Sally - AI Meeting Assistant

Privacy Policy for Sally AI

Last updated: 7 September 2026

Please note: This English text is a translation of the German original, provided for your convenience. Only the German version is legally binding. In the event of any discrepancy or dispute, the German version available at www.sally.io/de/saas-datenschutzerklaerung shall prevail.

The protection of your personal data is of particular importance to Aliru GmbH. Below we inform you about how we handle personal data in connection with the use of our software “Sally AI” (accessible at www.sally.io), for what purposes we process this data, and what rights you have as a data subject. Compliance with the General Data Protection Regulation (GDPR) and other relevant data protection regulations is a matter of course for us.

1. Controller Responsible for Data Processing

Aliru GmbH
Julian Kissel
Julius-Hatry-Straße 1
68163 Mannheim, Germany
contact@sally.io
+49 621 49088670

For questions or concerns regarding data protection, please contact our Data Protection Officer Norton Engele at privacy@sally.io or datenschutz@sally.io

Allocation of roles:The company that uses Sally AI and instructs us accordingly is the controller for the processing of meeting content (audio and video recordings, transcripts, summaries, and associated metadata). In this respect, Aliru GmbH acts as a processor pursuant to Art. 28 GDPR and exclusively on the instructions of that company. Data subject rights relating to meeting content must therefore be asserted against the company using Sally AI. Requests that reach us directly are forwarded to that company without undue delay, and we support them in handling such requests. We act as controller within the meaning of the GDPR for processing carried out under our own contractual relationship with our customers, in particular for registration, user administration, billing, and support.

2. Subject and Purpose of Data Processing

Sally AI is a software solution that supports companies in conducting, documenting, and following up on meetings. The AI-based application actively participates in online meetings on common platforms such as Zoom, Microsoft Teams, or Google Meet. In addition, in-person conversations can be recorded via the Sally app, and existing audio and video files can be uploaded and processed. After a meeting ends, Sally AI automatically generates a summary of the conversation content and identifies recognized tasks, which are then assigned to the respective responsible participants. The goal is to minimize the administrative effort associated with meetings and enable efficient follow-up.

The processing of personal data by Sally AI serves the following purposes:

  • Participation in meetings and processing of conversation recordings: Analysis and processing of spoken content from online meetings, from in-person conversations via the Sally app, and from uploaded audio and video files, in real time or retrospectively, for the creation of summaries.
  • Creation of summaries: Provision of a compact overview of the essential content and key results of the respective meeting.
  • Task recognition: Automated identification of tasks resulting from the conversation, as well as their system-supported assignment to responsible persons.
  • Management and documentation: Storage of summaries and recognized tasks in the collaboration platforms used (e.g., Microsoft Teams) for later review by authorized users.

Processing is carried out exclusively within the framework of the contractual agreements with our customers and on the basis of the relevant data protection regulations.

The processed personal data is not used for the purpose of further development or training of AI models.

3. Categories of Processed Data

Various categories of personal and non-personal data are processed in connection with the use of Sally AI. Data processing is carried out exclusively to the extent necessary to provide the contractually agreed services. The following data types may be affected in particular:

User data

  • First and last name, email address, user ID, team or department affiliation
  • Meeting metadata such as title, date, and time

Meeting content

  • Audio and video recordings as well as transcripts of online meetings, of in-person conversations via the Sally app, and of uploaded audio or video files, used to create automated summaries
  • Content contributions of participants, including discussed topics, tasks, and decisions made

Task recognition and management

  • Tasks identified through AI-based analysis and their contextual content (e.g., “Max Müller prepares the Q4 budget”)
  • Automated assignment of tasks to responsible persons via integrated tools (e.g., Microsoft Teams tasks or Microsoft Outlook)

Log and connection data

  • Time and duration of Sally AI's participation in virtual meetings
  • Information about the conference platform used (e.g., Zoom, Microsoft Teams, Google Meet)
  • Technical information such as IP address, device identifiers, browser used

Technical usage data

  • Usage statistics and telemetry data for optimization, error analysis, and stability improvement (e.g., frequency of use, features used)

Note: Processing is carried out exclusively for the purposes stated in Section 2. No other use of the content, in particular for training purposes or profiling, takes place.

