This English text is a translation provided for convenience. Only the German version of this page is legally binding. Go to the German version
Document A of three
Privacy — website and customer account
This notice applies to visiting this website and to your Protoki customer account. It does not apply to the content of your meetings — there we process on your behalf and on your instructions. That is set out in the product privacy information. For people who take part in a recorded meeting without being a customer, there is the participant information.
Version 1.0 · as of 8 August 2026
1. At a glance
- rooom AG in Jena is the controller. For meeting content it is your organisation — there we act on its behalf.
- Processing and storage take place in the European Union. There is no setting that turns this off.
- For transcription and producing minutes we use European model providers.
- Your content is not used to train AI models.
- This website uses no advertising or tracking services. For aggregated audience measurement on the public product and marketing pages, we use Vercel Web Analytics; it does not use cookies and does not create profiles.
- You have rights to access, rectification, erasure, restriction, data portability and objection — sections 8 and 9.
2. Controller and data protection officer
rooom AG, Löbstedter Str. 47a, 07749 Jena, Deutschland
Phone +49 3641 5549440 · info@rooom.com
Data protection officer: Landgraf Datenschutz GmbH, Markt 22, 07743 Jena, dsb@landgraf-datenschutz.de. You may contact them directly on any data protection matter, without going through us.
3. Processing operations in detail
For each processing operation we state the purpose, the data, the legal basis, the recipients and the duration. Where we rely on a legitimate interest, we name it individually rather than in general terms.
Delivering the website and defending against abuse
- Data:
- IP address, time, path requested, status code, browser identification
- Legal basis:
- Art. 6 (1) (f) GDPR
- Legitimate interest:
- technically fault-free operation and detection of automated attacks on the sign-in
- Recipients:
- Vercel (hosting, EU region)
- Duration:
- Connection logs are kept briefly and continuously overwritten
Creating and maintaining the customer account
- Data:
- Name, business email address, company, role in the account, chosen bot name
- Legal basis:
- Art. 6 (1) (b) GDPR
- Recipients:
- Supabase (database, Frankfurt)
- Duration:
- for the duration of the account, then erasure once statutory periods have passed
Signing in with your organisation’s Microsoft account (Entra ID)
- Data:
- Account identifier, display name, business email address
- Legal basis:
- Art. 6 (1) (b) GDPR
- Recipients:
- Microsoft as the operator of your own tenant
- Duration:
- for the duration of the account
Contract handling, invoicing and accounting
- Data:
- Company name, address, contact person, number of licences, hours consumed
- Legal basis:
- Art. 6 (1) (b) and (c) GDPR
- Recipients:
- Tax advisers, where required
- Duration:
- statutory retention periods (§ 147 AO, § 257 HGB)
Handling enquiries through the contact form or by email
- Data:
- Name, email address, company and the details of your message
- Legal basis:
- Art. 6 (1) (b) GDPR where a contract is being initiated, otherwise (f)
- Legitimate interest:
- answering enquiries addressed to our company
- Recipients:
- Resend (email delivery)
- Duration:
- until the matter is settled, then erasure once statutory periods have passed
System emails (sign-in link, minutes notification, warnings)
- Data:
- Email address, meeting title, summary and open tasks from the minutes
- Legal basis:
- Art. 6 (1) (b) GDPR
- Recipients:
- Resend (email delivery)
- Duration:
- Delivery logs are kept briefly
Aggregated audience measurement for the public marketing pages
- Data:
- Page path without query parameters or fragments, referrer, timestamp, approximate country, browser, operating system and device type; no meeting content and no permanent identifier
- Legal basis:
- Art. 6 (1) (f) GDPR
- Legitimate interest:
- Understanding the reach and use of the public product information and improving the offering
- Recipients:
- Vercel (Web Analytics)
- Duration:
- The temporary visitor assignment is discarded after 24 hours; aggregated measurements remain available for the reporting period configured in the Vercel project
5. Recipients and processors
We use the following service providers as processors under Art. 28 GDPR. The group headquarters column is there on purpose: it answers the question about possible access rights of non-European parent companies before you have to ask it.
