it.

Last updated
5 September 2026
Controller
Audiobly OÜ, Tallinn
Hosting
Germany (EU)
Supervisory authority
Andmekaitse Inspektsioon
Contact
privacy@audiobly.com

Audiobly OÜ (“Audiobly”, “we”, “us”) is a company registered in Estonia (registry code 17550070), with its registered office at Ahtri 12, Tallinn 15551, Estonia.

This policy covers our website (audiobly.com), the Audiobly platform and its API, the public registration and delegate pages we host on behalf of event organisers, and our sales and support communications.

Two things are worth reading before anything else.

We handle most personal data on behalf of our customers, not for ourselves. If you attended, spoke at, sponsored or registered for an event, the event organiser — not Audiobly — decides why your data is processed. Section 2 explains what that means for you, and section 12 tells you who to contact.
Audiobly processes recordings of what people said. Speech is personal data, and it is often unstructured and unpredictable. Section 5 sets out exactly what we do with audio, video and transcripts, including the automated redaction that runs before a human ever reads them.

01Who this policy is for

If you are…Read especially
A user of the Audiobly platform — an organiser, editor, analyst or administrator at a customer organisation§§ 3.1, 4, 9, 10, 11
A website visitor, or someone who contacts us about the product§§ 3.1, 4, 10, 13
An event attendee, delegate, speaker or sponsor contact whose data reached us through an organiser§§ 2, 3.2, 5, 6, 7, 8, 12

02Our two roles: controller and processor

Audiobly acts in two distinct capacities, and your rights differ depending on which one applies.

Controller for the data we decide the purposes of ourselves: platform user accounts and authentication, billing and account administration, our website, our marketing and sales contacts, support enquiries, and the security and operational logs we keep to run the service safely.

Processor for everything our customers put into the platform or generate with it: event audio and video, transcripts and their edits, speaker and attendee rosters, registration and ticketing records, analyses, generated content and reports. Our customer — the event organiser or media owner — is the controller of that data. We process it only on their documented instructions, under a data processing agreement, and for no independent purpose of our own.

Where we act as a processor, the organiser’s own privacy notice governs why your data was collected and how it is used. We can act on a request about that data only where the organiser instructs us to, or where the law requires us to act directly. We will always pass your request on to them and tell you we have done so.

03What personal data we process

3.1 As controller Controller

CategoryExamplesWhere it comes from
Account and identity dataName, work email address, organisation, role and permissions, password (stored only as an Argon2id hash), password-change historyYou, or an administrator at your organisation
Authentication and session dataSession records, refresh-token identifiers, IP address and browser user-agent at sign-in, sign-in timestamps, failed-attempt counters, API key identifiersGenerated when you use the service
Support and communications dataMessages you send us, the contents of enquiries, transactional email delivery recordsYou
Billing and commercial dataContracted plan, usage volumes, invoicing contacts, payment referencesYou and our payment providers
Website and operational dataPages requested, request identifiers, error and job logs, timing and diagnostic dataGenerated automatically when you use the site or platform
Sales and marketing dataBusiness contact details of prospective customers, correspondence, publicly available company informationYou, your employer’s website, public business sources

3.2 As processor, on behalf of an event organiser Processor

What we hold depends on which service an organiser takes, and the difference is significant. Most organisers take the content service only: we receive recordings and the information needed to attribute what was said — speakers, sessions and, at most, a delegate list of names, job titles and employers. For those organisers we never process registrations, orders or payment data, because we do not run their registration. Where an organiser also takes the registration and ticketing service — the public registration and delegate pages we host — the last three categories below additionally apply. The rows are marked accordingly.

CategoryExamples
Recorded contentEvent and session audio, video, and — where the organiser connects a conferencing or streaming source — live captured or streamed audio
Transcripts and derived textVerbatim transcripts, speaker-diarised segments, timestamps, editorial corrections and suggestions, glossary and terminology matches, extracted quotes
Analyses and generated assetsTopics, themes, named entities, sentiment (overall, per speaker and over time), summaries, articles, and branded PDF reports
Speaker and participant dataNames, honorifics, job titles, employers, biographies, session roles, photographs and links supplied by the organiser or published by the speaker
Attendee and delegate data — registration service only, except a delegate listName, email address, phone number, employer, job title, delegate type, country, dietary or accessibility notes and other free-text answers, marketing and lead-sharing consent flags, registration source and campaign attribution
Registration, ticketing and access data — registration service onlyOrders, ticket types, promotional codes, invitation codes, payment references and amounts, session registrations, check-in and attendance records. None of this arises for an organiser who does not take the registration and ticketing service
Contact graph dataA deduplicated cross-event record of a person within that organiser’s tenant, and the employer profile it resolves to
Integration and connection dataCredentials for conferencing and capture providers the organiser connects (encrypted at rest), and data imported from registration, CRM or agenda systems the organiser chooses to connect

We do not ask organisers for special-category data — health, religion, political opinion, biometric or similar — and the platform has no feature that requires it. Free-text fields, though, can contain it: a dietary note, an accessibility request, or something said out loud in a session. Where that happens we process it only as part of the content the organiser gave us, on their instructions and legal basis, and our redaction controls (§ 5) apply.

