Privacy Policy

INTRODUCTION

About Us

Happy Scribe Limited ("HappyScribe") is a private company limited by shares incorporated in Ireland with company number 604917 and having a registered office at The Black Church, Saint Mary's Place North, Dublin 7 ("we"/"us"/"our"). We provide transcription, subtitling, translation and meeting-notetaking services to our customers (the "Services") through our online platform at https://www.happyscribe.com (the "Website").

About this Privacy Policy

Data protection refers to the safeguarding of personal data, as defined by the General Data Protection Regulation ("GDPR"), which encompasses any information pertaining to an identified or identifiable natural person. An identifiable natural person is someone who can be directly or indirectly identified, particularly through an identifier such as a name, identification number, or other specific attributes. This Privacy Policy (the "Policy") outlines crucial information about your rights concerning the processing of your personal data for the purpose of using the website. It also specifies the basis on which any personal data we collect from you.

In compliance with data protection regulations, your personal data will:

We take our responsibilities seriously with regard to the processing of personal data. Please note that our Website may contain links to third-party websites. If you follow a link to any of those third-party websites, please note that they have their own privacy policies and that we do not accept any responsibility or liability for their policies or processing of your personal information. Please check these policies before you submit any personal information to such third-party websites.

The Website is not aimed at children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are under 16, please do not use our Services or provide any information to us through the Website.

This Policy should be read alongside, and in addition to, our Website Terms of Use, which can be found at: https://www.happyscribe.com/terms.

I. USERS PERSONAL DATA

a) Identity and contact information of the Data Controller

Unless we specify otherwise (see section II below) or unless we have entered into a different agreement with you, we will be what's known under the GDPR as the "controller" of the personal data you provide to us.

b) Personal information we may process about you

We collect and process the following data about you for the following purposes:

Personal data you give to us in order to use our services: We collect data about you that you provide to us by registering or filling in forms on our website, or by corresponding with us by phone, email, or other means. This includes the data collected:

In particular, we process the following information:

We collect this information to improve the content and navigation of our Website. To collect this information, we use cookies, which are stored on your browser in accordance with your cookie settings. For more information about cookies and how we use them, please refer to our Cookies Policy at: https://www.happyscribe.com/cookies_policy

Personal Data Why are personal data processed? Period for which data will be stored Legal basis for processing
Identity Data 1) To register you as a new customer. 2) To provide you with secure access to the platform. 3) Surveys and review We will store your identity data until you delete your account, plus any statutory retention period that applies. 1) Performance of a contract with you. 2) Necessary for our legitimate interests (to respond to new or existing customer queries and grow our business).
Identity Data Financial Data We collect this information to prepare the customer invoices. Statutory tax/accounting retention period (typically 6–10 years depending on jurisdiction) from the date of the relevant transaction. 1) Performance of a contract with you. 2) Compliance with legal obligations (tax / accounting).
Identity Data Technical Data To manage our relationship with you, including notifying you about changes to the Services, or our Privacy Policy. We will store your personal data until you delete your account. We may share your identity data with third parties to help store your account information. 1) Performance of a contract. 2) Necessary to comply with a legal obligation. 3) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products and Services).
Identity Data Technical Data To provide you with information about services we offer that are similar to those that you have enquired about. We will store your personal data until you delete your account. Necessary for our legitimate interests (to develop our products or Services and grow our business).
Identity Data Technical Data Where you have given us your consent to do so, to provide you with information about other services we feel may interest you. We will store your personal data until you withdraw the consent you have given us to send you information. Consent.
Identity Data Technical Data To ensure that content is presented in the most effective manner for you and for your computer or device. We will store your personal data until you delete your account. Necessary for our legitimate interests (to keep our Site and the Services updated and relevant and to develop and grow our business).
Identity Data Technical Data To administer and protect our business, our Site and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes. We will store your personal data until you delete your account, plus logs for up to 24 months for security purposes. Necessary for our legitimate interests (for running our business and as part of our efforts to keep our Site and the Services safe and secure).
Technical Data To use data analytics to improve or optimize our Site, marketing, customer relationships and experiences. We will store your personal data until you delete your account. Necessary for our legitimate interests (to define types of customers for our products and services, to keep our Site and the Services updated and relevant, to develop and grow our business and inform our marketing strategy).
Identity Data Content Data To train and improve machine-learning models only where you have opted in to this use at signup and only for as long as you remain opted in (see Section II.f). Until you withdraw consent. Where Content used in prior training has been de-identified so that it no longer relates to an identifiable person, that processing cannot be unwound (see Section II.f). Consent (Article 6(1)(a) GDPR). Freely given, separately collected at signup, withdrawable at any time without affecting any other Services and without affecting the lawfulness of processing carried out before withdrawal.

