This English text is a translation provided for convenience. Only the German version of this page is legally binding. Go to the German version
Document B of three
Processing of meeting content
What happens to audio, transcript and minutes — step by step, with provider and location. For the website and the customer account the general privacy notice applies; for participants without a contract with us there is the participant information.
Version 1.0 · as of 8 August 2026
1. Who is responsible for what
For the audio recording, transcript, minutes and participant data, your organisation is the controller within the meaning of the GDPR. rooom AG processes this data as a processor under Art. 28 GDPR, exclusively on your instructions and without purposes of its own.
The basis is a data processing agreement, concluded as a separate document, which takes precedence over the general terms and conditions where it contains differing provisions. The technical and organisational measures under Art. 32 GDPR are a fixed annex to that agreement and cannot be changed unilaterally by us.
2. The path your data takes
| Step | What happens | Provider | Location |
|---|---|---|---|
| 1 · Detecting the appointment | Calendar entry with meeting link, title, time span, invitees | Microsoft Graph in the customer’s tenant | Customer’s tenant |
| 2 · Joining | The bot joins, indicates the recording visibly, and records audio | Meeting BaaS | France (EU) |
| 3 · Transcription | The audio track is turned into text with speaker separation | Mistral AI (Voxtral) | France (EU) |
| 4 · Minutes and tasks | Minutes and proposed tasks are produced from the transcript; a second pass removes what was already settled during the meeting | Mistral AI | France (EU) |
| 5 · Storage | Transcript, minutes, tasks, participant metadata | Supabase | Frankfurt am Main (EU) |
| 6 · Deleting the audio recording | The audio recording is deleted after successful transcription, unless the customer has set a longer period | Protoki | Frankfurt am Main (EU) |
| 7 · Distribution | Minutes email with title, summary and open tasks to those involved | Resend | EU region (Ireland) |
3. What a voice recording means
An audio recording of the non-publicly spoken word is created. That is not a side effect but the core of the service — and § 201 StGB protects exactly this spoken word. A recording may only take place with the knowledge of all participants. Our bot indicates this visibly when it joins; this notice cannot be switched off.
For processing, the content has to be available in plain text: whoever transcribes and summarises cannot do so on encrypted data. We encrypt transport and storage. End-to-end encryption is technically impossible for a transcription service, and we do not claim it.
4. No biometric processing, no voice profiles
Speaker separation produces generic identifiers (“Speaker 1”, “Speaker 2”). Assignment to names happens through the meeting metadata or manually by you. No voice profiles are created and there is no recognition of voices across meetings. There is therefore no processing for the purpose of uniquely identifying a natural person within the meaning of Art. 4 (14) GDPR — the technology does not trigger Art. 9 GDPR.
5. Special categories that come up in passing
In a conversation, health details or details about religion or trade union membership may come up without anyone intending it. This cannot be ruled out technically, and we do not claim otherwise. Our countermeasures: short retention of the audio recording, tight purpose limitation, restricted access, and the option to delete individual passages.
To process such details you, as the controller, need your own basis under Art. 9 (2) GDPR. That assessment is one we cannot take off your hands.
6. Transparency in the meeting
The bot carries a name with the addition “recording” and points out the recording when it joins. Participants can object during the meeting — verbally or in the chat; the bot is then removed. A later objection is possible through the participant information, even without an account with us.
Even if several people from your organisation are invited, exactly one bot joins. The minutes are distributed afterwards. One processing operation instead of several parallel recordings of the same conversation is data minimisation under Art. 5 (1) (c) GDPR, and not merely a question of cost.
7. Artificial intelligence — what it does and what it does not do
Transcription and the production of minutes run with European model providers. Which provider handles which step is set out in the table in section 2. Generated minutes are marked as AI-produced; the verbatim transcript and the generated summary remain separately visible in the product. Results can be inaccurate and do not replace your own review.
Your content is not used to train AI models — neither by us nor by our providers. This commitment appears verbatim in the privacy notice, in the general terms and conditions and in the data processing agreement. Nor do we reserve any use of your content for our own business purposes — not even in aggregated or anonymised form.
Protoki analyses no moods, emotions or conversational climate and produces no evaluations of speaking share or performance. Emotion recognition in the workplace is prohibited under Art. 5 (1) (f) of the AI Act; our abstention goes further and also covers permissible but unwanted evaluations.
The bot cannot be chatted with. It accepts no input from the meeting. Any interaction surface would be an additional path by which content enters the system and leaves it again.
8. Access by our staff
Access to content exists only in so far as it is necessary for operation and fault-finding, and only for the people named for that purpose. Any access beyond that in a support case happens only after your express approval in the individual case. This rule is also in the data processing agreement — not only here.