04Why we process personal data, and our legal basis

Where we are a controller:

PurposeLegal basis
Providing the platform to our customer and the people it authorises to use itPerformance of a contract (Art. 6(1)(b)), or our legitimate interest in serving our customer where you are that customer’s staff member (Art. 6(1)(f))
Authenticating users, protecting accounts, rate limiting, detecting and preventing abuseLegitimate interests (Art. 6(1)(f)) — running a secure service
Support, service notifications and administrationContract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f))
Operating, monitoring, debugging and improving the serviceLegitimate interests (Art. 6(1)(f)) — a working, reliable product
Billing, accounting, tax and corporate recordsLegal obligation (Art. 6(1)(c)) and contract (Art. 6(1)(b))
Business-to-business marketing to prospective customersLegitimate interests (Art. 6(1)(f)), or consent where local law requires it. You can object or unsubscribe at any time
Responding to legal claims, regulators and lawful requestsLegal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f))

Where we are a processor, the organiser is responsible for identifying the legal basis for collecting and using event content, attendee data and recordings, and for giving participants notice — including notice that a session is being recorded and transcribed. Our contract requires them to have that basis in place before sending us the data.

05Audio, video and transcripts

This is the heart of what Audiobly does, so we set it out precisely.

What we receive. Audio and video files that an organiser uploads, or that we capture from a conferencing or streaming source the organiser connects. A recording of a conference session typically contains the voices of speakers, moderators and, where there is audience participation, attendees.

What we do with it. We store the media, convert speech to text using a specialist speech recognition service, separate speakers, clean the transcript, apply the organiser’s terminology, run automated personal-data detection over it, make it available to reviewers for correction, and then generate analyses, summaries, articles and reports from the approved text.

Automated detection and redaction. Before a transcript reaches a human reviewer, an automated detection pass runs over it. By default it redacts email addresses, telephone numbers, payment card numbers, bank account numbers (IBAN), national identifiers and IP addresses, replacing each with a placeholder such as [EMAIL] — and flags person and organisation names for a human decision rather than removing them, since a conference transcript in which every speaker’s name has been deleted is useless to the customer who commissioned it. Each organiser can tighten or relax this policy per category, and can require human review before a transcript proceeds. Our redaction audit log records what category was redacted and where, as a salted hash and a placeholder; it never stores the removed text itself.

Who can read a transcript. Users the organiser has authorised in their own tenant, and — where the organiser has engaged us for editorial review — Audiobly editorial staff assigned to that event. Access to transcripts and audio by editorial staff is logged. Tenants are isolated from one another in the database at the row level, so one customer’s staff cannot reach another customer’s content.

Consent to record. Audiobly does not obtain consent to record on anyone’s behalf, and cannot. The organiser is responsible for notifying participants that a session is recorded and transcribed, and for having a lawful basis to do so. If you were recorded at an event and want that addressed, contact the organiser — see § 12.

06Artificial intelligence

Audiobly uses machine learning and large language models to do the work the product exists to do. You should know exactly where.

Where AI is used: converting speech to text and separating speakers; detecting personal data in transcripts; suggesting corrections to a transcript; extracting topics, themes, entities, sentiment and quotes; classifying job titles into seniority and function; drafting summaries, articles and report narratives; matching a company name to its website and building an employer profile.

Where AI is not used: we do not use AI to make decisions about individuals that produce legal effects or similarly significant effects on them (see § 7). We do not use it to infer special categories of data about participants.

Training. We do not use customer content — audio, video, transcripts, attendee data or generated assets — to train, fine-tune or improve any general-purpose AI model, our own or anyone else’s. Our agreements with the AI and speech providers we use require that content sent to them through our integrations is not used to train their models and is not retained beyond what is needed to return a result. Where we improve our own product from usage, we do so from aggregated, non-identifying operational statistics.

Accuracy. Speech recognition and language models make mistakes. Transcripts, analyses and generated reports may contain errors, including misattributed speech. That is why the platform is built around a human review and approval step, and why nothing is presented as a verbatim record until a person has approved it. If a transcript or report says something inaccurate about you, you have a right to have it corrected — see §§ 11 and 12.

