Privacy Policy
Last updated: 9 August 2026 · Version 2026-08-09
The short version:
- Microphone and meeting audio is never stored by default — it is processed as a live stream and discarded. The exceptions are under your control: if you turn on recording, the file is saved on your device, and only with “Cloud copy” enabled is it uploaded to our EU storage. (We also cache synthesized voice-over audio for up to 7 days, in the EU.)
- Transcripts created under your account are visible in the product only to that account — they are not exposed through our admin interface, and our staff do not access them except where required by law or to investigate abuse, in which case the access is logged.
- By default, cloud transcripts are deleted automatically after 30 days. On Flow and Scale plans you can choose to keep them until you delete them yourself.
- You can delete any transcript, export your data, or erase your whole account yourself, at any time.
1. Who we are
Getix Translate (“we”, “us”) is operated by Getix Group, founder Alexander Kornienko, Valencia, Spain. Contact for all privacy matters: kornienko.mkt@gmail.com. We act as the data controller for your account data. For the content of your meetings you (the meeting host) are the controller and we act as your processor.
2. What we collect and why
- Account data — name, email, phone (optional), company (optional), password hash (we never store plain passwords). Legal basis: contract (Art. 6(1)(b) GDPR).
- Meeting content — audio is processed in real time to produce subtitles, translations and voice-over. Audio is streamed transiently and is not stored by us; it reaches our speech providers only as a live stream for processing (see their policies in section 3). Text transcripts are saved to your account so you can reread them: by default they are deleted automatically after 30 days; on plans that include the storage option (Flow, Scale) you may instead choose “keep until I delete” in Settings → Meeting storage. Transcripts created under your account are visible in the product only to your account; they are not exposed through our admin interface, and our staff do not access them except where required by law or to investigate abuse (such access is logged). Legal basis: contract; the host is responsible for informing meeting participants (Art. 28: we process on the host’s instructions).
- Recordings (optional) — if you turn on recording, the video/audio file is saved locally on your device. If you additionally enable “Cloud copy”, the file is uploaded to our EU storage so you can re-watch it; we delete cloud copies on your request while self-service deletion is being built. Legal basis: contract (you initiate it).
- Support chat — messages you type in the support widget are delivered to us via the Telegram Bot API (Telegram, non-EU) and are not linked to your account. Please do not include sensitive data in support chat; you can always email us instead.
- Waiting list — if signups are full, we store the name, email, phone and company you submit until we invite you or 12 months pass, whichever is earlier; write to us to be removed sooner.
- Balance and billing records — minutes ledger, subscriptions, access-code activations. Legal basis: contract and legal obligations (accounting).
- Consent journal — a record of every consent you give or withdraw, with policy version. Legal basis: legitimate interest (demonstrating compliance and defending legal claims, Art. 6(1)(f)).
- Technical logs — connection events for reliability, kept for up to 12 months. Legal basis: legitimate interest (running a stable service). We do not use advertising or analytics trackers, and we do not use automated decision-making or profiling.
3. Subprocessors
We use these providers to deliver the service (data processing agreements / SCCs where applicable):
- Soniox (speech recognition & translation, US — SCCs) — real-time audio processing; audio is processed in memory and not retained
- Deepgram (speech recognition, US — SCCs; EU endpoint) — backup real-time speech recognition, with model-training opt-out enforced on every request
- Speechmatics (speech recognition, UK — adequacy decision) — backup real-time speech recognition, EU region; real-time audio is not stored
- Cartesia (voice synthesis, US — SCCs) — spoken translation
- Skribby (meeting bot infrastructure, EU) — bot joins your Zoom/Meet/Teams call; call audio is retained by Skribby for up to 7 days
- Telegram (Telegram Bot API, non-EU) — delivery channel for support-chat messages only
- Supabase (database & realtime, EU region) — accounts, transcripts, subtitles delivery
- Vercel (hosting, EU/US — SCCs) — application hosting
- Cloudflare (storage, EU jurisdiction) — optional cloud recordings and voice cache
- Fly.io (server workers, EU region) — server-side meeting bot
4. Retention
- Cloud transcripts: deleted automatically after 30 days (default). If you switched a transcript-keeping plan (Flow, Scale) to “keep until I delete”, transcripts stay until you delete them — and we do not delete already-kept transcripts if your plan later lapses. Local copies stay on your device either way.
- Voice-over audio cache: up to 7 days (EU storage), then deleted automatically.
- Optional cloud recording copies: EU storage, kept until deleted on your request (self-service deletion is being built).
- Waiting-list entries: until invited or 12 months, whichever is earlier.
- Access-code activation records: up to 6 years after activation, as accounting evidence (legal obligation).
- Account data: while your account exists.
- Consent journal: after account deletion we retain each consent record (email address, consent type, timestamp, policy version) for up to 5 years as evidence of compliance and to honour opt-outs; IP address and device data are deleted at that point.
- Billing ledger: anonymised after account deletion; aggregates kept for accounting.
5. Your rights
Under GDPR (and, for users in Ukraine, the Law of Ukraine “On Personal Data Protection”) you have the right of access, rectification, erasure, restriction, portability and objection. Where processing is based on consent (marketing), you may withdraw it at any time in Settings or by emailing us, without affecting prior processing; you may object to direct marketing at any time. Self-service: Settings → Privacy → Download my data / Delete my account. You may also email us; we respond within one month (extendable by two months for complex requests). You can lodge a complaint with your supervisory authority (in Spain: AEPD, aepd.es; in Ukraine: the Parliament Commissioner for Human Rights).
6. International transfers
Some subprocessors are in the United States; transfers rely on Standard Contractual Clauses and provider DPAs. Meeting audio is processed transiently and not retained by us.
7. Security
Passwords are hashed (scrypt), sessions are signed httpOnly cookies, database access is server-only (row-level security fail-closed), transport is HTTPS everywhere, and access codes are single-use. Report security issues to the contact above.
8. Changes
We will post updates here with a new version date. Material changes will be announced in the app before they take effect.