FAQ: Security & privacy
Sally AI follows strict data protection and security standards. All data is encrypted at rest using AES-256 and in transit via TLS 1.3. Access is protected by role-based access controls and multi-factor authentication. All access and changes are recorded in a comprehensive audit log. Sally is fully GDPR-compliant, aligned with ISO 14001 and ISO 9001 standards, and operated in ISO 27001-certified data centers. Organizations can additionally define their own privacy policies.
All meeting content, transcripts and metadata are hosted exclusively in German data centers at Hetzner. Personal data is never processed or stored outside the EU. For organizations with specific requirements, Sally offers on-premises data storage in the customer's own infrastructure.
No. Your meeting data is never used for AI model training or any other proprietary purposes. Sally acts as a data processor (Art. 4(8) GDPR) and processes data exclusively on the customer's instructions to deliver the agreed-upon service. AI processing runs on Sally's own language model, operated end-to-end in our own infrastructure in Germany, without any external AI providers. Organizations with particularly strict requirements can also configure Sally to use only their own LLMs instead.
Sally meets the transparency requirements of Art. 13/14 GDPR automatically: when she joins, she posts a privacy notice with a link to the information sheet in the meeting chat. It tells participants what is processed and why, how long it is kept, and what rights they have. We also recommend mentioning at the start of the meeting that Sally is taking part, and covering this in your internal meeting guidelines. Participants can object at any point by typing "opt out" in the chat. Sally then leaves immediately and deletes everything recorded up to that point, irrevocably.
Sally can also email participants in advance to let them know she will be taking part. They then have to give their consent before she joins, and without it she does not.
Yes. As the data controller, you can instruct Sally to completely delete your data at any time. Sally processes deletion requests within 5 business days. Sally also supports every data subject right under the GDPR: access, rectification, erasure, restriction, portability, and objection. Temporary data, from the audio pipeline for example, is deleted as soon as processing is finished. When the contract ends, everything is deleted or handed back in a machine-readable format within 30 days, and you receive written confirmation.
Yes. Sally concludes a GDPR-compliant Data Processing Agreement (DPA) under Art. 28 GDPR with all customers. The DPA covers purpose limitation, deletion obligations, technical and organizational measures (TOMs), and subprocessor management. It includes annexes on TOMs, records of processing activities, subprocessor list, Data Protection Impact Assessment (DPIA), and an AI compliance statement under the EU AI Act. You can request and digitally sign the DPA directly online.
Request a DPA | All privacy documents in the Download Center
Yes. Sally AI is classified as Limited Risk under the EU AI Act and fulfills all applicable transparency obligations. Sally identifies herself clearly as an AI service, and how the data is processed is documented in full. A detailed AI compliance statement is included with the DPA.