Privacy Policy
INTRODUCTION
About Us
Happy Scribe Limited ("HappyScribe") is a private company limited by shares incorporated in Ireland with company number 604917 and having a registered office at The Black Church, Saint Mary's Place North, Dublin 7 ("we"/"us"/"our"). We provide transcription, subtitling, translation and meeting-notetaking services to our customers (the "Services") through our online platform at https://www.happyscribe.com (the "Website").
About this Privacy Policy
Data protection refers to the safeguarding of personal data, as defined by the General Data Protection Regulation ("GDPR"), which encompasses any information pertaining to an identified or identifiable natural person. An identifiable natural person is someone who can be directly or indirectly identified, particularly through an identifier such as a name, identification number, or other specific attributes. This Privacy Policy (the "Policy") outlines crucial information about your rights concerning the processing of your personal data for the purpose of using the website. It also specifies the basis on which any personal data we collect from you.
In compliance with data protection regulations, your personal data will:
- Be used in a legal, fair, and transparent manner.
- Only be collected for valid purposes that we have clearly explained to you and will not be used in a manner incompatible with those purposes.
- Be relevant to the purposes we have disclosed to you and limited only to those purposes.
- Be accurate and up to date.
- Be retained only for as long as necessary to fulfil the purposes we have indicated to you.
- Be kept and stored securely.
We take our responsibilities seriously with regard to the processing of personal data. Please note that our Website may contain links to third-party websites. If you follow a link to any of those third-party websites, please note that they have their own privacy policies and that we do not accept any responsibility or liability for their policies or processing of your personal information. Please check these policies before you submit any personal information to such third-party websites.
The Website is not aimed at children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are under 16, please do not use our Services or provide any information to us through the Website.
This Policy should be read alongside, and in addition to, our Website Terms of Use, which can be found at: https://www.happyscribe.com/terms.
I. USERS PERSONAL DATA
a) Identity and contact information of the Data Controller
Unless we specify otherwise (see section II below) or unless we have entered into a different agreement with you, we will be what's known under the GDPR as the "controller" of the personal data you provide to us.
b) Personal information we may process about you
We collect and process the following data about you for the following purposes:
Personal data you give to us in order to use our services: We collect data about you that you provide to us by registering or filling in forms on our website, or by corresponding with us by phone, email, or other means. This includes the data collected:
- when you register with us and set up an account to use our Services;
- when you contact us through the Website, by telephone, post, e-mail or through any other means;
- when you complete surveys that we use for research purposes (although you are not obliged to respond to them);
- when you use our Services.
In particular, we process the following information:
- Identity Data: We may collect personal information from you, such as your full name, job title, profession, contact information (such as email addresses and telephone numbers), postcode, password, subscriptions purchased by you, your preferences, feedback and survey responses, preferences and/or interests.
- Financial Data: We may collect financial data from you, such as billing contact email address, VAT number, and information about payments you have made to us or received from us for services purchased. Other Financial Data such as credit card details will be directly collected by our payment processor, who will process such data as data controllers according to their privacy policy. We will not have access to this data.
- Technical Data: In order to provide you with the best experience possible on our Website, we collect certain information from you. This includes your IP address, web browser type and version, and operating system, which are automatically collected. We also collect data to understand how you wish to use our Website and keep a record of any correspondence you have with us.