07Profiling and automated decision-making

The platform derives scores and classifications about people and companies from event data: a seniority and function classification from a job title, a per-attendee relevance score for a session, an aggregate measure of how well an audience matched the content, a company-level loyalty or churn-risk indicator, and buyer–seller matching between attendee interest and sponsor offerings. These are deterministic calculations over data the organiser already holds, presented to the organiser as analysis.

No solely automated decisions with legal or similarly significant effects are made about you by Audiobly. These outputs inform human judgement about programming, sponsorship and audience development. They do not determine access, pricing, employment, credit or any comparable outcome.

Where an organiser has enabled sponsor lead sharing, an individual delegate’s contact details are released to a sponsor only where that delegate’s marketing consent is recorded as given. Delegates who did not opt in are represented at company level only, never individually.

08Who we share personal data with

We do not sell personal data. We do not share it for third-party advertising.

With the event organiser and those they authorise. As processor, we make event content and participant data available to the organiser’s own users, and — at their instruction — to sponsors and exhibitors through sponsor-facing views and to delegates through the delegate portal, subject to the consent gate described in § 7.

With service providers acting on our instructions. We use a small number of specialist providers to run the service. They act only on our documented instructions, under written contracts containing the protections required by Article 28 GDPR, and may not use the data for their own purposes.

Category of providerWhat they receiveWhere processedTransfer safeguard
Cloud infrastructure and object storageAll hosted platform data: databases, media files, generated assetsFinland and Germany (EU)Not applicable — processed in the EU
Offsite backup providerEncrypted backup copies of the databases and of stored mediaIreland (EU)Not applicable — stored in the EU
Speech-to-text providerEvent audio and video, and the resulting transcriptEuropean Economic AreaNot applicable — processed in the EEA
Large language model providerTranscript text and analysis promptsEuropean Economic AreaNot applicable — processed in the EEA
Text embedding providerTerminology and transcript-derived text fragmentsEuropean Economic AreaNot applicable — processed in the EEA
Transactional email providerRecipient name and email address, and the content of account and service notificationsEEA / United StatesStandard Contractual Clauses, and certification under the EU–US Data Privacy Framework where the provider holds it
Payment providers — registration service onlyOrder reference, amount, currency, and the payer details needed to take payment. Not engaged at all for organisers who do not take the registration and ticketing serviceEEA / United KingdomAdequacy decision and/or Standard Contractual Clauses
Company and logo enrichment servicesA company name or website domain — not participant personal dataEEA / United StatesStandard Contractual Clauses where applicable

We maintain a current list naming each of these providers. Customers receive it as part of their data processing agreement and are notified before we add a new one; anyone else may request it at privacy@audiobly.com.

With conferencing and business systems you connect. If an organiser connects a conferencing, registration, agenda or CRM system, data flows between that system and Audiobly as the organiser configures. Those systems are governed by their own privacy notices and, in most cases, by the organiser’s contract with them rather than ours.

With professional advisers, acquirers and authorities. We may disclose personal data to our auditors and legal advisers under confidentiality, to a buyer or successor in a merger or acquisition (with notice to affected customers), and to courts, regulators or law enforcement where we are legally required to. We assess every such request, disclose no more than is required, and notify the affected customer unless legally prohibited from doing so.

09International transfers

Our application servers and platform databases are hosted in Finland, our media and generated-asset storage in Germany, and our encrypted offsite backups in Ireland — all within the European Union. Speech recognition, language model generation and embedding are each carried out on EEA-hosted endpoints. Customer content does not leave the EEA for hosting, storage or processing.

Where you or your organisation are in the United Kingdom, personal data moving between the UK and the EEA in either direction travels under the adequacy decisions in force. The European Commission renewed its adequacy decisions for the United Kingdom on 19 December 2025, running to 27 December 2031, and the United Kingdom recognises the EEA as adequate, so no additional transfer mechanism is required for that leg.

Customer content is processed within the EEA. Recordings, transcripts, analyses and generated assets are processed and stored on infrastructure and provider endpoints inside the European Economic Area, and our agreements with each provider prohibit the use of customer content to train their models. The providers, what each receives and where each processes are listed in § 8.

Two limited categories sit outside that. Account and service email — the name and business email address of your own platform users, and the notification or password-reset link sent to them — is handled by a transactional email provider in the United States under the Standard Contractual Clauses and EU–US Data Privacy Framework. It carries no event content and no attendee or speaker data. Payment processing, where an organiser takes our registration and ticketing service, runs through the providers in § 8. Where personal data is transferred outside the EEA we rely on the Standard Contractual Clauses, supplemented by encryption in transit, contractual restrictions on retention and on model training, and a transfer risk assessment. You may request a summary of these safeguards at privacy@audiobly.com.

