Privacy Policy

Last Updated: 27 July 2026

I. GENERAL

  • Respect for your privacy and the management, protection and security of your personal data are a priority for 100mentors Single Member PC (“100mentors”, “we”, “us”, “our”, and our subsidiaries or affiliates), a private company, registered in Greece, whose registered office is situated at Pl. Kornarou 31, Heraklion Crete, (email: support@wiserwork.ai). This Privacy Policy ("Privacy Policy") informs you, as visitors/ users to the website wiserwork.ai (“Website”), and web application (‘’Web App’’), (together, the “Platform” or ‘’wiserwork.ai’’ ), or in any other capacity using the services or products offered on the Platform (Services) or participating in promotional or other activities by the Company regarding its services, or using social media channels of the Platform or otherwise, ("you"):
  • of the types of users registered in the Platform,
  • of the types of data it collects or produces for you,
  • of the purpose of collecting and processing your data,
  • about how these data are processed,
  • about their recipients and the purpose for which they are processed,
  • about your personal data when you create, join, participate in, or otherwise interact with meetings processed through the Platform (including meeting recordings and meeting-related outputs),
  • about the security, transfer and retention of your data,
  • about your rights and choices on your personal data,
  • about how to contact us concerning any matter you may be concerned about in relation to your personal data.

This Policy does not apply to websites or services or practices of companies that 100mentors doesn’t own or control, such as third-party services you might access through links, integrations, or other features on the Platform. These other services have their own privacy policies and we encourage you to review them before providing them with personal information.

  • CHANGES IN PRIVACY POLICY

We may modify or replace all or / or part of this Policy at our sole discretion. If there are substantial changes to this Policy or our practices regarding your data change in the future, we will notify you by publishing the changes to our Platform. However, if you wish any clarification or information regarding the changes, or you wish to raise a dispute, a reservation or a question about such changes, you may contact us through e-mail at support@wiserwork.ai. Please note that any information/clarification provided to you in connection with any changes to this Policy does not constitute a replacement, substitution or modification of this Policy. In any case, we recommend that you review this Privacy Policy from time to time, taking advantage of the ability to always find it as a permanent information point on our Platform.

  • THE LEGAL FRAMEWORK

Our Privacy Policy is based on the terms used by the European legislator for the adoption of the General Data Protection Regulation (GDPR). Our data protection declaration should be legible and understandable for the general public, as well as our users. To ensure this, we would like to first explain the terminology used. In this Privacy Policy, we use, inter alia, the following terms:

‘’Personal data’’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

‘’Processing’’ means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

‘’Controller’’ means the competent authority which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

‘’Processor’’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;

‘’Recipient’’ means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not.

‘’Personal data breach’’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;

‘’Third party’’ is a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

‘’Consent’’ of the data subject is any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

​​“Customer Data” means any personal data processed by the Company on behalf of an Organization through the Services, including Meeting Data and related content.

Definitions used in this Privacy Policy have the meaning given to them under the GDPR.

4. By accessing or using the Platform or the Services, you acknowledge that you have been provided with access to this Privacy Policy and have had the opportunity to review it. When creating an account, you may be required to confirm through the Platform’s registration mechanism that you acknowledge having read this Privacy Policy. Your acknowledgment of this Privacy Policy does not constitute consent to any processing activity for which consent is required under applicable law. Where we rely on consent as the legal basis for a specific processing activity, including certain marketing communications or non-essential cookies, such consent will be requested separately through a specific, informed, and clearly distinguishable mechanism.

Your access to and use of the Platform and the Services are governed by our Terms & Conditions and Cookie Policy. If you do not wish your personal data to be processed as described in this Privacy Policy, you should not provide your personal data or use the relevant Services, without prejudice to your rights under applicable data protection law as described in Section IV below.

5. DATA CONTROLLER | ROLES OF PROCESSING

100mentors Single Member PC, a private company incorporated in Greece, with its registered office at Pl. Kornarou 31, Heraklion, Crete (“Wiserwork”, “we”, “us”), acts as a Data Controller for the personal data processed in connection with this Privacy Policy, except in the cases described below. Depending on how you use the Services, Wiserwork may act either as a Data Controller or as a Data Processor.

The Company acts as a Data Controller when processing personal data for its own business purposes, including but not limited to account registration and management, billing and subscription administration, customer support, product analytics, service improvement, and marketing communications.

Where you use the Services on behalf of or through an Organization (for example, as an employee, contractor, or collaborator of a customer of Wiserwork), the Organization acts as the Data Controller for meeting-related data and other Customer Data processed through the Platform. This includes, without limitation, meeting recordings, transcripts, summaries, action items, and related content generated through the Services.

In such cases, the Company acts as a Data Processor and processes personal data solely on behalf of and in accordance with the documented instructions of the relevant Organization. The Organization determines the purposes and means of such processing and is responsible for ensuring compliance with applicable data protection laws, including identifying an appropriate legal basis and, where required, obtaining consent from meeting participants.

Processing carried out by the Company in its role as a Data Processor is governed, where applicable, by a Data Processing Agreement (DPA) in accordance with Article 28 of the GDPR.

If your personal data is processed in the context of your relationship with one of our customers (Organization), the applicable privacy policy governing that processing may be the privacy policy of that Organization, and you are encouraged to review it for further information.

Where a separate agreement exists between the Company and an Organization (including a DPA or other commercial agreement), such agreement may take precedence over this Privacy Policy to the extent of any conflict, in accordance with applicable law.

Where you use the Services independently and not through an Organization or third-party customer, you have the role of the Organization and act as the data controller for any personal data contained in the content you create, upload, or process through the Services (including, without limitation, meeting-related data and other Customer Data processed through the Platform)

The Company acts as a data processor in relation to such content, processing it on your behalf and in accordance with your instructions. However, the Company acts as an independent data controller in relation to personal data necessary for the operation of the Services, including but not limited to account management, authentication, billing, security, compliance with legal obligations, and improvement of the Services.

