Privacy Policy
Effective 28 July 2026 · Last updated 28 July 2026 · Provided by Empha Studio Ltd.
Key commitments: We do not sell your personal data. We do not use your meeting content to train generalized AI models. You have full rights under GDPR including access, rectification, erasure, and objection.
1. Who We Are
Meetia is an AI-powered meeting intelligence platform operated by Empha Studio Ltd. ("Empha Studio", "Meetia", "we", "us", or "our"). We are incorporated in Cyprus (registration number: CY10438500L) with our registered address at Ntempyssi 22, 3120, Limassol, Cyprus.
For the purposes of EU data protection law, Empha Studio Ltd. acts as the data controller for personal data processed when you register and use the Service. Where Meetia processes personal data on behalf of an organization that has provided the Service to you (for example, your employer), that organization acts as the data controller and Meetia acts as the data processor; in that context, the organization's privacy policy also applies.
| Legal entity | Empha Studio Ltd. |
|---|---|
| Registration number | CY10438500L |
| Registered address | Ntempyssi 22, 3120, Limassol, Cyprus |
| General contact | contact@meetia.io |
| Data controller contact | contact@meetia.io |
| Legal contact | contact@meetia.io |
| DPA / GDPR enquiries | contact@meetia.io |
2. Scope of This Policy
This Privacy Policy applies to all personal data we collect and process when you access or use:
- the Meetia website at meetia.io;
- our desktop application;
- our browser-based transcription tools;
- any related services, integrations, or communications.
This Policy does not apply to data we process strictly on behalf of enterprise customers under a separate Data Processing Addendum (DPA). If your employer has deployed Meetia for your team, consult your employer's privacy notice for how they process your personal data.
We may update this Policy from time to time. We will notify you of material changes by email, in-app notification, or by updating the "Last Updated" date above. Continued use of the Service after the effective date constitutes acceptance.
3. Personal Data We Collect
3.1 Data You Provide Directly
When you register for or use Meetia, you may provide:
- Account data: name, email address, password (hashed), profile picture, company name, job title.
- Meeting transcripts and session data: Meetia transcribes meeting audio in real time; the audio is sent to the speech-to-text provider, transcribed, and discarded — meeting audio is not stored. We store the resulting text transcript, session metadata (status, timestamps, speaker labels), and any AI-generated outputs (summaries, action items).
- User-uploaded files: documents, images, audio, and video files uploaded manually to Knowledge or as message attachments are stored in our file storage. This is distinct from meeting audio, which is never stored.
- Calendar and scheduling data: meeting invitations, attendee lists, event titles and descriptions, meeting URLs — accessed when you connect a calendar integration.
- Chat messages: in-meeting and post-meeting chat messages, edits, and attachments.
- Payment data: billing name, address, and payment card details. Payment card data is collected directly by our payment processor (Stripe, Inc.) and is never stored on Meetia's servers.
- Communications: messages you send to our support team, responses to surveys or feedback requests.
3.2 Data We Collect Automatically
When you access or use the Service, we automatically collect:
- Log and technical data: IP address, browser type and version, operating system, access timestamps, pages viewed, features used, and session activity.
- Device data: device type, device identifiers, hardware model, network information.
- Usage data: how you interact with threads, workspaces, AI features, and integrations — including which features you use, the actions you take, and frequency patterns.
- Meeting metadata: meeting titles, participant names and email addresses, meeting platform, duration, and other contextual meeting information.
- Cookies and similar tracking technologies: see Section 8 for full details.
3.3 Speaker Identification Data
When Meetia transcribes a meeting, our speech-to-text provider (Mistral Voxtral, operating in the EU) processes the audio stream and emits speaker diarization signals that identify which speaker is active at each point in the transcript. From these signals, Meetia builds a speaker registry for each session.
What we store and what we do not:
- We store: speaker labels (e.g. "Speaker 1", or a name you assign), turn-level timestamps, and session speaker metadata in the session_speakers registry.
- We do not store: raw audio, voice prints, or biometric templates derived from voice characteristics. The audio stream is sent to Mistral under a confirmed zero-data-retention agreement (see Section 5.2) and is not retained after transcription.
Speaker label data is used solely to attribute transcript segments to individual participants. It is not used to identify or authenticate individuals outside of that context, and is not shared with third-party AI providers beyond the transcription pipeline.
