Security & GDPR Compliance
Use Sally with complete peace of mind

Data Protection Is Our Priority
100% GDPR compliant
Our solution fully adheres to the GDPR — ensuring maximum security and legal compliance.
Made in Germany
Developed and operated in Germany, Sally meets the highest standards in quality, reliability, and data protection.
Hosted in Germany
All personal data remains securely stored in Europe. We host exclusively with trusted European data centers.
Independently audited & certified
Sally meets internationally recognized standards for security, data protection, and quality — independently audited and continuously verified.
GDPR-Compliant Data Storage
Your data privacy is our top priority. All personal data collected while using Sally is securely stored on servers within the EU, preferably in Germany at Hetzner. We guarantee that your data will never be processed or shared without your consent, unless legally required. No third-country data transfers. By 21 August 2026 we will have moved entirely to German data centers, so that no component runs in another EU region.
Hosting and processing locations in detailCertifications & Compliance
Sally is independently and regularly audited against international standards. Our integrated management system is certified by DICIS (Digital Institute for the Certification of International Standards) against the standards of ISO 17021 and ISO 27006, register no. 260526 14 IMS, valid until 26 May 2028:
- ISO 27001:2022: Information Security Management, externally audited.
- ISO 9001:2015: Quality Management.
- ISO 14001:2015: Environmental Management.
- DORA: Digital Operational Resilience Act compliance for the financial sector.
- EU AI Act: Classified as a low-risk system with automatic transparency notices.
AI Processing & Data Masking
Before any language model processes your data, all personally identifiable information is automatically masked. Identifiable content never reaches the AI — and your data is fundamentally never used to train language models. Never.
- Automatic masking of personal data before every AI request.
- No AI training on customer data, contractually excluded.
- Current language model provider: Azure OpenAI, operated in the EU (Sweden).
- From 21 August 2026 every inference step runs on our own language model on our own infrastructure.
- Option to integrate your own LLM or on-premises hosting for maximum control.
Secure Collaboration with Subprocessors
For some features we collaborate with carefully selected subprocessors. These partners are contractually bound to strict data protection requirements and may only use your data for specified services. We provide a full, transparent subprocessor list and our technical and organizational measures (TOMs) as downloadable documents.
Download the subprocessor list and TOMsTechnical & Organizational Safeguards
To keep your data safe, we follow a multi-layered security approach:
- Encryption: AES-256 at rest, TLS/SSL in transit.
- Access controls: Multi-factor authentication and role-based permissions (RBAC) following the least-privilege principle.
- Tenant isolation: Data is strictly isolated per organization.
- Audit logs: Complete logging of all access events.
- Backups: Geo-redundant backups in ISO 27001-certified EU data centers.
- Penetration tests: Annual tests by external security firms.
- Data Protection Impact Assessment (DPIA) under Article 35 GDPR and regular internal audits.
- Incident notification: Customers are notified of security incidents within 24 hours.
Data Processing Agreement (DPA)
We sign a Data Processing Agreement (DPA / AVV) with every customer in accordance with Article 28 GDPR. This contractually governs the lawful processing of your meeting data — including all technical and organizational measures and a documented subprocessor list.
- Personalized DPA auto-generated and digitally signable online.
- Alternatively: download the DPA (English or German), sign, and email to privacy@sally.io, countersignature within 1 to 3 business days.
- Subprocessor list and TOM documentation always available.
Full Control Over Sally
Sally works transparently. At the start of every meeting she automatically posts a note in the chat that she is taking part. Any participant can object by typing the “opt out” command. Sally then leaves the meeting and all data captured up to that point is permanently deleted. If you prefer to obtain consent in advance, you can enable the email opt-in instead: Sally then only joins once consent has been given.
Privacy information for meeting participantsGo deeper
Full data protection documentation in our Help Center
Detailed information on certifications, subprocessors, security controls, the DPA process, and our roadmap is available in our public data protection area.
Our regularly updated data protection documentation in the Sally Help Center is authoritative for technical and contractual details.
Get Started - Fast & Easy
Sign up in just a few clicks and try out Sally AI's amazing features.
Need help?
Book a demo call with our experts.

Frequently Asked Questions
Yes, our platform is fully compliant with EU Data Privacy Laws. It is hosted entirely within the EU and adheres to all data protection regulations under these laws. For more details, you can review our privacy policy in our Privacy Policy.
Compliance overview in the Help CenterOnly authorized users within your organization have access to the meeting data. We use encryption and role-based access controls to ensure that your data is protected.
Manage user roles and permissionsNo. We do not pass your data on and we do not use it for our own purposes. To run the service we rely on a fixed, documented list of subprocessors, all with infrastructure in the EU and all contractually bound. You can find the full list in the Help Center.
View subprocessors and processing locationsThat is up to you. There is no fixed default retention period: you define rules per workspace for the automatic deletion of transcripts, recordings and summaries, and you can delete individual meetings yourself at any time. After the contract ends we delete all data within 30 days.
Configure automatic deletionYes, this is why Sally automatically informs participants at the start of the meeting that she is present by sending a message in the chat. This serves the purpose of transparency and compliance with data protection guidelines, in particular the GDPR.
Set up the in-meeting privacy noticeBy default, all data is stored in secure data centers in Germany that meet the highest security standards. Some components currently still run in other data centers within the EU; by 21 August 2026 we will have moved entirely to Germany. Data never leaves the EU.
Processing flow and storage locationsYes. Data is encrypted at rest with AES-256 and transmitted via TLS/SSL. Administrative access requires multi-factor authentication, all access is logged and continuously monitored. Once a year external security firms test Sally in a penetration test.
Enable multi-factor authenticationNo. You decide before every appointment whether Sally joins. In the meeting she posts a note in the chat that she is taking part, and any participant can object by typing “opt out”. Sally then leaves the meeting and deletes the data captured up to that point. Alternatively, an email opt-in can be placed upstream.
Set up the email opt-inOur data protection team continuously monitors changes in legislation and adapts our processes to ensure that Sally AI always remains compliant.
EU AI Act and declaration of conformityYour question is not covered here? In the Help Center we answer data protection questions in depth, including data subject rights, professional secrecy and external AI tools.
Go to the data protection FAQs