We do not use Customer Data for our own independent purposes unless explicitly stated in this Privacy Policy or required by law.

6. HOW TO CONTACT US

If you have any questions or concerns not already addressed in this Privacy Policy, send us an email: support@wiserwork.ai.

II. REGISTERED USERS

  • How Users Access the Services

You may access and use the Services through one of the following methods:

(a) Self-serve free trial

You may register independently through our Website and start using the Services without requiring an invitation.

(b) Invitation following a demo or customer interaction

After a demo or customer request, we may send an invitation email to allow you to create an account and complete the same onboarding steps as the self‑serve flow.

(c) Invitation by an Organization

You may be invited by an Organization (e.g., by an Owner or Admin) to join the Platform and access the Services under that Organization’s account.

During onboarding, you may be required to provide personal and Organization-related information (such as your name, email address, role, and company details), and you may optionally connect third-party integrations (such as calendar services).

The method through which you access the Services may affect how your personal data is processed and who acts as the Data Controller, as further described in this Privacy Policy.

  • User Categories and Roles

“You” may fall into one of the following categories of users:

i. Organization Owner

The user who initiates and manages the use of the Platform on behalf of an Organization under a paid subscription. The Organization Owner is responsible for overall account administration, including subscription management, billing, and user management. An Organization may have more than one Owner.

ii. Standard User

A user who registers to the Platform either independently (e.g., through a self-serve free trial) or following an invitation sent by us or by an Organization. Where a Standard User joins the Platform on a free trial case [case II 1(a) ] may choose to be Organization Owner or one of the below roles.

Where a Standard User joins the Platform through an Organization, they may be assigned one of the following roles:

a. Organization Admin : A user appointed by the Organization Owner to manage the Platform within the Organization. Admins may manage users, teams, and settings, and may have access to Organization-level insights and data, as permitted by the Platform and the Organization’s internal policies.

b. Team Manager: A user invited by an Organization Owner or Admin to oversee one or more teams. Team Managers may manage team membership and have limited visibility into team-related data, depending on assigned permissions.

c. Team Member: A user invited to participate in the Platform as part of a team. Team Members may access and use the Services for meetings they are invited to and may interact with meeting-related outputs, subject to permissions and settings.

Access to functionality and personal data is governed by role-based permissions and Organization settings. Certain roles (such as Organization Owners and Admins) may have the ability to access, manage, export, restrict, and to manage User access within the Organization workspace, as supported by the current functionality of the Platform and in accordance with applicable law and the Organization’s internal policies. If you access the Services through an Organization account, your access to the Platform and associated data may be modified, restricted, or terminated by the Organization at any time.

iii. Guest Users / External Participants

A natural person who participates in a meeting without registering for an account on the Platform. Guest Users / External Participants may be identified by limited information such as name, email address, or meeting participation details. Depending on the meeting configuration and the inviter’s settings, they may receive access to certain meeting-related outputs (such as recap emails or post-meeting links). Personal data of Guest Users is processed solely for the purpose of enabling meeting functionality and delivering related outputs, and such processing is carried out under the responsibility of the meeting organizer or the Organization using the Services.

III. WHAT PERSONAL DATA WE COLLECT AND HOW | THE PURPOSE AND THE WAY OF PROCESS | THE RECIPIENTS | THE SECURITY, TRANSFER, RETENTION

The types of personal data we collect depend on how you interact with the Platform, the features you use, and whether you use the Services independently or through an Organization. We process personal data in accordance with the principles of data minimization and purpose limitation, ensuring that only data necessary for the specific purposes described in this Privacy Policy is collected and processed.

1. WHAT types of data we collect from you

We collect and process only the personal data that is necessary for the purposes described in this Privacy Policy. We collect the following personal data:

i. Identity, Registration, Profile and Service Configuration Data: personal data and account preferences that you provide when registering for, accessing, or using the Platform and the Services.

The personal data and account information requested from you depend on your signup path, account type, role, and whether you create a new Organization or join an existing Organization following an invitation. Such data may include your email address, password where you register using email and password, full name, role or job title, time zone, profile image where optionally provided, selected calendar provider, and service configuration information associated with your account, role, or Organization.

Account creation may take place either directly by you (e.g. via self-service registration using email and password), through third-party authentication providers (such as Google or Microsoft), or following an invitation sent by us or by an Organization you work for.

Where you register or sign in through Google or Microsoft, we may receive certain account information, such as your name, email address, and authentication identifier, as permitted by the relevant provider and your account settings. We do not receive or store the password used for your Google or Microsoft account.

In particular for each type of User:

If you are an Organization Owner, you are required to provide your email, a password where you use the email-and-password signup method, full name, your job role, the name of the Organization, the domain/industry of the Organization, the Organization size, and your time zone. Where these selections form part of the applicable onboarding flow, you may also be required to select a supported calendar platform and configure the Organization’s default transcription language. The default transcription language is stored as an Organization-level setting and may apply to meetings conducted within that Organization unless overridden for a particular meeting as described below. A team name may be requested where a team is created as part of the Organization onboarding process.

All the other fields, e.g. User photo and organization logo, are optional.

If you are invited to join an existing Organization as an Organization Admin or Standard User, your email address may already be pre-filled based on the invitation. You are required to provide your full name, role or job title, and time zone. A team name is requested only where you choose or are authorized to create a team. You may also be asked to select or connect a supported calendar provider, depending on the applicable onboarding flow and the Organization’s configuration. The Organization’s default transcription language may apply to your meetings. Where supported by the Services, you may select a different transcription language for meetings that you organize or manage. Organization information, such as the Organization name, industry, and size, may be inherited from the existing Organization account and need not be entered again by the invited user. Other fields, such as your profile image, are optional.

