Legal

Privacy Policy

How NoteWave handles account data, meeting content, AI processing, analytics, integrations, retention, and privacy requests.

Updated

July 2, 2026

01

Privacy Overview

NoteWave is developed and operated by Blaze AI Solutions (Pty) Ltd ("Blaze AI Solutions", "we", "us", or "our"). For purposes of South Africa's Protection of Personal Information Act, 2013 ("POPIA"), we act as the responsible party for the personal information we process in connection with the Service, except where we process information strictly on behalf of another responsible party.

This Privacy Policy explains how we collect, use, store, share, retain, and protect information when you use NoteWave's AI-powered meeting transcription, summarisation, collaboration, recording, integration, and mobile app services.

We are a South African company and handle personal information in accordance with POPIA and, where applicable, the GDPR, CCPA/CPRA, consumer protection laws, electronic communications laws, and other privacy regulations that apply to your use of the Service.

By using NoteWave, you confirm that you are at least 18 years old. If you are under 18, you may not use the Service.

Privacy rights

You may have rights to access, correct, delete, object to, or restrict the processing of your personal information, depending on the laws that apply to you.
02

Your Privacy Rights

Depending on your location and applicable law, you may have some or all of the following rights:

  • Access: request a copy of personal information we hold about you.
  • Correction: ask us to correct inaccurate, outdated, or incomplete information.
  • Deletion: ask us to delete personal information, subject to legal, billing, fraud-prevention, backup, and operational retention requirements.
  • Objection or restriction: object to or restrict certain processing activities, including direct marketing.
  • Consent withdrawal: withdraw consent where processing is based on consent. This does not affect lawful processing that occurred before withdrawal.
  • Portability: receive certain information in a structured, commonly used, machine-readable format where applicable law provides this right.
  • Complaint: lodge a complaint with the Information Regulator or another competent supervisory authority.

To exercise these rights, contact us at contact@blazesolutions.ai. We will respond within the timeframes required by applicable law and may need to verify your identity before acting on a request.

03

Data We Collect

3.1 Account and profile information

  • Name, email address, contact details, profile preferences, and account settings.
  • Authentication data, including OAuth profile information from providers such as Google, Apple, or Microsoft. Passwords are hashed where password login is used.
  • Billing and subscription information. Web billing is handled by our payment processors, Paystack (South African Rand billing) and Lemon Squeezy (international billing), while mobile purchases are handled through the Apple App Store or Google Play with subscription entitlement support. Card details are entered on and stored by the payment processor; we never store full card numbers.

3.2 Meeting, audio, and customer content

  • Audio recordings uploaded, captured, or processed through the Service.
  • Meeting titles, dates, durations, source platform, participants, and related metadata.
  • Generated transcripts, summaries, action items, speaker labels, AI insights, and exports.
  • User edits, annotations, comments, sharing settings, folders, and workspace activity.
  • Meeting platform integration data from services you connect, including Zoom, Microsoft Teams, Google Meet, calendar events, recording links, webhook events, OAuth tokens, and processing status.
  • Speaker identification and diarisation data, including short speaker-verification snippets.

3.3 Technical, analytics, and device information

  • Device type, operating system, browser version, app platform, and diagnostic data.
  • IP address, approximate location, referral source, page views, and usage analytics.
  • Feature usage, performance data, error logs, crash reports, and security logs.
  • Cookies, local storage, pixels, SDKs, conversion measurement, and similar technologies described in our Cookie Policy.

3.4 Communication and support data

  • Support requests, emails, feedback, surveys, and user research responses.
  • Marketing communication preferences and engagement with service messages.
  • Team invitations, transcript sharing, workspace collaboration, and notification activity.

3.5 Participant data

Meeting content may include the voices, names, job titles, opinions, personal information, and other data of meeting participants. You are responsible for ensuring that you have a lawful basis and any required notices or consents before recording, uploading, sharing, or enabling us to process that content.

04

How We Use Your Data

We process personal information on lawful bases that may include contract performance, legitimate interests, legal obligations, consent where required, and protection of our rights, users, and systems.

