A recording of a sales or interview call is one of the most sensitive things a company creates. It carries identifiable voices, names, deal terms, salary figures, and sometimes health or immigration detail. So the question a data protection officer actually needs answered is narrow: once your notetaker captures that audio, who processes it, in which country, and how long do they keep it?
Marketing pages rarely answer that. The binding answers live in the documents vendors are legally required to publish: their Data Processing Agreement (DPA), their sub-processor list, and their privacy and security pages. So we read them. Over 14 September 2026 we retrieved the public DPAs, sub-processor lists and trust pages of eleven AI notetakers, extracted where audio is processed, which sub-processors touch it, the default retention, and whether the vendor trains AI on your content. We include Numi in the same table, on the same terms. Every cell is backed by the vendor's own source, linked below, with the retrieval date, so you can verify each claim yourself.
Residency is where the data physically sits. Jurisdiction is which legal system can compel it. A vendor can store your recording in Frankfurt and still be reachable under US law, such as the CLOUD Act, if the company or the sub-processor holding it is US-owned. EU regulators treat these as two separate questions. This table answers both: where processing happens, and who is in the chain.
The comparison table: 12 AI notetakers, from their own documents
Read the table as a starting point for your own due diligence, not a compliance verdict. Every one of these tools can be operated lawfully by an EU controller with the right DPA, transfer mechanism and risk assessment. What the table shows is the raw geography and retention you are signing up for by default, before you configure anything. All external rows were retrieved on 2026-09-14; the Numi row is from its published sub-processor list dated 2026-07-03.
| Notetaker | Where audio is processed | EU data residency? | Named sub-processors touching audio / transcripts | Default retention | Trains AI on your content? |
|---|---|---|---|---|---|
| Fireflies.aiFireflies.ai Corp., US | US AWS + Google Cloud |
Storage only, Enterprise tier. Data stored in EU but processed in the US. | AWS, Google Cloud (US). Full list at trust.fireflies.ai is a JavaScript app that did not render on retrieval; specific AI vendors not verifiable from a loading first-party page. | Retained until you delete it on standard plans; auto-delete is Enterprise-only. Account data purged ~30 days after closure. | States no. DPA carries no training prohibition and permits creating de-identified data to improve its products. |
| Otter.aiOtter.ai, Inc., US | US AWS |
None disclosed. | AWS, Google Cloud, Crusoe (cloud); Anthropic, OpenAI (LLM, barred from training on your data); Research Transcriptions (annotation). All US. | Retained until you delete it; trash purged after 30 days. | Yes. Trains its own models on de-identified recordings and transcripts. Third-party LLMs do not train. No clear opt-out found. |
| tl;dvTldx Solutions GmbH, DE | EEA default |
Yes, default. AI features can optionally process in the US if you select it. | Google Cloud, Wasabi, Hetzner (EU hosting). Security page names Anthropic as AI partner; granular third-party list returned HTTP 404 on retrieval. | Free: 3 months. Paid: until account deletion. | No. Explicit clause: content not used to train foundation or generative models. |
| FathomFathom Video, Inc., US | US only |
None. "All Fathom data is stored in the United States." DPA/SCC coverage only. | AI providers Anthropic, OpenAI, Google (barred from training). Cloud host and region not disclosed; full list behind a Vanta trust wall. | Indefinite until you delete it; time-based retention is Enterprise-only. On deletion, removed, plus 7 days from backups. | Yes. Trains its own in-house models on de-identified content by default. Opt-out in account settings. Third parties barred. |
| MetaviewMetaview Global Ltd., UK | UK AWS UK |
No EU tier. Hosts on AWS UK; DPA discloses processing in the US and Germany. | AWS (AWS UK), AssemblyAI (transcription), Anthropic (LLM), Datadog, FullEnrich. Full DPA schedule is NDA-gated. | Default 2 years, customizable on request. | No. States it does not use customer data for AI model training; DPA repeats it for third-party models. |
| GongGong.io Ltd., Israel | US / EU US default |