Where an invited user registers using email and password, a password is required. Where the user registers or signs in through a supported third-party authentication provider, the Company does not collect the password used with that provider.

Inviting other Users: As an Organization Owner or Organization Admin, you can invite other Users to join the Services by providing their email address. You represent and warrant that you have the legal right to share such personal data. We will collect and store the email you provide and treat it as personal data in accordance with this Privacy Policy.

Transcription Language Settings: The default transcription language selected during Organization setup is stored as an Organization-level service configuration. Where supported, individual users may override that default for meetings that they organize or manage. Such overrides may be stored in association with the relevant user and meeting in order to apply the selected transcription language and operate the transcription functionality. A user-level or per-meeting override does not modify the Organization’s default setting unless an authorized user expressly changes the Organization-level configuration.

ii. Contact Data: email address and any telephone number or other contact information that you voluntarily provide when contacting our customer support team, interacting with us through social media, when registering to the Platform as above or using its Services, or when contacting our customer support team, interacting with us through social media, or or consenting to receive commercial communications from our Company..

iii. Calendar & Meeting Metadata: calendar event information and meeting details to the extent you connect a supported calendar integration and enable the relevant service functionality. Such data may include event titles, event times, meeting links, organizer/host information, participant emails, and other calendar event details necessary to locate, prepare, and process meetings. We may also process your selected calendar provider and related integration status in order to configure and operate the relevant Services. For Organization accounts, the calendar provider may be configured at the Organization level. Each invited User may be required to connect and authorize their own calendar account through that provider. Calendar authorization and access are subject to the permissions granted by the relevant User and the settings of the applicable calendar provider and Organization.

Connection of a supported calendar integration is not mandatory for account registration but is required in order to access and use the core functionalities of the Services.

Where you connect a Google account, Wiserwork’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

iv. Integration and Connection Data

Where you or your Organization enable integrations such as webhooks or MCP connections, we may process information necessary to establish, operate, secure, and manage the relevant connection. This may include endpoint URLs, integration configuration, connection status, technical identifiers, authorization information, selected events, and related technical logs.

Where an MCP connection is enabled, Meeting Content made available to the connected client may include meeting information, transcripts, summaries, and action items, depending on the permissions granted and the functionality used.

Where webhooks are enabled, event notifications and related data may be transmitted to endpoints configured by the Organization. The data transmitted depends on the selected event and the applicable webhook configuration.

v. User Content and Services Use Information: Information associated with the Platform profile of an Organization Owner or Standard User who uses Platform Services under an account, or that is provided by a Guest / External Participant participating in a meeting. This may include text, files, images, audio, graphics, video, in-meeting messages, messaging content, meeting recordings (audio and/or video), transcriptions, summaries, action items, decisions, transcript edits, recommendations, responses to Users or feedback requests, as well as related context such as invitation details, meeting name, or meeting agenda. This category includes meeting-related data (“Meeting Data”), such as audio and/or video recordings, transcripts, meeting summaries, action items, decisions, and chat inputs and outputs generated or processed through the Services. Meeting Data is processed strictly to enable the functionality of the Services and in accordance with user and Organization instructions.

The Services may also generate descriptive analytics and metrics derived from the use of the Services and Meeting Data and associated with an Organization, team, meeting, or individual User, such as meeting counts, meeting duration, usage rates, efficiency or effectiveness indicators, action-item statistics, and related insights.

For transparency purposes, the Platform may provide visual indicators of recording where supported (e.g. presence of a meeting bot participant with recording status). However, such indicators may vary depending on the third-party conferencing platform and are not guaranteed to be visible to all participants at all times. Meeting Data is processed to provide core functionalities of the Services and may be processed on behalf of an Organization, as further described in this Privacy Policy. By participating in meetings where the Services are enabled, you acknowledge that such meetings may be recorded, transcribed, and processed, subject to the settings configured by the meeting organizer or the Organization.

vi. Activity Data and Other Data We May Collect Automatically: (When you access and interact with the Platform’s services, we may automatically collect specific information about these visits (log-in information, device information, network information, usage information, etc.). For example:

  • Login Information: We record information regarding your use of the Services, including your Internet Protocol (IP) address, the type of browser you use, frequency of access, pages viewed, number of clicks, and the page you visited before navigating to our Services.
  • Device Information: We collect information about the electronic computer or mobile device you use to access our Services, including hardware model, operating system, version, unique device identifiers, and mobile network information.
  • Network Information: We may gather details about your network, such as information related to devices, nodes, settings, connection speeds, and network and application performance.
  • Usage Information: We can collect data about the usage of our Services and certain tools, such as which pages on the Platform you have visited, how frequently tools are used, duration and quality of usage, test data, task configuration data, and central data.

vii. Data Collected by Cookies and Other Tracking Technologies: We may also collect cookies and other tracking technologies (such as browser cookies, pixels, beacons) to enhance your experience, allowing us to personalize our content based on your interests. These technologies can be utilized to gather and store activity data related to your use of the Platform's services, such as the pages you have visited, the videos and other content you have viewed, the search queries you have submitted, and the advertisements you have encountered. For more information, please refer to our Cookie Policy.

Please note that the types and amounts of personal data collected will vary depending on the type of the User, the signup path, the assigned role, the Organization’s configuration, and the features used on the Platform. We need certain types of personal data so that we can provide the Services to you. If you do not provide us with such data, identified as mandatory for the applicable registration or onboarding flow, or ask us to delete it, you may no longer be able to access or use our Services.