4.1 Providing the Service

  • Transcribe audio and video recordings and provide real-time transcription where available.
  • Create AI-generated summaries, action items, speaker labels, insights, and chat responses.
  • Store, organise, search, share, export, and manage transcripts and workspace content.
  • Support Zoom, Microsoft Teams, Google Meet, calendar, upload, mobile, and live recording workflows.
  • Manage accounts, subscriptions, entitlements, teams, permissions, and billing status.

4.2 Operations, security, and compliance

  • Provide customer support, service notices, security alerts, and administrative messages.
  • Detect, prevent, and investigate fraud, abuse, unauthorised access, policy violations, and security incidents.
  • Improve reliability, diagnose bugs, measure service performance, and plan product improvements.
  • Comply with legal obligations and respond to valid legal requests.

4.3 AI processing

To provide transcription, summarisation, AI chat, speaker identification, and related functionality, meeting content may be processed by third-party AI service providers acting as processors or service providers. We use these providers to deliver the Service, not to sell your meeting content or target advertising to meeting participants.

NoteWave's policy is that customer meeting content should not be used to train unrelated, general-purpose AI models for other customers. We support this through provider account settings, data processing terms, access controls, and vendor review processes where available. Providers, contracts, and technical controls may change over time, and we will update this Policy when material changes affect how your content is processed.

We may use aggregated, de-identified, or anonymised usage information internally to improve service reliability, understand feature adoption, and prioritise product development.

Data minimisation

If you need a stricter processing arrangement for sensitive workflows, contact us before uploading the content. Some AI-powered features may not be available without third-party AI processing.
05

Data Security and Protection

We use reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration, disclosure, or destruction.

  • Encryption: encryption in transit and at rest where supported by our infrastructure providers.
  • Access controls: authentication, session handling, role-based access controls, and restricted administrative access where applicable.
  • Infrastructure safeguards: we use established hosting, storage, and database providers that maintain recognised security programmes and certifications.
  • Monitoring and backups: diagnostic logging, operational monitoring, and provider-managed backups where available.

No system is perfectly secure. We cannot guarantee absolute security, and your own account practices, device security, meeting-sharing choices, and connected third-party platforms also affect the security of your information.

06

Data Sharing and International Transfers

We do not sell your data

NoteWave does not sell, rent, or trade your personal information or meeting content to third parties for their marketing or advertising purposes.

We share personal information only in limited circumstances:

  • Service providers: categories include cloud hosting, storage, database, authentication, backend infrastructure, AI transcription and summarisation, analytics, email delivery, payment processing, app-store billing support, customer support, security, and operational tooling.
  • Connected integrations: where you connect or use meeting platforms such as Zoom, Microsoft Teams, Google Meet, Google Calendar, or similar services, we exchange information needed to provide that integration.
  • Team and sharing features: where you invite team members, share transcripts, or use collaborative workspaces, relevant content and metadata are shared with the recipients you choose.
  • Legal and safety reasons: we may disclose information to comply with law, court orders, lawful requests, fraud prevention, security investigations, or to protect rights, safety, and property.
  • Business transfers: information may transfer in connection with a merger, acquisition, restructuring, financing, insolvency, or sale of assets, subject to appropriate notice where required.
  • With consent: we may share information for another purpose with your consent.

We may process information in countries outside South Africa, including through providers based in or supporting operations from the United States, European Union, United Kingdom, or other jurisdictions. Where required by POPIA, GDPR, or other applicable law, we rely on contractual, organisational, and technical safeguards for cross-border transfers.

We do not publish a detailed architecture list in this Policy. Relevant service-provider or subprocessor information can be requested at contact@blazesolutions.ai where appropriate.

07

Security Compromises and Breach Notification

If we become aware of a security compromise involving personal information, we will investigate, take reasonable containment and remediation steps, and notify affected data subjects, the Information Regulator, or other competent authorities where required by POPIA or other applicable law.

