← Blog

We Read the DPAs of 12 AI Notetakers: Who Processes Your Meeting Audio, and Where

    A recording of a sales or interview call is one of the most sensitive things a company creates. It carries identifiable voices, names, deal terms, salary figures, and sometimes health or immigration detail. So the question a data protection officer actually needs answered is narrow: once your notetaker captures that audio, who processes it, in which country, and how long do they keep it?

    Marketing pages rarely answer that. The binding answers live in the documents vendors are legally required to publish: their Data Processing Agreement (DPA), their sub-processor list, and their privacy and security pages. So we read them. Over 14 September 2026 we retrieved the public DPAs, sub-processor lists and trust pages of eleven AI notetakers, extracted where audio is processed, which sub-processors touch it, the default retention, and whether the vendor trains AI on your content. We include Numi in the same table, on the same terms. Every cell is backed by the vendor's own source, linked below, with the retrieval date, so you can verify each claim yourself.

    The one distinction that decides everything

    Residency is where the data physically sits. Jurisdiction is which legal system can compel it. A vendor can store your recording in Frankfurt and still be reachable under US law, such as the CLOUD Act, if the company or the sub-processor holding it is US-owned. EU regulators treat these as two separate questions. This table answers both: where processing happens, and who is in the chain.

    The comparison table: 12 AI notetakers, from their own documents

    Read the table as a starting point for your own due diligence, not a compliance verdict. Every one of these tools can be operated lawfully by an EU controller with the right DPA, transfer mechanism and risk assessment. What the table shows is the raw geography and retention you are signing up for by default, before you configure anything. All external rows were retrieved on 2026-09-14; the Numi row is from its published sub-processor list dated 2026-07-03.