| Provider | Purpose | Place of processing | Group headquarters |
|---|---|---|---|
| Spoke SAS („Meeting BaaS")On our deletion request the provider removes the recording, transcript, chat history and the names of participants and speakers. The session metadata — bot ID, status, timestamps, duration and token consumption — remain with them, and that includes the meeting URL. According to the provider on 31 August 2026 these rows are currently retained indefinitely; deletion or redaction is possible only on request via their support. | The recording bot joining the online meeting, and the audio recording | France (EU) | France |
| Scaleway SASvia Meeting BaaS | The data centre and storage on which Meeting BaaS runs its service | Paris, France (EU) | France |
| Gladia SASvia Meeting BaaSProtoki switches off transcription at Meeting BaaS and transcribes itself. On 31 August 2026 Meeting BaaS confirmed in writing that with transcription disabled no audio is sent to Gladia. That confirmation is conditional: it holds only as long as the provider’s own transcription stays switched off — for real-time streaming transcription Gladia would be the provider’s default. We therefore continue to list Gladia as a recipient, so that the condition remains visible. | Speech recognition within the Meeting BaaS offering | France (EU) | France |
| Mistral AI SAS | Transcription with speaker separation, and production of minutes and tasks | France (EU) | France |
| Supabase, Inc. | Database and file storage of the application | Frankfurt am Main, Germany (EU) | United States |
| Vercel, Inc. | Operation and delivery of the web application | EU region (Frankfurt am Main) | United States |
| Plus Five Five, Inc. („Resend") | Sending of the minutes emails and system emails | EU region (Ireland) for sending | United States |
| rooom AG (SovrGPT)(planned) | Second model provider for producing minutes and tasks | Germany (EU) | Germany |
Providers marked “planned” are contractually engaged but currently process no data. Providers marked “via” are not our contracting parties but are engaged by the service provider named before them — we name them because Art. 28 (4) GDPR means the whole chain and not only its first link. If the list changes, we inform our customers in advance; the right to object and the periods are set out in the data processing agreement.
6. Processing outside the EU
Processing and storage take place in the European Union. That is part of the architecture and cannot be deselected as a setting.
But we tell the whole truth about it: Supabase, Vercel and the email delivery are provided by companies headquartered in the United States, even though the processing runs in EU regions. Where data does reach a third country in an individual case — in support, for instance — we base this on standard contractual clauses under Art. 46 (2) (c) GDPR and additional measures. We expressly do not claim to manage without providers with a US connection. The model path — that is, transcription and producing minutes — runs entirely with European providers.
7. Retention periods
The periods for meeting content are set out in the product privacy information, because your organisation configures them. For the processing operations on this page, the “Duration” column in section 3 applies. We erase data as soon as the purpose ceases to apply and no statutory retention obligation stands in the way.
8. Your rights
- Access to the data processed about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Release in a portable format (Art. 20 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7 (3) GDPR)
Please contact protoki@rooom.com or our data protection officer directly. We answer without undue delay, at the latest within one month (Art. 12 (3) GDPR).
You may also lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is the Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit, Häßlerstraße 8, 99096 Erfurt.
9. Right to object under Art. 21 GDPR
Where we process data on the basis of a legitimate interest (Art. 6 (1) (f) GDPR), you have the right to object to that processing at any time on grounds relating to your particular situation. We will then no longer process the data concerned, unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
No particular form is required for an objection. A message to protoki@rooom.com is enough. How to object to a specific meeting recording is set out in the participant information.
10. Do you have to provide this data?
To visit this website you need to provide nothing. For a customer account we need your name and business email address; without these details no account can be maintained and no contract concluded. Any further details are voluntary.
11. No automated decision-making in individual cases
There is no automated decision-making, including profiling, within the meaning of Art. 22 (1) and (4) GDPR. Minutes and proposed tasks are produced by machine, but they have no legal effect and do not similarly significantly affect anyone; assessment and use lie with a human being.