Skip to main content

How We Process Your Data

This page explains exactly which data Sally AI processes, why we process it, where it is stored, and how long we keep it. Sally AI acts strictly as a Data Processor under Art. 28 GDPR, processing data only on your documented instruction and never for our own business interests. Read this for vendor assessments, RoPA entries, or to understand end-to-end what happens to customer data inside Sally.

What We Process

📝
Text Inputs

Prompts and comments entered directly in the product.

🔧
Technical Metadata

IP addresses, timestamps, system/meeting IDs, and log events.

🎙️
Meeting Data

If meeting features are enabled: audio/video and transcripts as defined in the DPA.

What We Never Do

✗ No AI training on customer data✗ No processing for our own business purposes✗ No data transfers outside the EU

Why We Process It

⚙️
Contract Performance

Providing the agreed service based on your documented instructions, fully GDPR-compliant under a signed DPA.

🛡️
Support & Security

Troubleshooting and abuse prevention, carried out within the scope of our technical and organisational measures (TOMs).

More on Data Handling