    Notetaker Where audio is processed EU data residency? Named sub-processors touching audio / transcripts Default retention Trains AI on your content?
    Fireflies.aiFireflies.ai Corp., US US
    AWS + Google Cloud
    Storage only, Enterprise tier. Data stored in EU but processed in the US. AWS, Google Cloud (US). Full list at trust.fireflies.ai is a JavaScript app that did not render on retrieval; specific AI vendors not verifiable from a loading first-party page. Retained until you delete it on standard plans; auto-delete is Enterprise-only. Account data purged ~30 days after closure. States no. DPA carries no training prohibition and permits creating de-identified data to improve its products.
    Otter.aiOtter.ai, Inc., US US
    AWS
    None disclosed. AWS, Google Cloud, Crusoe (cloud); Anthropic, OpenAI (LLM, barred from training on your data); Research Transcriptions (annotation). All US. Retained until you delete it; trash purged after 30 days. Yes. Trains its own models on de-identified recordings and transcripts. Third-party LLMs do not train. No clear opt-out found.
    tl;dvTldx Solutions GmbH, DE EEA
    default
    Yes, default. AI features can optionally process in the US if you select it. Google Cloud, Wasabi, Hetzner (EU hosting). Security page names Anthropic as AI partner; granular third-party list returned HTTP 404 on retrieval. Free: 3 months. Paid: until account deletion. No. Explicit clause: content not used to train foundation or generative models.
    FathomFathom Video, Inc., US US
    only
    None. "All Fathom data is stored in the United States." DPA/SCC coverage only. AI providers Anthropic, OpenAI, Google (barred from training). Cloud host and region not disclosed; full list behind a Vanta trust wall. Indefinite until you delete it; time-based retention is Enterprise-only. On deletion, removed, plus 7 days from backups. Yes. Trains its own in-house models on de-identified content by default. Opt-out in account settings. Third parties barred.
    MetaviewMetaview Global Ltd., UK UK
    AWS UK
    No EU tier. Hosts on AWS UK; DPA discloses processing in the US and Germany. AWS (AWS UK), AssemblyAI (transcription), Anthropic (LLM), Datadog, FullEnrich. Full DPA schedule is NDA-gated. Default 2 years, customizable on request. No. States it does not use customer data for AI model training; DPA repeats it for third-party models.
    GongGong.io Ltd., Israel US / EU
    US default
    Yes, selectable at sign-up. New customers can choose EU or US storage; US is the default. Both on AWS. AWS, Google Cloud EMEA, Microsoft Ireland (cloud, transcription, AI); MongoDB, Snowflake (storage); Twilio. No standalone LLM named. No fixed in-service default published. 30 days deletion after termination. States no ("never used to train generative models"), but only on a marketing trust page, not the binding DPA.
    ChorusZoomInfo Technologies LLC, US US
    only
    None disclosed for Chorus. Corporate-wide list: AWS, Google (cloud); Anthropic, OpenAI, Groq, LangChain (LLM). All US. No dedicated transcription vendor named. No fixed period published; retained "consistent with the original purpose." Yes, permitted. ZoomInfo policy lists "fine-tune or train LLMs or other AI models" as a use. No dedicated opt-out found.
    AvomaAvoma, Inc., US US
    AWS USA
    None. "Avoma hosts all its software in AWS facilities in the USA." List at trust.avoma.com returned HTTP 403 on retrieval. DPA confirms it governs AWS and others; specific vendors not verifiable from a live first-party page. No in-service default published. 30 days return or delete after termination. No commitment disclosed for meeting content. Only Google Workspace API data is excluded from training.
    JiminnyJiminny Holdings Ltd., UK EU / US
    selectable
    Yes. EU environment in Ireland where "all data is stored and processed"; or US in Ohio. Customer-movable. AWS (host); AssemblyAI, Gladia (transcription); OpenAI, Google Cloud, Fireworks, Together (LLM); Recall (capture); Twilio. 3 years by default. Shorter available via Customer Success. Not disclosed. No general no-training statement found; DPA restriction is scoped to California data only.
    ModjoRINGO SAS, FR EU
    AWS FR/EEA
    Yes, default. Extra-EEA access is an exception under SCCs. AWS (EU host); Recall (capture); Deepl (translation); OpenAI, Microsoft (Azure OpenAI), Google Cloud (AI, in EU data centers); Neo4j; Datadog, Sentry. Admin-configurable. Recommended 12 months (6 in France). AI sub-processors capped at 90 days. No. Contractually guaranteed; AI runs on transcripts only, not recordings.
    Clari CopilotClari, Inc., US US
    only
    None disclosed. All sub-processors listed as USA. AWS (hosting + AI), Google Cloud (speech-to-text + AI), Microsoft Azure (AI), Splunk. No named LLM provider. No in-service default published. 90 days return or delete after termination. Not disclosed for the product. Public no-training pledge explicitly excludes product AI; governed by a non-public AI Addendum.
    NumiNumi (Ron van Cann, Einzelunternehmer), DE EU
    Frankfurt
    Yes, default and only. Audio transcribed by self-hosted Whisper on Hetzner in Frankfurt; audio never leaves EU infrastructure. Hetzner (DE, hosting and audio). Transcript text goes to a customer-selectable coaching model: a self-hosted EU model (rolling out) or Anthropic (US) under SCCs and zero-retention. Embeddings via OpenAI (text only, zero-retention). Governed by the customer as controller under the DPA (AVV); content is processed on the customer's instructions. No. Content data is never used to train publicly accessible AI models.

    Legend: EU/EEA = processed in the EU or EEA by default. Mixed = a selectable or split posture (for example US default with an EU option, or UK hosting with disclosed US processing). US = processed in the United States on the pages we could load. Full disclosure: Numi publishes this table and is one of the vendors in it.

    What the table actually shows?

    Four patterns are worth pulling out, because they cut across the marketing.

    1. EU processing is the exception, not the norm. Only tl;dv, Modjo and Numi process by default inside the EU or EEA. Jiminny and Gong let you choose an EU region but do not default to it. Everyone else, Fireflies, Otter, Fathom, Avoma and Clari Copilot, processes in the United States, and Metaview stores on AWS UK while disclosing US and German processing in its DPA. If your requirement is "meeting audio stays under EU jurisdiction end to end," most of this category does not meet it out of the box.

    2. Storage residency is not processing residency. Fireflies is the clearest example: its EU option, on the Enterprise tier, stores data in the EU but, in its own words, processes it in the US. The recording still travels to the US to be worked on. Under GDPR it is the processing and the access that determine jurisdiction, not only where the bytes rest. When a vendor advertises an "EU region," read whether it covers storage, processing, or both.