Special category personal data

We do not intentionally request special category personal data and we kindly request that you do not send or disclose such data (e.g. genetic data, biometric data, data revealing racial or ethnic origin, political opinions, sex life, sexual orientation, religion or other beliefs, health data, criminal background or trade union membership), unless strictly necessary. If such data is disclosed through User Content (e.g. meeting recordings or transcripts), we will process it only as necessary to provide the Services requested by authorized users and in accordance with applicable legal requirements.

2. HOW do we collect your Personal Data

2.1. We collect DIRECTLY FROM YOU the personal information and data described above, including registration and profile data, communications, calendar connection information that you authorize, and User Content that you provide when using the Services.

2.2. We collect AUTOMATICALLY certain data described above through technical means, including usage data, log data, device data, and cookie-related data.

2.3. We collect data from third parties including authentication providers (as described below) and calendar providers, as described above.

2.4. Authentication Providers

We use third-party authentication providers (such as Clerk, Google, and Microsoft) to enable account registration and login. When you choose to sign up or log in through these providers, we receive certain profile information (such as your name and email address) as permitted by your settings with those providers and process such data in accordance with this Privacy Policy. This category also includes data collected from third-party providers who offer their services on the Platform and are subject to their own privacy policies.

2.5 Invitations and Onboarding Flows

We may collect personal data through invitation-based onboarding flows in the following cases:

(a) Invitation following a demo or customer request

Following a demo or interaction with our Company, we may send an invitation email to allow you to create an account and complete onboarding. In such cases, we process your email address and any additional information you provide during the onboarding process.

(b) Invitation by an Organization

You may receive an invitation from an Organization administrator (e.g. Owner or Admin) to join the Platform. In such cases, we process your email address and any registration data you provide upon accepting the invitation.

(c) Invitation of third parties by Users

Where a User provides us with the email address of another individual in order to invite them to the Platform, the User represents and warrants that they have obtained prior authorization to share such personal data. The User shall be solely responsible for ensuring compliance with applicable data protection laws and shall indemnify 100mentors against any claims arising from unauthorized or unlawful invitations.

In such cases, the inviting User or Organization acts as the source of the personal data.

For clarity, the categories of personal data collected as described above correspond to the data types set out in Section 1 (i–vi), depending on the source and method of collection.

  • Personal Data from Children

The Services are intended for business/professional use and are not addressed to minors. We do not knowingly collect personal data from persons under the age of 18. If you believe that a minor has provided personal data to us, please contact us at support@wiserwork.ai.

  • HOW do we use your personal data

4.1. The primary purpose of processing your personal data is to provide, operate, and maintain the Services of the Platform, including functionalities related to meeting preparation, participation, recording, transcription, summarization, action item management, meeting insights, and collaboration features, as enabled by authorized users and configured settings. In particular, we use your personal data for the following purposes:

- To provide and deliver the Services and any User Content, including Customer Data (such as Meeting Data, recordings, transcripts, summaries, and action items), in accordance with your instructions or those of your Organization.

- To operate, maintain, and improve the Platform, including measuring performance, analyzing usage, developing new features, and enhancing functionality.

- To manage user accounts, onboarding processes, and access controls, including role-based permissions within Organizations.

- To store and apply the selected calendar provider, the Organization’s default transcription language, and any user-level or meeting-specific transcription language override, in order to configure and provide the relevant meeting transcription functionality.

- To associate a transcription language override with the relevant user and meeting where a user selects a different language for a meeting that they organize or manage.

-To establish, authenticate, operate, and manage integrations selected by you or your Organization, including calendar connections, webhooks, and MCP connections.

- To transmit data to external clients, services, or endpoints where you or your Organization have enabled and authorized the relevant integration.

- To generate and display Organization-, team-, meeting-, and User-level analytics and insights to authorized Users, in accordance with the Organization’s settings, permissions, and instructions.

- To communicate with you, including responding to requests, providing customer support, and sending service-related communications, updates, technical notices, and security alerts.

- To detect, prevent, and address fraud, unauthorized access, misuse of the Services, and to ensure the security and integrity of our systems.

- To comply with applicable legal obligations, regulatory requirements, and legal processes, including responding to requests from competent authorities.

- To complete corporate transactions, such as mergers, acquisitions, reorganizations, or transfers of assets, where personal data may be disclosed as part of such transactions in accordance with applicable law.

- To enforce our Terms and Conditions and other contractual rights, including investigating potential violations and protecting our legal interests.

- To satisfy and respond to requests for the exercise of data subject rights.

- To create aggregated and/or de-identified data, which no longer identifies any individual, for the purposes of analytics, research, product development, and service improvement. Such data may be used and shared in accordance with applicable law.

- To provide limited personalization of the Services, including improving user experience and delivering relevant content, where permitted by applicable law.

Where you use the Services as part of an Organization account, certain processing activities may be carried out on behalf of that Organization (acting as data controller), in accordance with its instructions and applicable agreements. Customer Data retained in a restricted archived state following the closure or deactivation of an Organization is processed only for the limited retention purposes described in Section 11 below.

Existence of automated decision-making

The Platform provides descriptive insights, recommendations, and AI-assisted outputs intended to support user decision-making. However, the Company does not carry out automated decision-making producing legal effects or similarly significant effects within the meaning of Article 22 GDPR.The availability of descriptive analytics or indicators does not mean that the Company makes employment, disciplinary, performance-management, or other similarly significant decisions concerning Users. Any decision made by an Organization using such information is made under the Organization’s responsibility as Data Controller.

4.2. AI Processing and Data Use Restrictions

We do not use your personal data, including Meeting Data (such as recordings, transcripts, summaries, or other User Content), to train or fine-tune artificial intelligence or machine learning models (whether our own or those of third-party providers), unless explicitly agreed otherwise by the Organization through a clear opt-in mechanism.

In addition, third-party service providers engaged for AI processing or transcription services are contractually bound to:

- process personal data solely for the purpose of providing the Services;

- not retain personal data for longer than necessary to perform such services;

- not use personal data to train, improve, or develop their own models;

- not use personal data for advertising or any unrelated purposes.