We collect this information to improve the content and navigation of our Website. To collect this information, we use cookies, which are stored on your browser in accordance with your cookie settings. For more information about cookies and how we use them, please refer to our Cookies Policy at: https://www.happyscribe.com/cookies_policy
| Personal Data | Why are personal data processed? | Period for which data will be stored | Legal basis for processing |
|---|---|---|---|
| Identity Data | 1) To register you as a new customer. 2) To provide you with secure access to the platform. 3) Surveys and review | We will store your identity data until you delete your account, plus any statutory retention period that applies. | 1) Performance of a contract with you. 2) Necessary for our legitimate interests (to respond to new or existing customer queries and grow our business). |
| Identity Data Financial Data | We collect this information to prepare the customer invoices. | Statutory tax/accounting retention period (typically 6–10 years depending on jurisdiction) from the date of the relevant transaction. | 1) Performance of a contract with you. 2) Compliance with legal obligations (tax / accounting). |
| Identity Data Technical Data | To manage our relationship with you, including notifying you about changes to the Services, or our Privacy Policy. | We will store your personal data until you delete your account. We may share your identity data with third parties to help store your account information. | 1) Performance of a contract. 2) Necessary to comply with a legal obligation. 3) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products and Services). |
| Identity Data Technical Data | To provide you with information about services we offer that are similar to those that you have enquired about. | We will store your personal data until you delete your account. | Necessary for our legitimate interests (to develop our products or Services and grow our business). |
| Identity Data Technical Data | Where you have given us your consent to do so, to provide you with information about other services we feel may interest you. | We will store your personal data until you withdraw the consent you have given us to send you information. | Consent. |
| Identity Data Technical Data | To ensure that content is presented in the most effective manner for you and for your computer or device. | We will store your personal data until you delete your account. | Necessary for our legitimate interests (to keep our Site and the Services updated and relevant and to develop and grow our business). |
| Identity Data Technical Data | To administer and protect our business, our Site and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes. | We will store your personal data until you delete your account, plus logs for up to 24 months for security purposes. | Necessary for our legitimate interests (for running our business and as part of our efforts to keep our Site and the Services safe and secure). |
| Technical Data | To use data analytics to improve or optimize our Site, marketing, customer relationships and experiences. | We will store your personal data until you delete your account. | Necessary for our legitimate interests (to define types of customers for our products and services, to keep our Site and the Services updated and relevant, to develop and grow our business and inform our marketing strategy). |
| Identity Data Content Data | To train and improve machine-learning models only where you have opted in to this use at signup and only for as long as you remain opted in (see Section II.f). | Until you withdraw consent. Where Content used in prior training has been de-identified so that it no longer relates to an identifiable person, that processing cannot be unwound (see Section II.f). | Consent (Article 6(1)(a) GDPR). Freely given, separately collected at signup, withdrawable at any time without affecting any other Services and without affecting the lawfulness of processing carried out before withdrawal. |
HappyScribe does not actively collect special category ("sensitive") data as part of the Services. If you choose to share sensitive data with us, it is retained for as long as necessary to fulfil the purposes for which you provided it and is subject to the same security measures as all other personal data.
Data that is received from third parties. We will receive personal data about you from third parties such as:
- Hotjar;
- Google Analytics;
- Intercom;
- Typeform;
- Stripe;
- YouTube API*
- Vimeo;
- Dropbox;
- Apollo;
- Wistia;
- Hubspot;
- Sentry;
*Users that choose to upload files using the YouTube upload integration are agreeing to be bound by the YouTube Terms of Service (https://www.youtube.com/t/terms), which are related to the Google Privacy Policy (http://www.google.com/policies/privacy).
For the full and up-to-date list of subprocessors we use to deliver the Services, please refer to our Trust Center at https://trust.happyscribe.com, which we update whenever subprocessors are added or replaced.
c) We will disclose your personal information to third party recipients
- in the event that we intend to sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of our business or assets.
- if we, or substantially all of our assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
- if we are under a duty to disclose or share your personal data in order to comply with any law, legal obligation or court order, or in order to enforce rights under the GDPR or other agreements.
- to third-party services you choose to connect to your HappyScribe account through our integrations, as described in Section III below.
Any third parties to whom we disclose your personal data are required to respect the security of your personal data and process it in accordance with applicable data protection laws.
d) International Transfers
Where we transfer your personal data to service providers whose servers are located outside the European Economic Area ("EEA"), we do so on the basis of one or more of the following safeguards required by Chapter V of the GDPR: (i) the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914); (ii) where applicable, the recipient's certification under the EU–US Data Privacy Framework; or (iii) any other valid transfer mechanism permitted by Articles 45 or 46 of the GDPR.
For more information about this and the safeguards in place relating to the transfer, please contact us by email at dataprotection@happyscribe.com
e) Keeping Data Secure
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
HappyScribe operates a SOC 2 Type II security programme, independently audited against the AICPA Trust Services Criteria (Security). The current SOC 2 Type II report is available under non-disclosure agreement on request through our Trust Center at https://trust.happyscribe.com, where you can also find an up-to-date summary of our technical and organisational measures and our subprocessor list.
Further information about our technical and organisational measures is available at https://www.happyscribe.com/security and https://trust.happyscribe.com.
f) Your Rights
As a data subject, you have the following rights under the GDPR. To exercise any of these rights, please email dataprotection@happyscribe.com. We will respond within one month and will only charge a fee or refuse a request if it is manifestly unfounded, repetitive or excessive.
- Right of access — request a copy of the personal data we hold about you. We may need to verify your identity.
- Right of rectification — request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — request deletion where the data is no longer necessary for its original purpose or where you withdraw the consent on which processing is based, subject to limited legal exceptions.