Note on legal classification: Whether speaker labels constitute biometric data under GDPR Article 9 or applicable national law depends on the specific implementation and jurisdiction. We do not store voice prints or biometric templates. You should seek independent legal advice if your use case involves processing in a regulated sector.
3.4 Data from Third-Party Integrations
If you connect Meetia to third-party services (such as Google Calendar, Zoom, Microsoft Teams, Slack, CRM platforms, or others), we may receive data from those services as required to enable the integration. The data we receive depends on which integration you enable and the permissions you grant. You can manage and revoke integrations at any time in your account settings.
3.5 Data About Meeting Participants
When you use Meetia to transcribe a meeting, personal data of meeting participants (such as their name, email address, and statements) is processed through the Service. As the user initiating transcription, you act as the data controller for that participant data and are responsible for ensuring participants have been properly informed and that you have a lawful basis for processing under GDPR and applicable national law. See Section 12 for your obligations.
3.6 Data We Derive
We may derive inferences from data we collect — for example, approximate location from IP address, or meeting type from session metadata. These inferences are used to improve the Service and personalise your experience, not to build behavioural profiles for advertising purposes.
4. How We Use Your Personal Data
We process your personal data only for specified, legitimate purposes and only to the extent necessary. The table below summarises our main processing activities and the legal basis under GDPR Article 6 for each.
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Provide the Service (transcription, AI features, threads, workspaces, search) | Account data, meeting transcripts, session metadata, usage data, integrations | Art. 6(1)(b) — contractual necessity |
| Account setup and authentication | Account data, device data | Art. 6(1)(b) — contractual necessity |
| Process payments and manage subscriptions | Payment data, billing information | Art. 6(1)(b) — contractual necessity |
| Customer support and troubleshooting | Account data, communication data, usage data | Art. 6(1)(b) — contractual necessity; Art. 6(1)(f) — legitimate interest |
| Service improvement, product analytics, and internal research | Aggregated/de-identified usage data (consent-gated via PostHog) | Art. 6(1)(a) — consent (PostHog analytics); Art. 6(1)(f) — legitimate interest (internal aggregates) |
| Send transactional communications (e.g. account notices, security alerts) | Account data | Art. 6(1)(b) — contractual necessity |
| Send marketing communications and product updates | Account data, usage preferences | Art. 6(1)(a) — consent (opt-in; you may withdraw at any time) |
| Security, fraud prevention, and legal compliance | Account data, log data, usage data | Art. 6(1)(c) — legal obligation; Art. 6(1)(f) — legitimate interest |
| Defend or assert legal claims | Any relevant data | Art. 6(1)(f) — legitimate interest |
| Comply with regulatory and legal obligations | Any relevant data | Art. 6(1)(c) — legal obligation |
We do not use your meeting content — including transcripts or AI-generated outputs — to train generalised AI or large language models. We may use anonymised, aggregated, de-identified data for internal product improvement. You may opt out of analytics data collection in your account settings.
5. AI Features and Your Content
Meetia will not use your User Content to train, retrain, or fine-tune any generalised AI or machine learning models without your explicit, informed consent.
5.1 How AI Processing Works
Meetia uses Mistral AI (operating in France, EU) for speech-to-text transcription, speaker diarization, LLM-based summarisation and AI chat, and embeddings for semantic search. When you transcribe a meeting:
- Meeting audio is streamed to Mistral's speech-to-text API for transcription. A temporary audio buffer exists only during conversion and is not written to persistent storage.
- The resulting text transcript is stored in our database and used for all subsequent AI features (summarisation, action item extraction, AI chat).
- No audio file is stored by Meetia or by Mistral after transcription completes.
All AI processing by Mistral is governed by a Data Processing Agreement and the confirmed zero-data-retention arrangement described in Section 5.2.
5.2 Zero Data Retention with Mistral
We have confirmed a Zero Data Retention (ZDR) arrangement with Mistral AI covering all endpoints we use: speech-to-text (Voxtral), LLM completions and summarisation, and embeddings. Under this arrangement:
- Audio sent to Mistral for transcription is not stored after the transcription response is returned.
- Text sent to Mistral for summarisation or chat completions is not stored or logged by Mistral after processing.
