Privacy Overview
NoteWave is developed and operated by Blaze AI Solutions (Pty) Ltd ("Blaze AI Solutions", "we", "us", or "our"). For purposes of South Africa's Protection of Personal Information Act, 2013 ("POPIA"), we act as the responsible party for the personal information we process in connection with the Service, except where we process information strictly on behalf of another responsible party.
This Privacy Policy explains how we collect, use, store, share, retain, and protect information when you use NoteWave's AI-powered meeting transcription, summarisation, collaboration, recording, integration, and mobile app services.
We are a South African company and handle personal information in accordance with POPIA and, where applicable, the GDPR, CCPA/CPRA, consumer protection laws, electronic communications laws, and other privacy regulations that apply to your use of the Service.
By using NoteWave, you confirm that you are at least 18 years old. If you are under 18, you may not use the Service.
Privacy rights
Your Privacy Rights
Depending on your location and applicable law, you may have some or all of the following rights:
- Access: request a copy of personal information we hold about you.
- Correction: ask us to correct inaccurate, outdated, or incomplete information.
- Deletion: ask us to delete personal information, subject to legal, billing, fraud-prevention, backup, and operational retention requirements.
- Objection or restriction: object to or restrict certain processing activities, including direct marketing.
- Consent withdrawal: withdraw consent where processing is based on consent. This does not affect lawful processing that occurred before withdrawal.
- Portability: receive certain information in a structured, commonly used, machine-readable format where applicable law provides this right.
- Complaint: lodge a complaint with the Information Regulator or another competent supervisory authority.
To exercise these rights, contact us at contact@blazesolutions.ai. We will respond within the timeframes required by applicable law and may need to verify your identity before acting on a request.
Data We Collect
3.1 Account and profile information
- Name, email address, contact details, profile preferences, and account settings.
- Authentication data, including OAuth profile information from providers such as Google, Apple, or Microsoft. Passwords are hashed where password login is used.
- Billing and subscription information. Web billing is handled by our payment processors, Paystack (South African Rand billing) and Lemon Squeezy (international billing), while mobile purchases are handled through the Apple App Store or Google Play with subscription entitlement support. Card details are entered on and stored by the payment processor; we never store full card numbers.
3.2 Meeting, audio, and customer content
- Audio recordings uploaded, captured, or processed through the Service.
- Meeting titles, dates, durations, source platform, participants, and related metadata.
- Generated transcripts, summaries, action items, speaker labels, AI insights, and exports.
- User edits, annotations, comments, sharing settings, folders, and workspace activity.
- Meeting platform integration data from services you connect, including Zoom, Microsoft Teams, Google Meet, calendar events, recording links, webhook events, OAuth tokens, and processing status.
- Speaker identification and diarisation data, including short speaker-verification snippets.
3.3 Technical, analytics, and device information
- Device type, operating system, browser version, app platform, and diagnostic data.
- IP address, approximate location, referral source, page views, and usage analytics.
- Feature usage, performance data, error logs, crash reports, and security logs.
- Cookies, local storage, pixels, SDKs, conversion measurement, and similar technologies described in our Cookie Policy.
3.4 Communication and support data
- Support requests, emails, feedback, surveys, and user research responses.
- Marketing communication preferences and engagement with service messages.
- Team invitations, transcript sharing, workspace collaboration, and notification activity.
3.5 Participant data
Meeting content may include the voices, names, job titles, opinions, personal information, and other data of meeting participants. You are responsible for ensuring that you have a lawful basis and any required notices or consents before recording, uploading, sharing, or enabling us to process that content.
How We Use Your Data
We process personal information on lawful bases that may include contract performance, legitimate interests, legal obligations, consent where required, and protection of our rights, users, and systems.
4.1 Providing the Service
- Transcribe audio and video recordings and provide real-time transcription where available.
- Create AI-generated summaries, action items, speaker labels, insights, and chat responses.
- Store, organise, search, share, export, and manage transcripts and workspace content.
- Support Zoom, Microsoft Teams, Google Meet, calendar, upload, mobile, and live recording workflows.
- Manage accounts, subscriptions, entitlements, teams, permissions, and billing status.
4.2 Operations, security, and compliance
- Provide customer support, service notices, security alerts, and administrative messages.
- Detect, prevent, and investigate fraud, abuse, unauthorised access, policy violations, and security incidents.
- Improve reliability, diagnose bugs, measure service performance, and plan product improvements.
- Comply with legal obligations and respond to valid legal requests.
4.3 AI processing
To provide transcription, summarisation, AI chat, speaker identification, and related functionality, meeting content may be processed by third-party AI service providers acting as processors or service providers. We use these providers to deliver the Service, not to sell your meeting content or target advertising to meeting participants.
