Data Controller
Under the GDPR, Conference Ink is the data controller for the personal data processed through the app and website.
Organization
NOERPOL (operating Conference Ink)
CVR
DK-34275076
Country
Denmark
Contact
hello@conferenceink.com
Website
conferenceink.com
Role
Data Controller (GDPR Art. 4(7))
We do not currently have a Data Protection Officer (DPO) as we do not meet the thresholds requiring mandatory DPO appointment. Privacy inquiries should be directed to hello@conferenceink.com.
Legal Basis for Processing
We process personal data only where we have a valid legal basis under GDPR Article 6. Below is a breakdown of what we process and why:
Processing necessary to deliver the service you subscribed to.
- Account management
- Session storage and sync
- Transcription processing
- AI summary generation
- Subscription management
Processing for our legitimate business interests where your rights are not overridden.
- Security monitoring and fraud prevention
- Short-lived server logs used to keep the service stable and secure
Processing required by applicable law.
- Retaining billing records under the Danish Bookkeeping Act, bogføringsloven (5 years)
- Responding to lawful authority requests
Optional processing you can turn off at any time.
- Location tagging of recordings (requires your device location permission; toggle in the app settings)
Your Rights as a Data Subject
As an EEA/UK resident, you have the following rights under the GDPR. We will respond to all requests within 30 days (extensible to 90 days for complex requests, with notice).
We will never charge a fee for handling data subject requests unless they are manifestly unfounded or excessive. In that case, we will notify you before proceeding.
Data Processing Agreements (DPAs)
All third-party processors that handle personal data on our behalf offer GDPR Article 28 data processing terms as part of their service agreements, which we rely on. These terms require each processor to:
- Process data only on documented instructions
- Implement appropriate technical and organizational security measures
- Assist in responding to data subject rights requests
- Delete or return data upon termination of the agreement
- Make available the information necessary to demonstrate compliance
Questions about our processors and their data processing terms? Email hello@conferenceink.com with the subject "DPA Request".
Data Location and Cross-Border Transfers
Our primary database and file storage is hosted by Supabase on AWS in the EU (eu-central-1, Frankfurt). Audio transcription (Deepgram) and read-aloud voice (Google Cloud) run on EU endpoints, so your data primarily stays within the EU.
Some processing activities involve transfers outside the EU. Here is where each processor operates and the transfer mechanism we rely on:
| Processor | Location | Transfer Mechanism |
|---|---|---|
| Supabase | EU (AWS eu-central-1, Frankfurt) | No transfer (EU-based) |
| Deepgram | EU endpoint (api.eu.deepgram.com) for all audio; US API used only to mint short-lived access keys (no audio) | Data Processing Agreement; Model Improvement Program opt-out (audio not used for training, not retained beyond processing) |
| Anthropic | USA (requests may be routed globally) | Data Processing Addendum in Anthropic's Commercial Terms + Standard Contractual Clauses (SCCs) |
| Google Cloud (Text-to-Speech) | EU endpoint (eu-texttospeech.googleapis.com) | Cloud Data Processing Addendum |
| RevenueCat | USA | Data Processing Agreement + Standard Contractual Clauses (SCCs) |
| Apple | Global | Merchant of record for in-app purchases; Apple's data processing terms |
| Stripe | USA / Global (website payments, when enabled) | Data Processing Agreement + Standard Contractual Clauses (SCCs) |
| Cloudflare | Global CDN (website hosting for conferenceink.com) | Data Processing Addendum |
Standard Contractual Clauses (SCCs) are the European Commission-approved legal mechanism for transferring personal data to third countries that do not have an adequacy decision. We rely on the 2021 SCCs adopted by the European Commission.
Location Tagging (Optional)
If location tagging is enabled, the app captures the approximate place where a session was recorded — GPS coordinates and a place name (e.g. "Berlin, Germany") — once, when a recording starts. It is used only to label the session so you can tell similar sessions apart, and is synced together with the session to our EU database (Supabase, Frankfurt).
Location tagging is enabled by default and can be turned off at any time with the location tagging toggle in the app settings. The location label is stored with the session until the session is deleted.
Data Retention
Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority. You may contact the supervisory authority in your country of residence, place of work, or the country where the alleged infringement occurred.
We encourage you to contact us first at hello@conferenceink.com so we can try to resolve the issue directly. We take all privacy complaints seriously and aim to respond within 15 business days.
Lead Supervisory Authority (Denmark)
Datatilsynet (Danish Data Protection Agency)
www.datatilsynet.dkExercise your GDPR rights
We're committed to honoring your rights promptly and transparently. Reach out and we'll guide you through the process.
Submit a GDPR request