Privacy Policy

Last updated 30 July 2026 · Applies to Amaya (the web application, the mobile application and the meeting notetaker).

The short version. Your meetings belong to your organisation. We process them to produce transcripts, summaries and action items. Before any of that content reaches an AI provider, we strip out names, contact details, government IDs and card numbers, and we refuse to send credentials at all. We do not sell your data and we do not train any model on it.

1. Who is responsible for your data

When your organisation subscribes to Amaya, your organisation is the data fiduciary (controller) for the meeting content it records, and we act as a data processor on its instructions. Your organisation decides what is recorded, who may see it, and when it is deleted.

For the account information we hold about you directly — your email address, name and sign-in activity — we are the data fiduciary.

2. What we collect

CategoryWhat it includesWhy
Account Name, work email, password hash, role, department, organisation To sign you in and decide what you may see
Meeting content Audio and video you record or upload, transcripts, summaries, action items, metadata you add The service itself
Meeting context Participant names from the platform roster, start and end times, calendar entries if you connect a calendar To label who spoke and to join scheduled meetings
Reference material Documents you upload to the knowledge base To improve transcription of your own terminology
Security and audit Sign-in events, IP address, what the masking pipeline detected (the kind of item, never the value) To secure accounts and to give you an audit trail
Operational logs Errors, timings and request metadata To keep the service working

We do not use advertising trackers, we do not build behavioural profiles, and we do not sell personal data to anyone.

3. How we use it

  • To transcribe, summarise and index the meetings you record
  • To authenticate you and enforce your organisation's access rules
  • To show your organisation what the masking pipeline found and hid
  • To detect and investigate abuse or a security incident
  • To meet a legal obligation where one applies

We do not use your meeting content to train models, improve our own algorithms, or for any purpose other than delivering the service to the organisation that recorded it.

4. AI processing, and what the provider actually sees

Producing a transcript and a summary requires sending text to an AI provider. Before that happens, the content passes through our data-loss prevention pipeline:

  • Detection. Names, email addresses, phone numbers, locations, Aadhaar and PAN numbers, payment card numbers, medical terms and credentials are identified using pattern matching and named-entity recognition.
  • Masking. What is found is replaced with placeholders such as [NAME_1] before the request leaves. The same person keeps the same placeholder so the model can still follow the conversation.
  • Blocking. Credentials — passwords, API keys — are not masked and sent. The request is refused.
  • Restoration. Real values are put back in what you read. The provider only ever received the placeholders.

One deliberate exception, stated because it is a real trade-off: speaker identification asks the model to attribute turns to the people who introduced themselves, which it cannot do if the names are masked. That single call passes names through. Everything else on it — credentials, government IDs, card numbers, emails, phone numbers — is still masked, and blocking still applies.

Your organisation can see all of this per meeting on the Security Log page inside the product. That page records the kind of each item, never the value, so the record cannot itself become a disclosure.

5. Subprocessors

We use the following third parties to deliver the service:

ProviderPurposeWhat it receives
Google Cloud Platform Hosting, database, file storage, key management All service data, encrypted at rest
Google Vertex AI Summaries, action items, speaker labelling Transcript text with sensitive values masked
Sarvam AI Speech-to-text for Indian languages Meeting audio
Google Cloud Speech-to-Text Speech-to-text for other languages Meeting audio
Google Cloud Translation Translation of transcript segments Transcript segments

We use Google Vertex AI under enterprise terms, under which customer content is not used to train Google's models.

6. Where your data is held

This deployment stores and processes data in its configured region, and AI processing is pinned to the same region. Where regional processing is a contractual requirement, the deployment is configured to refuse to start if it finds itself running outside its policy region, rather than continuing quietly in another jurisdiction.

Speech-to-text and translation for some languages are performed by services located outside that region, as listed in section 5. If regional processing matters to you, ask us before you record in those languages.

7. How we protect it

  • In transit: TLS 1.2 or above on every connection
  • At rest: AES-256 encryption on all stored data
  • Stored secrets: API keys, two-factor secrets and calendar tokens are additionally encrypted with a unique key per value, so a copy of the database alone reveals none of them
  • Passwords: hashed with bcrypt, never stored or recoverable in readable form
  • Access: role-based, scoped to your organisation and then to your department; two-factor authentication is available and can be made mandatory
  • Audit: a hash-chained trail in which altering past records breaks the chain and reports where

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify your organisation's administrators and the relevant authority as required by law.

8. How long we keep it

  • Meeting content is kept until you or your administrator deletes it, or until your organisation's account is closed.
  • Account data is kept while the account is active.
  • Audit and security records are kept for as long as they are needed to investigate an incident.

When your organisation closes its account, tell us and we will delete its content. We do not currently offer automatic retention schedules; if you need one, contact us.

9. Your rights under DPDP Act, 2023 and Applicable Privacy Laws

Under India's Digital Personal Data Protection Act, 2023 (DPDP Act) and global data protection regulations, you (as a Data Principal) have the following statutory rights:

  • Right to Access: You have the right to request a summary of digital personal data processed by us and the identities of third-party subprocessors with whom it has been shared.
  • Right to Correction and Erasure: You have the right to request correction of inaccurate or misleading personal data, completion of incomplete data, and erasure of personal data that is no longer necessary for the purpose for which it was processed.
  • Right of Grievance Redressal: You have the right to readily available grievance redressal mechanisms provided by the Data Fiduciary regarding performance of obligations or exercise of rights under the DPDP Act.
  • Right to Nominate: You have the right to nominate an individual who shall, in the event of death or incapacity, exercise your data principal rights.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw your consent at any time through your workspace settings or by writing to our Grievance Officer.

Because your organisation acts as the Data Fiduciary for meeting audio, transcripts, and summaries, please raise requests regarding meeting records directly with your organisation's administrator. For account credentials and direct data held by Amaya, or if your organisation fails to act, you may contact our Grievance Redressal Officer below.

10. Recording consent and Participant Notice

Informed Recording Consent. Recording conversations in Google Meet, Zoom, or Microsoft Teams may require explicit consent of all participants under Indian and international wiretapping / privacy laws. You are responsible for ensuring that all attendees are informed and have consented before deploying the Amaya notetaker. The Amaya bot automatically identifies itself in meeting rosters with active visual recording indicators.

11. Protection of Children's Data

Amaya is an enterprise workplace platform and is not directed at individuals under 18 years of age. In compliance with Section 9 of the DPDP Act, 2023, we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children, nor do we knowingly process children's personal data.

12. Changes to this policy

If we change this policy in a way that materially affects how your data is handled, we will notify organisation administrators by email and update the date at the top of this page before the change takes effect.

13. Grievance Redressal Officer & Contact

In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Rules, our designated Grievance Redressal Officer can be contacted for any data protection concerns, consent withdrawal, or rights enforcement:

Designation: Grievance Redressal Officer
Email: grievance@amaya.ai · privacy@amaya.ai
Security & Vulnerabilities: security@amaya.ai
Jurisdiction: Bengaluru, Karnataka, India

All grievances will be acknowledged within 24 hours and addressed within the statutory period of 30 days.