All such processing is carried out strictly under our instructions and subject to appropriate contractual, technical, and organizational safeguards, in accordance with applicable data protection laws. We do not use Meeting Data or Customer Data for profiling, behavioral advertising, or similar purposes.

5. Newsletter and Marketing Communications

If you subscribe to our newsletter or otherwise provide your email address through relevant forms on our Platform, we may process your email address in order to send you marketing communications, updates, and promotional content relating to our Services.

Where required by applicable law, such communications are sent based on your prior consent (Article 6(1)(a) GDPR and applicable ePrivacy rules).

If you are an existing user or customer of our Services, we may also send you communications relating to similar products or services, where permitted by applicable law, based on our legitimate interest (Article 6(1)(f) GDPR), provided that you are given the opportunity to opt out at the time of data collection and in each subsequent communication.

You may withdraw your consent or object to receiving marketing communications at any time by clicking the “unsubscribe” link included in each communication or by contacting us.

6. ON WHAT LEGAL BASIS do we use your personal data

We process your personal data only where we have a valid legal basis under applicable data protection laws (including the GDPR). The legal bases on which we rely are the following:

i. Performance of a contract (Article 6(1)(b) GDPR)

Processing is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract.

ii. Legitimate interests (Article 6(1)(f) GDPR)

Processing is necessary for the purposes of the legitimate interests pursued by the Company, except where such interests are overridden by your fundamental rights and freedoms.

iii. Compliance with legal obligations (Article 6(1)(c) GDPR)

Processing is necessary for compliance with legal obligations to which we are subject.

iv. Consent (Article 6(1)(a) GDPR)

Where required, we rely on your consent, which you may withdraw at any time.

Where you use the Services through an Organization account, certain processing activities may be carried out on behalf of the Organization acting as data controller, in accordance with its instructions and applicable agreements.

In particular:

Purpose of ProcessingData we process for this purposeLegal Basis
To provide, operate, and deliver the Services and Meeting Data (including recordings, transcripts, summaries, action items, and related outputs) through the Platform and integrated third-party providersIdentity - Registration and Profile DataUser Content and Services Use Information (including Meeting Data)Calendar & Meeting MetadataActivity Data and Other Data We Collect AutomaticallyData from third-party integrations(a) Performance of a contract(b) Legitimate interests (service functionality, improvement, security)(c) Compliance with legal obligations
Customer service, support, and user communications (including handling requests, complaints, and data subject rights)Identity - Registration and Profile DataContact DataUser Content and Services Use InformationInformation provided in communications(a) Performance of a contract(b) Legitimate interests (customer support)(c) Compliance with legal obligations(d) Consent (where applicable)
Security, fraud prevention, and platform integrityIdentity - Registration and Profile DataActivity Data and Other Data We Collect AutomaticallyTechnical and usage data(a) Legitimate interests (security, fraud prevention)(b) Compliance with legal obligations
Business analytics, product improvement, and service optimizationIdentity - Registration and Profile DataUser Content and Services Use Information (limited/aggregated where possible)Activity DataCookie-related data(a) Legitimate interests (service improvement)(b) Performance of a contract (where necessary)
Advertising, marketing, and user engagementIdentity - Registration and Profile DataContact DataActivity DataCookie-related data(a) Legitimate interests (direct marketing where permitted)(b) Consent (cookies, electronic communications,newsletter)
Aggregated and de-identified analytics and researchAggregated or anonymized data derived from all categories(a) Legitimate interests (analytics and research)
Corporate transactions and legal complianceAny categories of personal data as necessary(a) Compliance with legal obligations(b) Legitimate interests (business continuity)

Where processing is based on your consent, you have the right to withdraw such consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. You may exercise this right by contacting us at support@wiserwork.ai.

7. WHEN we act as Controller or Processor

As mentioned in Section I.5., depending on how you use the Services, the Company may act either as a data controller or as a data processor in relation to your personal data.

  • Data Controller

We act as a data controller in relation to personal data processed for our own business purposes, including:

- account registration, onboarding, and profile management;

- subscription management, billing, and payments;

- customer support and communications;

- service-related communications (including technical and security notifications);

- marketing communications and user engagement (where permitted by applicable law);

- product analytics, service improvement, and business operations;

- ensuring platform security, fraud prevention, and enforcement of our Terms and Conditions.

In these cases, we determine the purposes and means of processing your personal data in accordance with this Privacy Policy.

B. Data Processor (Services provided to Organizations)

Where you use the Services through, or in connection with, an Organization (for example, as an employee, collaborator, or invited user of a customer of the Company), we act as a data processor in relation to certain categories of Customer Data processed on behalf of that Organization.

In particular, we act as a data processor with respect to Meeting Data and related User Content processed through the Services, including:

- audio and/or video recordings of meetings;

- transcripts and speech-to-text outputs;

- summaries, action items, decisions, and insights;

- chat inputs and outputs and other in-meeting content;

- related metadata (such as meeting titles, participant identifiers, timestamps, and interaction data).

In such cases:

- the Organization acts as the data controller;

- we process personal data solely on the documented instructions of the Organization;

- access to and sharing of such data is determined by the Organization’s settings, permissions, and policies;

- Organization administrators (e.g. Owners or Admins) may access, manage, export, or restrict access to such data and manage User access, in accordance with their internal policies, applicable law, the functionality currently available through the Platform, and any verified requests submitted to the Company..

- Organization administrators may remove or deactivate a User’s access to the Organization workspace. Such removal or deactivation does not automatically delete the User’s overall account or Meeting Data associated with the Organization. Requests concerning the closure of an Organization or the return or permanent deletion of Customer Data are handled as described in Section 11 below.