NoteWave's policy is that customer meeting content should not be used to train unrelated, general-purpose AI models for other customers. We support this through provider account settings, data processing terms, access controls, and vendor review processes where available. Providers, contracts, and technical controls may change over time, and we will update this Policy when material changes affect how your content is processed.
We may use aggregated, de-identified, or anonymised usage information internally to improve service reliability, understand feature adoption, and prioritise product development.
Data minimisation
Data Security and Protection
We use reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration, disclosure, or destruction.
- Encryption: encryption in transit and at rest where supported by our infrastructure providers.
- Access controls: authentication, session handling, role-based access controls, and restricted administrative access where applicable.
- Infrastructure safeguards: we use established hosting, storage, and database providers that maintain recognised security programmes and certifications.
- Monitoring and backups: diagnostic logging, operational monitoring, and provider-managed backups where available.
No system is perfectly secure. We cannot guarantee absolute security, and your own account practices, device security, meeting-sharing choices, and connected third-party platforms also affect the security of your information.
Security Compromises and Breach Notification
If we become aware of a security compromise involving personal information, we will investigate, take reasonable containment and remediation steps, and notify affected data subjects, the Information Regulator, or other competent authorities where required by POPIA or other applicable law.
- We will provide notice as soon as reasonably possible where required by law.
- We will describe the nature of the compromise, likely consequences, and practical steps affected users can take where appropriate.
- We may delay direct notice only where law enforcement, regulatory guidance, or applicable law permits or requires delay.
Data Retention
We retain information only for as long as reasonably necessary for service delivery, user control, operational reliability, legal compliance, billing, tax, dispute resolution, fraud prevention, and security.
- Account data: retained while your account is active and then deleted or anonymised within a reasonable period after account deletion, except where retention is legally or operationally required.
- Main meeting audio: retained for playback, recovery, and processing for the retention period associated with your plan or settings. Current default windows are Free: 7 days, Pro: 14 days, and Business/Enterprise: 30 days, after which main audio may be expired or deleted.
- Speaker-verification snippets: small snippets used for speaker identification may be retained for up to 120 days unless deleted earlier as part of account, meeting, or operational cleanup.
- Transcripts, summaries, and workspace content: retained until you delete them, close your account, or the content is removed under our retention and account policies.
- Analytics and diagnostic data: retained for a reasonable period and aggregated, anonymised, or deleted where practicable.
- Legal, tax, billing, and financial records: retained for periods required by applicable law, including South African record-keeping obligations.
You can request deletion of your personal information through the Service or by emailing contact@blazesolutions.ai. We may retain limited records where required for legal, billing, security, fraud-prevention, backup, or dispute-resolution purposes.
Children's Privacy
NoteWave is not intended for people under 18, and we do not knowingly offer the Service directly to children. If meeting content includes a child or another vulnerable person, the user who records or uploads that content is responsible for ensuring a lawful basis, required notices, and required consent.
If we learn that personal information relating to a child has been collected or processed in a way that requires action under applicable law, we will take appropriate steps to address it.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Service, technology, vendors, integrations, law, or business operations.
- We will update the "Last updated" date when this Policy changes.
- Where a material change adversely affects your rights, we will provide reasonable notice through email, the Service, or another appropriate channel.
- Your continued use of the Service after the effective date means you accept the updated Policy.
Additional Information for International Users
12.1 South African residents
Under POPIA, you may request access to or correction of personal information, object to certain processing, request deletion where permitted, opt out of direct marketing, and complain to the Information Regulator.
12.2 EU/EEA and UK residents
Where GDPR applies, you may have rights of access, correction, deletion, portability, objection, restriction, withdrawal of consent, and complaint to a supervisory authority. Our legal bases may include contract necessity, legitimate interests, legal obligations, and consent where required.
12.3 California residents
Where CCPA/CPRA applies, California consumers may have rights to know, access, delete, correct, and opt out of certain sharing or sale. NoteWave does not sell personal information for monetary value. To submit a request, email us with "CCPA Request" in the subject line.
Contact Our Privacy Team
Blaze AI Solutions (Pty) Ltd
Privacy and Information Officer requests: contact@blazesolutions.ai
For privacy inquiries, POPIA requests, data subject access requests, PAIA requests, or subprocessor information requests, include the request type in your subject line. Our PAIA manual and company address details can be requested through the same contact channel until published in a dedicated public format.
Information Regulator
By creating an account or using NoteWave, you acknowledge that you have read this Privacy Policy and our Terms of Service.