Yes, selectable at sign-up. New customers can choose EU or US storage; US is the default. Both on AWS. | AWS, Google Cloud EMEA, Microsoft Ireland (cloud, transcription, AI); MongoDB, Snowflake (storage); Twilio. No standalone LLM named. | No fixed in-service default published. 30 days deletion after termination. | States no ("never used to train generative models"), but only on a marketing trust page, not the binding DPA. |
| ChorusZoomInfo Technologies LLC, US | US only |
None disclosed for Chorus. | Corporate-wide list: AWS, Google (cloud); Anthropic, OpenAI, Groq, LangChain (LLM). All US. No dedicated transcription vendor named. | No fixed period published; retained "consistent with the original purpose." | Yes, permitted. ZoomInfo policy lists "fine-tune or train LLMs or other AI models" as a use. No dedicated opt-out found. |
| AvomaAvoma, Inc., US | US AWS USA |
None. "Avoma hosts all its software in AWS facilities in the USA." | List at trust.avoma.com returned HTTP 403 on retrieval. DPA confirms it governs AWS and others; specific vendors not verifiable from a live first-party page. | No in-service default published. 30 days return or delete after termination. | No commitment disclosed for meeting content. Only Google Workspace API data is excluded from training. |
| JiminnyJiminny Holdings Ltd., UK | EU / US selectable |
Yes. EU environment in Ireland where "all data is stored and processed"; or US in Ohio. Customer-movable. | AWS (host); AssemblyAI, Gladia (transcription); OpenAI, Google Cloud, Fireworks, Together (LLM); Recall (capture); Twilio. | 3 years by default. Shorter available via Customer Success. | Not disclosed. No general no-training statement found; DPA restriction is scoped to California data only. |
| ModjoRINGO SAS, FR | EU AWS FR/EEA |
Yes, default. Extra-EEA access is an exception under SCCs. | AWS (EU host); Recall (capture); Deepl (translation); OpenAI, Microsoft (Azure OpenAI), Google Cloud (AI, in EU data centers); Neo4j; Datadog, Sentry. | Admin-configurable. Recommended 12 months (6 in France). AI sub-processors capped at 90 days. | No. Contractually guaranteed; AI runs on transcripts only, not recordings. |
| Clari CopilotClari, Inc., US | US only |
None disclosed. All sub-processors listed as USA. | AWS (hosting + AI), Google Cloud (speech-to-text + AI), Microsoft Azure (AI), Splunk. No named LLM provider. | No in-service default published. 90 days return or delete after termination. | Not disclosed for the product. Public no-training pledge explicitly excludes product AI; governed by a non-public AI Addendum. |
| NumiNumi (Ron van Cann, Einzelunternehmer), DE | EU Frankfurt |
Yes, default and only. Audio transcribed by self-hosted Whisper on Hetzner in Frankfurt; audio never leaves EU infrastructure. | Hetzner (DE, hosting and audio). Transcript text goes to a customer-selectable coaching model: a self-hosted EU model (rolling out) or Anthropic (US) under SCCs and zero-retention. Embeddings via OpenAI (text only, zero-retention). | Governed by the customer as controller under the DPA (AVV); content is processed on the customer's instructions. | No. Content data is never used to train publicly accessible AI models. |
Legend: EU/EEA = processed in the EU or EEA by default. Mixed = a selectable or split posture (for example US default with an EU option, or UK hosting with disclosed US processing). US = processed in the United States on the pages we could load. Full disclosure: Numi publishes this table and is one of the vendors in it.
What the table actually shows?
Four patterns are worth pulling out, because they cut across the marketing.
1. EU processing is the exception, not the norm. Only tl;dv, Modjo and Numi process by default inside the EU or EEA. Jiminny and Gong let you choose an EU region but do not default to it. Everyone else, Fireflies, Otter, Fathom, Avoma and Clari Copilot, processes in the United States, and Metaview stores on AWS UK while disclosing US and German processing in its DPA. If your requirement is "meeting audio stays under EU jurisdiction end to end," most of this category does not meet it out of the box.
2. Storage residency is not processing residency. Fireflies is the clearest example: its EU option, on the Enterprise tier, stores data in the EU but, in its own words, processes it in the US. The recording still travels to the US to be worked on. Under GDPR it is the processing and the access that determine jurisdiction, not only where the bytes rest. When a vendor advertises an "EU region," read whether it covers storage, processing, or both.
