Privacy statement
Status: October 14, 2024
The protection of your personal data is particularly important to Aliru GmbH. In the following, we inform you about how we handle personal data when using our “Sally AI” software (available at www.sally.de) for what purposes we process it and what rights you are entitled to as a data subject. Compliance with the General Data Protection Regulation (GDPR) and other relevant data protection regulations is a matter of course for us.
1. person responsible for data processing
Aliru GmbH
Julian Kissel
Julius-Hatry-Strasse 1
68163 Mannheim
kontakt@sally.de
+49 621 49088670
If you have any questions or concerns about data protection, you can contact our data protection officer at kontakt@sally.de.
2. object and purpose of data processing
Sally AI is a software that supports companies in conducting and following up online meetings. Sally AI actively participates in virtual meetings via platforms such as Zoom, Microsoft Teams and Google Meet. Following the meetings, Sally AI creates automatically generated summaries and identifies relevant tasks, which it distributes to the responsible participants. These functions aim to reduce the administrative burden of meetings and ensure efficient follow-up.
Sally AI processes personal data for the following purposes:
- Participation in Virtual Meetings: Analysis and processing of spoken content in real-time or afterward to create summaries.
- Creation of Summaries: Providing a concise overview of the meeting's content and key takeaways.
- Task Identification: Detecting tasks resulting from the meeting and automatically assigning them to the responsible participants.
- Management and Documentation: Storing meeting summaries and tasks on the platforms used (e.g., Microsoft Teams) for future reference.
- Software Optimization: Analyzing usage data and feedback to improve Sally AI's AI capabilities and features.
Processing is carried out in accordance with the contractual agreements with our customers and exclusively on the basis of the applicable data protection regulations.
3. What data do we process?
As part of the use of Sally AI different categories of data are processed. These include both personal and non-personal data. Processing is carried out exclusively to the extent necessary to provide our services. The following types of data may be affected:
1. User data:
- Name, email address, user ID, department, or team membership
- Meeting data, such as title, date, and time
2. Meeting content:
- Audio recordings or transcripts of meetings that are used to create summaries
- Discussion contributions from individual participants, e.g. discussed topics, tasks or decisions
3. Task assignment and task management:
- Identified tasks and responsibilities from the meeting (e.g. “Max Müller prepares the budget for Q4”)
- Assignment of tasks to the responsible persons via the integrated systems (e.g. Microsoft Teams tasks or Outlook)
4. Log and connection data:
- When and how long Sally AI will attend meetings
- Information about the platform used (e.g. Zoom, Microsoft Teams, Google Meet)
- Technical data such as IP address, device information and browser used
5. Technical usage data:
- Software usage statistics for optimization and troubleshooting (e.g. frequency of use, functions called up)
Important note: Sally AI does not process content for purposes other than those mentioned above. Sound recordings are only temporarily stored to the extent necessary to create summaries and are then deleted, provided that there are no contractual or legal storage obligations.
Data storage period:
- Audio and transcription data: Are deleted after the summary has been generated, unless otherwise agreed.
- Summaries and tasks: Are stored for as long as is necessary to fulfill the contractual purposes or as long as there are legal storage obligations.
- Technical data and log files: Are usually deleted after 90 days, unless there are legitimate interests in further storage (e.g. for troubleshooting).
This use of data ensures that the software works efficiently and remains compliant with data protection regulations. Processing is always carried out on the basis of Art. 6 para. 1 lit. b DSGVO (contract fulfillment) and Art. 6 para. 1 lit. f DSGVO (legitimate interest, e.g. software optimization).
4. Which external service providers are used?
To operate and deploy Sally AI, we use a range of trusted third-party service providers who help us with infrastructure, payment services, analytics, and other features. All service providers are carefully selected and contractually bound to comply with the GDPR (Art. 28 GDPR). All data processing is carried out within the European Union or in accordance with applicable data protection standards. Below you will find detailed information about the providers used and their data protection regulations:
1. Microsoft Azure
We use Microsoft Azure cloud infrastructure to provide scalable computing and storage capacity. All Azure resources used for Sally AI are hosted in data centers within the European Union.
- Microsoft privacy statement: https://privacy.microsoft.com/de-de/privacystatement
2. Microsoft Dynamics 365
For customer management and the administration of user contacts, we use Microsoft Dynamics 365, which is hosted exclusively on servers within the EU.
