Privacy policy

Last updated: September 23, 2026

DeciDesk is a B2B tool for structured team decision-making. To run that service we collect a limited amount of personal data — your name, email, and the content you choose to create inside DeciDesk. This page explains exactly what we collect, why, who processes it for us, how long we keep it, and what rights you have over it.

1. Who we are

DeciDesk is operated by Dennis Heemskerk, Voorhouterweg 25, 2231 NB Rijnsburg, the Netherlands (Chamber of Commerce/KVK 42123032, VAT NL005511818B93). For any privacy-related question, reach us at privacy@decidesk.ai.

2. What we collect

We collect only what we need to provide the service:

  • Account information: your name, email address, and password (hashed, never stored in clear text).
  • Profile photo: optional. If you upload one, it is stored on Vercel Blob (EU region) and shown alongside your name inside DeciDesk. You can remove it at any time from your profile page.
  • Meeting recordings: anyone who can open a meeting can record it: in a room with their phone, or online (Teams, Google Meet or Zoom) with our recording bot. The audio is stored in Vercel Blob (EU region) and sent to our transcription provider (ElevenLabs) to generate a text transcript; with the recording bot, the names of the participants in the online meeting come along. The transcript is posted into the meeting. Audio files are automatically deleted 90 days after the recording; transcripts are retained until the meeting is deleted. The person who made the recording, anyone above them in the line and the organization's administrators can delete a recording (audio + the placeholder in chat) at any time.
  • Questions to the DeciDesk Assistant: your question is sent, together with the DeciDesk data you may see yourself and that the answer needs, to Azure OpenAI (EU) to create an answer. We do not keep your conversations with the assistant. If you submit a feature request through the assistant, we keep that question with your name so we can assess the request.
  • Organization data: the name of your organization, company, departments, teams, projects, and the meetings and decisions you create inside DeciDesk.
  • Usage data: pages visited, features used, and basic device information (operating system, browser, app version). We use this to keep DeciDesk reliable and fix bugs.
  • Billing information: card details are collected and stored by our payment processor Stripe. We never see or store your full card number. We do store the billing email, company/VAT details, and an identifier that lets us look up your invoices in Stripe.
  • Communications: if you contact us by email or via the contact form, we keep the message so we can reply.

3. Why we collect it

  • To create and maintain your account and let you sign in. Legal basis: performance of the contract.
  • To provide the core DeciDesk product (decisions, meetings, notifications, AI features). Legal basis: performance of the contract.
  • To send transactional emails: verification, password reset, invitations, daily overview. Legal basis: performance of the contract.
  • To process subscriptions and invoices. Legal basis: performance of the contract; we keep invoices to meet a legal obligation (tax record keeping).
  • To keep the service secure, debug issues, and improve features. Legal basis: our legitimate interest in a secure, well-functioning service.
  • To answer your support questions. Legal basis: performance of the contract if you are a customer, otherwise our legitimate interest in answering your question.

Each purpose lists its legal basis under Article 6 of the GDPR. Where we rely on our legitimate interest, you can object to that processing (see section 8).

We do not sell your data, and we do not use it for advertising. We do not share it with third parties except for the service providers below, who process it strictly on our behalf.

4. AI features

Some DeciDesk features use AI (for example, title suggestions and summaries). When you use these features, the relevant text is processed by AI models hosted on Microsoft Azure in the European Union (Sweden) to generate the output. We do not train AI models on your data, and Microsoft does not use your inputs to train models. The same applies to transcription: ElevenLabs does not use your meeting audio or transcripts to train AI models — audio is processed solely to generate your transcript.

5. Service providers

We use a small number of processors to run DeciDesk. Each is contractually required to protect your data and only process it for the agreed purpose.

  • Neon (EU) — Postgres database hosting.
  • Vercel — application hosting, content delivery, and file storage (Vercel Blob, EU region) for meeting audio and optional profile photos.
  • Stripe — payment processing, subscription management, invoicing, and tax calculation (Stripe Tax). Stripe is based in Ireland (Stripe Payments Europe Ltd.) for EU customers and the United States for non-EU customers.
  • Microsoft Azure (EU, Sweden) — AI language models for summaries, action suggestions and the DeciDesk Assistant (Azure OpenAI Service).
  • ElevenLabs (US) — speech-to-text transcription for meeting recordings. Audio is processed solely to generate the transcript and is not used to train AI models. Transfers take place under EU Standard Contractual Clauses.
  • Recall.ai (US, processing in the EU region Frankfurt) — the recording bot that joins an online meeting in Teams, Google Meet or Zoom at a user's request and records the audio. Recall keeps the recording for three days at most.
  • Mijndomein (NL) — delivery of the app's emails, such as notifications, invitations and invoices.
  • Microsoft 365 (Microsoft Ireland) — hosting of our mailboxes, including support@ and privacy@. Messages you send us, also through the support form, arrive there.
  • Microsoft / Apple — desktop app distribution and update delivery.

6. Where your data lives

Our primary database is hosted in the European Union. Some processors above operate in the United States; in those cases data is transferred under Standard Contractual Clauses (SCCs) or equivalent safeguards approved by the European Commission.

7. How long we keep it

  • Account and organization data: as long as your account is active. When you delete your account, we delete or anonymize it within 30 days, except where we are legally required to retain it (e.g. invoices, which we keep for 7 years per Dutch tax law).
  • Backups: included in encrypted backups for up to 35 days after deletion.
  • Support emails: up to 2 years.

8. Your rights

Under the GDPR (and equivalent laws), you can:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and associated data.
  • Export your data in a portable format.
  • Object to or restrict certain processing.
  • Withdraw any consent you previously gave.
  • Lodge a complaint with your local data protection authority (in the Netherlands: the Autoriteit Persoonsgegevens).

You can update your profile photo and language yourself in your account settings. Your name and the days on which you receive notification emails are changed for you by the owner or an administrator of your organization; push notifications are turned on or off in the settings of your device. To exercise any of the other rights above, email privacy@decidesk.ai. We respond within one month, as required by the GDPR.

9. Cookies

We use only functional cookies that the site and the service need to work: an authentication cookie to keep you signed in, a CSRF token for security, a cookie that remembers your language and, in the app, a cookie that remembers which company you are working in. These cookies do not require consent. We do not use advertising or tracking cookies.

10. Security

We protect your data with industry-standard measures: TLS encryption in transit, encryption at rest, hashed passwords (bcrypt), role-based access control, audit logging, and regular dependency updates. No system is 100% secure, but we take this seriously and will notify affected users in the event of a data breach as required by law.

A limited number of DeciDesk administrators may technically access stored data — including uploaded profile photos — when strictly necessary for operating the service, such as incident response, debugging a customer-reported issue, or honouring a deletion request. Access is restricted, requires multi-factor authentication, and is never used for any purpose other than running the service.

11. Children

DeciDesk is a B2B product intended for use by adults in a work context. It is not directed at children under 16, and we do not knowingly collect data from them.

12. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top reflects the most recent change. For material changes we will notify active users by email.

13. Contact

Questions, requests, or concerns? Email privacy@decidesk.ai or visit the contact page.

Privacy policy — DeciDesk