9. What administrators of your organisation can do — and what they cannot
They can:
- assign and withdraw licences
- set retention periods for transcripts, minutes and audio
- manage internal domains, company assignment and templates
- view administrative data such as status, error codes and counters
They cannot:
- record without the knowledge of participants — the notice cannot be switched off
- view other people’s minutes or transcript content in the administration area; only metadata is shown there
- override the objection of a participating person
10. Deletion concept
| Data | Period | Trigger |
|---|---|---|
| Audio recording from the meeting | immediately after successful transcription; otherwise up to the period set by the customer | successful transcription |
| Uploaded audio file | after 7 days at the latest | upload; regardless of whether speakers have been assigned |
| Transcript | set by the customer, default 12 months | creation |
| Minutes and tasks | set by the customer, default 24 months | creation |
| Calendar metadata for appointments without a recording | together with the associated meeting | deletion of the meeting |
| Recording, transcript, chat history and the names of participants and speakers at the bot provider | after Protoki has taken over the artefacts | completion of processing |
| Session metadata of the bot at the bot provider (ID, status, timestamps, duration, token consumption — and the meeting URL) | none — according to the provider on 31 August 2026 these details are retained indefinitely, even after our deletion request | on request only: redaction of the meeting URL or deletion of the session metadata via the provider’s support — there is no interface for it |
If transcription fails, the audio recording is not deleted but kept for another attempt and then treated under the same rule. On backup copies we deliberately make no commitment yet: the backup cycle, and the period within which a deletion also takes effect there, are not yet finally settled technically. A commitment we cannot demonstrate would be worth less in an audit than this disclosure.
11. Operation in your Microsoft tenant
Protoki requests only the permissions it actually needs, and justifies each one. Expressly not requested are: a tenant-wide right to send emails, tenant-wide calendar access, and a change to your global Teams meeting policy. Access by the service account can be restricted to a user group you name; in our own operation it is.
12. Employee data protection and co-determination
A system that attributes conversational contributions by name is objectively capable of monitoring conduct and performance. For its introduction this objective capability is sufficient — a corresponding intention is not required. Its introduction therefore requires co-determination under § 87 (1) no. 6 BetrVG; § 90 (1) no. 3 and § 80 (3) sentence 2 BetrVG apply in addition.
We say this expressly instead of working around it. As a legal basis for employee data, Art. 6 GDPR directly or a works agreement under § 26 (4) BDSG come into consideration — not § 26 (1) sentence 1 BDSG, which the Court of Justice of the European Union has rejected as an independent basis. We provide a system description under § 90 BetrVG; it describes functions, data types, permissions, processing locations and deletion periods, and states what the system cannot do technically. No evaluation for performance assessment takes place.
13. Support with your obligations
We support you with data subject requests, with the obligations under Art. 32 to 36 GDPR, and with the technical details you need for a data protection impact assessment. We notify you without undue delay of any personal data breach, so that you can meet your 72-hour deadline under Art. 33 GDPR.
14. Sub-processors
- Spoke SAS („Meeting BaaS") — The recording bot joining the online meeting, and the audio recording. Place of processing France (EU), Group headquarters France. Receives: Meeting URL, bot name, audio track, participant list and chat messages of the platform.On our deletion request the provider removes the recording, transcript, chat history and the names of participants and speakers. The session metadata — bot ID, status, timestamps, duration and token consumption — remain with them, and that includes the meeting URL. According to the provider on 31 August 2026 these rows are currently retained indefinitely; deletion or redaction is possible only on request via their support.
- Scaleway SAS — engaged by Meeting BaaS — The data centre and storage on which Meeting BaaS runs its service. Place of processing Paris, France (EU), Group headquarters France. Receives: Everything that arises at Meeting BaaS: audio recording, session data of the bot, meeting URL.
- Gladia SAS — engaged by Meeting BaaS — Speech recognition within the Meeting BaaS offering. Place of processing France (EU), Group headquarters France. Receives: Audio track — where the bot provider’s own transcription is used.Protoki switches off transcription at Meeting BaaS and transcribes itself. On 31 August 2026 Meeting BaaS confirmed in writing that with transcription disabled no audio is sent to Gladia. That confirmation is conditional: it holds only as long as the provider’s own transcription stays switched off — for real-time streaming transcription Gladia would be the provider’s default. We therefore continue to list Gladia as a recipient, so that the condition remains visible.
- Mistral AI SAS — Transcription with speaker separation, and production of minutes and tasks. Place of processing France (EU), Group headquarters France. Receives: Audio track, transcript, participant names from the meeting metadata.
- Supabase, Inc. — Database and file storage of the application. Place of processing Frankfurt am Main, Germany (EU), Group headquarters United States. Receives: Account and meeting data, transcripts, minutes, and audio recordings temporarily.
- Vercel, Inc. — Operation and delivery of the web application. Place of processing EU region (Frankfurt am Main), Group headquarters United States. Receives: Connection data of requests, and content passing through request processing.
- Plus Five Five, Inc. („Resend") — Sending of the minutes emails and system emails. Place of processing EU region (Ireland) for sending, Group headquarters United States. Receives: Recipient address, meeting title, summary and open tasks from the minutes.
Providers with the addition “engaged by” are further sub-processors under Art. 28 (4) GDPR: they have a contract not with us but with the service provider named. We inform you in advance of changes to this list; the right to object and the periods are governed by the data processing agreement.
15. Documents of evidence
The data processing agreement, the annex on technical and organisational measures, the deletion concept, the template for your data protection impact assessment and the system description under § 90 BetrVG are available on request via info@rooom.com. We are working on making them available for download without a request.