- Right of restriction — request that we restrict processing in certain circumstances (e.g., while we verify the accuracy of contested data).
- Right to data portability — where processing is automated and is based on consent or contract, request a copy of your data in a structured, commonly used machine-readable format and, where technically feasible, that we transmit it to another controller.
- Right to object — object at any time to processing based on legitimate interests, to direct marketing, and to profiling related to direct marketing.
- Right to withdraw consent — where processing is based on consent (including ML training under Section I.b and II.f, and electronic marketing), withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
The rights described in this section are personal rights and are exercisable only by the individual person (or data subject) concerned.
g) Marketing Communications
General.
We will process your personal data to send you marketing communications regarding products or similar services to those initially contracted, on the basis of our legitimate interest.
Your right to object.
You have the right to object to the processing of your personal data for our marketing communications by contacting us at dataprotection@happyscribe.com. You may also opt out of receiving marketing communications at any time by selecting the unsubscribe option when you receive an electronic marketing communication from us.
h) How Long We Keep Your Information:
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. This means that the period of time for which we store your personal data may depend on the type of data we hold. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. For more information about our data retention policies please contact us at dataprotection@happyscribe.com.
i) If You Fail To Provide Personal Data.
Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with our Services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.
We store the data for the duration of the contract term and, if applicable, for the duration of statutory retention periods. We will delete your account upon your request after the cancellation of the account, subject to those statutory retention periods.
II. CONTENT DATA
In order for us to provide you with our Services you will share with us texts, audio or video files. You can do this in three principal ways:
- by uploading existing files to our Website or through our API;
- by recording audio or video directly through our mobile or web applications — for example, to capture an interview, an in-person meeting, a lecture, a voice memo or dictation; or
- by using the Meeting Notetaker, which records your online meetings on supported video-conferencing platforms (such as Zoom, Google Meet and Microsoft Teams). The Meeting Notetaker captures the audio, video and on-screen content of the meetings it joins. You can launch the Meeting Notetaker manually by providing a meeting URL, or — if you have separately connected a calendar to HappyScribe (a distinct integration described in Section III) — have it join scheduled meetings automatically. Use of the Meeting Notetaker does not require a connected calendar, and connecting a calendar does not by itself cause any recording to take place.
We will use these texts, audio and video files and recordings (together, the "Content") to provide transcription, subtitling, translation, note-taking and meeting summaries.
Such Content may include personal data — including, in the case of audio and video, the voice and image of identifiable individuals. You, as the person uploading the Content or initiating a recording, are the data controller of that personal data, and you are responsible for obtaining any consents required and complying with any applicable information duties before that personal data is shared with us.
In particular:
- If you use the Meeting Notetaker, you must inform meeting participants that the meeting will be recorded (including their voice, image and the contents of the meeting) and provide them with the option to oppose the recording.
- If you use our direct recording features on mobile or web to record other people, you must inform any data subject before the recording starts and obtain their consent where required by applicable law. National laws on recording differ within the EU and elsewhere — for example, some jurisdictions require the consent of all parties to record an in-person or telephone conversation, and recording confidential spoken communications without consent may constitute a criminal offence. We provide the recording tool; you, as the controller, are responsible for using it lawfully in your jurisdiction.
Regardless of how the Content reaches us, our obligations as Processor with respect to the personal data it contains are the same and are set out below.
We process personal data included in the Content acting as what's known under the GDPR as the "Processor" and while doing so we will comply with the following obligations:
a) Data Processing
We will only process the personal data in your Content to provide the Services, on your documented instructions, and not for our own purposes (including statistical purposes). The one exception is machine-learning training: where you have opted in, we use your Content to improve our models, as described in Section II.f. Because that training is our own purpose and rests on your consent rather than your instructions, for that activity we act as controller rather than as your processor.
We will only grant access to personal data in the Content to those employees and/or third parties necessary for providing the Services to you. Our employees and contractors are trained in data protection, are bound by confidentiality, and only access Content as required to provide the Services (including troubleshooting, supporting users and quality assurance). Access for any other purpose is restricted to data that has been de-identified.
b) Security Measures
We adopt the technical and organisational measures necessary to ensure the security, confidentiality and integrity of the personal data in the Content and to prevent its alteration, loss, unauthorised processing or access, taking into account the state of technology, the nature of the data and the risks to which it is exposed. These measures form part of our SOC 2 Type II security programme described in Section I.e, which applies to the processing of Content as well as to other personal data we hold.
c) Notification of Incidents/Security Breaches
In the event of a security incident — destruction, loss, modification, accidental disclosure, unauthorised or illegal access to personal data — we will notify you, as Controller, without undue delay, together with all relevant information for documentation and communication of the incident. Notification is not required when it is unlikely that the breach will result in a risk to the rights and freedoms of natural persons.
