Privacy Policy

SAS SPOKE

  • Registered Office: 35 rue Pauline Borghèse, 92200 Neuilly sur Seine, France
  • SIREN Number: 883 755 654 (a unique identification number assigned to each business in France)

At SPOKE, protecting your personal data is our priority.

When you use the website spoke.app (hereinafter the "Website") or our Spoke computer software downloadable (hereinafter the "Application"), we are required to collect personal data about you.

The purpose of this policy is to inform you on how we process your personal data in compliance with the Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the "GDPR").

Entry into force: 21/09/2021 Last Updated: 5th of October 2026

0. Compliance with Google API Services

Spoke's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. When you connect your Google account to our services, we access your Google user data to provide and improve our services. This data may include your email address, profile information, and other relevant details. We use this data solely for the purposes described in this privacy policy and in compliance with the Google API Services User Data Policy.

1. Who is the data processor and the data controller?

SPOKE, through its service Meeting BaaS, acts as a data processor when a client uses our services to record and transcribe conversations. In this context, the client is the data controller, and we act according to the client's instructions.

**For our own operational purposes, SPOKE acts as a data controller. **We are a simplified joint-stock company, registered with the Registry of Trade and Companies of Nanterre under the number 883 755 654, and our head office is located at 35 rue Pauline Borghèse, 92200 NEUILLY-SUR-SEINE (hereinafter referred to as "Us" or "We").

2. What personal data do we process as a data controller?

As a data processor, we process data based on the actions of our clients while using our services. This can include recordings, and transcriptions of calls. By default, recordings, transcriptions and summaries of users will only be stored for a maximum of 90 days, when Spoke acts as a data processor.

  • Purpose: To perform operations related to contracts, orders, invoices, and customer relationship management

  • Legal Basis: Performance of a contract to which you are party

  • Data retention period: Personal data are retained for the duration of our business relationship. In addition, the data relating to your transactions (with the exception of your banking data) are archived for probationary purposes for a period of 5 years. The data related to your credit card are retained by our payment service provider (Stripe; https://stripe.com/) until the end of your subscription. The CVV2 (Card Verification Value), listed on your credit card details, will not be stored. Invoices are archived for a period of 10 years.

  • Purpose: To carry out sponsorship operations

  • Legal Basis: Our legitimate interest in developing and promoting our business

  • Data retention period: Personal data are retained during the necessary time to carry out the sponsorship operation and for a maximum period of 1 year.

  • Purpose: To compile a database of customers and prospects

  • Legal Basis: Our legitimate interest in developing and promoting our business

  • Data retention period: For our clients: personal data are retained for the duration of the business relationship plus a period of 3 years from the termination of this relationship. For our prospects: personal data are retained for a period of 1 year starting from the last contact with us (e.g. communication, action).

  • Purpose: To send newsletters, requests and direct marketing mailings

  • Legal Basis: For our clients: our legitimate interest in developing and promoting our business. For our prospects: your consent.

  • Data retention period: Personal data are retained for a period of 3 years starting from the last contact with us (e.g. communication, action).

  • Purpose: To comply with our legal and regulatory obligations

  • Legal Basis: Legal and regulatory obligations

  • Data retention period: Invoices are archived for a period of 10 years. In addition, the data relating to your transactions (with the exception of your banking data) are archived for probationary purposes for a period of 5 years.

  • Purpose: To process data subjects' requests to exercise their rights

  • Legal Basis: Legal and regulatory obligations

  • Data retention period: If we ask you a proof of identity: we only retain it for the necessary time to verify your identity. Once the verification has been carried out, the proof is deleted. If you exercise your right to object to stop your data being used for direct marketing: we keep this information for 3 years.

4. Who are the recipients of your personal data?

Will have access to your personal data:

  • The staff of our company;

  • Our processors: hosting provider, CRM tool, mailing provider

  • Our transcription partners

  • If applicable: public and private bodies, exclusively to comply with our legal obligations.

For a more detailed information, please consult our Data Processing Agreement.

5. Are your personal data likely to be transferred outside the European Union?

Your personal data is hosted for the duration of the processing on the servers of the company Amazon Web Services, located in the European Union.