- Mistral does not use any content processed under our agreement to train or improve its models.
5.3 De-Identified Data for Product Improvement
Meetia may derive and use de-identified, aggregated data derived from service interactions (not your meeting content) for internal analytics and to improve the Service. This data cannot reasonably be used to identify you. You may opt out of analytics data collection in your account settings.
6. Data Retention
We retain personal data for as long as necessary to fulfil the purposes for which it was collected, to provide the Service, and to comply with legal obligations. Our key retention principles:
- Account data is retained for the duration of your account. If you delete your account, we will anonymise and soft-delete your personal data and memberships within 30 days, subject to exceptions below.
- Meeting transcripts and session metadata (text transcripts, AI summaries, action items, speaker labels, session status) are retained until you delete the thread or delete your account. Meeting audio is not stored — it is transcribed and discarded.
- User-uploaded files (documents, images, audio, video uploaded to Knowledge or as attachments) are retained until you delete them or delete your account.
- Financial and transaction records are retained for the period required by applicable tax and accounting law (in Cyprus, generally 7 years).
- Technical log data (server logs, security logs) is retained for up to 12 months for security and operational purposes.
- Analytics events (PostHog) are collected only after user consent and retained in accordance with PostHog's data retention settings.
- Marketing consent records are retained until consent is withdrawn and for a reasonable period thereafter for compliance evidence.
We may retain certain data for longer where required by applicable law, court order, or regulatory obligation, or where necessary for the establishment, exercise, or defence of legal claims.
Once a retention period expires, we delete or anonymise the data in a secure and irreversible manner.
7. Third-Party Service Providers and Disclosures
7.1 Sub-Processors
All of our core infrastructure is hosted within the European Union. We share personal data with the following sub-processors:
| Contabo GmbH | VPS hosting — PostgreSQL, Redis, NATS, MinIO/S3, and all application services. Region: EU. |
|---|---|
| Auth0 / Okta | Authentication and identity management (login, password reset, MFA). Region: EU tenant. |
| Mistral AI | LLM (chat, summarisation), embeddings, and Voxtral speech-to-text. Region: EU, France. Zero-data-retention confirmed. |
| PostHog | Product analytics and usage events. Collected only after user consent. Region: EU (eu.i.posthog.com). |
| Stripe, Inc. | Payment processing and subscription billing. Stripe acts as an independent data controller for payment processing. |
| Brevo (Sendinblue) | Marketing email delivery (newsletters, product updates). Consent-gated. |
| AWS Simple Email Service | Transactional email delivery (verification, password reset notifications sent outside Auth0 flows). |
A current and complete sub-processor list is maintained at meetia.io/subprocessors. We will update this list and provide reasonable notice before adding new sub-processors that process personal data.
7.2 Integration Partners
If you enable third-party integrations (such as Zoom, Google Meet, Microsoft Teams, Slack, HubSpot, Salesforce, or others), we share data with those platforms to the extent necessary to enable the integration. Each integration partner processes data under its own terms and privacy policy. We encourage you to review those policies before enabling any integration.
7.2.1 Google API: Google Calendar data
If you choose to connect your Google Calendar, Meetia requests the following OAuth scopes:
- https://www.googleapis.com/auth/calendar.readonly – to list your calendars and read event details (title, description, start and end time, attendees, and conferencing links). We use this to display your upcoming meetings in Meetia, to answer questions about your schedule, and to start recording and transcription at the start of each meeting.
- https://www.googleapis.com/auth/calendar.events – to create and update events on your calendars. We only do this when you explicitly ask us to, for example, when you ask the assistant to schedule a follow-up meeting. Every such action is shown to you for approval before it is performed.
How we handle this data. Calendar data is requested from Google only when it is needed to fulfill your request; we do not maintain a separate copy of your calendar. To generate the assistant's answers, the relevant calendar content is sent to our AI provider (Mistral AI) solely to produce a response for you.
Your OAuth tokens are stored encrypted (AES) and are used only to call the Google APIs listed above.
We do not sell your Google user data, do not use it for advertising, and do not use it to develop, improve, or train generalized AI or machine learning models. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect Google Calendar at any time in Settings > Integrations, and you can revoke Meetia's access at https://myaccount.google.com/permissions.