Where the breach poses a risk to the rights and freedoms of natural persons, we will also notify the Irish Data Protection Commission (as our lead supervisory authority) without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
d) Subprocessors
We work with third-party service providers to deliver, support and improve the Services and our technical infrastructure. We enter into a written contract with each subprocessor that imposes data-protection obligations no less protective than those set out in this Policy. The complete and up-to-date list of subprocessors is published at https://trust.happyscribe.com, where customers may also subscribe to receive email notifications of changes. The contractual mechanics governing notice of subprocessor changes, the right to object, emergency replacements and excluded changes (such as intra-group reorganisations, name changes and successor entities by merger) are set out in our Data Processing Agreement.
e) International Data Transfer
Where Content data is transferred to subprocessors located outside the EEA, the same safeguards described in Section I.d apply (Standard Contractual Clauses, the EU-US Data Privacy Framework, or another valid Chapter V transfer mechanism).
f) Retention, Return and Deletion of Content; Machine-Learning Training
Default rule. Upon termination or expiration of the relationship between us (whether due to closure of your account or your express request), we will return or destroy all Content you have provided us in connection with the Services, except where applicable regulations require us to retain it. Files you delete from your account are retained for 10 days as a precautionary measure to allow recovery, and are then permanently deleted.
Machine-learning training. Machine-learning training is opt-in and separate from your use of the Services — you can use HappyScribe in full without opting in. Where you opt in at signup, your consent (Article 6(1)(a) GDPR) lets us use your Content, and license or share it with our partners and other third parties, to develop and train machine-learning models — whether ours or theirs. We de-identify your Content before any such use or sharing, require recipients to keep it de-identified, and will not re-identify it except where the law requires. You can withdraw consent at any time from your account settings or by emailing dataprotection@happyscribe.com; withdrawal applies going forward and cannot unwind Content already de-identified.
We do not retroactively change the basis on which Content provided before the Effective Date was collected; that Content continues to be handled under its original terms, and you can object or change how it is used at any time from your account settings.
g) Professional secrecy/confidentiality
We are bound by professional secrecy with respect to any personal data to which we have access due to our provision of Services to the Controller. This obligation will continue even after the relationship between the parties has ended, thus constituting an indefinite obligation.
You, as the data controller, represent and warrant that the personal data included in the content has been collected in accordance with applicable laws, and that the disclosure of such personal data to us for the purposes mentioned herein is compliant with applicable laws.
h) Data Subject Rights (Content)
If we receive a request from a data subject in respect of Content (for example, an access, rectification or erasure request from a meeting participant whose voice has been recorded), we will let you know without undue delay and assist you in responding to that request, in line with our obligations as a Processor under Article 28 GDPR.
III. INTEGRATIONS AND THIRD-PARTY SHARING
You can connect HappyScribe to third-party services to extend how you work with your Content. Connections may either bring data into HappyScribe — for example, a calendar integration that lets you select scheduled meetings for the Meeting Notetaker to join — or send data out, for example forwarding a transcription or meeting summary to a chat assistant, your CRM or a communication tool. In either direction, a connection only occurs when you initiate it by enabling the integration and authorising it from your account. Outbound data sharing only takes place when you take an in-product action that requires data to flow to the third party; we do not transfer personal data to integrated services unless you have actively triggered that flow.
Each integrated service is operated by its provider under that provider's own terms and privacy policy, and we encourage you to review those policies before enabling any integration. We are not responsible for the privacy practices of third-party services you choose to connect.
a) Lawful basis
- For data about you and your workspace (Identity and Workspace Data) we share with an integrated service in response to your in-product action, the lawful basis is the performance of our contract with you and our legitimate interest in providing the integration you requested.
- For Calendar Data that we receive from your calendar provider through the Calendar Integration you have authorised, we act as Processor on your documented instructions as data controller: we use Calendar Data to operate the integration you enabled (for example, to surface meetings the Meeting Notetaker can join) and not for any other purpose. As the controller of that data you are responsible for ensuring you have a lawful basis to share participant calendar metadata with HappyScribe.
- For data within your Content (Content Data, Meeting Data and People Data — see below), we share on your documented instructions as data controller, in accordance with Section II of this Policy.
b) Categories of personal data that may be shared, depending on the integration
- Identity and Workspace Data: your organisation's name, your name, email address, and role within the organisation.
