Privacy Policy
Your calls stay in the EU.
Here's the rest.
Draft dated 16 August 2026 · not yet in force
1. Who's responsible
TalkWith is operated by [Contracting entity — TBD]. For your account data (name, email, billing details, usage) we are the controller. For the calls your product carries — the participants, the media, any recordings — you are the controller and we are your processor, acting on your instructions.
2. What we collect, and why
- Account data — name, email, organization, and Stripe billing details. Needed to run your account and bill you (contract).
- Usage metering — participant-minutes, monthly actives, peak concurrency, recording storage. Captured raw so your bill is honest (contract, legitimate interest).
- Call metadata — room names, participant identities your app supplies, timestamps, connection quality. Needed to route calls and debug them (contract).
- Call media — audio and video flow through our EU servers to reach the other participants. It is not stored unless you enable recording.
- Recordings — only when your project enables them; stored encrypted in EU object storage and deleted on your retention schedule (see §5).
We don't sell personal data, don't run advertising, and don't use your call content to train AI models.
3. Where data lives
EU data residency is a design constraint, not a plan tier: media servers, TURN relay, recordings, the database, and AI processing all run in the EU. The narrow exceptions are in the subprocessor list below (e.g. payments), and where a subprocessor processes limited data outside the EU, transfers rely on standard contractual clauses. [Verify per-vendor — legal review.]
4. Subprocessors
The complete list of third parties that may process personal data on our behalf:
| Subprocessor | Purpose | Region |
|---|---|---|
| Hetzner Online GmbH | Media servers — call routing and TURN relay | Germany (Nuremberg) |
| Amazon Web Services (eu-central-1) | Control plane, APIs, token minting, dashboard hosting | Germany (Frankfurt) |
| Neon | Managed Postgres — account, project, and usage data | EU (Frankfurt) |
| Stripe | Payments — card details never touch our servers | EU/US (payment data only) |
| Cloudflare R2 (EU jurisdiction) | Recording storage, when you enable recording | EU |
| Grafana Cloud | Operational metrics, logs, and alerting | EU region |
| AWS Bedrock (EU) | AI processing for transcription and summaries — coming soon | EU |
We'll update this list before adding a subprocessor, with notice to account owners.
5. How long we keep things
- Live call media: not retained. It passes through our servers and is gone when the call ends.
- Recordings: kept for your project's retention window —30 days by default, configurable per project — then deleted automatically. Deleting a project deletes its recordings.
- Transcripts and AI summaries (when those features ship): same consent and retention rules as recordings.
- Usage and billing records: kept while your account is open and then as long as tax and accounting law requires.
- Account data: deleted within 30 days of account closure, except what the law requires us to keep.
6. Your rights
Under the GDPR you can ask us for access to, correction of, deletion of, or a portable copy of your personal data, and you can object to or restrict certain processing. Write to [Contact email — TBD] and we'll respond within a month. If you're a participant in a call run by one of our customers, the customer is the controller — we'll route your request to them. You can also complain to your local data-protection authority.
7. Security
Media is encrypted in transit; recordings are encrypted at rest; secret API keys are hashed and shown once. Access to production data is limited to what operating the service requires. If a breach affects your data, we'll notify you without undue delay.
8. Changes and contact
Material changes to this policy get 30 days' email notice. Questions: [Contact email — TBD] · [Contracting entity — TBD], [registered address — TBD].