Privacy Policy
Last updated: March 20, 2026
Your privacy matters to us
1. Privacy Overview
NoteWave is developed and operated by Blaze AI Solutions (Pty) Ltd ("Blaze AI Solutions", "we", "us", or "our"), which is the responsible party (as defined under POPIA) for processing your personal information. This Privacy Policy explains how we collect, use, store, and protect your information when you use our AI-powered meeting transcription services.
We are committed to handling personal information in accordance with applicable data protection laws, including South Africa's Protection of Personal Information Act (POPIA) and, where applicable, the European Union's General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant privacy regulations.
By using NoteWave, you confirm that you are at least 18 years of age. If you are under 18, you may not use the Service.
Your Privacy Rights: You have the right to access, correct, delete, or port your data. You can also restrict processing and withdraw consent at any time.
2. Your Privacy Rights
Under applicable privacy laws (GDPR, POPIA, CCPA), you have the following rights:
- Right to Access: Request a copy of your personal data we hold
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data
- Right to Data Portability: Export your data in a machine-readable format
- Right to Object: Object to processing for direct marketing or legitimate interests
- Right to Restrict Processing: Limit how we use your data in certain circumstances
- Right to Withdraw Consent: Withdraw consent for data processing at any time
- Right to Lodge a Complaint: File a complaint with a supervisory authority (e.g., South Africa's Information Regulator)
To exercise your rights, contact our privacy team at contact@blazesolutions.ai or use the contact information in Section 13. We will respond within 30 days.
3. Data We Collect
3.1 Account Information
- Name, email address, and contact information
- Account credentials and authentication data (passwords are securely hashed using industry-standard practices)
- Billing and payment information (processed securely by LemonSqueezy)
- Profile preferences, settings, and user configurations
- OAuth data from Google, Microsoft, or GitHub integrations
3.2 Meeting & Audio Data
- Audio recordings uploaded or recorded through our service
- Meeting metadata (date, duration, participant information, meeting titles)
- Generated transcripts, summaries, and AI insights
- User annotations, comments, edits, and action items
- Meeting platform integration data (Zoom, Microsoft Teams, etc.)
- Speaker identification and diarization data
3.3 Technical Information
- Device information (type, operating system, browser version)
- IP address and approximate geographic location
- Usage analytics, feature usage, and app performance data
- Cookies, local storage, and similar tracking technologies (see our Cookie Policy)
- Error logs and diagnostic information for troubleshooting
3.4 Communication Data
- Customer support requests and interactions
- Feedback, survey responses, and user research data
- Marketing communication preferences and engagement
- Team collaboration and sharing activities
3.5 Zoom and Teams Integration Data
When you connect your Zoom or Microsoft Teams account, we collect:
- Meeting metadata (start/end time, participants, meeting IDs)
- Cloud recording files and associated transcripts
- User email address associated with platform login
- Platform account information and OAuth tokens
- Recording processing status and webhook event data
This data is used solely for transcription, speaker identification, and summarization. We do not target our services toward anyone under 18 years of age.
3.6 Customer Content and Participant Data
When you record or upload meeting content, that content may include the voices, names, and other personal information of meeting participants. You are responsible for ensuring that you have a lawful basis and any required consents or notices for the meeting recordings and participant information you submit or enable us to process. We process meeting content to provide transcription, summarisation, speaker identification, and related features as part of delivering the Service to you.
4. How We Use Your Data
We process personal information on the following lawful bases, as applicable: (1) performance of our contract with you (providing the Service), (2) our legitimate business interests (improving the Service, security, fraud prevention), (3) compliance with legal obligations, and (4) your consent (where required by applicable law). Where we rely on consent, you may withdraw it at any time.
4.1 Core Service Provision
- Processing audio recordings to generate accurate transcripts
- Creating AI-powered meeting summaries, action items, and insights
- Providing real-time transcription during live meetings
- Storing, organizing, and managing your transcripts and data
- Enabling collaboration, sharing, and team features
- Supporting integrations with meeting platforms and tools
4.2 Account & Business Operations
- Creating and maintaining your user account
- Processing payments and managing subscriptions
- Providing customer support and technical assistance
- Sending important service notifications, updates, and security alerts
- Managing team accounts and permissions
- Enforcing our Terms of Service and detecting fraud
4.3 Third-Party AI Service Processing
To deliver transcription and AI-powered features, your audio recordings and meeting content are processed by third-party artificial intelligence service providers. These services operate under their own terms of service and privacy policies.
Based on the current terms of our AI providers, they process your data to deliver the requested services and are not permitted to use your data to train their general AI models. We recommend reviewing the privacy policies of these providers for the most current information.
We use aggregated and anonymized usage data internally to:
- Analyze service performance and reliability
- Develop new features and functionality
- Understand usage patterns to enhance user experience
- Conduct product research and improvements
Data Minimization: If you prefer to limit sharing of your content with third-party AI services, you can contact us at contact@blazesolutions.ai to discuss alternative arrangements. Please note that this may affect the availability of certain AI-powered features.
4.4 Security & Legal Compliance
- Enhancing security and preventing fraud, abuse, or unauthorized access
- Complying with legal obligations and regulations (GDPR, POPIA, CCPA, etc.)
- Responding to valid legal requests, court orders, and government inquiries
- Enforcing our Terms of Service and protecting our rights and property
- Investigating security incidents, policy violations, and disputes
5. Data Security & Protection
We use reasonable technical and organisational measures designed to protect your data from unauthorised access, loss, misuse, or disclosure:
- Encryption: Encryption in transit and at rest, where supported by our infrastructure providers
- Infrastructure Security: Certain infrastructure providers we use (such as Supabase and Vercel) maintain recognised security certifications such as SOC 2 and ISO 27001
- Access Controls: Authentication safeguards and role-based access control where applicable
- Backups: Automated backups maintained by our infrastructure providers
No system is 100% secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security. Security measures depend in part on the practices of our infrastructure providers.