As part of the tools, we use (see article 4 on the recipients of your personal data, especially our processors), your personal data may be transferred outside the European Union. The transfer of your personal data in this context is secured with the use of following safeguards:

  • Either personal data are transferred to a country that has been recognized as ensuring an adequate level of protection by a decision of the European Commission;

  • Or specific contracts have been executed with our processors for the transfer of your personal data outside the European Union, based on the Standard Contractual Clauses between a controller and a processor approved by the European Commission;

  • Or appropriate safeguards as defined by the GDPR have been undertaken.

6. What rights do you have regarding your personal data?

You have the following rights with regard to your personal data:

  • Right to be informed: this is precisely why we have drafted this privacy policy as defined by articles 13 and 14 of the GDPR.
  • Right of access: you have the right to access all your personal data at any time as defined by article 15 of the GDPR.
  • Right to rectification: you have the right to rectify your inaccurate, incomplete or obsolete personal data at any time as defined by article 16 of the GDPR.
  • Right to restriction of processing: you have the right to restrict the processing of your personal data in certain cases defined in article 18 of the GDPR.
  • Right to erasure ("right to be forgotten"): you have the right to request that your personal data be deleted and to prohibit any future collection as defined by article 17 of the GDPR.
  • Right to file a complaint to a competent supervisory authority (in France, the CNIL), under GDPR article 77, if you consider that the processing of your personal data constitutes a breach of applicable regulations.
  • Right to define instructions related to the retention, deletion and communication of your personal data after your death (article 40-1 of French law "informatique et libertés").
  • Right to data portability: under specific conditions defined in article 20 of the GDPR, you have the right to receive the personal data you have provided us in a standard machine-readable format and to require their transfer to the recipient of your choice.
  • Right to object: You have the right to object to the processing of your personal data as defined by article 21 of the GDPR. Please note that we may continue to process your personal data despite this opposition for legitimate reasons or for the defense of legal claims.

7. Using Meeting BaaS through an AI assistant (Meeting Agent)

Meeting BaaS can be connected to an AI assistant such as Claude (Anthropic) or ChatGPT (OpenAI) under the name Meeting Agent. In that case the assistant acts on your account through a connection you authorize, and the following applies in addition to the rest of this policy.

  • What we receive from the assistant: the meeting link, the display name and message you choose for the recording bot, and the arguments of each action the assistant performs for you (for example a meeting identifier or a date range). We never receive your conversation with the assistant, its memory or any file you share with it.
  • What we return to the assistant: meeting metadata (platform, start and end time, participant names as shown in the meeting), transcripts as text with speaker names and timestamps, links to recordings, and your account's recording time and retention setting. The assistant provider (Anthropic or OpenAI) receives these results as part of your conversation, under its own terms and privacy policy.
  • Recording other people: the bot joins the meeting under a visible name and posts a notice that the meeting is being recorded and transcribed. Hosts may refuse or remove it. You remain responsible for informing participants and for obtaining their consent where the law requires it.
  • Retention: recordings, transcripts and chat logs are kept for the number of days you choose when connecting (you can change it at any time from the assistant or your account) and deleted automatically afterwards. Deleting a meeting removes its recording, transcript and chat log immediately.
  • Calendar access: if you connect a Google or Microsoft calendar, we keep a read-only calendar token to find meeting links and times. We read no other calendar data and never write to your calendar. Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements (see article 0). Disconnecting the calendar deletes the token.
  • Access tokens: the assistant holds an OAuth access token bound to one of your workspaces. Access tokens expire after one hour and can be renewed for up to 30 days; revoking the connection (disconnecting the assistant) stops access immediately.
  • Payment: recording time beyond the free allowance is prepaid by card through our payment service provider (Stripe), which alone retains your card details; see the Terms and Conditions. We never collect card details through the assistant.
  • Recipients: in addition to the recipients listed in article 4, the assistant provider you chose receives the results described above. Our transcription partners and hosting providers process the recordings as described in articles 4 and 5.

8. Contact information for data privacy matters

Contact email: privacy@spoke.app Security reports: support@meetingbaas.com Contact address: SPOKE, 35 Pauline Borghèse street 92200 NEUILLY-SUR-SEINE

9. Modifications

We may modify this privacy policy at any time, in particular in order to comply with any regulatory, jurisprudential, editorial or technical change.

These modifications will apply on the date of entry into force of the modified version. Please regularly consult the latest version of this privacy policy. You will be kept posted of any significant change of the privacy policy.