Denne siden finnes bare på nederlandsk og engelsk. Bare den nederlandske versjonen er juridisk bindende. Nederlands
Privacy Policy
Last updated: 8 October 2026
Notulist records meetings, transcribes them and turns them into reports. That involves a lot of personal data: yours as a user, and that of everyone who speaks in a meeting. This policy explains which data we process, why, who we share it with, how long we keep it and what your rights are.
1. Who we are
Notulist is a service of KKX B.V., Keulenstraat 1, Deventer, the Netherlands, registered with the Dutch Chamber of Commerce under number 93019424 (“KKX”, “we”). Privacy questions go to hello@notulist.io.
This policy covers the website notulist.io, the web app, the apps for iPhone, Android and Mac, and the connections with other services (such as Claude, ChatGPT and Siri).
2. Two roles: controller and processor
The GDPR distinguishes the controller, who decides why and how data is processed, from the processor, who processes it on the controller’s behalf.
- KKX is the controller for your account, your sign-in details, data about your use of Notulist, the security of the service and your contact with us.
- KKX is a processor for the content of your meetings: recordings, transcripts, speakers, reports, tags, the people and companies in your library, your vocabulary, chats and search index. We process that data only to provide the service to you, following your instructions. If you use Notulist for business, your organisation (or you, as a self-employed professional) is the controller for that content, and our Data Processing Agreement applies. If your account belongs to an organisation in Notulist, that organisation is responsible for the content you record on its behalf.
Were you recorded in someone else’s meeting? Then the user who recorded it (or their organisation) decides about that recording. If you want access or deletion, contact that user first. If that doesn’t work, email us; we’ll help you or pass your request on.
3. What we process and why
| Data | Purpose | Legal basis |
|---|---|---|
| Account: name, email address, the ID of your Microsoft, Google or Apple account, language and other settings, your access request during the beta | Creating your account, signing in, setting up the service the way you want | Performance of the contract |
| Organisation: membership, role, invitations, verified domains, SCIM connection, audit log of admin changes | Running an organisation and giving its members access | Performance of the contract; for the organisation, its legitimate interest |
| Meeting content: audio, transcripts, speakers and their talk time, reports, tags, titles, people and companies (names, email addresses, descriptions), vocabulary, chats, search index | Providing the service: recording, transcribing, writing reports, searching, sharing | As a processor, on behalf of the user or organisation |
| Calendar (only if you connect one): events with title, times and invitees (name and email address), encrypted access keys | Linking a recording to an event, taking over its title and suggesting speakers | Performance of the contract; you can disconnect at any time |
| Sharing: who you share a meeting with and when | Giving read access and emailing the recipient | As a processor, on behalf of the user |
| Connected apps (such as Claude or ChatGPT via MCP): which app, which permissions, since when | Giving that app access to your meetings for as long as you want | Performance of the contract |
| Technical data: sign-in sessions with the type of device or browser, error reports, server logs | Securing the service, preventing abuse and fixing errors | Legitimate interest (a secure, working service) |
| Usage: number of meetings, hours recorded, last activity (no content) | Running and improving the service, monitoring capacity and costs, showing organisations their usage | Legitimate interest |
| Contact: your messages to us | Answering your question | Legitimate interest; performance of the contract |
We don’t sell your data, use it for advertising or build marketing profiles.
4. Recording, AI and automated processing
- Transcription. After a recording, we send the audio to ElevenLabs, which turns it into a transcript with speakers and timestamps. Your vocabulary is sent along so names and terms are spelled correctly.
- Reports, chat and suggestions. For reports, chat answers, titles, tags, speakers and vocabulary corrections, we send the necessary text to Anthropic (Claude). For speaker suggestions, names from your library and the invitees of a linked calendar event are included.
- Search. To search by meaning, we use OpenAI to create a mathematical representation (embedding) of passages from transcripts and reports.
- No training. KKX doesn’t use your data to train AI models, and under their terms for business customers, our AI providers don’t either.
- No biometrics. Notulist tells speakers apart from the conversation. We don’t create voiceprints or recognise anyone by their voice, so we don’t process biometric data.
- Suggestions, not decisions. Suggestions for speakers, tags and corrections are never applied automatically; you choose. Notulist makes no decisions about you that have legal effects or similarly significantly affect you.
- Check the result. Transcripts and reports are generated automatically and may contain errors.