HappyScribe does not actively collect special category ("sensitive") data as part of the Services. If you choose to share sensitive data with us, it is retained for as long as necessary to fulfil the purposes for which you provided it and is subject to the same security measures as all other personal data.

Data that is received from third parties. We will receive personal data about you from third parties such as:

*Users that choose to upload files using the YouTube upload integration are agreeing to be bound by the YouTube Terms of Service (https://www.youtube.com/t/terms), which are related to the Google Privacy Policy (http://www.google.com/policies/privacy).

For the full and up-to-date list of subprocessors we use to deliver the Services, please refer to our Trust Center at https://trust.happyscribe.com, which we update whenever subprocessors are added or replaced.

c) We will disclose your personal information to third party recipients

Any third parties to whom we disclose your personal data are required to respect the security of your personal data and process it in accordance with applicable data protection laws.

d) International Transfers

Where we transfer your personal data to service providers whose servers are located outside the European Economic Area ("EEA"), we do so on the basis of one or more of the following safeguards required by Chapter V of the GDPR: (i) the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914); (ii) where applicable, the recipient's certification under the EU–US Data Privacy Framework; or (iii) any other valid transfer mechanism permitted by Articles 45 or 46 of the GDPR.

For more information about this and the safeguards in place relating to the transfer, please contact us by email at dataprotection@happyscribe.com

e) Keeping Data Secure

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

HappyScribe operates a SOC 2 Type II security programme, independently audited against the AICPA Trust Services Criteria (Security). The current SOC 2 Type II report is available under non-disclosure agreement on request through our Trust Center at https://trust.happyscribe.com, where you can also find an up-to-date summary of our technical and organisational measures and our subprocessor list.

Further information about our technical and organisational measures is available at https://www.happyscribe.com/security and https://trust.happyscribe.com.

f) Your Rights

As a data subject, you have the following rights under the GDPR. To exercise any of these rights, please email dataprotection@happyscribe.com. We will respond within one month and will only charge a fee or refuse a request if it is manifestly unfounded, repetitive or excessive.

The rights described in this section are personal rights and are exercisable only by the individual person (or data subject) concerned.

g) Marketing Communications

General.

We will process your personal data to send you marketing communications regarding products or similar services to those initially contracted, on the basis of our legitimate interest.

Your right to object.

You have the right to object to the processing of your personal data for our marketing communications by contacting us at dataprotection@happyscribe.com. You may also opt out of receiving marketing communications at any time by selecting the unsubscribe option when you receive an electronic marketing communication from us.

h) How Long We Keep Your Information:

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. This means that the period of time for which we store your personal data may depend on the type of data we hold. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. For more information about our data retention policies please contact us at dataprotection@happyscribe.com.

i) If You Fail To Provide Personal Data.

Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with our Services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.

We store the data for the duration of the contract term and, if applicable, for the duration of statutory retention periods. We will delete your account upon your request after the cancellation of the account, subject to those statutory retention periods.

II. CONTENT DATA

In order for us to provide you with our Services you will share with us texts, audio or video files. You can do this in three principal ways:

We will use these texts, audio and video files and recordings (together, the "Content") to provide transcription, subtitling, translation, note-taking and meeting summaries.

