Clerqly

Privacy statement

Version 1.0, updated 17 August 2026


1. Who processes your data

Clerqly is the service; below is the company responsible for what happens to your data. If you have a question or want to exercise one of your rights, this is the address.

Company

Clerqly I.O

Address

[nog invullen: straat, postcode en plaats]

Chamber of Commerce number

[nog invullen: KvK-nummer]

VAT number

[nog invullen: btw-nummer]

2. What data we process, and why

For each kind of data, the table shows what we use it for, on what legal basis under the GDPR, and how long we keep it. Anything not listed here, we do not process.

DataUsed forLegal basisHow long
Name, email address and passwordCreating your account and signing you in securelyPerformance of the contractAs long as your account exists
Two-factor authentication: your key and your recovery codesProtecting your account against misuse of a stolen passwordPerformance of the contractAs long as you have two-factor authentication switched on
Billing details: company name, address, Chamber of Commerce and VAT number, billing email addressIssuing invoices and remitting VATLegal obligationSeven years (statutory tax retention)
Subscription and usage: your plan, the number of users and the minutes transcribedRunning your subscription and invoicing usagePerformance of the contractSeven years, as part of the invoicing records
Microsoft connection: access tokens, your tenant ID, object ID, email address and display nameFetching your meeting transcript and placing the minutes in your OneDriveYour consent, given when you connectUntil you disconnect or delete your account
Meeting data: the transcript, the names of participants and the minutes produced from themProducing the minutes you buy from usPerformance of the contractNo more than seven days after processing
Invitations: your colleague’s email address and the status of their consentLetting your colleague join the minute-taking serviceConsent from your colleague themselvesThe link expires after seven days; the data disappears once you remove the colleague
Verification code when starting a trial or subscriptionChecking that the email address is yoursPerformance of the contractThe code expires within minutes
Recordings you supply yourself: the file you upload and your IP addressProducing the minutes and keeping the upload endpoint from being abusedPerformance of the contract and our interest in preventing abuseNo more than seven days after processing
Support: what you send us by email or through the chatAnswering your questionOur legitimate interest in helping customersAs long as needed to handle your question
Visitor analytics: how you use our public pagesImproving the siteYour consent in the cookie bannerSee the cookie policy
3. What happens to your meetings

This is the most sensitive thing we touch, so we spell it out. Clerqly records nothing itself. Microsoft Teams makes the recording and the transcript inside your own organisation’s environment; we are notified once that transcript is ready and fetch it then. If you meet in person, you supply the file yourself.

The transcript then goes through our processing: a European AI model fills in the fields of your template, a document is produced from it, and that document lands in your own organisation’s OneDrive. The minutes return to the place the transcript came from.

A transcript also contains other people’s data: the names of participants and everything they said. For those people you are the controller and we process on your instructions. So make sure your participants know that a transcript is being made. That duty sits with your organisation, not with us.

Whatever we record along the way is cleared out within seven days of processing. The transcript and the intermediate results do not stay with us; the minutes themselves live in your own organisation’s OneDrive and remain there for as long as you keep them.

You decide who takes part. Every colleague you add gives consent themselves through their own link. Remove someone and we withdraw their Microsoft connection and clear out their tokens.

4. Who we share your data with

We do not sell your data and we do not use it for advertising. To deliver the service we do rely on a number of parties. These are all of them.

PartyUsed forWhere
Microsoft 365Supplies the transcript and receives the minutes. This is your own organisation’s environment, not a supplier we bring inYour own tenant
Mistral AIFills in the fields of your template based on the transcriptFrance
ZohoProduces the Word document, manages subscriptions and invoices, and provides the live chat and visitor analyticsEU data centre
MollieCollects your subscription fee by SEPA direct debit or credit cardThe Netherlands
Bullnice B.V.Runs the automation that processes your meeting and sends our emailsEU
Our hosting providerRuns the application and the databaseEU region

With every party that processes personal data on our instructions we conclude a data processing agreement. Beyond that, nothing goes to third parties unless the law requires it.

Processing takes place within the European Union. We use no American AI service and no Google Analytics. The only American company in the chain is Microsoft, and that is precisely the environment your organisation was already using.

5. How we protect your data

  • Your Microsoft tokens are stored encrypted (AES-256-GCM). The automation that processes your meeting does not hold that key.
  • We do not keep your password, only an irreversible encryption of it. You can also switch on two-factor authentication.
  • Your session cookie is HttpOnly, so scripts cannot read it, and it expires after seven days.
  • All traffic runs over https, under a strict policy governing which scripts are allowed to run.
  • Session recordings for visitor analytics run only on our public pages, not in your dashboard and not during checkout.
6. Your rights

The GDPR gives you a number of rights. Email us at the address at the bottom of this page; we respond within a month.

  • Access: a copy of the data we hold about you.
  • Rectification: having incorrect data corrected.
  • Erasure: having your account and your data deleted, except what we are legally required to keep.
  • Restriction and objection: having the use of your data halted, or objecting to it.
  • Portability: receiving your data in a common file format.
  • Withdrawing consent: anything you switched on based on consent you can switch off again. That applies to the Microsoft connection just as much as to cookies.

If you believe we are not handling your data carefully, you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). We would appreciate it if you came to us first, so we can put it right.

7. Cookies

Which cookies and comparable storage we use, what they do and how to adjust or withdraw your choice per purpose is set out in a separate statement.

Read the cookie policy
8. Changes

If something about the service changes and this statement no longer holds, we update it and put a new version date at the top. That date is shown at the top of this page.

9. Contact

Questions about this statement or about your data? Email us at support@clerqly.ai