- Content Data: transcription text, speaker names, timestamps and associated file metadata.
- Calendar Data (only when you connect a calendar via the Calendar Integration): scheduled event names, dates, times, participant email addresses, organiser information, and meeting URLs. HappyScribe receives Calendar Data from your calendar provider through the integration you have authorised and uses it to present you with the meetings the Meeting Notetaker can be configured to join. We do not modify your calendar.
- Meeting Data (only when you use the Meeting Notetaker service): the meetings the Meeting Notetaker has joined or recorded, the recording status of those meetings, the meeting URL the Notetaker was instructed to join, and attendance information for participants present in those recordings.
- People Data: names, email addresses, job titles, company affiliations, and (where extracted by you) public profile links of individuals identified in your transcriptions.
- Subtitle and Caption Data: subtitle files and associated metadata.
c) Categories of third-party services you can connect
Inbound integrations — data flowing into HappyScribe:
- Calendar providers (e.g., Google Calendar, Microsoft Outlook / 365) — when you connect a calendar via the Calendar Integration. HappyScribe reads scheduled event metadata so that you can select which meetings the Meeting Notetaker should join. The Calendar Integration is independent of the Meeting Notetaker: you can connect a calendar without enabling the Notetaker, and you can use the Notetaker without connecting a calendar (by providing a meeting URL manually). We do not modify your calendar.
Outbound integrations — data flowing from HappyScribe to a third party at your request:
- AI assistants and large-language-model providers (e.g., OpenAI, Anthropic) — to power AI assistant features inside HappyScribe and to enable connectors you have installed (such as the HappyScribe app for ChatGPT). Data sent to these providers under our enterprise-tier API agreements is not used by them to train their models, as confirmed by each provider's published API policy.
- Video platforms (e.g., YouTube, Vimeo) — when you export subtitles or transcriptions.
- CRM platforms (e.g., HubSpot) — when you connect a CRM integration to synchronise meeting outcomes, people and companies.
- Communication platforms (e.g., Slack) — when you connect a communication integration to share notes or summaries with your team.
The current list of integrated services, the data categories each one sends or receives, and their processing locations is maintained at https://trust.happyscribe.com.
d) Your control
You can connect or disconnect integrations at any time from your account settings. Disconnecting an integration stops future data flows to that service but does not retrieve data already shared. To delete data already shared, contact the third-party service in accordance with its own privacy policy; we will assist you on request (see Section II.h).
e) International transfers via integrations
Some integrated services are operated outside the EEA. The same safeguards described in Sections I.d and II.e apply (Standard Contractual Clauses, EU-US Data Privacy Framework, or another valid Chapter V mechanism), and the relevant transfer mechanism for each provider is identified at https://trust.happyscribe.com.
IV. ADDITIONAL INFORMATION
Third Party Material
We always endeavour to deal with vendors and other third parties who are GDPR compliant or, in the case of the third parties located outside of the EEA, who have adequate security measures in place to safeguard the security of personal data. We comply with all the GDPR requirements when engaging with those third parties. That said, we, our employees and agents accept no liability however arising for the content or reliability of any third-party materials or websites referenced by hyperlink or other means on the Site or for the data collection and use practices or security measures used by such third parties. If you submit personal data to any of those sites, your personal data is governed by their privacy policy. We encourage you to carefully read their privacy policies.
Changes To This Privacy Policy
We may update this Policy from time to time. Any changes will be posted on the Website with an updated effective date, and we will notify you of material changes by email or by a notice in your account. Continued use of the Services after an update constitutes your acknowledgement of the updated Policy.
Change of Purpose
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us at dataprotection@happyscribe.com. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Effective Date of this Policy: 8 June 2026
Contact us
If you have any questions or complaints relating to this Policy, please contact us at:
HappyScribe, The Black Church, Saint Mary's Place North, Dublin 7
Supervisory Authority
We are committed to complying with the terms of the GDPR and to the processing of personal data in a fair, lawful and transparent manner. If, however, you believe that we have not complied with our obligations under the GDPR, you have the right to lodge a complaint with the Data Protection Commission in Ireland (https://www.dataprotection.ie), as our lead supervisory authority.
Governing Law
This Policy is governed by Irish law. If you are a business customer, the courts of Ireland have exclusive jurisdiction. If you are a consumer, nothing in this clause deprives you of the protection of the mandatory jurisdiction rules of your country of habitual residence: you may bring proceedings in your local courts, and your mandatory statutory consumer rights in that country are not affected.