Privacy Policy
Last updated: 20 July 2026
This policy explains how CERNO LABS, obrt za marketing i računalno programiranje, vl. Marko Filipović, Donjozelinska ulica 16, 10380 Donja Zelina, Croatia (OIB: 22778960778, MBS: 99286572) ("Sottly", "we"), the business that operates and sells the Sottly SaaS product, processes personal data in connection with the Sottly application and website. Contact: privacy@sottly.ai.
1. Roles: controller vs. processor
- Account & billing data — we are the data controller for data about registered users (hosts/admins) and website visitors.
- Meeting content — the customer company hosting a meeting is the data controller of meeting audio, transcripts, and participant names. We process this data as a processor on the customer's behalf, under our Data Processing Addendum.
2. Data we process
| Category | Examples | Purpose |
|---|---|---|
| Account data | Name, email, password hash or Google account ID | Authentication, account management |
| Onboarding answers | Role, meeting types, goals | Personalizing the product experience |
| Billing data | Company name, billing address, VAT ID, payment status | Subscription billing via Stripe (we never store card numbers) |
| Meeting content | Audio streams, speaker-separated transcripts, participant names, meeting context | Providing live transcription, AI suggestions, and meeting history |
| Consent records | Participant name, meeting, timestamp of consent | Evidence that guests agreed to recording/transcription |
| Technical data | IP address, device/browser info, logs | Security, debugging, service operation |
3. Legal bases (GDPR)
- Performance of contract — account, billing, providing the Service.
- Consent — guest participation in recorded meetings.
- Legitimate interest — security, fraud prevention, service improvement.
- Legal obligation — tax and accounting records.
4. Subprocessors and recipients
We share data only with providers needed to run the Service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, serverless functions | EU (Ireland, AWS eu-west-1) |
| Hetzner Online GmbH | Servers hosting audio infrastructure (LiveKit) | Germany / Finland (EU) |
| Deepgram, Inc. | Speech-to-text transcription | USA (SCCs / EU-U.S. DPF) |
| OpenAI, L.L.C. | AI analysis and suggestions (GPT models via API) | USA (SCCs / EU-U.S. DPF) |
| Stripe Payments Europe, Ltd. | Payment processing and invoicing | EU / USA (SCCs / DPF) |
| Cloudflare, Inc. | DNS and network security | Global (SCCs / DPF) |
Where data is transferred outside the EEA, we rely on adequacy decisions (including the EU-U.S. Data Privacy Framework) or Standard Contractual Clauses. Audio and transcripts are not used by us or our subprocessors to train AI models.
5. Retention
- Account data — for the life of the account, then deleted within 30 days.
- Meeting transcripts and analyses — until deleted by the customer, and at the latest 30 days after the subscription ends (see the DPA).
- Raw audio — processed for transcription in real time; recordings, where enabled, are retained per the customer's settings.
- Billing records — as required by tax law (typically 10 years).
6. Your rights
You have the right to access, rectify, erase, restrict, or port your personal data, and to object to processing based on legitimate interest. Contact privacy@sottly.ai. You may also lodge a complaint with your supervisory authority — in Croatia, the Agencija za zaštitu osobnih podataka (AZOP). Meeting participants whose data was processed on behalf of a customer should contact that customer first; we will assist as processor.
7. Security
Data in transit is encrypted (TLS/WSS). Access to production data is limited and role-based (row-level security). Payment data is handled entirely by Stripe.
8. Changes
We will announce material changes to this policy by email or in-app before they take effect.