This processing is governed by applicable data processing agreements (DPAs) entered into with the Organization, in accordance with Article 28 GDPR.

C. User Responsibilities in Organizational Context

Where you use the Services on behalf of, or within, an Organization, you acknowledge that:

- your Organization is responsible for determining the lawful basis for processing personal data (including Meeting Data);

- your Organization is responsible for ensuring compliance with applicable laws, including laws relating to recording, monitoring, and processing of communications;

- your Organization may control access to, and retention of, Meeting Data and related content.

The Organization and/or the meeting organizer is solely responsible for ensuring that any recording, transcription, or processing of communications is carried out in compliance with applicable laws, including obtaining any required consents or providing appropriate notices to participants.

D. External Participants (Guest Users)

Where you participate in a meeting as a Guest User / External Participant without registering for an account, your personal data (including any Meeting Data you contribute) is processed on behalf of the Organization or user that enabled the Services for that meeting.

In such cases:

- we act as a data processor;

- the relevant Organization or meeting host acts as the data controller;

- you should refer to the privacy policy of that Organization or host for further information on how your personal data is processed.

E. No Processing Outside Defined Roles

We do not process Meeting Data for our own independent purposes (such as marketing or AI model training), except where explicitly stated in this Privacy Policy or where data has been aggregated or de-identified so that it no longer relates to an identifiable individual.

8. How and Where We Share Your Personal Data

We may disclose personal data, where necessary and in accordance with this Privacy Policy, to the following categories of recipients:

  • Service Providers and Subprocessors

We may share personal data with third-party service providers that support the operation of the Platform and the provision of the Services, including providers of hosting, cloud infrastructure, authentication, calendar integration, AI and transcription services, customer support, analytics, communications, payment processing, and other information technology services. Such providers process personal data solely on our behalf, under our instructions, and only to the extent necessary to perform their services. We ensure that all such providers are bound by appropriate contractual safeguards, including confidentiality obligations and, where applicable, Standard Contractual Clauses.

A current list of our subprocessors, including their roles and locations, is available here: Subprocessors List. We may update our list of subprocessors from time to time. Where required by applicable law, we will provide notice of material changes.

  • Professional Advisers

We may disclose personal data to professional advisers, including lawyers, accountants, auditors, and consultants, where necessary for the purposes of legal compliance, financial reporting, audits, dispute resolution, or the establishment, exercise, or defense of legal claims.

  • Organizations and Administrative Users

When you use the Services through an Organization account, we may make personal data and Customer Data available to the Organization and its authorized administrators in accordance with their assigned roles, permissions, meeting participation, Organization settings, and applicable law. Depending on the functionality and permissions available through the Platform, this may include account and membership information, Meeting Data, and Organization-, team-, meeting-, and User-level analytics and insights, such as meeting counts, usage, duration, efficiency or effectiveness indicators, and action-item metrics. Access to Meeting Data is not automatically granted to all Organization administrators and may be limited by the relevant User’s role, meeting participation, and the Organization’s settings and policies. The Organization acts as Data Controller in relation to its access to and use of such Customer Data and analytics and is responsible for ensuring that such access and use comply with applicable law.

  • Meeting Participants and Sharing Recipients

Where the Services are used in connection with meetings, certain personal data and Meeting Data may be shared with meeting participants and recipients, including:

  • participants invited to or attending a meeting;
  • users with access to post-meeting pages, summaries, or shared links;
  • recipients of recap emails or shared outputs.

Such sharing is determined by meeting settings, user actions, and Organization policies. The Company does not control how meeting organizers or participants use or share such data outside the Platform.

  • External Participants (Guest Users)

When you participate in a meeting as a Guest User / External Participant, your personal data may be visible to other meeting participants and to the Organization that enabled the Services for that meeting, in accordance with meeting settings and applicable policies.

- User-Directed Integrations and External Recipients

Where you or your Organization enable an MCP connection, webhook, or other external integration, we may disclose or make available personal data and Customer Data to the third-party client, service, or endpoint selected and authorized by you or your Organization.

Such disclosure is made at your or the Organization’s direction. The relevant third party may process the data under its own terms and privacy policy, and you or your Organization are responsible for ensuring that the recipient is authorized and that the integration is configured and used lawfully.

Third-party services independently selected by a User or Organization are not necessarily our Subprocessors.

  • Affiliates

We may share personal data with our affiliated companies for purposes consistent with this Privacy Policy.

  • Business Transfers

In the event of a merger, acquisition, reorganization, sale of assets, or other corporate transaction, personal data may be disclosed to counterparties and transferred as part of such transaction, subject to appropriate safeguards.

  • Legal and Regulatory Authorities

We may disclose personal data to courts, regulatory authorities, law enforcement agencies, or other third parties where required by law, or where necessary to:

  • comply with legal obligations;
  • protect our rights, property, or safety;
  • prevent fraud or unlawful activity;
  • enforce our Terms and Conditions;
  • respond to legal claims or proceedings.
  • Social Media and Advertising Partners

Where permitted by applicable law, we may share limited personal data with social media platforms or advertising partners for marketing, analytics, or audience measurement purposes, subject to your preferences and applicable consent requirements. Where such sharing takes place, it is subject to applicable consent requirements, user preferences, and cookie settings, in accordance with applicable law.

  • With Your Consent

We may share your personal data with third parties where you have provided your explicit consent.

Aggregated and De-Identified Information

We may share aggregated or de-identified information that does not identify any individual, for purposes such as analytics, research, marketing, or demonstrating how the Platform is used.

We do not sell your personal data to third parties. All disclosures are made in accordance with applicable data protection laws and limited to what is necessary for the purposes described in this Privacy Policy.