Special categories of personal data:Sally AI is also used in conversational contexts in which special categories of personal data pursuant to Art. 9 GDPR may arise, for example in HR, recruitment, or advisory conversations. Such data is not collected deliberately. The company using Sally AI is responsible for ensuring that a legal basis pursuant to Art. 9(2) GDPR exists.

4. In-Meeting Notice and Objection (Opt-out)

After joining, Sally AI informs participants in the meeting chat that recording and transcription are in progress and links to the data protection information. Any participant may request, by entering “opt out” in the meeting chat, that all meeting data processed up to that point, meaning audio, video, transcript, and metadata, be deleted without undue delay. Sally AI then leaves the meeting. The process is logged by the system.

For recordings of in-person conversations via the Sally app and for uploaded audio or video files, these technical notice and objection functions are not available. In these cases, informing the data subjects is the responsibility of the company using Sally AI.

5. Use of External Service Providers

For the operation and provision of Sally AI's features, we rely on specialized, contractually bound external service providers. These providers handle tasks in particular in the areas of infrastructure, system hosting, translation, and payment processing. All service providers have been carefully selected and are contractually obliged to comply with data protection requirements.

The processing and storage of the data processed on behalf of our customers (conversation content, transcripts, and metadata) takes place exclusively in data centers in the Federal Republic of Germany. No transfer of personal data to third countries takes place.

The AI-supported processing of conversation content is carried out using a language model operated by us on servers in Germany. No external providers of language models are used for this purpose.

Below we distinguish between service providers that process meeting content on behalf of our customers and service providers we use exclusively to handle our own contractual relationship.

5.1 Service providers processing data on behalf of our customers

The following service providers are engaged as processors pursuant to Art. 28 GDPR and process meeting data on behalf of the respective controller company. Processing takes place exclusively in data centers in Germany.

Hetzner Online GmbH

Provision of cloud infrastructure, web hosting, and data backups. The servers used are located exclusively in data centers in Germany.

https://www.hetzner.com/legal/privacy-policy/

DeepL

Used for translating meeting summaries and task descriptions. Processing takes place exclusively on servers in Germany.

https://www.deepl.com/privacy

Strato

German hosting provider used for certain web services. Data processing takes place exclusively in data centers located in Germany.

https://www.strato.de/datenschutz/

5.2 Service providers for handling our contractual relationship

The following service providers receive no access to meeting content, transcripts, or associated metadata. They are used exclusively to handle our own contractual relationship with our customers. In this respect, we are the controller within the meaning of the GDPR. Processing takes place exclusively within the European Union.

Stripe

Processing and handling of payments (e.g., subscriptions). Stripe processes data according to European data protection standards, including PCI-DSS certification.

https://stripe.com/privacy

Microsoft Dynamics 365

Used for managing customer and user data within our internal CRM system. Hosting takes place exclusively on servers within the EU.

https://privacy.microsoft.com/en-us/privacystatement

6. Legal Basis for Data Processing

The processing of personal data in connection with the use of Sally AI is carried out in compliance with the relevant data protection regulations, in particular the General Data Protection Regulation (GDPR). Depending on the purpose and context of the processing, it is based on the following legal grounds:

  • Art. 6(1)(b) GDPR– for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract (e.g., use of Sally AI's features under a contractual agreement);
  • Art. 6(1)(c) GDPR– for compliance with legal obligations to which we are subject (e.g., commercial and tax retention obligations);
  • Art. 6(1)(f) GDPR– for the purposes of the legitimate interests pursued by our company or a third party, provided that the interests or fundamental rights and freedoms of the data subject do not override those interests (e.g., to ensure IT security, for error analysis, or to optimize the service);
  • Art. 6(1)(a) GDPR– on the basis of freely given consent, where such consent is required (e.g., for certain optional features or third-party integrations that are not necessary for the performance of the contract).

The legal basis applicable in each specific case follows from the purpose of the data processing, about which we provide transparent information in this privacy policy and, where applicable, as part of separate information obligations.

7. No Automated Decision-Making

Automated decision-making within the meaning of Art. 22 GDPR that produces legal effects concerning data subjects or similarly significantly affects them does not take place. The AI-supported analysis serves exclusively to summarize conversation content and recognize tasks. No evaluation of the performance or behavior of individual persons, no analysis of emotions or facial expressions, and no biometric identification is carried out.

8. Disclosure of Personal Data to Third Parties

Personal data is transferred to third parties only to the extent necessary for the fulfillment of contractual obligations, where based on a legal obligation, or on the basis of express consent from the data subject.

