1. Who is responsible
The controller for Callsect account administration and private-beta operations is Maurizio Ciocca, Rotwandstraße 6, 81539 Munich, Germany. Privacy and support requests can be sent to privacy@callsect.com.
Callsect is currently operated as a limited private beta for professional users.
When a professional user connects a work meeting account or uploads a work call on behalf of an employer or another organisation, that organisation may be the controller for the call content and Callsect may act as its service provider or processor. The user and their organisation must determine the correct roles, lawful instructions and participant notices before importing or uploading conversations. This notice does not itself create a data processing agreement with an organisation.
2. Data we process
- Account data: name, email address, optional password hash, linked sign-in provider and stable provider identifier, account type and legal-acceptance records.
- Call data: title, customer or company label, call date, transcript, speaker segments, duration and transcription metadata.
- Integration data: connected Google account identity, encrypted OAuth credentials, sync timestamps, Meet conference identifiers and participant display names.
- Generated data: dissection, CRM notes, coaching, next-call preparation, relationship timelines and Writing DNA profiles.
- Operational data: beta quota counters, rate-limit records, first-party onboarding and feature-use events, and limited technical request information.
Account, integration and upload data come from the user or the connected meeting provider. Transcripts and generated results are derived from an authorised Google Meet transcript, a user-supplied full transcript, or an uploaded recording. Account credentials and the information required to process a call are necessary to provide the service. Profile labels, Writing DNA and optional metadata are voluntary. Product events record only limited workflow facts such as whether a guide was completed, an upload was started, a result section was opened or a CRM note was generated. They do not include transcript text, call titles, customer names or raw audio.
3. Audio and transcript lifecycle
- For manual upload, the backend writes audio to temporary server storage for validation and sends it to AssemblyAI's EU API endpoint for transcription, language detection, speaker labels and timestamps.
- After retrieving a manual-upload result, Callsect requests immediate deletion of the AssemblyAI transcript and associated audio; the temporary server file is also deleted, including failure paths.
- For Google Meet, Callsect uses the user's encrypted OAuth connection to read generated transcript entries and participant metadata through Google's read-only Meet API. It does not download the original Meet recording.
- If a participant cannot be matched safely to one existing Customer, the transcript waits in Meeting Inbox until the user confirms the Customer. Dismissal removes the staged transcript and keeps only a minimal source identifier to prevent re-import.
- For direct transcript import, Callsect parses the uploaded file or pasted text into a short-lived preview. The user must confirm the YOU/CLIENT mapping before analysis. Unconfirmed previews expire after one hour; confirmed preview content is removed after the saved call is created.
- Direct transcript imports are not sent to AssemblyAI. Summary-only notes and one-speaker transcripts are rejected before analysis.
- The resulting transcript, not the original audio, is sent to OpenAI's API to generate dissection, CRM notes, coaching, next-call preparation and relationship memory.
The original recording is not stored in the Callsect database. If an AssemblyAI upload succeeds but no transcript identifier is created, or if a remote deletion request fails, immediate deletion cannot be confirmed and the provider's standard retention rules may apply. Such failures are recorded in backend logs for operational follow-up.
4. Why we use the data
- To connect authorised meeting accounts and provide transcript ingestion, transcription, dissection, CRM-note, coaching, next-call preparation and relationship-memory features.
- To authenticate users, secure the service and prevent abuse.
- To administer quotas, measure beta activation, identify onboarding friction and operate the private beta.
- To meet legal obligations and establish or defend legal claims where necessary.
The principal legal bases are performance of the private-beta agreement (Article 6(1)(b) GDPR), legitimate interests in operating and securing the service and preventing abuse (Article 6(1)(f)), and compliance with legal obligations where applicable (Article 6(1)(c)). Consent is relied on only where the relevant law requires it.
Where consent or notice is required for recording, transcription, import or processing, the user and their organisation are responsible for satisfying those requirements before connecting or uploading. OAuth authorisation and the in-app confirmation record the user's instructions; they do not prove that every legal, employment, confidentiality or contractual requirement has been met.
5. Service providers and international processing
- Render: application hosting and temporary server-side audio processing.
- MongoDB Atlas: storage of account data, transcripts, metadata and generated results.
- Zoho Mail: mailbox hosting and receipt of privacy, support and beta-administration correspondence.
- Resend: outbound delivery of transactional emails such as beta invitations, email verification, password resets and owner notifications.
- AssemblyAI: audio transcription, language detection, speaker diarization and timestamps through the configured EU API endpoint.
- Google: account authentication using the user's stable Google identifier, name and email; and, only when separately connected, read-only access to generated Google Meet transcripts, conference metadata and participant display names.
