Product AI notes Pricing For teams Developers & API Security Standards & compliance
Start free Sign in
Trust · Data protection

GDPR, in specifics.

Which data we hold, on what lawful basis, for how long, who else touches it, and what you can demand of us. Written to be read by a data protection officer, not a marketing department.

Roles

Who is the controller depends on the data.

Compliance is shared. This is the line between your obligations and ours.

You are the controller of meeting content

Your meetings, agendas, chat, transcripts and summaries are yours. You decide who is invited, whether captions are used and how long transcripts are kept. Codexal acts as your processor for all of it, on your documented instructions under the DPA.

We are the controller of account data

For the account itself — name, email, sign-in records, billing — Codexal is the controller, because we decide what is needed to provide and secure the service. That processing is described in the privacy policy.

Article 30 record

What we process, and why we are allowed to.

Category
Purpose and lawful basis
Status
Account identityName, email, password hash
To create and secure your account and to send service messages. Art. 6(1)(b) — performance of a contract.
Implemented
Meeting metadataTitle, agenda, times, attendance
To run the meeting, show the agenda and keep an honest participant list. Art. 6(1)(b) — performance of a contract, on the controller's instruction.
Implemented
Chat messagesText sent in the room
To deliver messages to the room and include them in the recap. Processed for the customer as controller.
Implemented
Captions & transcriptsSpeech transcribed in the browser
To produce the meeting summary. Transcription is opt-in per participant and can be switched off mid-meeting, which is how we meet Art. 5(1)(c) data minimisation for the most sensitive category we touch.
Implemented
Guest detailsDisplay name, optional email
To show who is in the room and, if the guest chooses to give an address, to send them the recap. The email field is optional by design.
Implemented
Technical logsSign-in events, errors, admissions
To keep the service secure and available. Art. 6(1)(f) — legitimate interests, balanced and documented. Logs carry no meeting content.
Implemented
Audio & videoThe call itself
Not processed by us at all. Media is encrypted browser to browser and never stored server-side; there is nothing in our systems to disclose, export or breach.
Not applicable
Article 5(1)(e)

Storage limitation, with numbers.

Transcripts
14 days
Deleted automatically. Configurable per organisation.
Summaries
Life of the meeting
Kept so attendees can read them; deleted with the account.
Chat
Life of the meeting
Deleted with the meeting record.
Account data
Until deletion
Removed within 30 days of a deletion request.
Technical logs
90 days
Rolling window for security investigation.
Backups
30 days
Encrypted, then rotated out.

A deletion request is honoured in live systems immediately and works its way out of backups as they rotate, within 30 days.

Articles 15–22

Your rights, and how to use them.

Write to info@codexal.co from the address on the account. We answer within 30 days, free of charge, and we tell you what we did rather than only that we did something.

If we are processing on behalf of a customer, we forward the request to that controller and assist them in answering it, as Art. 28(3)(e) requires.

  • Access (Art. 15). A copy of the personal data we hold about you.
  • Rectification (Art. 16). Correct your name or email yourself in Settings, or ask us.
  • Erasure (Art. 17). Delete the account and everything attached to it.
  • Restriction (Art. 18). Freeze processing while a dispute is resolved.
  • Portability (Art. 20). Your meetings, transcripts and summaries in a machine-readable export.
  • Objection (Art. 21). Object to processing based on legitimate interests.
  • No automated decisions (Art. 22). Nothing in Codexal Meet makes a decision with legal effect about a person. AI writes notes; it does not judge.
Article 28(2)

Every sub-processor, named.

We tell customers before adding one, and you may object.

Sub-processor
What it does and what it sees
Status
Hosting providerMiddle East region
Runs the application, database and signalling servers. Holds account data, meeting metadata, transcripts and summaries at rest, on encrypted volumes.
Implemented
Language model providerSummary generation
Receives the text of captions and chat when a meeting ends, and returns the summary. Processes under contract, does not retain the text and does not train on it. Never receives audio or video.
Implemented
Email providerTransactional mail
Delivers recaps, invitations and service messages. Sees recipient addresses and the content of the email it is asked to send.
Implemented
TURN relayRestrictive networks only
Forwards encrypted media packets when a direct peer-to-peer path is impossible. Handles ciphertext and cannot decrypt it, so it processes no personal data in readable form.
Implemented

Want the legal entities, jurisdictions and contract dates? The full sub-processor schedule forms part of the Data Processing Agreement, and we send it on request rather than publishing supplier contract terms openly. Ask at info@codexal.co and it comes back the same day.

