Privacy Policy

Last updated: 20 July 2026

This policy explains how CERNO LABS, obrt za marketing i računalno programiranje, vl. Marko Filipović, Donjozelinska ulica 16, 10380 Donja Zelina, Croatia (OIB: 22778960778, MBS: 99286572) ("Sottly", "we"), the business that operates and sells the Sottly SaaS product, processes personal data in connection with the Sottly application and website. Contact: privacy@sottly.ai.

1. Roles: controller vs. processor

2. Data we process

CategoryExamplesPurpose
Account dataName, email, password hash or Google account IDAuthentication, account management
Onboarding answersRole, meeting types, goalsPersonalizing the product experience
Billing dataCompany name, billing address, VAT ID, payment statusSubscription billing via Stripe (we never store card numbers)
Meeting contentAudio streams, speaker-separated transcripts, participant names, meeting contextProviding live transcription, AI suggestions, and meeting history
Consent recordsParticipant name, meeting, timestamp of consentEvidence that guests agreed to recording/transcription
Technical dataIP address, device/browser info, logsSecurity, debugging, service operation

3. Legal bases (GDPR)

4. Subprocessors and recipients

We share data only with providers needed to run the Service:

ProviderPurposeLocation
SupabaseDatabase, authentication, serverless functionsEU (Ireland, AWS eu-west-1)
Hetzner Online GmbHServers hosting audio infrastructure (LiveKit)Germany / Finland (EU)
Deepgram, Inc.Speech-to-text transcriptionUSA (SCCs / EU-U.S. DPF)
OpenAI, L.L.C.AI analysis and suggestions (GPT models via API)USA (SCCs / EU-U.S. DPF)
Stripe Payments Europe, Ltd.Payment processing and invoicingEU / USA (SCCs / DPF)
Cloudflare, Inc.DNS and network securityGlobal (SCCs / DPF)

Where data is transferred outside the EEA, we rely on adequacy decisions (including the EU-U.S. Data Privacy Framework) or Standard Contractual Clauses. Audio and transcripts are not used by us or our subprocessors to train AI models.

5. Retention

6. Your rights

You have the right to access, rectify, erase, restrict, or port your personal data, and to object to processing based on legitimate interest. Contact privacy@sottly.ai. You may also lodge a complaint with your supervisory authority — in Croatia, the Agencija za zaštitu osobnih podataka (AZOP). Meeting participants whose data was processed on behalf of a customer should contact that customer first; we will assist as processor.

7. Security

Data in transit is encrypted (TLS/WSS). Access to production data is limited and role-based (row-level security). Payment data is handled entirely by Stripe.

8. Changes

We will announce material changes to this policy by email or in-app before they take effect.