Back to ClosePeak
Security

Security
and data location

This page states where your data lives, who has access to it, how long it stays, and what we do not claim to do. It states only what is actually enforced.

Last updated: September 2026 · Version 1.6

Database: Ireland
Audio and processing: North America

Where your data lives

Our data does not all live in the same place, and saying otherwise would be false:

  • The database, which holds your account, your calls and your analyses, is hosted in the European Union, in Ireland.
  • Audio recordings and call processing are hosted in North America, with our host.
  • File storage stays in the same region as compute at that host: the audio therefore follows the processing, not the database.

Who has access

Eight service providers are involved in the service, in the roles below. The detail of who receives your data is set out in the Privacy Policy, which is where it belongs.

Call transcription
Post-call analysis
Suggestions during a live call
Database hosting
Service and recording hosting
Payment
Anti-bot verification on the access forms
Email delivery (team invitations, error reports)

In an Agency team, the admin account sees, for each member, their name, email address, date of joining, the copilot hours used in the current cycle and their monthly limit, as well as the report of the calls made since joining the team. It sees a call's transcript, and the prospect's exact words, only if the member shares that call with it; no other member has access to it.

Company documents uploaded by the admin account are never kept as files: only their text is kept. A brief drawn from that text is sent to the analysis provider with every analyzed call from a team account, and a short version to the live suggestions provider during every live call. Only the admin account sees the documents and the brief.

Our transcription provider keeps the audio sent to it only for as long as needed to transcribe it, and does not use it to improve its speech recognition models. This is what the consent text you accept before any transcription states.

For how long

The periods below are the ones the product enforces automatically, and there are no others:

Audio recordings
24 hours at most, and deleted as soon as transcription completes.
Transcripts
6 months, then automatic deletion. You can delete them sooner by deleting the call.
Calls whose processing definitively failed
Deleted 24 hours after the failure is established.
Browsing on public pages
13 months, then automatic deletion.
Team invitations not accepted
Deleted 30 days after they expire, which is itself 7 days after they were sent.
Data of a canceled team
Company documents, team brief, criteria and team offer analysis: deleted 30 days after a canceled Agency subscription ends.
Deleted account
Deleting the account erases the personal data that is not subject to a legal retention obligation. The necessary accounting records are kept for the applicable legal period.
The full detail, category by category, lives in the Data Retention Policy.

How access is protected

Three guarantees, in place in the product today:

  • Your session cannot be read by the code running in the page.
  • Your browser never accesses the database directly.
  • Your recordings are reachable only through a temporary link.

Your contact's consent

Before any transcription, the server requires an attestation: you declare that you have informed your contacts the call is being transcribed, and obtained their agreement. Until that attestation is given, the server refuses.

That refusal covers the three routes through which a call enters the product: uploading a recording, pasting a transcript by hand, and running a live call from the extension. None can be taken without an attestation.

The text you accept is written and served by the server, never copied into the page or the extension: this is what guarantees that the attested text is the one you were shown. You remain responsible for your contacts' data.

Your rights

Export all your data

Open 'Settings', the 'My data' section, then 'Export my data'. The JSON file you get contains all of your personal data, and the download is immediate.

Delete your account

Open 'Settings', the 'Danger zone' section, then 'Delete my account'. Confirmation is done by typing a keyword. There is no cooling-off period, no bin, and no way to restore. Deleting the account erases the personal data that is not subject to a legal retention obligation. The necessary accounting records are kept for the applicable legal period.

For any other request relating to your data: privacy@closepeak.io

What we do not claim

A security page that lists only its strengths teaches nothing. Here is what we do not have:

  • We hold no security certification, neither ISO 27001 nor SOC 2.
  • No external security audit has been carried out on this product.
  • No penetration test has been carried out on this product.
  • We run no vulnerability disclosure programme.
ClosePeak is a young product, published by a small company. These will come if they become necessary; announcing them before having them would protect nobody.

Reporting a security issue

If you find a security issue on ClosePeak, write to us. We run no bounty programme, but every report is read and handled.

ORBIS ML, Data Protection Team
Email: privacy@closepeak.io
Privacy Policy · Data Retention Policy · Legal Notice

© 2026 ORBIS ML · ClosePeak·Legal Notice·Privacy Policy·Terms of Service·Back to app