Chapter V

Where the data goes.

Your meeting data is stored in the Middle East. Where a sub-processor operates outside the EEA, the transfer is covered by Standard Contractual Clauses and a transfer impact assessment, and the data reaching it is limited to what that service needs to do its job.

Organisations that need a specific region contractually should ask about a dedicated Enterprise instance, where residency is written into the agreement rather than inferred from a hosting map.

  • Primary storage in the Middle East for accounts, meetings, transcripts and summaries.
  • Standard Contractual Clauses with any sub-processor outside the EEA.
  • Media never transfers anywhere. It goes between the participants' browsers and is not stored in any region, by anyone.
  • Named-region instances available under an Enterprise agreement.
Regional law

Jordan's Personal Data Protection Law

Codexal is a Jordanian company, so Law No. 24 of 2023 applies to us directly, alongside GDPR for our European customers. The two are close in substance, and we run one programme rather than two.

  • Consent and contract. Personal data is processed to deliver the service you asked for, and consent is sought where the law requires it — captions are the clearest example, which is why they are opt-in per person rather than on by default.
  • Purpose limitation. Data collected to run a meeting is used to run that meeting and to write its recap, and not repurposed.
  • Local storage. Data is held in the region by default, which keeps cross-border transfer obligations narrow.
  • Rights of the data subject. Access, correction and erasure are handled through the same process as a GDPR request, at the same address, in the same 30 days.
  • Disclosure. We disclose personal data to an authority only where a valid legal instrument compels it, and we tell the customer unless we are prohibited from doing so.
Article 28

The Data Processing Agreement

Every customer can sign a DPA with Codexal, at any plan. It is the document that turns the commitments on this page into obligations, and it contains what Art. 28(3) requires:

  • The subject matter, duration, nature and purpose of the processing, and the categories of data subject.
  • Processing only on your documented instructions, including for transfers.
  • A confidentiality undertaking from everyone with access.
  • The security measures of Art. 32 — the ones set out on our security page.
  • Terms for engaging sub-processors, with notice to you and a right to object.
  • Assistance with data subject requests, breach notification and impact assessments.
  • Deletion or return of all personal data at the end of the agreement.
  • Audit and information rights, so you can verify rather than trust.

Ask for it at info@codexal.co and we will send the current version for signature.

Reporting a concern

If you believe we have handled personal data badly, write to info@codexal.co and say so plainly. We will investigate and reply. You also have the right to complain to your own supervisory authority, and nothing here asks you to come to us first.

Questions

Asked by data protection officers.

Is Codexal Meet GDPR compliant?
Codexal acts as a processor for meeting content and as a controller for account data. We offer a Data Processing Agreement, name our sub-processors, minimise what we collect, delete transcripts on a retention timer and answer data subject requests within 30 days. GDPR compliance is shared between us and you as the controller: we provide the controls and the contract, you decide who is invited and what is discussed.
Do you use meeting content to train AI models?
No. The text of captions and chat is sent to a language-model provider to write the summary, under a contract that excludes retention and training on that content. Audio and video never leave the peer-to-peer path, so they cannot be used for training by anyone.
Can we sign a Data Processing Agreement?
Yes, on any plan. Write to info@codexal.co and we will send the current version. It covers documented instructions, confidentiality, Art. 32 security measures, sub-processor notice, assistance with data subject requests and breach notification, deletion at the end of the agreement, and your audit rights.
How quickly are we told about a data breach?
Within 72 hours of confirming a personal data breach affecting your data, with what we know at that point rather than a finished report. Our incident procedure names an owner and a severity scale, and we follow up with the detail as the investigation proceeds.
Can we ask for a shorter transcript retention period?
Yes. Fourteen days is the default; organisations can have it shortened, and some set it to delete as soon as the summary has been written. Talk to us about the value that fits your own retention schedule.
Where is meeting data stored?
On servers in the Middle East. Enterprise customers can have a dedicated instance in a named region so that residency is a contractual commitment rather than a current fact. Media is never stored anywhere, in any region.

Ask for the DPA.

Signed on any plan, sent the same working day.