3. Even EU-resident tools carry US-owned sub-processors. Modjo hosts in France and commits contractually to no training, which is a genuinely strong posture. But its named AI sub-processors, OpenAI, Microsoft and Google, are US-owned companies operating EU data centers. tl;dv is a German company hosting in the EEA, and its AI partner is Anthropic, a US company. EU residency is not the same as EU corporate control, and a US-owned processor in an EU region can still fall within US extraterritorial reach. This is the residency-versus-jurisdiction gap in practice, and it is where sovereignty-focused buyers should spend their attention.
4. Training on your content splits the field. Otter and Fathom train their own in-house models on de-identified meeting content by default (Fathom offers an opt-out; we could not confirm one for Otter). ZoomInfo's policy permits training LLMs. tl;dv, Modjo and Metaview commit not to train. Gong says it does not train generative models, but that statement lives on a marketing trust page rather than its binding DPA, so verify it in your contract. Avoma and Clari Copilot do not publish a clear no-training commitment for meeting content at all. When the promise is not in the DPA, it is not a promise you can enforce.
How to use this for your own DPA review
If you are running vendor due diligence, the table is the input, not the output. Turn each column into a question you put to the vendor in writing, and hold the answer against their DPA rather than their sales deck:
- Where is audio processed, not just stored? Ask for the processing region explicitly, and confirm whether an "EU region" covers processing or only storage.
- Who is in the sub-processor chain, and where is each one? Get the current list, and check the corporate ownership of the AI and transcription vendors, not only their data-center location.
- What is the default retention, and can you shorten it? If auto-deletion is gated to an Enterprise tier, your data persists by default. Confirm the number and the tier.
- Is the no-training commitment in the binding DPA? A statement on a trust page is marketing. A clause in the DPA is enforceable. Ask for the latter, and confirm it flows down to sub-processors.
- Which transfer mechanism carries your data, and how stable is it? Most US vendors rely on the EU-US Data Privacy Framework, the third transatlantic transfer basis after Safe Harbor and Privacy Shield were struck down. Name it in your records and monitor its status.
For a deeper structured version of this, see our 5-question AI vendor due diligence checklist and our per-vendor breakdowns of Fireflies, Otter, tl;dv, Fathom, Metaview, Chorus, Avoma, Jiminny and Modjo.
Where Numi fits, honestly
We built Numi so that the audio never leaves EU infrastructure. Recordings are transcribed by a self-hosted Whisper model on Hetzner in Frankfurt, so the audio itself is not sent to a third-party transcription vendor at all. That is the part of the chain most of this category routes through a US-owned processor.
The honest caveat, and the reason we put ourselves in the same table on the same terms, is the coaching step. Numi's coaching model is customer-selectable. We are rolling out a self-hosted EU coaching model where transcript text also stays inside our EU infrastructure. Until a customer is moved to it, coaching runs on Anthropic under Standard Contractual Clauses and zero-retention terms, which means transcript text (not audio) is processed by a US-owned provider. We do not claim "no US processing" as an absolute, because for that step it would not be true. What we do commit to, in our DPA and sub-processor list, is that audio stays in the EU, content is never used to train public models, and every sub-processor is disclosed with its location and safeguard.
Methodology and limitations
We retrieved each vendor's public DPA, privacy policy, sub-processor list and security or trust page on 14 September 2026 (Numi's figures are from its published sub-processor list dated 3 July 2026). We extracted only what the documents actually state. Where a claim appears on a marketing page but not the binding DPA, we flag it. Where the wording is scoped narrowly (for example a no-training pledge that only covers one data source), we say so rather than generalizing it.
Some sub-processor lists are gated. Fireflies' list is a JavaScript application that did not render, Fathom's sits behind a Vanta signed API, Metaview's full schedule is NDA-gated, and Avoma's page returned an HTTP 403. In those cases we cite only the vendors we could confirm from a page that loaded, and we mark the gap rather than filling it from a third-party summary. This is a point-in-time snapshot: sub-processors, regions and retention settings change, so treat the vendors' own live pages, linked below, as the authority and re-check before you rely on any single cell.