Such Content may include personal data — including, in the case of audio and video, the voice and image of identifiable individuals. You, as the person uploading the Content or initiating a recording, are the data controller of that personal data, and you are responsible for obtaining any consents required and complying with any applicable information duties before that personal data is shared with us.

In particular:

Regardless of how the Content reaches us, our obligations as Processor with respect to the personal data it contains are the same and are set out below.

We process personal data included in the Content acting as what's known under the GDPR as the "Processor" and while doing so we will comply with the following obligations:

a) Data Processing

We will only process the personal data in your Content to provide the Services, on your documented instructions, and not for our own purposes (including statistical purposes). The one exception is machine-learning training: where you have opted in, we use your Content to improve our models, as described in Section II.f. Because that training is our own purpose and rests on your consent rather than your instructions, for that activity we act as controller rather than as your processor.

We will only grant access to personal data in the Content to those employees and/or third parties necessary for providing the Services to you. Our employees and contractors are trained in data protection, are bound by confidentiality, and only access Content as required to provide the Services (including troubleshooting, supporting users and quality assurance). Access for any other purpose is restricted to data that has been de-identified.

b) Security Measures

We adopt the technical and organisational measures necessary to ensure the security, confidentiality and integrity of the personal data in the Content and to prevent its alteration, loss, unauthorised processing or access, taking into account the state of technology, the nature of the data and the risks to which it is exposed. These measures form part of our SOC 2 Type II security programme described in Section I.e, which applies to the processing of Content as well as to other personal data we hold.

c) Notification of Incidents/Security Breaches

In the event of a security incident — destruction, loss, modification, accidental disclosure, unauthorised or illegal access to personal data — we will notify you, as Controller, without undue delay, together with all relevant information for documentation and communication of the incident. Notification is not required when it is unlikely that the breach will result in a risk to the rights and freedoms of natural persons.

Where the breach poses a risk to the rights and freedoms of natural persons, we will also notify the Irish Data Protection Commission (as our lead supervisory authority) without undue delay and, where feasible, within 72 hours of becoming aware of the breach.

d) Subprocessors

We work with third-party service providers to deliver, support and improve the Services and our technical infrastructure. We enter into a written contract with each subprocessor that imposes data-protection obligations no less protective than those set out in this Policy. The complete and up-to-date list of subprocessors is published at https://trust.happyscribe.com, where customers may also subscribe to receive email notifications of changes. The contractual mechanics governing notice of subprocessor changes, the right to object, emergency replacements and excluded changes (such as intra-group reorganisations, name changes and successor entities by merger) are set out in our Data Processing Agreement.

e) International Data Transfer

Where Content data is transferred to subprocessors located outside the EEA, the same safeguards described in Section I.d apply (Standard Contractual Clauses, the EU-US Data Privacy Framework, or another valid Chapter V transfer mechanism).

f) Retention, Return and Deletion of Content; Machine-Learning Training

Default rule. Upon termination or expiration of the relationship between us (whether due to closure of your account or your express request), we will return or destroy all Content you have provided us in connection with the Services, except where applicable regulations require us to retain it. Files you delete from your account are retained for 10 days as a precautionary measure to allow recovery, and are then permanently deleted.

Machine-learning training. Machine-learning training is opt-in and separate from your use of the Services — you can use HappyScribe in full without opting in. Where you opt in at signup, your consent (Article 6(1)(a) GDPR) lets us use your Content, and license or share it with our partners and other third parties, to develop and train machine-learning models — whether ours or theirs. We de-identify your Content before any such use or sharing, require recipients to keep it de-identified, and will not re-identify it except where the law requires. You can withdraw consent at any time from your account settings or by emailing dataprotection@happyscribe.com; withdrawal applies going forward and cannot unwind Content already de-identified.

We do not retroactively change the basis on which Content provided before the Effective Date was collected; that Content continues to be handled under its original terms, and you can object or change how it is used at any time from your account settings.

g) Professional secrecy/confidentiality

We are bound by professional secrecy with respect to any personal data to which we have access due to our provision of Services to the Controller. This obligation will continue even after the relationship between the parties has ended, thus constituting an indefinite obligation.