5. Who we share data with
We use these providers (sub-processors). We have agreements with each of them to protect your data.
| Provider | Purpose | Location |
|---|---|---|
| Microsoft (Azure) | Hosting, database, audio storage | EU (Netherlands) |
| ElevenLabs | Transcription | United States |
| Anthropic | Reports, chat and suggestions (Claude) | United States |
| OpenAI | Embeddings for search | United States |
| Lettermint | Sending email | EU |
| Sentry | Error reports (with only a user ID, no content) | EU (Germany) |
Beyond that, we only share data:
- with whoever you choose: colleagues you share a meeting with, your organisation’s admins (who see usage numbers and manage accounts, but not the content of your meetings) and apps you connect yourself;
- with Microsoft, Google and Apple, as far as you sign in through them or connect your calendar; they are responsible for that themselves;
- when the law requires it, for example by court order.
KKX staff don’t look at the content of your meetings, unless you explicitly ask for that for a specific support request, or the law requires it.
6. Transfers outside the European Economic Area
ElevenLabs, Anthropic and OpenAI process data in the United States. These transfers are based on the EU-US Data Privacy Framework, where the provider is certified under it, and otherwise on the European Commission’s Standard Contractual Clauses with supplementary measures. You can ask us for a copy of these safeguards.
7. How long we keep data
| Data | Retention |
|---|---|
| Account and meeting content | As long as your account exists. You can delete meetings, reports and people yourself at any time. |
| After you delete your account | Your account is blocked at once and permanently deleted after 7 days. Backups and deleted audio are gone at most 14 days later. |
| Recordings that were never finished | 30 days; after that we keep a marker for 1 year, so your app knows the recording needs to be uploaded again |
| Download link of a data export | 7 days |
| Sign-in sessions | At most 90 days; expired sessions are deleted after 7 days |
| An organisation’s audit log | 1 year |
| Server logs | 30 days |
| Error reports (Sentry) | At most 90 days |
| At our AI providers | Only as long as needed to process the request and monitor abuse; at Anthropic and OpenAI at most 30 days |
| Contact with us | As long as needed to handle your question, and at most 2 years after that |
We keep data longer only when the law requires it, for example the 7-year tax retention period for invoices once there are paid plans.
8. Security
We take appropriate technical and organisational measures, including:
- all connections are encrypted (TLS), and data is stored encrypted;
- you sign in with Microsoft, Google or Apple; we don’t store passwords;
- sign-in and access keys are only stored hashed or encrypted, and sessions are short-lived and rotate;
- hosting and storage are in the EU, with backups that let us restore up to 14 days back;
- access to production systems is limited to the staff who need it.
Suspect a security problem? Let us know at hello@notulist.io.
9. Your rights
You have the right to access, correct and delete your data, to restrict processing, to data portability, and to object to processing based on legitimate interest. Much of this you can do yourself in the app:
- in Settings you can download all your data as a zip at any time, including audio;
- in Settings you can delete your account (with 7 days to change your mind);
- you can edit or delete meetings, reports, people and tags yourself.
For other requests, email hello@notulist.io. We respond within one month. If your request concerns meeting content someone else is responsible for, we pass it on or help that party handle it.
If you disagree with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the authority in your own country. We’d like to hear from you first, so we can solve it together.
10. Cookies and local storage
- Website (notulist.io): only a functional cookie
site_langif you pick a language yourself. No analytics, tracking or advertising cookies, and nothing is loaded from third parties. - Web app: only necessary cookies for your sign-in session, your language and the security of signing in. While you record, audio is temporarily kept in your browser so nothing is lost if it crashes.
- Apps: recordings stay on your device until they are uploaded. The apps ask for access to your microphone; the Mac app also for the audio of calling apps. The Mac app sees locally which app is using your microphone to detect a call; that information never leaves your Mac.
11. Google user data
If you connect your Google Calendar, Notulist only asks for read access (calendar.readonly). We use calendar data only to link recordings to events, take over titles and suggest speakers from the invitees. For those speaker suggestions, invitees’ names and email addresses are sent to Anthropic, solely to provide that feature. We don’t create, change or delete events, don’t use the data for advertising or to train AI models, and staff don’t read it without your explicit permission.
Notulist’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke access at any time in Notulist or in your Google account.
Signing in with Google, Microsoft or Apple only gives us your name, email address and a permanent account ID.
12. Age
Notulist is meant for people aged 16 and over. We don’t knowingly process data of younger children as users.
13. Changes
We update this policy when the service or the law changes. We’ll tell you about important changes in advance by email or in the app. The date at the top shows when the text last changed.