- OpenAI: analysis and generation from transcript text; the original audio is not sent to OpenAI in the current implementation.
Providers may use subprocessors and may process limited account, usage, security or support data outside Germany or the EEA under their current contractual transfer safeguards. Use of an EU API endpoint does not remove the need to review the provider's DPA, subprocessors and international-transfer arrangements.
Callsect does not intentionally submit call content for provider model training. OpenAI states that API inputs and outputs are not used for training by default unless the API customer opts in. Callsect sends audio to AssemblyAI through its European endpoint; AssemblyAI states that files submitted through its European servers are not used for model training. A change away from that endpoint requires a fresh legal and notice review.
6. Retention and deletion
- Saved account and call data remain until the user deletes the relevant call or account.
- The Google Sign-In identity is removed when unlinked or when the account is deleted. Google Meet OAuth credentials are encrypted at rest and removed when the user disconnects Meet or deletes the account.
- Unmatched Meet transcripts remain in Meeting Inbox until confirmed, dismissed, disconnected or the account is deleted. Dismissed items retain only a minimal deduplication identifier.
- Unconfirmed direct-transcript previews expire automatically after one hour and are deleted immediately when dismissed or when the account is deleted.
- Callsect requests deletion of the AssemblyAI transcript and associated uploaded audio immediately after retrieving the transcription result.
- The temporary Render-side audio file is deleted after the transcription attempt.
- OpenAI states that default API abuse-monitoring logs may retain customer content for up to 30 days, subject to legal exceptions and any approved account-level retention controls.
- Short-lived security and rate-limit records expire automatically or are deleted with the account.
- User-linked onboarding and feature-use events are included in account export and deleted with the account.
- After account deletion, a minimal beta access-control record containing the email address, deleted status and deletion timestamp is retained for the duration of the beta to prevent accidental recreation and abuse.
- Account-unlinked aggregate beta counters may remain for spend-control integrity.
- Infrastructure logs and backups may follow provider-configured retention periods.
Users can delete individual calls, export their account data as JSON and permanently delete their account in the app. Deleting a call removes its saved Callsect transcript, analysis, CRM notes and coaching and updates or removes the related customer-memory record.
7. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or object to processing. You may withdraw consent where consent is the legal basis, without affecting earlier lawful processing. Requests should be sent to privacy@callsect.com.
You may also complain to a competent data-protection authority. For a private-sector controller established in Bavaria, the relevant authority is generally the Bavarian State Office for Data Protection Supervision (BayLDA).
8. Data protection safeguards
Callsect applies technical and organisational safeguards designed to protect personal data against unauthorised access, disclosure, alteration and loss. These safeguards include:
- HTTPS encryption while data is transmitted between the user, Callsect and its service providers.
- Encryption at rest for stored Google Meet OAuth credentials. Application credentials and encryption keys are kept in restricted server-side environment configuration and are not exposed to the browser.
- Authenticated, user-scoped access controls so users can access only data associated with their own account. Passwords are stored as salted hashes rather than plaintext.
- A restricted production-origin allowlist, server-side rate limits and short-lived OAuth state records to reduce unauthorised requests and abuse.
- Data minimisation, temporary-file cleanup, limited transcript-preview retention and user-controlled deletion as described in this notice.
- Operational access limited to the operator and service providers where reasonably necessary to run, secure or troubleshoot the service, respond to the user, or comply with law. Suspected security incidents are investigated and affected credentials can be revoked or rotated.
No internet service can guarantee absolute security. Questions or reports concerning data security can be sent to privacy@callsect.com.
9. Google API Services User Data and Limited Use
The use and transfer of raw or derived user data received from Google Workspace APIs by Callsect adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google Workspace data is used only to provide or improve the user-facing Callsect features described in this notice. It is not sold, used for advertising, used to determine creditworthiness or lending, or transferred for unrelated purposes. Callsect does not permit humans to read Google Workspace data except with the user's affirmative agreement for support, where necessary for security or abuse investigation, to comply with applicable law, or where the data has been aggregated and anonymised. Transfers to the service providers identified above are limited to what is necessary to provide those user-facing features and are subject to applicable confidentiality and data-protection obligations.
10. Automated analysis and security
Callsect generates probabilistic AI-assisted observations and coaching. They may be incomplete or wrong and are not used by Callsect to make legal or similarly significant decisions about people. Passwords are stored as hashes, access is authenticated, and stored user data is scoped to the signed-in account.
11. Changes
Material changes require a new legal version. Existing users must review and accept the current Privacy Notice and Private Beta Terms before returning to protected features.
The 3 September 2026 update clarifies existing data-protection safeguards and Google API Limited Use commitments. It does not expand the categories of data collected or the purposes for which they are used.

