English · Deutsche Version
Free tool · Compliant Rollout Kit 3 of 4
Check any AI meeting vendor's data processing agreement and privacy posture against 15 criteria: EU hosting, ownership, sub-processors, no-training clause, biometric voiceprints, deletion terms and more. You get a score and a red-flag report to copy or download. Below it sits a sourced comparison table for Otter, Fireflies, Gong, Granola, Fathom and two EU vendors. Every claim is linked; where no reliable source exists, it says nicht belegt (not documented).
Updated: 30 July 2026 · Template, not legal advice
Template, not legal advice. The scorer is an educational aid. It does not replace an individual assessment of the DPA and privacy posture by your data protection officer. A vendor's rating depends on the specific deployment, configuration and legal basis. Made with numigtm.com.
An AI notetaker processes personal data on your behalf as a processor. Under Article 28 GDPR you remain the liable controller. The DPA and sub-processor chain decide where data sits, who can access it, whether your data is used for training and whether a third-country transfer happens. These 15 criteria cover the questions a European rollout must answer. Five are knockout criteria.
| No. | Criterion | Why it counts |
|---|---|---|
| 1 KO | EU data hosting | Customer data is stored in the EU by default, not only as an enterprise option. |
| 2 | EU region is default | The EU region is preset, not a US default you must switch. |
| 3 | AI processing in the EU | Transcription and LLM analysis run in the EU, not through a US cloud API. |
| 4 | No US parent company | No US CLOUD Act access risk to the vendor, regardless of server location. |
| 5 | No US cloud AI in the chain | No US AI services such as OpenAI, Anthropic or Google as a sub-processor. |
| 6 KO | DPA under Art. 28 available | A data processing agreement is mandatory once the vendor processes your data. |
| 7 | SCCs for third-country transfer | For transfers to third countries, a documented transfer basis, usually SCCs, is required. |
| 8 KO | Sub-processor list public | The list must be viewable without an email gate; otherwise the chain cannot be checked. |
| 9 KO | No training on customer data | The vendor trains no models on your data, not even de-identified. |
| 10 | Sub-processors barred from training | AI sub-processors are contractually barred from training on your data. |
| 11 | No biometric voiceprints | No persistent voiceprint for recognition across meetings; that would be Art. 9 data. |
| 12 | Audio deleted after transcription | The raw recording is not retained once the transcript exists. |
| 13 | Configurable retention | Retention and deletion are configurable and documented. |
| 14 | Certification documented | SOC 2 Type 2 and/or ISO 27001 are certified, not just claimed as a framework. |
| 15 KO | No documented lawsuit or fine | No documented consent or biometric lawsuit and no GDPR fine against the vendor. |
An EU data center is not the same as sovereign. A server in Frankfurt does not shield against a US parent's disclosure obligation under the CLOUD Act. That is why the scorer separates data location (criteria 1 to 3) from ownership (criteria 4 to 5). Sovereignty means control, not just origin.
This overview summarises the key criteria for eight vendors. Every value is backed below in Evidence and sources with a link. Where no reliable public source exists, it says nicht belegt; that is an honest marker of missing documentation, not a judgement. All values as of 30 July 2026.
| Vendor | HQ / owner | Data hosting | Trains on customer data | Sub-processor list | Biometrics / voiceprint | Documented lawsuit / fine | Certification |
|---|---|---|---|---|---|---|---|
| Otter.ai | USA | US (AWS), no EU region | Yes, own models on de-identified data | Public | Speaker ID named as biometric | Brewer v. Otter.ai (US, 2025) | SOC 2 Type 2; ISO 27001 framework only |
| Fireflies.ai | USA | US default; EU enterprise only | No (per vendor) | Public (trust center) | Vendor denies; suit alleges otherwise | Cruz v. Fireflies.AI (US, BIPA, 2025) | SOC 2 Type 2, HIPAA; no ISO 27001 |
| Gong | USA | US or EU region (AWS), US default | No (trust page) | Public | nicht belegt | None documented | SOC 2, ISO 27001, ISO 42001, DPF |
| Granola | USA (Delaware) / UK | US (AWS) | Yes, de-identified (opt-out) | On request only (gated) | nicht belegt | None documented | SOC 2 Type 2; no ISO 27001 |
| Fathom | USA | US (AWS) | Yes, de-identified (opt-out) | Referenced via trust center | nicht belegt | None documented | SOC 2 Type 2, HIPAA; no ISO 27001 |
| tl;dv | Germany (Aachen) | EU (Google Cloud, Hetzner, Wasabi DE) | No (per vendor) | In privacy policy; US sub-processors | nicht belegt | None documented | SOC 2 Type 2; ISO 27001 hosting only |
| Jamie | Germany | Server Frankfurt; AI via OpenAI/Replicate (US) | No (per vendor) | nicht belegt (no public DPA) | nicht belegt | None documented | ISO 27001 (to verify) |
| Numi | Germany | EU (Hetzner DE), self-hosted | No | Public | Per-meeting diarization, no voiceprint DB | None documented | No formal certification (beta) |
Green = favourable for European processing · Amber = partial or with caveats · Red = critical · nicht belegt = no public source found. Numi is scored by the same public criteria, including its open weakness on formal certification.
Every statement in the table is backed here with a source. Primary sources are preferred: vendors' privacy, DPA or trust pages and public court records. Where a vendor and a lawsuit disagree, both sides are named. Values as of 30 July 2026; later vendor changes are possible.
Corrections welcome. All values rest on public sources as of 30 July 2026. If a vendor has changed its documentation or a value is inaccurate, tell us via our contact form and we will check and correct it.
Otter.ai stores customer data on AWS in the US per its own privacy policy and documents no EU data residency. The parent company is US-based, creating a US CLOUD Act access risk. The privacy policy states Otter trains its own models on de-identified recordings and transcripts by default, and names speaker identification as biometric information. Since August 2025 the Brewer v. Otter.ai class action alleges recording without all-party consent. A DPA with SCCs is available. GDPR compliance depends on the use case and legal basis; the points above are material to a European assessment. Every claim is linked to a source above.
Fireflies.ai hosts in the US by default; an EU region is enterprise-only via a bring-your-own bucket. Fireflies states it does not use customer data for AI training and offers a DPA with SCCs and a sub-processor list. It also states it does not process voiceprints on its own servers. Against this, the Cruz v. Fireflies.AI suit filed in December 2025 alleges exactly the collection and storage of voiceprints without consent under the Illinois BIPA. Both sides are documented with sources above. As a US company, a CLOUD Act access risk applies.
Gong lets new customers choose a US or EU data region, both on AWS, with the US as default. It publishes a sub-processor list, offers a DPA with SCCs and the EU-US Data Privacy Framework, and holds SOC 2 Type 2, ISO 27001 and ISO 42001 among others. Its trust page states customer data is not used to train generative models. As a US company with a US default region, a CLOUD Act access risk applies. No documented statement on biometric processing was found. Details with sources above.
Not automatically. An EU data center does not prevent a US parent from being compelled to hand over data under the US CLOUD Act, regardless of server location. Sovereignty means control, not just origin. A robust assessment also weighs the vendor's ownership structure, the AI sub-processors it uses, and whether a genuine transfer basis exists. The scorer separates these criteria deliberately.
No. The scorer and comparison table are templates and educational aids, not legal advice. All statements about competitors rest on public sources as of the stated date and are linked; where no reliable source exists, it says nicht belegt. Assess the vendor case by case with your data protection officer and, in doubt, with legal counsel.
Four legally required artifacts belong to every German AI-notetaker rollout. This is the third. The others are reachable from the Rollout Kit overview.