When you disconnect the integration or delete your Meetia account, the stored Credentials are deleted.
7.3 Other Disclosures
We may also disclose personal data in the following circumstances:
- Legal requirements: where required by law, court order, regulatory authority, or legitimate law enforcement request;
- Protection of rights: where necessary to protect the rights, property, or safety of Meetia, our users, or others;
- Corporate transactions: in connection with a merger, acquisition, sale of assets, or other business transfer. We will notify you and take appropriate steps to protect your data in such events;
- With your consent: where you have given specific consent for a disclosure.
We do not sell personal data to third parties. We do not share meeting content with advertisers or third-party advertising networks.
8. Cookies and Tracking Technologies
Meetia uses cookies and similar technologies on our website and in our applications. We categorise these as:
- Strictly necessary cookies: essential for the Service to function (e.g. authentication, session management). These cannot be disabled without degrading the Service.
- Functional cookies: remember your preferences and settings (e.g. language, display settings).
- Analytical/performance cookies: help us understand how users interact with the Service (e.g. page views, feature usage). We use PostHog (EU region) for product analytics, configured in privacy-preserving modes. Analytics cookies are only placed after you give consent.
- Marketing cookies: used to deliver relevant communications. We use these only with your consent.
You can manage cookie preferences through the cookie consent banner displayed when you first visit meetia.io, and subsequently via the cookie settings link in the footer. You can also configure cookie settings in your browser. Note that disabling certain cookies may affect service functionality.
We do not engage in cross-site behavioural advertising or share cookie data with advertising networks for targeting purposes.
9. International Data Transfers
Empha Studio Ltd. is incorporated in Cyprus and all core infrastructure operates within the European Economic Area. The following sub-processors involve transfers outside the EEA:
- Stripe, Inc. (United States) — payment processing only; governed by Standard Contractual Clauses.
- AWS Simple Email Service (United States) — transactional email only; governed by Standard Contractual Clauses.
For all transfers outside the EEA, we ensure an adequate level of protection by relying on Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by appropriate technical and organisational measures where required by our transfer impact assessments.
You may request a copy of the transfer safeguards applicable to your data by contacting contact@meetia.io.
10. Data Security
We implement and maintain appropriate technical and organisational security measures to protect personal data. Our current security measures include:
- Encryption in transit: all data exchanged between clients and our servers, and between our servers and sub-processors, is protected using TLS.
- Encryption at rest (partial): API keys and OAuth credentials for integrations and calendar are encrypted at the application level using AES-256. Meeting transcripts and uploaded files are stored in object storage that encrypts every object at rest with AES-256, managed by the storage provider. Database backups are encrypted with AES-256 before they leave our servers and are stored separately from the production system. The contents of our database are not separately encrypted at the storage layer.
- Access controls: role-based permissions limit access to personal data to authorised personnel only.
- Security monitoring: application and infrastructure logs are aggregated centrally for monitoring and forensic investigation.
- Personal data breach handling in accordance with our obligations under GDPR Articles 33 and 34, as described below.
- Contractual security requirements imposed on all sub-processors.
Despite these measures, no security system is impenetrable. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR.
11. Your Rights
11.1 Rights Under GDPR
If you are located in the European Union, European Economic Area, or United Kingdom, you have the following rights in relation to your personal data:
| Right | What it means | How to exercise |
|---|---|---|
| Access (Art. 15) | Obtain confirmation that we process your data and receive a copy of it. | Email contact@meetia.io or use your account settings. |
| Rectification (Art. 16) | Correct inaccurate or incomplete personal data. | Edit directly in account settings or contact us. |
| Erasure (Art. 17) | Request deletion of your personal data where it is no longer necessary or processing is unlawful. Account deletion triggers anonymisation and soft deletion of your personal data and memberships. | Delete your account via Settings, or email contact@meetia.io. We will process the request within 30 days. |
| Restriction (Art. 18) | Restrict processing while a dispute about accuracy or lawfulness is resolved. | Contact contact@meetia.io. |
| Objection (Art. 21) | Object to processing based on legitimate interests, including profiling. | Contact contact@meetia.io. |
| Withdraw consent | Withdraw any consent you have given at any time, without affecting lawfulness of prior processing. | Use in-app settings (analytics opt-out, marketing preferences) or contact us. |
| Lodge a complaint | Lodge a complaint with your local data protection authority. | See the list of EU supervisory authorities at edpb.europa.eu. |
We will respond to all verifiable data subject requests within one month of receipt. If a request is complex or numerous, we may extend this by a further two months and will inform you accordingly.