    3. Even EU-resident tools carry US-owned sub-processors. Modjo hosts in France and commits contractually to no training, which is a genuinely strong posture. But its named AI sub-processors, OpenAI, Microsoft and Google, are US-owned companies operating EU data centers. tl;dv is a German company hosting in the EEA, and its AI partner is Anthropic, a US company. EU residency is not the same as EU corporate control, and a US-owned processor in an EU region can still fall within US extraterritorial reach. This is the residency-versus-jurisdiction gap in practice, and it is where sovereignty-focused buyers should spend their attention.

    4. Training on your content splits the field. Otter and Fathom train their own in-house models on de-identified meeting content by default (Fathom offers an opt-out; we could not confirm one for Otter). ZoomInfo's policy permits training LLMs. tl;dv, Modjo and Metaview commit not to train. Gong says it does not train generative models, but that statement lives on a marketing trust page rather than its binding DPA, so verify it in your contract. Avoma and Clari Copilot do not publish a clear no-training commitment for meeting content at all. When the promise is not in the DPA, it is not a promise you can enforce.

    How to use this for your own DPA review

    If you are running vendor due diligence, the table is the input, not the output. Turn each column into a question you put to the vendor in writing, and hold the answer against their DPA rather than their sales deck:

    1. Where is audio processed, not just stored? Ask for the processing region explicitly, and confirm whether an "EU region" covers processing or only storage.
    2. Who is in the sub-processor chain, and where is each one? Get the current list, and check the corporate ownership of the AI and transcription vendors, not only their data-center location.
    3. What is the default retention, and can you shorten it? If auto-deletion is gated to an Enterprise tier, your data persists by default. Confirm the number and the tier.
    4. Is the no-training commitment in the binding DPA? A statement on a trust page is marketing. A clause in the DPA is enforceable. Ask for the latter, and confirm it flows down to sub-processors.
    5. Which transfer mechanism carries your data, and how stable is it? Most US vendors rely on the EU-US Data Privacy Framework, the third transatlantic transfer basis after Safe Harbor and Privacy Shield were struck down. Name it in your records and monitor its status.

    For a deeper structured version of this, see our 5-question AI vendor due diligence checklist and our per-vendor breakdowns of Fireflies, Otter, tl;dv, Fathom, Metaview, Chorus, Avoma, Jiminny and Modjo.

    Where Numi fits, honestly

    We built Numi so that the audio never leaves EU infrastructure. Recordings are transcribed by a self-hosted Whisper model on Hetzner in Frankfurt, so the audio itself is not sent to a third-party transcription vendor at all. That is the part of the chain most of this category routes through a US-owned processor.

    The honest caveat, and the reason we put ourselves in the same table on the same terms, is the coaching step. Numi's coaching model is customer-selectable. We are rolling out a self-hosted EU coaching model where transcript text also stays inside our EU infrastructure. Until a customer is moved to it, coaching runs on Anthropic under Standard Contractual Clauses and zero-retention terms, which means transcript text (not audio) is processed by a US-owned provider. We do not claim "no US processing" as an absolute, because for that step it would not be true. What we do commit to, in our DPA and sub-processor list, is that audio stays in the EU, content is never used to train public models, and every sub-processor is disclosed with its location and safeguard.

    Methodology and limitations

    We retrieved each vendor's public DPA, privacy policy, sub-processor list and security or trust page on 14 September 2026 (Numi's figures are from its published sub-processor list dated 3 July 2026). We extracted only what the documents actually state. Where a claim appears on a marketing page but not the binding DPA, we flag it. Where the wording is scoped narrowly (for example a no-training pledge that only covers one data source), we say so rather than generalizing it.

    Some sub-processor lists are gated. Fireflies' list is a JavaScript application that did not render, Fathom's sits behind a Vanta signed API, Metaview's full schedule is NDA-gated, and Avoma's page returned an HTTP 403. In those cases we cite only the vendors we could confirm from a page that loaded, and we mark the gap rather than filling it from a third-party summary. This is a point-in-time snapshot: sub-processors, regions and retention settings change, so treat the vendors' own live pages, linked below, as the authority and re-check before you rely on any single cell.

