Security
What happens to a recording from the moment it reaches us, and who — apart from us — is entrusted with any part of it.
Three things we promise outright
We show the audio path plainly
The current transcription mode is shown below. In local mode, audio does not leave Talkenda's hosting. If external inference is enabled later, its company and data scope appear here automatically from the same configuration that routes the file.
We do not train on meeting content
Talkenda does not create a training dataset from recordings, transcripts or notes. An external model may go live only after its terms confirm the training restriction, retention, location and full downstream sub-processor chain.
Summaries can be switched off entirely
The service has a mode without an external model: it produces a transcript but no summary. We do not yet promise a per-account switch — this is currently a deployment-wide setting.
Current data configuration
This status is calculated on every page view from safe runtime flags. Secrets, tokens and private service addresses are never exposed.
- Transcription and diarization:
- Talkenda's own worker in Poland over a private encrypted tunnel; no new company in the chain
- Summaries:
- Talkenda's own model in Poland over a private encrypted tunnel; the transcript is not sent to another company
Who is entrusted with meeting content
This table contains only companies enabled in this deployment that store or receive audio, transcripts or notes. A provider merely available in the code is not presented as active.
| Company | Role | Registered office and data | What it receives |
|---|---|---|---|
| OVHcloud (hosting) | Hosting for the app, database, files and operational logs | Registered office: France; declared deployment: EU, exact data centre requires evidence from the OVH order | Account, calendar and meeting data, including recording files |
Account, calendar, payment and messaging data
This is a separate list of active integrations. We do not send them audio, transcripts or notes, but they may process account, event, billing or correspondence data.
| Company | Role | Registered office and data | What it receives |
|---|---|---|---|
| OAuth sign-in and reading a connected Google Calendar | Google infrastructure; location depends on the user's account and service | Profile, email, OAuth tokens and event data; no audio or transcripts | |
| Stripe | Checkout, subscriptions, payments and invoices | For the EEA: Stripe Payments Europe, Ireland; global processing, including the US | Account, billing, device and payment data; no meeting content |
| OVHcloud (Zimbra email) | Transactional email delivery over SMTP | Headquarters: France; service location as specified in the OVHcloud agreement | Recipient address and message content, including password reset links |
The meeting platform is the customer's choice
Meet, Teams, Zoom, Webex or GoTo carries the conversation chosen by the customer. Talkenda sends the bot’s presence and display name when joining. The Data Processing Agreement and Privacy Policy describe customer-selected platforms and integrations.
We announce changes in advance
The Data Processing Agreement provides at least thirty days’ notice before adding or changing a sub-processor and the opportunity to raise a reasoned objection. The published agreement sets out the detailed change and termination terms.
Data processing agreement
The Data Processing Agreement is published in Polish and English. You can read and download it before processing begins and before purchase. We record the version and time of acceptance.
Status calculated from the deployment's current configuration · Questions: kontakt@talkenda.com