Such disclosure is limited to carefully selected processors and other recipients involved in providing the service (e.g., hosting providers, payment service providers, technical service providers). All recipients are contractually obliged pursuant to Art. 28 GDPR to comply with data protection requirements.

The processing and storage of the data processed on behalf of our customers takes place exclusively in data centers in the Federal Republic of Germany. Service providers we use to handle our own contractual relationship process data exclusively within the European Union. A transfer of personal data to so-called third countries within the meaning of the GDPR does not take place and is not intended.

9. Data Security

Aliru GmbH implements appropriate technical and organizational security measures to protect personal data pursuant to Art. 32 GDPR. These include, among others, encrypted data transmission, encrypted storage of data, access and authorization controls, logging, and regular security audits including annual external penetration tests.

Our integrated management system is certified to ISO/IEC 27001:2022, ISO 9001:2015, and ISO 14001:2015 (register no. 260526 14 IMS, issued by DICIS, valid until 26 May 2028). The certificate is available at https://profile.dicis.org/Aliru-GmbH.

Detailed information about our security measures can be found in our DPA and its Annex (1) on technical and organizational measures: https://www.sally.io/dpa

10. Storage Duration and Deletion of Data

Personal data is stored only for the period necessary to fulfill the respective processing purposes or where statutory retention periods require longer storage. Once the processing purpose ceases to apply or the relevant statutory retention periods expire, the data is deleted or anonymized without undue delay, unless further legal or contractual obligations to store the data exist.

The following criteria apply to data from meetings:

  • Temporary raw data required solely to carry out transcription and analysis is deleted automatically once the respective processing operation is completed, unless storage has been configured.
  • The retention period for transcripts and summaries is determined by the company using Sally AI. Fixed retention tiers are available for selection in the system.
  • Authorized users can delete content themselves at any time. We implement deletion requests within five working days.
  • After the contractual relationship ends, data processed on behalf of the customer is deleted within 30 days at the latest, or returned upon request.

11. Rights of Data Subjects

In connection with the processing of their personal data, data subjects have the following rights under the General Data Protection Regulation (GDPR):

  • Right of access (Art. 15 GDPR): You have the right to obtain information about the personal data we process, as well as about the purpose, categories, recipients, storage period, and your further rights.
  • Right to rectification (Art. 16 GDPR): You may request the immediate rectification of inaccurate personal data or the completion of incomplete personal data.
  • Right to erasure (Art. 17 GDPR): You have the right to request the erasure of your personal data, unless statutory retention periods, other legal obligations, or legitimate interests preclude erasure.
  • Right to restriction of processing (Art. 18 GDPR): Under certain conditions, you may request the restriction of the processing of your personal data.
  • Right to data portability (Art. 20 GDPR): You have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format, or to have it transmitted to another controller, where technically feasible.
  • Right to object (Art. 21 GDPR):You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data where the processing is based on Art. 6(1)(f) GDPR.
  • Right to withdraw consent (Art. 7(3) GDPR): You may withdraw consent you have given at any time with effect for the future. The lawfulness of processing carried out up to the point of withdrawal remains unaffected.

To exercise your rights, please contact us using the contact details provided above. We will review and handle your request in accordance with the statutory requirements.

12. Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes data protection regulations.

The complaint may be lodged with the supervisory authority responsible for us, or with the supervisory authority of your habitual residence, your place of work, or the place of the alleged infringement.

13. Changes to this Privacy Policy

We reserve the right to amend this privacy policy at any time with effect for the future, in particular to adapt it to legal requirements, regulatory requirements, or technical developments of our services.

The current version is available at any time on our website at www.sally.io. We recommend reviewing the privacy policy at regular intervals. We will announce material changes in an appropriate manner.

14. Data Processing Agreement (DPA)

The data processing agreement pursuant to Art. 28 GDPR and the overview of the technical and organizational measures (TOMs) in place are available at the following link: https://www.sally.io/dpa

15. Contact

For questions or concerns regarding this privacy policy or the processing of your personal data, you can reach us at:

Aliru GmbH
Julius-Hatry-Straße 1
68163 Mannheim, Germany
contact@sally.io

Note:This privacy policy serves to provide comprehensive information pursuant to Art. 12 et seq. GDPR and ensures that the processing of your personal data is transparent and GDPR-compliant.