    Sources: verify every row yourself

    Each vendor's primary sources, with the URL we retrieved on 2026-09-14 (Numi: 2026-07-03). Where a source failed to load, we say so.

    Fireflies.ai
    Otter.ai
    tl;dv
    • tldv.io/privacy - privacy policy (EEA hosting on Google Cloud, Wasabi, Hetzner; retention; no-training clause)
    • intercom.help/tldv/en/articles/5946387 - third-party providers help article; returned HTTP 404 on retrieval
    Fathom
    Metaview
    Gong
    Chorus (ZoomInfo)
    Avoma
    Jiminny
    Modjo
    Clari Copilot
    • clari.com/gdpr - sub-processor list (AWS, Google Cloud speech-to-text, Azure, Splunk; all USA)
    • clari.com/dpa - DPA (international transfers, 90-day post-termination)
    • clari.com/privacy - privacy policy (no-training scope excludes product AI)
    Numi

    Frequently asked questions

    Which AI notetakers process meeting audio inside the EU?

    As of 14 September 2026, based on the vendors' own documents: tl;dv (a German company) and Modjo (a French company) process in the EU or EEA by default, and Numi processes audio only on EU infrastructure in Frankfurt. Jiminny offers a customer-selectable EU environment in Ireland; Gong lets new customers choose EU or US storage, with US as the default. Fireflies, Otter, Fathom, Avoma and Clari Copilot process in the United States on the pages we could load. Metaview stores on AWS UK and discloses processing in the US and Germany.

    Do AI notetakers train their AI on my meetings?

    It varies, and the distinction that matters is between a vendor's own models and its third-party LLMs. By their own documents, Otter and Fathom train their in-house models on de-identified meeting content by default (Fathom offers an opt-out). tl;dv, Modjo and Metaview state they do not train. Gong states it does not train generative models, but that claim sits on a marketing page rather than its binding DPA. ZoomInfo's policy (Chorus) permits training LLMs. Avoma and Clari Copilot do not publish a clear no-training commitment for meeting content.

    Is storing meeting data in the EU the same as it being under EU jurisdiction?

    No. Residency is where the bytes physically sit; jurisdiction is which legal system can compel the data. A US-headquartered provider, or a US-owned sub-processor operating an EU region, can still be reached under US law such as the CLOUD Act regardless of where the server sits. EU regulators treat residency and jurisdiction as two separate questions. A vendor can host in Frankfurt and still route audio, transcription or AI analysis through a US-owned processor, which is exactly the gap this table is designed to surface.

    How long do AI notetakers keep my recordings by default?

    Default retention differs sharply. tl;dv keeps free-tier data 3 months and paid data until account deletion. Jiminny defaults to 3 years and Metaview to 2 years. Modjo is admin-configurable with a recommended 12 months (6 in France). Fireflies and Fathom retain meeting content until you delete it, with automatic expiry gated to Enterprise plans. Gong, Chorus, Avoma and Clari Copilot do not publish a fixed in-service retention period; they publish a 30 to 90 day deletion window after contract termination.

    Does a signed DPA make my AI notetaker GDPR compliant?

    A DPA is necessary but not sufficient. It sets out the processing terms and the transfer mechanism, but it cannot contract away statutory reach such as the US CLOUD Act, and it does not change where audio is physically processed. Compliance for a recording tool also depends on where identifiable personal data lives, which sub-processors touch it, how consent is captured, and your own transfer risk assessment. Use the DPA as the baseline document, then verify processing region, sub-processors and retention against it.

    How was this comparison built, and can I verify it?

    Every cell is drawn from the vendor's own public DPA, privacy policy, sub-processor list or security page, retrieved on 14 September 2026 (Numi's row is from its published sub-processor list dated 3 July 2026). Each vendor's source URLs are listed in the Sources section so you can check every claim yourself. Where a sub-processor list was gated behind a JavaScript app, a Vanta or SafeBase trust wall, or returned an HTTP error, we say so and cite only what actually loaded rather than guessing.

    Numi keeps meeting audio on EU infrastructure in Frankfurt, transcribes it with a self-hosted model, and discloses every sub-processor. See exactly how the data path works before you commit.

    Get Early Access