  • We will provide notice as soon as reasonably possible where required by law.
  • We will describe the nature of the compromise, likely consequences, and practical steps affected users can take where appropriate.
  • We may delay direct notice only where law enforcement, regulatory guidance, or applicable law permits or requires delay.
08

Data Retention

We retain information only for as long as reasonably necessary for service delivery, user control, operational reliability, legal compliance, billing, tax, dispute resolution, fraud prevention, and security.

  • Account data: retained while your account is active and then deleted or anonymised within a reasonable period after account deletion, except where retention is legally or operationally required.
  • Main meeting audio: retained for playback, recovery, and processing for the retention period associated with your plan or settings. Current default windows are Free: 7 days, Pro: 14 days, and Business/Enterprise: 30 days, after which main audio may be expired or deleted.
  • Speaker-verification snippets: small snippets used for speaker identification may be retained for up to 120 days unless deleted earlier as part of account, meeting, or operational cleanup.
  • Transcripts, summaries, and workspace content: retained until you delete them, close your account, or the content is removed under our retention and account policies.
  • Analytics and diagnostic data: retained for a reasonable period and aggregated, anonymised, or deleted where practicable.
  • Legal, tax, billing, and financial records: retained for periods required by applicable law, including South African record-keeping obligations.

You can request deletion of your personal information through the Service or by emailing contact@blazesolutions.ai. We may retain limited records where required for legal, billing, security, fraud-prevention, backup, or dispute-resolution purposes.

09

Cookies and Similar Technologies

We use cookies, local storage, pixels, SDKs, and similar technologies for authentication, security, preferences, diagnostics, analytics, performance measurement, and advertising conversion measurement. See our Cookie Policy for details.

  • Essential technologies: login sessions, authentication, security, fraud prevention, app state, and core service functionality.
  • Preference technologies: remembered choices such as theme, layout, notifications, and browser/app preferences.
  • Analytics and measurement: privacy-focused web analytics, referral attribution, conversion measurement, performance insights, and feature usage.

You can control many cookies through browser settings. Some essential technologies are required for the Service to function, and browser controls may not block all local storage, pixels, or SDK behaviour.

10

Children's Privacy

NoteWave is not intended for people under 18, and we do not knowingly offer the Service directly to children. If meeting content includes a child or another vulnerable person, the user who records or uploads that content is responsible for ensuring a lawful basis, required notices, and required consent.

If we learn that personal information relating to a child has been collected or processed in a way that requires action under applicable law, we will take appropriate steps to address it.

11

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Service, technology, vendors, integrations, law, or business operations.

  • We will update the "Last updated" date when this Policy changes.
  • Where a material change adversely affects your rights, we will provide reasonable notice through email, the Service, or another appropriate channel.
  • Your continued use of the Service after the effective date means you accept the updated Policy.
12

Additional Information for International Users

12.1 South African residents

Under POPIA, you may request access to or correction of personal information, object to certain processing, request deletion where permitted, opt out of direct marketing, and complain to the Information Regulator.

12.2 EU/EEA and UK residents

Where GDPR applies, you may have rights of access, correction, deletion, portability, objection, restriction, withdrawal of consent, and complaint to a supervisory authority. Our legal bases may include contract necessity, legitimate interests, legal obligations, and consent where required.

12.3 California residents

Where CCPA/CPRA applies, California consumers may have rights to know, access, delete, correct, and opt out of certain sharing or sale. NoteWave does not sell personal information for monetary value. To submit a request, email us with "CCPA Request" in the subject line.

13

Contact Our Privacy Team

Blaze AI Solutions (Pty) Ltd

Privacy and Information Officer requests: contact@blazesolutions.ai

For privacy inquiries, POPIA requests, data subject access requests, PAIA requests, or subprocessor information requests, include the request type in your subject line. Our PAIA manual and company address details can be requested through the same contact channel until published in a dedicated public format.

Information Regulator

South African data subjects may contact the Information Regulator at enquiries@inforegulator.org.za, 010 023 5200, or via the regulator's official eServices and complaints channels.

By creating an account or using NoteWave, you acknowledge that you have read this Privacy Policy and our Terms of Service.