Privacy Policy
BYKI Notetaker watches your calendar (read-only), sends a bot that joins your online meetings after being admitted, records and transcribes them with consent, and uses a language model to generate meeting notes that are delivered to you. This policy explains how we process personal data under the EU General Data Protection Regulation (GDPR).
1. Data controller
Byki is the data controller for your account. [PLATSHÅLLARE: full legal company name, company registration number, registered address, VAT number — Byki is currently being incorporated.] Contact: privacy@byki.app [VERIFIERA: contact address]. For the content of your meetings, Byki acts as a data processor on your behalf as the account owner.
2. What data we process
- Account data: name and email address from your Google or Microsoft sign-in.
- Calendar data: only the time, title and meeting link of upcoming events — never the contents of your email or files.
- Meeting data: audio — and video on plans that include video recording — transcripts, speaker labels and generated notes for the meetings the bot attends (with your and the participants' consent), plus any notes or comments you add yourself.
- Delivery data: where you enable it, generated notes delivered to your chosen channel (email, Slack, Microsoft Teams, a webhook, Notion, Google Docs or a Word document).
- Billing data: handled by Stripe — card numbers never touch our systems.
3. How your meeting data flows
The service works as a chain: (1) calendar watching reads your upcoming meetings read-only; (2) a self-hosted bot joins the online meeting (Google Meet, Microsoft Teams or Zoom) once admitted by the host, and posts a consent message in the meeting chat; (3) the meeting is recorded on our own EU infrastructure and transcribed within the EU — primarily at OVHcloud (France), with our own server in Sweden as fallback; (4) a language model at OVHcloud (EU, France) generates the meeting notes; (5) the notes are delivered to the app and by email, and optionally to Slack, Microsoft Teams, a webhook, Notion, Google Docs or as a Word document. If several Notetaker users attend the same meeting, a single bot attends and each user receives their own private copy of the notes — your own notes and comments are never visible to other users. Each step is described on our Sub-processors page.
4. Google user data and Limited Use
When you sign in with Google, Notetaker requests the following permissions:
- openid, email, profile — to create and identify your account (name and email).
- Google Calendar, read-only (.../auth/calendar.events.readonly) — to read the time, title and meeting link of your upcoming events so the bot knows when and where to join. We never read your email, contacts, Drive files or any other content.
- Google Docs / Drive — only where you choose to have notes delivered to Google Docs, and only to create the document we deliver. [VERIFIERA: exact Docs/Drive scope requested.]
We use Google data solely to provide the service's features to you. We never sell Google data, never use it for advertising, and never use it to train generalized AI/ML models. No human reads your Google data except with your explicit consent, where required for security or troubleshooting, or where required by law.
Notetaker's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Microsoft user data
When you sign in with Microsoft, we request identity (name and email) and read-only access to your calendar for the same purpose — to detect the time, title and meeting link of your upcoming meetings. We never read your mailbox, files or other content.
6. Purposes and legal basis
We process data to deliver the service (performance of a contract) and for invoicing (legal obligation, VAT). Recording of meetings is based on consent; the bot posts a consent message in the meeting chat when it joins.
7. Data residency — EU-first
Byki follows an EU-first principle: the entire processing chain is kept within the EU, and we treat jurisdiction — not only certificates — as decisive. Hosting is at Strato in Germany, transcription runs primarily at OVHcloud (France) with our own server in Gothenburg, Sweden (faster-whisper) as fallback, and meeting notes are generated at OVHcloud AI Endpoints in France as the primary model; if that is unavailable, Mistral AI (France, EU) is the fallback, with our own Swedish server as last resort. There are no US providers in the processing chain, and no step routes your meeting data outside the EU.
8. Sub-processors
The meeting bot, the recording and our fallback transcription server (faster-whisper in Gothenburg, Sweden) run on our own self-hosted EU infrastructure — no third party receives that data. For the third parties we do engage — OVHcloud (LLM and speech-to-text, EU), Mistral AI (LLM fallback, France, EU), Strato (hosting, Germany), Brevo (email), Stripe (payments), and the sign-in and delivery integrations you choose to connect — see our Sub-processors page for the current list, including each provider's role, the data processed and the region.
9. No AI training on your data
Your meetings are never used to train AI models. Our AI providers are contractually prohibited from using your data for machine learning or model training, and our own models learn nothing from your data.
10. Retention
Notes, transcripts and recordings are kept for your plan's retention period — 30 days on Starter (and during the trial), 1 year on Pro and Business — and are deleted after that period. Video and audio recordings are always deleted together with the transcripts when your plan's retention period expires — no plan retains meeting data longer than 1 year — and deletion is enforced automatically. You can delete individual meetings at any time — deleted meetings go to a trash bin for 30 days, or you can delete them permanently right away, which also removes the recording on the meeting-bot side. When you delete your account, all your data is removed. Inactive or unpaid accounts are deleted after 91 days, following reminder emails.
11. Your rights
You have the right to access, rectification, erasure, restriction, data portability and to object. Delete your account directly in the app, or contact privacy@byki.app. You can lodge a complaint with your supervisory authority (in Sweden, the Swedish Authority for Privacy Protection, IMY).
12. Security
Data is protected with encryption in transit (TLS) and at rest, access control, tenant isolation and an immutable audit log.
← Back to start