You, as the data controller, represent and warrant that the personal data included in the content has been collected in accordance with applicable laws, and that the disclosure of such personal data to us for the purposes mentioned herein is compliant with applicable laws.

h) Data Subject Rights (Content)

If we receive a request from a data subject in respect of Content (for example, an access, rectification or erasure request from a meeting participant whose voice has been recorded), we will let you know without undue delay and assist you in responding to that request, in line with our obligations as a Processor under Article 28 GDPR.

III. INTEGRATIONS AND THIRD-PARTY SHARING

You can connect HappyScribe to third-party services to extend how you work with your Content. Connections may either bring data into HappyScribe — for example, a calendar integration that lets you select scheduled meetings for the Meeting Notetaker to join — or send data out, for example forwarding a transcription or meeting summary to a chat assistant, your CRM or a communication tool. In either direction, a connection only occurs when you initiate it by enabling the integration and authorising it from your account. Outbound data sharing only takes place when you take an in-product action that requires data to flow to the third party; we do not transfer personal data to integrated services unless you have actively triggered that flow.

Each integrated service is operated by its provider under that provider's own terms and privacy policy, and we encourage you to review those policies before enabling any integration. We are not responsible for the privacy practices of third-party services you choose to connect.

a) Lawful basis

b) Categories of personal data that may be shared, depending on the integration

c) Categories of third-party services you can connect

Inbound integrations — data flowing into HappyScribe:

Outbound integrations — data flowing from HappyScribe to a third party at your request:

The current list of integrated services, the data categories each one sends or receives, and their processing locations is maintained at https://trust.happyscribe.com.

d) Your control

You can connect or disconnect integrations at any time from your account settings. Disconnecting an integration stops future data flows to that service but does not retrieve data already shared. To delete data already shared, contact the third-party service in accordance with its own privacy policy; we will assist you on request (see Section II.h).

e) International transfers via integrations

Some integrated services are operated outside the EEA. The same safeguards described in Sections I.d and II.e apply (Standard Contractual Clauses, EU-US Data Privacy Framework, or another valid Chapter V mechanism), and the relevant transfer mechanism for each provider is identified at https://trust.happyscribe.com.

IV. ADDITIONAL INFORMATION

Third Party Material

We always endeavour to deal with vendors and other third parties who are GDPR compliant or, in the case of the third parties located outside of the EEA, who have adequate security measures in place to safeguard the security of personal data. We comply with all the GDPR requirements when engaging with those third parties. That said, we, our employees and agents accept no liability however arising for the content or reliability of any third-party materials or websites referenced by hyperlink or other means on the Site or for the data collection and use practices or security measures used by such third parties. If you submit personal data to any of those sites, your personal data is governed by their privacy policy. We encourage you to carefully read their privacy policies.

Changes To This Privacy Policy

We may update this Policy from time to time. Any changes will be posted on the Website with an updated effective date, and we will notify you of material changes by email or by a notice in your account. Continued use of the Services after an update constitutes your acknowledgement of the updated Policy.

Change of Purpose

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us at dataprotection@happyscribe.com. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

Effective Date of this Policy: 8 June 2026

Contact us

If you have any questions or complaints relating to this Policy, please contact us at:

HappyScribe, The Black Church, Saint Mary's Place North, Dublin 7

Email: dataprotection@happyscribe.com

Supervisory Authority

We are committed to complying with the terms of the GDPR and to the processing of personal data in a fair, lawful and transparent manner. If, however, you believe that we have not complied with our obligations under the GDPR, you have the right to lodge a complaint with the Data Protection Commission in Ireland (https://www.dataprotection.ie), as our lead supervisory authority.

Governing Law

This Policy is governed by Irish law. If you are a business customer, the courts of Ireland have exclusive jurisdiction. If you are a consumer, nothing in this clause deprives you of the protection of the mandatory jurisdiction rules of your country of habitual residence: you may bring proceedings in your local courts, and your mandatory statutory consumer rights in that country are not affected.