Skip to main content

How We Process Your Data

Sally AI acts strictly as a Data Processor, processing data only on your documented instruction, only for agreed purposes, and never for our own business interests.

What We Process

📝
Text Inputs

Prompts and comments entered directly in the product.

🔧
Technical Metadata

IP addresses, timestamps, system/meeting IDs, and log events.

🎙️
Meeting Data

If meeting features are enabled: audio/video and transcripts as defined in the DPA.

What We Never Do

✗ No AI training on customer data✗ No processing for our own business purposes✗ No data transfers outside the EU

Why We Process It

⚙️
Contract Performance

Providing the agreed service based on your documented instructions, fully GDPR-compliant under a signed DPA.

🛡️
Support & Security

Troubleshooting and abuse prevention, carried out within the scope of our technical and organisational measures (TOMs).

Where It's Stored

🇪🇺 EU-only🇩🇪 100% DE by end of May 2026🔒 Encrypted
Primary Location

German data centers at Hetzner. Until end of May 2026, alternative EU regions may still be used. After that, exclusively Germany. No third-country transfers, ever.

On-Premises Option

Store data in your own MS SQL database on-premises. Data never leaves your infrastructure.

Retention & Deletion

During contract

Data is retained only as needed for the agreed purposes, per your explicit instructions.

Temporary processing data

Audio pipeline artifacts and other transient data are automatically deleted after transcript creation, unless you have enabled recording storage.

After contract end

Deletion or return within 30 days, with written confirmation as specified in the DPA.

✓ 30-day deletion guarantee after contract end

Data Masking for AI

🔐 Personal Data Never Reaches the AI

Before any data is sent to a large language model (LLM), all personally identifiable information is masked. Names, email addresses, and other identifiers are replaced with anonymized placeholders before content reaches the AI. The original data is restored only within our own secure infrastructure after processing.

Additionally, the Bring Your Own LLM option lets you configure Sally to use your organization's own language models exclusively, so no data ever leaves your infrastructure for AI processing.

No personal data in LLM processing
EU-region Azure OpenAI only
Bring Your Own LLM supported