9. International Data Transfers

As a general rule, we process and store personal data within the European Economic Area (“EEA”). However, in order to provide the Services, we may transfer personal data to third countries outside the EEA, including to countries that may not provide the same level of data protection as the EEA (such as the United States). These transfers may occur, for example, where we engage service providers, subprocessors, or infrastructure providers located outside the EEA, or where access to the Services involves international data flows. Where such transfers take place, we ensure that appropriate safeguards are implemented in accordance with applicable data protection laws, including the GDPR. In particular, we rely on one or more of the following mechanisms:

- Standard Contractual Clauses (SCCs) approved by the European Commission;

- transfers to countries that have been recognized by the European Commission as providing an adequate level of data protection;

- other lawful transfer mechanisms as may be available under applicable law.

We also implement appropriate technical and organizational measures to ensure that personal data remains protected in accordance with this Privacy Policy. We assess such transfers on a case-by-case basis to ensure an adequate level of protection for personal data. Where required by applicable law, you may request additional information regarding the safeguards applied to international data transfers by contacting us at support@wiserwork.ai.

10. Data Security

We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, taking into account the nature, scope, context, and purposes of processing, as well as the risks to individuals’ rights and freedoms. We also implement appropriate policies and procedures to ensure ongoing compliance with applicable data protection laws..Such measures include, where appropriate:

- encryption of data in transit;

- access control mechanisms to restrict access to personal data on a need-to-know basis;

- authentication and authorization procedures;

- monitoring and logging of system activity;

- contractual obligations imposed on third-party service providers and subprocessors to ensure the protection and confidentiality of personal data.

We require all third-party service providers and subprocessors to implement appropriate security safeguards and to process personal data only in accordance with our instructions and applicable data protection laws. Access to meeting-related data (including recordings, transcripts, and summaries) is restricted based on user roles, permissions, and meeting participation. In particular, meeting recordings and related content are only generated when the meeting bot is explicitly admitted into the meeting by an authorized participant. If recording is not permitted or is stopped by the meeting organizer or participants, no further recording or processing takes place. Please note that, while we apply appropriate safeguards to protect personal data, no method of transmission over the internet or method of electronic storage is completely secure. Therefore, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for ensuring that the devices, software, and communication networks you use to access the Services are adequately secured. Failure to do so may result in unauthorized access to your account or personal data. To the extent required by applicable law, we will notify the competent supervisory authority and affected individuals without undue delay in the event of a personal data breach. We maintain procedures for detecting, investigating, and responding to personal data breaches and security incidents. We regularly review and update our security measures to address evolving threats and technological developments.

11. Data Retention & Deletion

We retain personal data only for as long as necessary for the purposes for which it was collected or otherwise processed, including the provision of the Services, compliance with legal obligations, security, the resolution of disputes, the enforcement of agreements, and the establishment, exercise, or defence of legal claims. Retention periods depend on the type of data, the purposes of processing, the instructions of the relevant Organization, applicable contractual obligations, and applicable law.

Account and Profile Data

We generally retain account and profile data for as long as the relevant account remains active. Where an account is permanently deleted, the associated account and profile data will be deleted or, where appropriate, irreversibly anonymized, unless limited retention is required by applicable law or for security, fraud-prevention, accounting, tax, or legal-claims purposes. The removal, suspension, or deactivation of a User from an Organization terminates or restricts that User’s access to the relevant Organization workspace but does not automatically delete the User’s overall account or the Meeting Data associated with that Organization. Meeting Data created or processed within the Organization may remain under the control of the Organization.

Meeting Data and Customer Data

Meeting Data, including recordings, transcripts, summaries, action items, chat content, and related information, is retained while the relevant Organization remains active or as otherwise instructed by the Organization acting as Data Controller. Customer Data is processed by us on behalf of the relevant Organization and remains subject to the Organization’s instructions, the applicable Data Processing Agreement, and applicable data protection law.

Organization Closure and Restricted Retention

At present, automated self-service functionality for the closure or permanent deletion of an Organization is not available through the Platform. An authorized Organization Owner may request the closure of an Organization or the return or permanent deletion of its Customer Data by contacting us at support@wiserwork.ai. We may verify the identity and authority of the requester before processing the request. Where an Organization cancels its subscription or closes its account without requesting the immediate return or permanent deletion of its Customer Data, access to the Organization will be deactivated and the relevant Customer Data may be retained in a restricted archived state for up to twelve (12) months from the effective date of closure. During this restricted retention period, the Customer Data will not be available for the ordinary use of the Services and its processing will be limited to purposes reasonably necessary for account administration, support, data return or export, security, fraud prevention, legal compliance, dispute resolution, or the establishment, exercise, or defence of legal claims. An authorized Organization Owner may request the return or permanent deletion of Customer Data at any time during the restricted retention period. Unless earlier return or deletion is requested, the relevant Customer Data will be deleted or, where appropriate, irreversibly anonymized upon expiry of the twelve (12)-month period, subject to applicable law.

Permanent Deletion Requests

Where an authorized Organization Owner submits a verified request for permanent deletion, the twelve (12)-month restricted retention period will not apply to the Customer Data covered by that request. We will process the request within a reasonable technical period in accordance with the applicable Data Processing Agreement, the Organization’s documented instructions, and applicable law. Where requested and technically feasible, requests for the return or export of Customer Data may be handled through support before permanent deletion is completed.

Billing, Accounting and Tax Data

We may retain invoices, credit notes, payment and transaction records, subscription records, and other information necessary for tax, accounting, audit, or legal-compliance purposes for the period required by applicable law. Under applicable Greek accounting requirements, accounting records are generally retained for five (5) years from the end of the relevant period or for a longer period where required by other applicable legislation. The retention of billing, accounting, or tax data does not ordinarily require the continued retention of unrelated recordings, transcripts, summaries, action items, chat content, or other Meeting Data.