Sources: verify every row yourself
Each vendor's primary sources, with the URL we retrieved on 2026-09-14 (Numi: 2026-07-03). Where a source failed to load, we say so.
Fireflies.ai
- fireflies.ai/privacy - privacy policy
- fireflies.ai/data-processing-agreement - DPA
- fireflies.ai/security - security page (AWS + Google Cloud, retention, training language)
- trust.fireflies.ai/subprocessors - sub-processor list; JavaScript app, did not render on retrieval
Otter.ai
- otter.ai/privacy-policy - privacy policy (AWS in the US, proprietary-model training)
- otter.ai/subprocessors - sub-processor list (AWS, GCP, Crusoe, Anthropic, OpenAI, Research Transcriptions)
- otter.ai/privacy-security - privacy and security page (30-day trash purge, de-identification)
tl;dv
- tldv.io/privacy - privacy policy (EEA hosting on Google Cloud, Wasabi, Hetzner; retention; no-training clause)
- intercom.help/tldv/en/articles/5946387 - third-party providers help article; returned HTTP 404 on retrieval
Fathom
- fathom.ai/privacy - privacy policy (US storage, in-house model training, opt-out)
- fathom.ai/dpa - DPA
- help.fathom.video/en/articles/296512 - "Is Fathom secure?" (Anthropic, OpenAI, Google; no third-party training)
- help.fathom.video/en/articles/6057089 - retention policies
- trust.fathom.video/subprocessors - Vanta trust center; list not extractable
Metaview
- metaview.ai/data-processing-agreement - DPA (UK/US/Germany processing, no-training clause)
- trust.metaview.ai - trust center overview (AWS, AssemblyAI, Anthropic, Datadog, FullEnrich)
- metaview.ai/privacy - privacy and security page (AWS UK, 2-year retention)
Gong
- gong.io/legal/sub-processors - sub-processor list
- gong.io/legal/data-processing-addendum - DPA (30-day post-termination deletion)
- gong.io/legal/privacy-policy - privacy policy
- gong.io/platform/trust - trust page (no-training statement)
- help.gong.io security and privacy FAQ - US/EU residency choice
Chorus (ZoomInfo)
- zoominfo.com/legal/subprocessors - sub-processor list (AWS, Google, Anthropic, OpenAI, Groq, LangChain)
- zoominfo.com privacy policy - US processing, LLM training as a permitted use
- zoominfo.com/legal/data-processing-addendum - DPA; returned HTTP 403 on retrieval
Avoma
- avoma.com/privacy-policy - privacy policy (Google Workspace no-training scope)
- avoma.com/data-processing-addendum - DPA (sub-processor authorization, 30-day deletion)
- avoma.com/security - security page ("hosts all its software in AWS facilities in the USA")
- trust.avoma.com/subprocessors - sub-processor list; returned HTTP 403 on retrieval
Jiminny
- help.jiminny.com sub-processors - list with region tags (AWS, AssemblyAI, Gladia, OpenAI, Google, Recall)
- help.jiminny.com data storage - EU (Ireland) / US (Ohio) regions, 3-year default retention
- jiminny.com/legal/dpa - DPA
Modjo
- modjo.ai trust center sub-processors - list, all tagged EU
- modjo.ai DPA - EEA/France hosting, 90-day AI sub-processor cap
- help.modjo.ai retention policy - recommended 12 months (6 in France)
- help.modjo.ai AI sub-contractor transparency - no-training guarantee, transcripts only
Clari Copilot
- clari.com/gdpr - sub-processor list (AWS, Google Cloud speech-to-text, Azure, Splunk; all USA)
- clari.com/dpa - DPA (international transfers, 90-day post-termination)
- clari.com/privacy - privacy policy (no-training scope excludes product AI)
Numi
- numigtm.com/legal/subprocessors - sub-processor list, dated 2026-07-03 (Hetzner Frankfurt, self-hosted Whisper, Anthropic under SCC)
- numigtm.com/legal/dpa - Data Processing Agreement (AVV)