English · Deutsche Version

Free tool · Compliant Rollout Kit 3 of 4

AI Notetaker GDPR Check: DPA scorer and sourced vendor comparison

Check any AI meeting vendor's data processing agreement and privacy posture against 15 criteria: EU hosting, ownership, sub-processors, no-training clause, biometric voiceprints, deletion terms and more. You get a score and a red-flag report to copy or download. Below it sits a sourced comparison table for Otter, Fireflies, Gong, Granola, Fathom and two EU vendors. Every claim is linked; where no reliable source exists, it says nicht belegt (not documented).

Updated: 30 July 2026 · Template, not legal advice

DPA and GDPR scorer

Answer each question for the vendor you are checking. Five are knockout criteria: if one fails, the vendor is hard to justify for European processing regardless of the total. Everything runs in your browser, nothing is uploaded.

0 / 15
    Copied

    Template, not legal advice. The scorer is an educational aid. It does not replace an individual assessment of the DPA and privacy posture by your data protection officer. A vendor's rating depends on the specific deployment, configuration and legal basis. Made with numigtm.com.

    The 15 criteria and why they matter

    An AI notetaker processes personal data on your behalf as a processor. Under Article 28 GDPR you remain the liable controller. The DPA and sub-processor chain decide where data sits, who can access it, whether your data is used for training and whether a third-country transfer happens. These 15 criteria cover the questions a European rollout must answer. Five are knockout criteria.

    No.CriterionWhy it counts
    1 KOEU data hostingCustomer data is stored in the EU by default, not only as an enterprise option.
    2EU region is defaultThe EU region is preset, not a US default you must switch.
    3AI processing in the EUTranscription and LLM analysis run in the EU, not through a US cloud API.
    4No US parent companyNo US CLOUD Act access risk to the vendor, regardless of server location.
    5No US cloud AI in the chainNo US AI services such as OpenAI, Anthropic or Google as a sub-processor.
    6 KODPA under Art. 28 availableA data processing agreement is mandatory once the vendor processes your data.
    7SCCs for third-country transferFor transfers to third countries, a documented transfer basis, usually SCCs, is required.
    8 KOSub-processor list publicThe list must be viewable without an email gate; otherwise the chain cannot be checked.
    9 KONo training on customer dataThe vendor trains no models on your data, not even de-identified.
    10Sub-processors barred from trainingAI sub-processors are contractually barred from training on your data.
    11No biometric voiceprintsNo persistent voiceprint for recognition across meetings; that would be Art. 9 data.
    12Audio deleted after transcriptionThe raw recording is not retained once the transcript exists.
    13Configurable retentionRetention and deletion are configurable and documented.
    14Certification documentedSOC 2 Type 2 and/or ISO 27001 are certified, not just claimed as a framework.
    15 KONo documented lawsuit or fineNo documented consent or biometric lawsuit and no GDPR fine against the vendor.

    An EU data center is not the same as sovereign. A server in Frankfurt does not shield against a US parent's disclosure obligation under the CLOUD Act. That is why the scorer separates data location (criteria 1 to 3) from ownership (criteria 4 to 5). Sovereignty means control, not just origin.

    Sourced vendor comparison

    This overview summarises the key criteria for eight vendors. Every value is backed below in Evidence and sources with a link. Where no reliable public source exists, it says nicht belegt; that is an honest marker of missing documentation, not a judgement. All values as of 30 July 2026.

    VendorHQ / ownerData hostingTrains on customer dataSub-processor listBiometrics / voiceprintDocumented lawsuit / fineCertification
    Otter.aiUSAUS (AWS), no EU regionYes, own models on de-identified dataPublicSpeaker ID named as biometricBrewer v. Otter.ai (US, 2025)SOC 2 Type 2; ISO 27001 framework only
    Fireflies.aiUSAUS default; EU enterprise onlyNo (per vendor)Public (trust center)Vendor denies; suit alleges otherwiseCruz v. Fireflies.AI (US, BIPA, 2025)SOC 2 Type 2, HIPAA; no ISO 27001
    GongUSAUS or EU region (AWS), US defaultNo (trust page)Publicnicht belegtNone documentedSOC 2, ISO 27001, ISO 42001, DPF
    GranolaUSA (Delaware) / UKUS (AWS)Yes, de-identified (opt-out)On request only (gated)nicht belegtNone documentedSOC 2 Type 2; no ISO 27001
    FathomUSAUS (AWS)Yes, de-identified (opt-out)Referenced via trust centernicht belegtNone documentedSOC 2 Type 2, HIPAA; no ISO 27001
    tl;dvGermany (Aachen)EU (Google Cloud, Hetzner, Wasabi DE)No (per vendor)In privacy policy; US sub-processorsnicht belegtNone documentedSOC 2 Type 2; ISO 27001 hosting only
    JamieGermanyServer Frankfurt; AI via OpenAI/Replicate (US)No (per vendor)nicht belegt (no public DPA)nicht belegtNone documentedISO 27001 (to verify)
    NumiGermanyEU (Hetzner DE), self-hostedNoPublicPer-meeting diarization, no voiceprint DBNone documentedNo formal certification (beta)