Invitation Data

Where personal data, such as an email address, is provided for invitation purposes, we may retain such data for a reasonable period to enable account creation, onboarding, invitation administration, and security, unless earlier deletion is requested or required by applicable law.

Aggregated and Anonymized Data

We may retain information that has been irreversibly anonymized and no longer identifies or can reasonably be linked to an individual or Organization. Such anonymized information may be retained and used for analytics, research, and service improvement.

Legal Obligations, Security and Disputes

Limited personal data may be retained for longer where required by applicable law or reasonably necessary for security, fraud prevention, regulatory compliance, the resolution of disputes, or the establishment, exercise, or defence of specific legal claims. Any such retention will be limited to the information necessary for the relevant purpose and will not ordinarily include Meeting Data unless specific Meeting Data is required by law or reasonably necessary in connection with an identified legal claim or dispute.

Backups

Deletion may not be immediate across all systems. Residual copies may remain temporarily in secure backup systems until they are overwritten or deleted in accordance with the applicable backup retention procedures. Data retained solely in backups will not be available for the ordinary use of the Services.

IV. YOUR PERSONAL DATA RIGHTS

1. With regard to your personal data we collect and process, you have the following rights under Regulation (EU) 2016/679 on personal data protection (“GDPR”), subject to applicable limitations:

Where we process personal data on behalf of an Organization acting as data controller, you should direct your request to the relevant Organization. We will assist the Organization in responding to such requests where required by applicable law. Where we act as a data processor, we may not be able to fulfill certain requests directly and may be required to redirect your request to the relevant Organization acting as data controller.

  • Right of confirmation. You have the right to obtain from us confirmation as to whether or not personal data concerning you are being processed.
  • Right of access. You have the right to obtain information about your personal data and, where applicable, a copy of such data. We may charge a reasonable fee or refuse requests that are manifestly unfounded or excessive, in accordance with applicable law.
  • Right to rectification. You have the right to obtain from us the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the ability to correct or complete any incomplete or inaccurate data we hold about you. Please note that you should provide accurate and up-to-date information and notify us of any changes. As a general rule, you must provide only your own personal data, unless otherwise permitted under this Privacy Policy.
  • Right to erasure (Right to be forgotten). You have the right to obtain from us the erasure of personal data concerning you where one of the following grounds applies:
    • your personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
    • you withdraw consent on which the processing is based and there is no other legal ground for processing;
    • you object to the processing pursuant to Article 21 GDPR and there are no overriding legitimate grounds;
    • the personal data have been unlawfully processed;
    • the personal data must be erased for compliance with a legal obligation;
    • the personal data have been collected in relation to the offer of information society services under Article 8(1) GDPR.
  • Right of restriction of processing. You have the right to obtain restriction of processing where one of the following applies:
    • the accuracy of the personal data is contested by you;
    • the processing is unlawful and you oppose erasure;
    • we no longer need the personal data but you require them for legal claims;
    • you have objected to processing pending verification of legitimate grounds.
  • Right to data portability. You have the right to receive the personal data concerning you in a structured, commonly used, and machine-readable format and to transmit those data to another controller, where processing is based on consent or contract and carried out by automated means.
  • Right to object. You have the right to object, on grounds relating to your particular situation, at any time, to processing of personal data based on Article 6(1)(e) or (f) GDPR. If we process personal data for direct marketing purposes, you have the right to object at any time to such processing. This right also applies to profiling based on those provisions.
  • Right not to be subject to automated decision-making. You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects, subject to the conditions set out in Article 22 GDPR. As described in this Privacy Policy, we do not carry out automated decision-making producing such effects.
  • Right to withdraw consent. Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
  • Right to lodge a complaint. You have the right to lodge a complaint with the competent supervisory authority. In Greece, this is the Hellenic Data Protection Authority (www.dpa.gr). You also have the right to seek a judicial remedy where you consider that your rights under applicable data protection laws have been infringed.

Please note that these rights are not absolute and may be subject to limitations under applicable law. In addition, certain rights may be restricted where personal data is processed as part of meeting-related content controlled by an Organization. We may request additional information to verify your identity before responding to your request. Where permitted by applicable law, we may refuse or limit requests that are manifestly unfounded, excessive, or repetitive.

2. If you wish to exercise any of your rights or have any complaints, you may contact us using the contact details provided in this Privacy Policy. We will respond to your request within one (1) month from receipt. This period may be extended by an additional two (2) months where necessary, taking into account the complexity and number of requests. We may request additional information to verify your identity before processing your request, in order to ensure that personal data is not disclosed to unauthorized persons. Where applicable, we may take reasonable steps to inform third parties processing your personal data of your request, in accordance with applicable law.

If you believe that your rights have been infringed, you may also file a complaint with the competent supervisory authority:

Hellenic Data Protection Authority (www.dpa.gr). Postal address: 1-3, Kifissias Avenue, PC 115 23, Athens. Call Center: +30 210 6475600. Fax: +30 210 6475628. E-mail: contact@dpa.gr

We do not sell your personal data and do not share personal data for cross-context behavioral advertising within the meaning of applicable laws.

3. Additional Rights for Certain Jurisdictions

If you are located outside the European Economic Area (EEA), please note that your rights may vary depending on the applicable data protection laws of your jurisdiction. In particular, residents of certain jurisdictions, such as the United States (including California), may have specific rights regarding their personal data under applicable laws. However, we apply the principles of the GDPR as a global standard for the protection of personal data and aim to provide all users with a consistent level of privacy protection, subject to applicable legal requirements. ​​Where required by applicable law, we will comply with additional local data protection requirements that may apply to you based on your location.

V. CONTACT

If you have any questions about this Privacy Policy or our data practices, you may contact us at support@wiserwork.ai.

We apply the principles of data protection by design and by default when developing and operating the Platform.