10How long we keep personal data

DataRetention
Event content processed as a processor — media, transcripts, analyses, rosters, registrationsFor the period the organiser configures on their account, 365 days from creation by default, after which the event, its associated records and its stored files are permanently deleted. Deletion at the organiser’s instruction happens on request, ahead of that period.
Data export files generated on request7 days, then automatically expired
Platform user accounts and authentication recordsFor the life of the account. Sign-in sessions expire after 30 days of inactivity, access tokens after 15 minutes, password-reset links after 60 minutes
Support correspondenceFor the duration of the customer relationship and a reasonable period afterwards for reference and dispute handling
Billing, invoicing and accounting recordsAs required by Estonian accounting and tax law — generally 7 years
Security, audit and operational logsFor as long as needed to investigate incidents, meet audit obligations and keep the service reliable
Marketing contact data for prospective customersUntil you object or unsubscribe, and reviewed periodically for continued relevance

When a customer’s contract ends, we return or delete the personal data we hold as processor in accordance with that contract, and we record the deletion so it can be evidenced. Deleting an event removes its database records and its stored media and generated files together.

11Security

We protect personal data with measures appropriate to its sensitivity, including:

  • Tenant isolation enforced in the database. Row-level security policies constrain every query to the tenant it belongs to, so a customer’s data cannot be reached from another customer’s session, independent of application logic.
  • Role-based access control across the platform, with permissions granted per organisation and per role, and platform-staff access separated from customer administration.
  • Encryption in transit for all traffic to and between our services, and encryption at rest for stored third-party credentials.
  • Argon2id password hashing, password-reuse prevention, throttling and lockout on repeated failed sign-ins, short-lived access tokens with server-side revocable sessions, and refresh tokens held only in HTTP-only, Secure, SameSite=Strict cookies scoped to the authentication endpoints.
  • Automated personal-data redaction in the transcript pipeline (§ 5), with an audit log that stores hashes rather than the redacted text.
  • Access logging for editorial access to transcripts and audio.
  • Backups and restore testing for the databases and object storage that hold customer content.

No system is perfectly secure. If we become aware of a personal data breach we will notify the affected customer without undue delay and in any event within the period our contract requires, and notify the supervisory authority and affected individuals where the law requires it. To report a vulnerability or a suspected breach, write to privacy@audiobly.com.

Note that brand assets — logos and similar images uploaded for report branding — are served from a public URL so they can be embedded in generated documents. Do not upload personal photographs or confidential images as brand assets.

12Your rights

Under the GDPR you have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing (including objecting to direct marketing at any time, and to processing based on legitimate interests), to data portability, and to withdraw consent where processing relies on it. Withdrawal does not affect processing already carried out.

How to exercise them. Email privacy@audiobly.com. We will respond within one month, and will tell you if we need to extend that by up to two further months because a request is complex. We do not charge a fee unless a request is manifestly unfounded or excessive. We may ask for information to confirm your identity, and we will use it only for that purpose.

If your data reached us through an event organiser, that organiser is the controller — send your request to them. If you send it to us instead, we will forward it to the organiser without undue delay and tell you we have done so, and we will assist them in answering it. We cannot delete or alter an organiser’s records on our own initiative.

Complaints. You can complain to us first — we would like the chance to put things right — and you have the right to complain to a supervisory authority. Ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee). You may also complain to the authority in your own country of residence or work.

13Cookies and similar technologies

The Audiobly application uses strictly necessary cookies only: a single HTTP-only refresh-token cookie, scoped to the authentication endpoints, that keeps you signed in. Your access token is held in browser memory and is discarded when the tab closes. We do not use advertising cookies, cross-site tracking, web beacons or third-party analytics on the platform, so no consent banner is required for it.

Public registration and delegate pages we host on behalf of an organiser record how a registration was referred — campaign attribution — where the organiser has configured it. That information forms part of the registration record the organiser controls.

If we later introduce optional analytics, we will ask for your consent first and update this policy before doing so.

14Children

Audiobly is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. Where an organiser’s event admits participants under 16, that organiser is responsible for obtaining any parental consent required. If you believe we hold data about a child, tell us at privacy@audiobly.com and we will delete it or refer it to the responsible organiser.

15Changes to this policy

We review this policy regularly. When we make a material change we will update the date at the top, publish the new version, and notify platform administrators by email or in-app notice before it takes effect. Continued use of the service after a change takes effect means the updated policy applies.

16How to contact us

Privacy enquiries, data subject requests and security reports: privacy@audiobly.com.

Audiobly OÜ · Ahtri 12, Tallinn 15551, Estonia · Registry code 17550070

privacy@audiobly.com

Andmekaitse Inspektsioon · Tatari 39, 10134 Tallinn, Estonia · www.aki.ee