Privacy Policy.
Your team's context is the most valuable thing you trust us with. This policy explains what we collect, why, and the rights you have over your data.
Last updated: 22 July 2026
Notio is built to meet GDPR data-protection requirements and maintains SOC 2 Type II certification. Customer data is encrypted in transit and at rest, access is least-privilege and logged, and our controls are independently audited each year.
1. Who we are
Notio Labs ("Notio", "we", "us") provides a shared intelligence platform for teams. This policy describes how we handle personal data across our platform, websites, and services (the "Service"). For personal data our customers submit to the Service, the customer is the data controller and Notio acts as a data processor; for our own websites and account records, Notio is the controller.
2. Information we collect
- Account data — name, work email, organisation, and role, provided when you sign up or are invited.
- Customer Data — the meetings, transcripts, documents, files, and other content you and your team add to the Service.
- Connected sources — data from integrations you authorise, such as cloud storage, calendars, and meeting tools, limited to the scopes you grant.
- Usage data — logs, device and browser information, and analytics about how the Service is used, to keep it secure and improve it.
- Billing data — plan and payment records, processed by our payment provider (we do not store full card numbers).
3. How we use information
- To provide, maintain, and secure the Service and generate the Output you request.
- To authenticate users, manage workspaces, and enforce access controls.
- To provide support and communicate about your account and service changes.
- To improve reliability, performance, and features using aggregated or de-identified usage data.
- To comply with legal obligations and enforce our terms.
We do not sell personal data, and we do not use your Customer Data to train foundation models for other customers.
4. Legal bases (GDPR)
Where the GDPR applies, we process personal data on one or more of these legal bases: performance of a contract with you; our legitimate interests in operating and securing the Service; your consent, where we ask for it; and compliance with a legal obligation. Where we rely on legitimate interests, we balance them against your rights and freedoms.
5. AI processing
To generate Output, Customer Data may be processed by large-language-model providers acting as our subprocessors under contractual confidentiality and data-protection terms. These providers are instructed not to use your Customer Data to train their models. Processing occurs within our controlled infrastructure and only as needed to deliver the feature you invoke.
6. Sharing and subprocessors
We share personal data only with service providers who help us run the Service — cloud hosting, database and vector storage, AI model providers, analytics, and payment processing — each bound by contracts that require appropriate safeguards. We may also disclose data where required by law. A current list of subprocessors is available on request at privacy@getnotio.com.
7. International transfers
We may process data in countries other than your own. Where personal data protected by the GDPR is transferred outside the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.
8. Data retention
We retain Customer Data for as long as your account is active and as needed to provide the Service. After termination, you may export your data for a reasonable period, after which we delete or de-identify it in line with our retention schedule, unless a longer period is required by law. Account and billing records are retained as required for legal and accounting purposes.
9. Your data rights
Subject to applicable law, and in particular under the GDPR, you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your personal data ("right to be forgotten").
- Restriction and objection — limit or object to certain processing.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent — where processing is based on consent, at any time.
Where Notio is a processor, we will forward your request to the relevant customer (controller) and assist them in responding. To exercise any right, contact privacy@getnotio.com. You also have the right to lodge a complaint with your local data-protection authority.
10. Data security
We maintain a SOC 2 Type II information security program. Data is encrypted in transit (TLS) and at rest, access is least-privilege and logged, secrets are managed centrally, and our controls are independently audited each year. We maintain a documented incident-response process and will notify affected customers of a personal data breach without undue delay as required by law.
11. Cookies and analytics
Our websites use cookies and similar technologies for essential functionality and to understand aggregate usage via analytics tools such as Google Analytics. You can control cookies through your browser settings. Essential cookies are required for the Service to function.
12. Children's privacy
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or in-app before they take effect. The "last updated" date above always reflects the current version.
14. Contact us
For any privacy question or request, contact our privacy team at privacy@getnotio.com, or write to Notio Labs, Lvl 1, 888 Brunswick Street, New Farm QLD 4005, Australia. See also our Terms of Service.