    Green = favourable for European processing · Amber = partial or with caveats · Red = critical · nicht belegt = no public source found. Numi is scored by the same public criteria, including its open weakness on formal certification.

    Evidence and sources

    Every statement in the table is backed here with a source. Primary sources are preferred: vendors' privacy, DPA or trust pages and public court records. Where a vendor and a lawsuit disagree, both sides are named. Values as of 30 July 2026; later vendor changes are possible.

    US vendor

    Otter.ai

    Otter.ai, Inc. (formerly AISense), Mountain View, California

    US vendor

    Fireflies.ai

    Fireflies.AI Corp., USA

    US vendor

    Gong

    Gong.io, San Francisco (US parent), R&D in Israel, EU entity in Ireland

    US vendor

    Granola

    Granola, Inc. (Delaware, USA) and Granola Labs Ltd (England)

    US vendor

    Fathom

    Fathom Video, Inc., San Francisco

    EU vendor

    tl;dv

    Tldx Solutions GmbH, Aachen, Germany

    EU vendor

    Jamie

    meetjamie.ai, Germany

    Scored by the same criteria

    Numi

    numigtm.com, Germany. Scored by the same public criteria, including open weaknesses.

    Corrections welcome. All values rest on public sources as of 30 July 2026. If a vendor has changed its documentation or a value is inaccurate, tell us via our contact form and we will check and correct it.

    Frequently asked questions

    Otter.ai stores customer data on AWS in the US per its own privacy policy and documents no EU data residency. The parent company is US-based, creating a US CLOUD Act access risk. The privacy policy states Otter trains its own models on de-identified recordings and transcripts by default, and names speaker identification as biometric information. Since August 2025 the Brewer v. Otter.ai class action alleges recording without all-party consent. A DPA with SCCs is available. GDPR compliance depends on the use case and legal basis; the points above are material to a European assessment. Every claim is linked to a source above.

    Fireflies.ai hosts in the US by default; an EU region is enterprise-only via a bring-your-own bucket. Fireflies states it does not use customer data for AI training and offers a DPA with SCCs and a sub-processor list. It also states it does not process voiceprints on its own servers. Against this, the Cruz v. Fireflies.AI suit filed in December 2025 alleges exactly the collection and storage of voiceprints without consent under the Illinois BIPA. Both sides are documented with sources above. As a US company, a CLOUD Act access risk applies.

    Gong lets new customers choose a US or EU data region, both on AWS, with the US as default. It publishes a sub-processor list, offers a DPA with SCCs and the EU-US Data Privacy Framework, and holds SOC 2 Type 2, ISO 27001 and ISO 42001 among others. Its trust page states customer data is not used to train generative models. As a US company with a US default region, a CLOUD Act access risk applies. No documented statement on biometric processing was found. Details with sources above.

    Not automatically. An EU data center does not prevent a US parent from being compelled to hand over data under the US CLOUD Act, regardless of server location. Sovereignty means control, not just origin. A robust assessment also weighs the vendor's ownership structure, the AI sub-processors it uses, and whether a genuine transfer basis exists. The scorer separates these criteria deliberately.

    No. The scorer and comparison table are templates and educational aids, not legal advice. All statements about competitors rest on public sources as of the stated date and are linked; where no reliable source exists, it says nicht belegt. Assess the vendor case by case with your data protection officer and, in doubt, with legal counsel.

    Part of the Compliant Rollout Kit

    Four legally required artifacts belong to every German AI-notetaker rollout. This is the third. The others are reachable from the Rollout Kit overview.