Sally - AI Meeting Assistant

Security & GDPR Compliance

Use Sally with complete peace of mind

Data security and GDPR compliance

Data Protection Is Our Priority

100% GDPR compliant

100% GDPR compliant

Our solution fully adheres to the GDPR — ensuring maximum security and legal compliance.

Made in Germany

Made in Germany

Developed and operated in Germany, Sally meets the highest standards in quality, reliability, and data protection.

Hosted in Germany

Hosted in Germany

All personal data remains securely stored in Europe. We host exclusively with trusted European data centers.

Independently audited & certified

Sally meets internationally recognized standards for security, data protection, and quality — independently audited and continuously verified.

DICIS certificate covering ISO 9001:2015, ISO 14001:2015 and ISO 27001:2022
ISO 9001 · 14001 · 27001
GDPR-compliant
GDPR-compliant
BAFA-listed
BAFA-listed
AZAV-certified
AZAV-certified

GDPR-Compliant Data Storage

Your data privacy is our top priority. All personal data collected while using Sally is securely stored on servers within the EU, preferably in Germany at Hetzner. We guarantee that your data will never be processed or shared without your consent, unless legally required. No third-country data transfers. By 21 August 2026 we will have moved entirely to German data centers, so that no component runs in another EU region.

Hosting and processing locations in detail

Certifications & Compliance

Sally is independently and regularly audited against international standards. Our integrated management system is certified by DICIS (Digital Institute for the Certification of International Standards) against the standards of ISO 17021 and ISO 27006, register no. 260526 14 IMS, valid until 26 May 2028:

  • ISO 27001:2022: Information Security Management, externally audited.
  • ISO 9001:2015: Quality Management.
  • ISO 14001:2015: Environmental Management.
  • DORA: Digital Operational Resilience Act compliance for the financial sector.
  • EU AI Act: Classified as a low-risk system with automatic transparency notices.
View certificates and audit reports

AI Processing & Data Masking

Before any language model processes your data, all personally identifiable information is automatically masked. Identifiable content never reaches the AI — and your data is fundamentally never used to train language models. Never.

  • Automatic masking of personal data before every AI request.
  • No AI training on customer data, contractually excluded.
  • Current language model provider: Azure OpenAI, operated in the EU (Sweden).
  • From 21 August 2026 every inference step runs on our own language model on our own infrastructure.
  • Option to integrate your own LLM or on-premises hosting for maximum control.
How data masking works

Secure Collaboration with Subprocessors

For some features we collaborate with carefully selected subprocessors. These partners are contractually bound to strict data protection requirements and may only use your data for specified services. We provide a full, transparent subprocessor list and our technical and organizational measures (TOMs) as downloadable documents.

Download the subprocessor list and TOMs

Technical & Organizational Safeguards

To keep your data safe, we follow a multi-layered security approach:

  • Encryption: AES-256 at rest, TLS/SSL in transit.
  • Access controls: Multi-factor authentication and role-based permissions (RBAC) following the least-privilege principle.
  • Tenant isolation: Data is strictly isolated per organization.
  • Audit logs: Complete logging of all access events.
  • Backups: Geo-redundant backups in ISO 27001-certified EU data centers.
  • Penetration tests: Annual tests by external security firms.
  • Data Protection Impact Assessment (DPIA) under Article 35 GDPR and regular internal audits.
  • Incident notification: Customers are notified of security incidents within 24 hours.
Read the full security measures

Data Processing Agreement (DPA)

We sign a Data Processing Agreement (DPA / AVV) with every customer in accordance with Article 28 GDPR. This contractually governs the lawful processing of your meeting data — including all technical and organizational measures and a documented subprocessor list.

  • Personalized DPA auto-generated and digitally signable online.
  • Alternatively: download the DPA (English or German), sign, and email to privacy@sally.io, countersignature within 1 to 3 business days.
  • Subprocessor list and TOM documentation always available.
Request or download the DPA

Full Control Over Sally

Sally works transparently. At the start of every meeting she automatically posts a note in the chat that she is taking part. Any participant can object by typing the “opt out” command. Sally then leaves the meeting and all data captured up to that point is permanently deleted. If you prefer to obtain consent in advance, you can enable the email opt-in instead: Sally then only joins once consent has been given.

Privacy information for meeting participants

Go deeper

Full data protection documentation in our Help Center

Detailed information on certifications, subprocessors, security controls, the DPA process, and our roadmap is available in our public data protection area.

Our regularly updated data protection documentation in the Sally Help Center is authoritative for technical and contractual details.

Data Protection Officer

Norton Engele

privacy@sally.io

Get Started - Fast & Easy

Sign up in just a few clicks and try out Sally AI's amazing features.

Need help?
Book a demo call with our experts.

Sally AI in video conferences across Microsoft Teams, Google Meet and Zoom

Frequently Asked Questions

Yes, our platform is fully compliant with EU Data Privacy Laws. It is hosted entirely within the EU and adheres to all data protection regulations under these laws. For more details, you can review our privacy policy in our Privacy Policy.

Compliance overview in the Help Center

Only authorized users within your organization have access to the meeting data. We use encryption and role-based access controls to ensure that your data is protected.

Manage user roles and permissions

No. We do not pass your data on and we do not use it for our own purposes. To run the service we rely on a fixed, documented list of subprocessors, all with infrastructure in the EU and all contractually bound. You can find the full list in the Help Center.

View subprocessors and processing locations

That is up to you. There is no fixed default retention period: you define rules per workspace for the automatic deletion of transcripts, recordings and summaries, and you can delete individual meetings yourself at any time. After the contract ends we delete all data within 30 days.

Configure automatic deletion

Yes, this is why Sally automatically informs participants at the start of the meeting that she is present by sending a message in the chat. This serves the purpose of transparency and compliance with data protection guidelines, in particular the GDPR.

Set up the in-meeting privacy notice

By default, all data is stored in secure data centers in Germany that meet the highest security standards. Some components currently still run in other data centers within the EU; by 21 August 2026 we will have moved entirely to Germany. Data never leaves the EU.

Processing flow and storage locations

Yes. Data is encrypted at rest with AES-256 and transmitted via TLS/SSL. Administrative access requires multi-factor authentication, all access is logged and continuously monitored. Once a year external security firms test Sally in a penetration test.

Enable multi-factor authentication

No. You decide before every appointment whether Sally joins. In the meeting she posts a note in the chat that she is taking part, and any participant can object by typing “opt out”. Sally then leaves the meeting and deletes the data captured up to that point. Alternatively, an email opt-in can be placed upstream.

Set up the email opt-in

Our data protection team continuously monitors changes in legislation and adapts our processes to ensure that Sally AI always remains compliant.

EU AI Act and declaration of conformity

Your question is not covered here? In the Help Center we answer data protection questions in depth, including data subject rights, professional secrecy and external AI tools.

Go to the data protection FAQs