Privacy Policy
Last updated: 28 July 2026
[YOUR LEGAL BUSINESS NAME] operates the Transcript service and is the data controller for the personal data described here, except for the contents of recordings our customers upload, where the customer decides what is collected and why, and we process it on their instructions. Contact: [support@yourdomain.uk].
What we collect
- Account data — your name, organisation, email address, and a hashed password. We never store passwords in readable form.
- Recordings and transcripts — the audio and video you upload, the transcripts produced from them, and your edits. Recordings of conversations can include personal data — sometimes sensitive — about the people speaking.
- Audit records — who did what and when (uploads, views, edits, approvals, exports, sign-ins), with IP address and browser information. These form a tamper-evident chain; that integrity protection is central to the product.
- Billing data — handled by our payment provider, Paddle, who act as merchant of record. We receive confirmation of your subscription status but never your card details.
- Contact messages — what you send through our contact form.
Why we process it
- To provide the service you have an account for — storing, transcribing, and exporting your recordings (performance of a contract).
- To keep the service and its evidential guarantees secure — authentication, audit trails, abuse prevention (legitimate interests and, for some records, legal obligation).
- To take payment and manage subscriptions (performance of a contract, via Paddle).
- To respond when you contact us (legitimate interests).
We do not sell personal data, and we do not use your recordings or transcripts to train AI models or show you advertising.
Where your data is processed
Recordings, transcripts, and account data are stored on our own server in a United Kingdom data centre, and speech recognition runs on that server by default — audio is not sent to third-party AI services unless your organisation's plan explicitly chooses a cloud processing option, in which case processing is pinned to a UK region.
Who we share it with
- Paddle (payments, invoicing, and tax, as merchant of record) — see Paddle's privacy policy.
- Our hosting provider, which supplies the UK data centre where the server runs.
- Authorities or courts where the law requires it.
How long we keep it
You control your recordings and transcripts: they stay until you delete them or your organisation's retention settings remove them, subject to any legal hold. Nothing is deleted for non-payment. Audit records are retained for as long as the material they attest to, because deleting them would break the evidential chain. Account data is kept while your account exists and for a short period after closure.
Security
Connections are encrypted in transit; passwords are stored as BCrypt hashes; every upload is fingerprinted with SHA-256 so tampering is detectable; original recordings are immutable once stored; and access is restricted by role within your organisation.
Your rights
Under UK data protection law you can ask for a copy of your personal data, ask us to correct or delete it, object to or restrict processing, and take your data elsewhere. Some requests have limits — for example, audit records or material under legal hold may need to be preserved. Write to [support@yourdomain.uk] and we will respond within a month. If a recording held by one of our customers contains your voice, the request is usually for that organisation as controller, but we will help route it. You can also complain to the Information Commissioner's Office (ico.org.uk).
Cookies
We use one essential cookie (transcript.auth) to keep you signed
in. There are no advertising or tracking cookies. Paddle's checkout sets its
own cookies when you pay; those are covered by Paddle's policy.
Changes
If we change this policy materially we will notify account holders by email or in the product before the change takes effect.