- Microsoft privacy statement: https://privacy.microsoft.com/de-de/privacystatement
3. Microsoft Clarity
We use Microsoft Clarity to optimize the user experience. This tool helps us understand how users interact with our website by collecting anonymous user interaction data.
- Microsoft Clarity Privacy Statement: https://privacy.microsoft.com/de-de/privacystatement
4. Amazon Web Services (AWS)
Parts of the infrastructure and data processing are run on Amazon Web Services (AWS), with all resources used being hosted exclusively in the European Union.
- AWS Privacy Policy: https://aws.amazon.com/de/compliance/data-privacy/
5th DeepL
For automated translations, we use the DeepL service, which is also hosted within the EU. DeepL provides reliable translations with a particular focus on data protection.
- DeepL's privacy policy: https://www.deepl.com/privacy
6. Google Analytics
We use Google Analytics, a web analysis service from Google, to analyze user behavior. IP addresses are anonymized and all data is processed within the EU. Google Analytics enables us to better understand and optimize the use of our software.
- Google's privacy policy: https://policies.google.com/privacy
- Information about Google Analytics and data protection: https://support.google.com/analytics/answer/6004245
7. Stripe
We use Stripe to process payments. Stripe processes payment data in accordance with European data protection regulations and is GDPR-compliant. All relevant data is transmitted in encrypted form.
- Stripe's privacy policy: https://stripe.com/de/privacy
8th Strato
To host parts of our infrastructure, we use Strato, a German hosting provider that operates exclusively data centers based in Germany.
- Strato's privacy policy: https://www.strato.de/datenschutz/
5. Legal basis of data processing
Personal data is processed on the basis of:
- Art. 6 para. 1 lit. b GDPR (Fulfilment of a contract or implementation of pre-contractual measures)
- Art. 6 para. 1 lit. c GDPR (compliance with legal obligations)
- Art. 6 para. 1 lit. f DSGVO (Safeguarding legitimate interests, e.g. ensuring the security of the application)
Insofar as consent is required, processing is carried out on the basis of Art. 6 para. 1 lit. a GDPR.
6. Transfer of data to third parties
Personal data will only be passed on to third parties if this is necessary to fulfill the contract, if we are legally obliged to do so or if you have given your express consent. We transfer data exclusively to service providers within the EU. There is no data transfer to third countries.
7. Data security
Aliru GmbH uses technical and organizational security measures to protect the data we store against loss, misuse and unauthorized access. This includes encrypted data transmissions, access controls and regular security checks.
8. Storage period and deletion of data
We only store personal data for as long as is necessary to fulfill the respective purpose or as long as there are legal retention periods. After the purpose has been achieved or legal deadlines have expired, the data will be deleted immediately.
9. Rights of data subjects
As a data subject, you have the following rights:
- Right to information: You have the right to obtain information about the processing of your data (Article 15 GDPR).
- Right of rectification: You can request the correction of incorrect or incomplete data (Art. 16 GDPR).
- Right of deletion: You have the right to request the deletion of your data unless there is a legal obligation to store it (Art. 17 GDPR).
- Right to restrict processing: You can request that the processing of your data be restricted (Art. 18 GDPR).
- Data portability: You have the right to receive your data in a structured, common and machine-readable format (Art. 20 GDPR).
- Right to object: You can object to the processing of your data for reasons arising from your particular situation (Article 21 GDPR).
- Right of withdrawal: You can withdraw your consent at any time with effect for the future (Article 7 (3) GDPR).
To exercise your rights, please contact us using the contact details above.
10. Right to lodge a complaint with the supervisory authority
If you believe that the processing of your data violates the GDPR, you have the right to lodge a complaint with a supervisory authority.
11. Changes to this privacy policy
We reserve the right to change this privacy policy at any time in order to adapt it to legal or technical developments. The latest version can always be found on our website www.sally.de.
12. contact
If you have any questions or concerns about this privacy policy or the processing of your personal data, please contact us at:
Aliru GmbH
Julius-Hatry-Strasse 1
68163 Mannheim
kontakt@sally.de
Note: These data protection regulations ensure that all relevant aspects of data protection are taken into account and that your personal data is processed in full compliance with GDPR.