How we process your data
This page explains exactly which data Sally AI processes, why we process it, where it is stored, and how long we keep it. Sally AI acts strictly as a Data Processor under Art.Β 28 GDPR, processing data only on your documented instruction and never for our own business interests. Read this for vendor assessments, RoPA entries, or to understand end-to-end what happens to customer data inside Sally.
What we processβ
Prompts and comments entered directly in the product.
IP addresses, timestamps, system/meeting IDs, and log events.
If meeting features are enabled: audio/video and transcripts as defined in the DPA.
What we never doβ
Why we process itβ
Providing the agreed service based on your documented instructions, fully GDPR-compliant under a signed DPA.
Troubleshooting and abuse prevention, carried out within the scope of our technical and organisational measures (TOMs).
More on data handlingβ
How AI processing runs on Sally's own LLM inside our own infrastructure in Germany, plus the Bring Your Own LLM option.
Read moreΒ βWhere data is stored: exclusively in German data centers at Hetzner, subprocessors in Germany only, no third-country transfers.
Read moreΒ βRetention model during the contract, temporary data handling, and 30-day deletion guarantee after contract end.
Read moreΒ β