6. Data Sharing & Transfers
We Do NOT Sell Your Data: NoteWave never sells, rents, or trades your personal information to third parties for marketing or advertising purposes.
We share data only in the following limited circumstances:
6.1 Trusted Service Providers
We share data with carefully selected service providers who process data on our behalf:
- LemonSqueezy: Payment processing and subscription management
- Supabase: Secure database storage, authentication, and real-time features
- Vercel: Frontend hosting and content delivery
- Fly.io: Backend Python hosting for transcription processing
- ElevenLabs: AI transcription services
- OpenAI: AI summarization and processing services
- RevenueCat: In-app subscription management for mobile applications (purchase validation, entitlement delivery, and subscription status tracking)
- Zoom, Microsoft Teams: Meeting platform integrations (when you connect your account)
All providers are contractually required to protect your data and use it only for specified purposes.
6.2 Legal Requirements
When required by law, court order, subpoena, or government regulation, or to:
- Comply with legal processes and obligations
- Protect our rights, property, or safety, or that of our users
- Investigate fraud, security breaches, or Terms of Service violations
- Respond to emergency situations involving potential harm
6.3 Business Transfers
In case of merger, acquisition, bankruptcy, or sale of assets, your data may be transferred to the acquiring entity. We will notify you via email and provide opt-out options where possible.
6.4 With Your Consent
Any other data sharing requires your explicit consent, which you can withdraw at any time.
6.5 International Data Transfers
Your data may be processed in countries outside your location, including the United States and European Union. Where required by applicable law, we rely on appropriate safeguards for cross-border data transfers. Our infrastructure providers may use mechanisms such as Standard Contractual Clauses (SCCs) to support lawful transfers.
7. Data Breach Notification
If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify affected users without undue delay and within the timeframes required by applicable law
- Inform relevant supervisory authorities or regulators as required by law
- Provide clear information about the nature of the breach, potential consequences, and remedial actions
- Take reasonable steps to contain and remediate the breach
8. Data Retention
We retain data only as long as necessary for business purposes and legal obligations:
- Account Data: Retained until account deletion, then purged within 30 days (except as required for legal/financial obligations)
- Audio Files: Retained only as long as needed for transcription processing, then deleted in accordance with our operational procedures unless explicitly saved by the user
- Transcripts: Retained until user deletion or account termination
- Analytics Data: Retained for a reasonable period and anonymised where practicable
- Backup Data: Retained in encrypted backups for a limited period before being cycled out
- Legal/Financial Records: Retained for 7 years as required by South African law
User Control: You can request deletion of your data at any time through account settings or by contacting contact@blazesolutions.ai. We will process deletion requests within 30 days unless legally required to retain data.
9. Cookies & Tracking Technologies
We use cookies and similar technologies to enhance your experience. For detailed information, see our Cookie Policy.
Types of cookies we use:
- Essential Cookies (Required): Login sessions, authentication, security, and core functionality
- Preference Cookies (Optional): Language, theme, and display settings
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect service functionality. See our Cookie Policy for more details.
10. Children's Privacy
NoteWave is not intended for children under 18 years of age. We do not knowingly offer the Service directly to anyone under 18. Users are responsible for ensuring they have a lawful basis to record and process meeting content involving any participants.
If we learn that personal information relating to a child under 18 has been collected in a way that requires action under applicable law, we will take appropriate steps to address the situation. If you believe a user is under 18, please contact us at contact@blazesolutions.ai.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Notify you via email or through prominent notice in the Service
- Provide at least 30 days' notice for material changes that adversely affect your rights
Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy. If you do not agree, you must stop using the Service.
12. Additional Information for International Users
California Residents (CCPA/CPRA)
California consumers have additional rights under the California Consumer Privacy Act:
- Right to know what personal information we collect and how it's used
- Right to delete personal information (with certain exceptions)
- Right to opt-out of "sale" of personal information (we don't sell data)
- Right to non-discrimination for exercising CCPA rights
To exercise CCPA rights, email contact@blazesolutions.ai with "CCPA Request" in the subject line.
EU/EEA and UK Residents (GDPR)
Under GDPR, you have enhanced rights including:
- Right to lodge a complaint with your local Data Protection Authority
- Right to object to automated decision-making and profiling
- Right to withdraw consent at any time (where processing is based on consent)
Our legal basis for processing: (1) Contractual necessity, (2) Legitimate interests, (3) Legal obligations, (4) Your consent.
South African Residents (POPIA)
Under POPIA, you have rights including:
- Right to access and correct personal information
- Right to object to processing and lodge complaints with the Information Regulator
- Right to request that we stop processing your data for direct marketing
Privacy Contact: Blaze AI Solutions (Pty) Ltd (contact details in Section 13)
13. Contact Our Privacy Team
Privacy Contact
Blaze AI Solutions (Pty) Ltd
Email: contact@blazesolutions.ai
Response Time: We aim to respond to privacy requests within the timeframes required by applicable law, and in many cases within 30 days.
For privacy inquiries, POPIA requests, data subject access requests, or requests under the Promotion of Access to Information Act (PAIA), please reference the applicable request type in your subject line. Our PAIA manual is available upon request.
Our Privacy Commitment
NoteWave is committed to handling personal information in accordance with applicable data protection laws, including POPIA (South Africa) and, where applicable, GDPR (EU/UK) and CCPA/CPRA (California).
By creating an account or using NoteWave, you acknowledge that you have read and agree to this Privacy Policy and our Terms of Service. You confirm that you are at least 18 years of age.