There is no charge for exercising your rights, except where requests are manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline.
11.2 Right to Erasure — How It Works
Deletion of your account via account settings or upon written request triggers the following sequence: personal data fields are anonymised, your memberships and content associations are soft-deleted, and your account is marked for permanent removal. This process is completed within 30 days. Certain data (e.g. financial records) may be retained longer as required by applicable law.
Note: data portability (Art. 20 — machine-readable export) is not currently available as a self-service feature. If you require a copy of your data, contact contact@meetia.io and we will assess your request manually.
11.3 Supervisory Authority
Empha Studio Ltd. is incorporated in Cyprus. Our lead supervisory authority for GDPR purposes is the Commissioner for Personal Data Protection of the Republic of Cyprus:
| Authority | Office of the Commissioner for Personal Data Protection |
|---|---|
| Website | dataprotection.gov.cy |
| commissioner@dataprotection.gov.cy | |
| Address | 1 Iasonos Street, 1082 Nicosia, Cyprus |
You also have the right to lodge a complaint with the data protection authority in your country of residence or place of work.
12. Your Obligations When Using Meetia to Transcribe Meetings
When you use Meetia to transcribe a meeting, you become the data controller for the personal data of other participants. GDPR and national laws impose obligations on you, not just on Meetia.
Meetia transcribes meetings through browser-based capture or desktop application — there is no third-party bot that joins the meeting on your behalf. Because transcription begins when you start it in your browser or desktop app, the responsibility to inform participants lies entirely with you.
Before transcribing any meeting using Meetia, you must:
- Inform all participants that the meeting is being transcribed;
- Obtain any legally required consents under applicable law (consent requirements for recording and transcription vary significantly by jurisdiction and may require explicit verbal or written consent);
- Ensure you have a lawful basis under GDPR Article 6 for processing participant data;
- Provide participants with information about how their data will be used, retained, and who has access to it (GDPR Articles 13/14 transparency obligations);
- Respect any objections raised by participants.
Meetia is a tool provider. Any liability arising from unauthorised transcription, failure to obtain required consents, or breach of applicable surveillance or data protection law rests solely with you.
13. Age Restrictions
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from users under 16. This minimum age aligns with Cyprus's implementation of GDPR Article 8 for information society services.
If we become aware that we have inadvertently collected personal data from a user under 16, we will delete that data promptly and terminate the account. If you believe a user under 16 has registered, please contact us at contact@meetia.io.
14. Third-Party Links and Services
The Service may contain links to third-party websites or integrate with third-party platforms. This Privacy Policy does not apply to those third parties. We encourage you to read the privacy policies of any third-party services you use in connection with Meetia. Meetia is not responsible for the privacy practices of third-party services.
15. EU AI Act Compliance
The EU AI Act obligations applicable to providers of AI-integrated services come into force in August 2026. Meetia is actively preparing for compliance. Relevant transparency measures will include:
- Clear labelling of AI-generated content (transcripts, summaries, action items);
- User controls over AI feature usage;
- Documentation of AI system capabilities and limitations.
We will update this Policy and our practices as specific obligations become applicable. Users in the EU may contact us at contact@meetia.io with any questions about our AI systems.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will notify you of material changes by:
- email to the address associated with your account;
- prominent in-app notification;
- updating the "Last Updated" date at the top of this document.
Where changes affect processing activities based on your consent, we will collect fresh consent where required. If you do not accept the updated Policy, you should stop using the Service before the effective date and may request deletion of your data.
17. Contact Us
For any questions, requests, or concerns about this Privacy Policy or our data practices, please contact us:
| Data controller | Empha Studio Ltd. |
|---|---|
| Registered address | Ntempyssi 22, 3120, Limassol, Cyprus |
| Registration number | CY10438500L |
| General contact | contact@meetia.io |
| Website | meetia.io/privacy |
| DPA / data processing | meetia.io/dpa |
We aim to respond to all privacy-related enquiries within 5 business days, and to all formal data subject rights requests within one month.