Segua.ai

Privacy and data processing

What Segua.ai collects, where it goes, who sees it and for how long.

In short

Segua.ai records meetings, transcribes them and turns the transcript into project documentation.

Audio is never stored: it is used only to produce the transcript and then discarded.

Transcripts are kept for 30 days by default (users can change this in Settings) and then deleted automatically. Generated documents stay until you delete them.

Before any text is sent to the AI model, personal names, emails, phone numbers, IBANs, links and the customer name are replaced with stable pseudonyms (e.g. Persona_1, Cliente_1). The mapping never leaves our database and real names are restored in the final document.

For AI calls we keep technical metadata only (timestamp, model, size and a cryptographic hash of the input): never the content.

Meeting recording

Participants' voices are personal data. Before every recording Segua.ai asks for an explicit confirmation that everyone present has been informed and that a lawful basis exists.

That confirmation is stored with date, time and the user who started the recording, and is visible in the activity log.

The meeting organiser is the data controller towards their participants; Segua.ai acts as processor on their behalf.

Who can see the data

Only the project owner. Every row is protected at database level by rules matching the reader's identity against the project owner: no other account can read someone else's projects, meetings or documents.

No commercial or advertising access to content. No profiling.

AI providers and retention

Transcripts and text sent to AI models are not used to train models: the commercial terms of the providers used exclude training on API inputs and outputs.

Inputs and outputs are retained by the provider for up to 30 days and then deleted.

Zero Data Retention agreements can be arranged directly with the model provider for customers who require them; some models are excluded from such agreements and keep a mandatory 30-day retention. Official provider documentation must be checked before making contractual commitments.

Sub-processors

AI model provider: turns the pseudonymised transcript into minutes, requirements and the other documents. Inputs and outputs are not used for training and are retained by the provider for up to 30 days.

Transcription provider: converts meeting audio into text. Audio is streamed for transcription and never stored by us.

Recall.ai, meeting bot: joins the meeting, records it, and the recording is deleted from Recall.ai right after transcription.

Retention with the bot provider, recordings on Recall.ai: deleted immediately after transcription, at most 24 hours. If a deletion does not go through at the first attempt it is retried automatically, and the meeting shows a "Recording cleanup pending" note until it succeeds.

Where the data lives

Projects, transcripts and documents are stored on managed infrastructure, encrypted in transit and at rest.

AI processing may take place outside the European Union. EU-region model routing is available on request for customers with data residency requirements.

Security

Sign-in with passwords checked against public breach databases, anonymous sign-ups disabled, and optional two-step verification with an authenticator app.

Every view, download, export and deletion of documents and transcripts is written to an activity log the user can inspect.

Cookies and staying signed in

Segua.ai uses only strictly necessary first-party cookies. There are no advertising or third-party tracking cookies, so no cookie banner is required.

Visits to our public pages are measured with cookieless statistics: pages opened, buttons clicked, referrer, campaign tag, approximate country, device type, browser and time on page. The identifier that links the steps of one visit exists only in the memory of the open tab, is never stored in cookies or local storage, and is lost as soon as the tab is closed, so the same person cannot be recognised on a later visit. No IP address is stored, no profile is built and no visitor is identified. Legal basis: legitimate interest in understanding how the site is used.

When you tick "Keep me signed in on this device" at sign-in, we store a cookie with that choice and with your email address, so the next visit already recognises you. It lasts up to one year and contains no password.

If you leave the box unticked, the sign-in is dropped as soon as you close the browser and you will be asked to sign in again.

Your session itself is kept in the browser's local storage together with the sign-in token needed to keep you authenticated. Signing out, or clearing your browser data, removes both the cookies and the session immediately.

Who is responsible for what

Segua.ai is a service of Atherya Srl ("we"). For our own account and billing data we act as data controller. For everything you upload, record or import into a project we act only as processor: you, or your organisation, are the controller and decide the purposes and the lawful basis.

That means you are responsible for informing meeting participants, for holding a valid lawful basis, for the accuracy and lawfulness of the material you bring in, and for answering the requests of the people it concerns. We support you with export, deletion and person-erasure tools, but we cannot assess the lawfulness of your processing on your behalf.

We do not review, moderate or verify the content you upload or generate, and we have no obligation to do so.

What we collect as controller, and why

Account data (name, email, password hash, two-step verification setting): to create and secure your account. Legal basis: performance of the contract.

Billing data: handled by our payment provider, Stripe, which is a separate controller for payment, tax and invoicing data. We receive only the subscription status and plan.

Technical and usage data (timestamps, device and browser information, IP address, feature usage, AI call metadata and input hashes, never content): to run, secure and improve the Service and to prevent fraud and abuse. Legal basis: legitimate interest and legal obligation.

Support messages: to answer you. Legal basis: contract and legitimate interest.

We do not sell personal data, do not profile you for advertising, and do not use your content to train AI models.

Who we share data with

Service providers acting for us: hosting and database, AI model providers, transcription, and support tooling. They act on our instructions under written agreements, and are listed on the Legal page.

Stripe, as payment provider, for the sale, subscription management, payments, tax compliance and invoicing.

Professional advisers (legal, accounting) and authorities where we are legally required to disclose.

Optional connectors (Microsoft, Google, Slack, Jira, Azure DevOps, GitHub) only if you authorise them with your own account, under their own terms and privacy notices, for which we are not responsible.

AI output is not a statement of fact

Everything the Service generates is produced by artificial intelligence and can be wrong, incomplete or invented, including names, numbers, dates, standards references and technical statements. It is a draft to be checked, never a verified record.

Scores, ratings, competitive assessments, estimates, budgets and schedules are indicative outputs, not valuations, audits or professional advice.

You must review the output before using it, sharing it or acting on it. To the extent permitted by law we accept no liability for decisions taken on the basis of generated content. This is set out in full in the Terms of Service.

We perform no emotion or attitude inference about people, in line with Art. 5 of Regulation (EU) 2024/1689, and every export is labelled as AI-generated.

International transfers

Some providers, in particular AI model providers, process data outside the EU/EEA, mainly in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where the provider is certified, with text pseudonymised before it is sent.

If you need EU-only processing, tell us before signing: generation can be routed to European infrastructure.

Retention

Audio is never stored. Transcripts follow the retention you set (7, 30, 90 days or no expiry). Generated documents stay until you delete them. Account and billing records are kept as long as required by tax and accounting law. Security and access logs are kept for up to 12 months.

When data is no longer needed it is deleted or anonymised. After account closure data is removed within 30 days and backups are overwritten within 35 days.

Your rights

You can export all your data as a single file at any time, delete individual meetings, transcripts and documents, or request full account deletion.

Where the GDPR applies you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time without affecting prior processing. We reply within one month.

If the data belongs to a project run by another organisation, address your request to that organisation as controller; we will forward it.

You may lodge a complaint with your local supervisory authority. To exercise your rights, or for any data protection enquiry, write to support@segua.ai and we will reply within one month.

Security and its limits

We apply appropriate technical and organisational measures: encryption in transit and at rest, database-level project isolation, role-based access, optional two-step verification, leaked-password checks, server-side-only API keys and append-only access logs.

No online service can be guaranteed absolutely secure. We do not warrant that the Service will be uninterrupted or free of vulnerabilities, and our liability for security incidents is limited as set out in the Terms of Service.

Segua.ai is a service of Atherya Srl. Informational document; have it reviewed by your legal counsel before attaching it to a contract or tender.