Where your data lives
Our data does not all live in the same place, and saying otherwise would be false:
- The database, which holds your account, your calls and your analyses, is hosted in the European Union, in Ireland.
- Audio recordings and call processing are hosted in North America, with our host.
- File storage stays in the same region as compute at that host: the audio therefore follows the processing, not the database.
Who has access
Eight service providers are involved in the service, in the roles below. The detail of who receives your data is set out in the Privacy Policy, which is where it belongs.
In an Agency team, the admin account sees, for each member, their name, email address, date of joining, the copilot hours used in the current cycle and their monthly limit, as well as the report of the calls made since joining the team. It sees a call's transcript, and the prospect's exact words, only if the member shares that call with it; no other member has access to it.
Company documents uploaded by the admin account are never kept as files: only their text is kept. A brief drawn from that text is sent to the analysis provider with every analyzed call from a team account, and a short version to the live suggestions provider during every live call. Only the admin account sees the documents and the brief.
For how long
The periods below are the ones the product enforces automatically, and there are no others:
How access is protected
Three guarantees, in place in the product today:
- Your session cannot be read by the code running in the page.
- Your browser never accesses the database directly.
- Your recordings are reachable only through a temporary link.
Your contact's consent
Before any transcription, the server requires an attestation: you declare that you have informed your contacts the call is being transcribed, and obtained their agreement. Until that attestation is given, the server refuses.
That refusal covers the three routes through which a call enters the product: uploading a recording, pasting a transcript by hand, and running a live call from the extension. None can be taken without an attestation.
The text you accept is written and served by the server, never copied into the page or the extension: this is what guarantees that the attested text is the one you were shown. You remain responsible for your contacts' data.
Your rights
Open 'Settings', the 'My data' section, then 'Export my data'. The JSON file you get contains all of your personal data, and the download is immediate.
Open 'Settings', the 'Danger zone' section, then 'Delete my account'. Confirmation is done by typing a keyword. There is no cooling-off period, no bin, and no way to restore. Deleting the account erases the personal data that is not subject to a legal retention obligation. The necessary accounting records are kept for the applicable legal period.
What we do not claim
A security page that lists only its strengths teaches nothing. Here is what we do not have:
- We hold no security certification, neither ISO 27001 nor SOC 2.
- No external security audit has been carried out on this product.
- No penetration test has been carried out on this product.
- We run no vulnerability disclosure programme.
Reporting a security issue
If you find a security issue on ClosePeak, write to us. We run no bounty programme, but every report is read and handled.
Email: privacy@closepeak.io
Privacy Policy · Data Retention Policy · Legal Notice