REKORD is designed for European organisations that cannot send meeting audio to a US-hosted model and call it a day. This page is the short map of how we treat the GDPR. The binding documents are the privacy policy and the DPA.
Roles
For this website and for early-access records, REKORD is the controller. For customer recordings, transcripts and summaries processed on REKORD Cloud, the customer is the controller and REKORD is the processor. For customer-cloud and on-premise deployments, REKORD typically does not process the content at all after the software is delivered.
Lawful bases we rely on
- Contract (Art. 6(1)(b)): answering an early-access request, providing the service, invoicing.
- Legitimate interests (Art. 6(1)(f)): securing the website, preventing abuse, answering a sales question that is not yet a contract.
- Legal obligation (Art. 6(1)(c)): tax and accounting records in Belgium.
- Customer instructions (Art. 28 and 6(1)(b) or 6(1)(f) of the controller): product content is processed only on documented instructions.
Special-category data can appear inside a meeting. The controller must have a lawful basis for that content. REKORD does not need, and does not ask for, a separate consent to "improve the model".
Residency
On REKORD Cloud, audio is uploaded to Paris, processed in Frankfurt, and stored in both. Transcription and summarisation models run on REKORD infrastructure inside the European Union. There is no US subprocessor in the product path and no fallback region outside the Union. See subprocessors.
Data-subject rights
Access, rectification, erasure, restriction, portability and objection are available. For website and early-access data, write to [email protected]. For product content, the customer (your employer or vendor) is the right first contact, because they are the controller. We will help them respond.
Every recording, transcript and summary can leave in one export call. Deletion is logged and the log is exportable.
Records we keep ready
Before you sign, we can provide the DPA, a transfer impact assessment where one is relevant, records of processing, the subprocessor list, and a summary of the latest penetration test. ISO 27001, ISO 27701 and SOC 2 Type II reports are available under NDA.
Supervisory authority
You can lodge a complaint with the Belgian Data Protection Authority, or with the authority in your own Member State. We would rather hear from you first: [email protected].
EU AI Act
REKORD is built so a customer can meet transparency and logging duties that apply to AI used in a workplace. Recording state is visible on the device. Automations are attributable. We do not claim a specific EU AI Act conformity assessment on this page until that assessment is complete and dated.