انتقل إلى المحتوى الرئيسي

Privacy Policy

الإصدار 420d29fآخر تحديث 3 أغسطس 2026تسود النسخة الإنجليزية في حال وجود أي تعارض.

Read this first if you attended a meeting

If you're here because you saw "Khulasa" in a meeting participant list, or received a meeting summary, Section 9 is written for you. It explains who holds your data and how to exercise your rights.

1Who we are

LEINO SYSTEMS SOFTWARE DESIGN FZCO, a free zone company registered in IFZA, Dubai, United Arab Emirates, under licence number 87738, registered office at Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, UAE.

Contact: hello@leino.dev

This policy explains how we handle personal data. It applies to our website, the Khulasa platform, and our sales and support activities.

2Two different roles — and why it matters

This is the most important thing to understand about how we handle data.

We are a Processor for meeting content. When an organisation uses Khulasa to record and summarise a meeting, that organisation decides which meetings are recorded, why, who attends, and who receives the summary. They are the Controller. We only process that content on their instructions. Our obligations to them are set out in our Data Processing Addendum.

We are a Controller for our own business data. Account registration, billing, support conversations, website analytics and platform usage telemetry are ours to decide about, and this policy governs them.

If your question is about a meeting you attended, the organisation that recorded it is the right first point of contact — see Section 9.

3Data we hold as Controller

CategoryExamplesWhy we process itLawful basis
Account dataName, work email, job title, organisation, password hashCreate and secure accounts, authenticate usersPerformance of a contract
Billing dataBilling contact, address, TRN, payment method token, invoicesTake payment, meet tax and accounting obligationsContract; legal obligation
Support dataEmails, chat transcripts, screenshots you send usAnswer questions and resolve issuesContract; legitimate interests
Usage telemetryLog-ins, feature usage, meeting counts and durations, device and browser, IP addressOperate, secure, debug and improve the ServiceLegitimate interests
Marketing dataContact details, communication preferences, engagement with our emailsSend information about our productsConsent; legitimate interests
Website dataCookies and similar technologies — see Section 8Operate the site, measure usageConsent for non-essential cookies

We do not sell personal data. We do not share it with advertising networks.

4Meeting content — what we do as Processor

When our customer uses the Service, we process:

  • Audio captured from the meeting by the Meeting Assistant
  • Transcripts produced from that audio
  • Speaker attribution data derived from the audio
  • Summaries, action items and insights generated from the transcript
  • Participant details — names, and where the meeting platform provides them, email addresses
  • Calendar metadata — meeting titles, times, invitee lists, where the customer connects a calendar

We process this only to provide the Service to our customer: transcription, translation, summarisation, action-item extraction, and delivery to the recipients the customer designates.

We do not use meeting content to train our models unless the customer has explicitly opted in, and when they do, they must confirm they have obtained the separate consent of participants for that purpose. Opt-in is off by default. See our Terms of Service Clause 7.4.

Customer Data is retained until you delete it. There is no automatic expiry by default. On deletion — whether by you, by your retention schedule, or on termination — media files are erased immediately and irrecoverably. Copies of the associated database records may persist in encrypted backups for up to fourteen days, after which they are erased, except where retention is legally required..

5Who we share data with

Sub-processors. We use third parties for hosting, speech recognition and language model inference.

Professional advisers — auditors, lawyers, accountants, under confidentiality.

Payment providersStripe, Inc.. We do not store full card details.

Authorities — where required by a lawful order from a UAE court, the Public Prosecution, the UAE Data Office, a police authority, or an equivalent authority elsewhere. We notify the affected customer unless legally prohibited.

Corporate transactions — in a merger, acquisition or asset sale, subject to equivalent protections.

6International transfers

We process data in France, elsewhere in the EU, and in the USA. Some sub-processors give us no choice of region, so processing may take place in any country in which they operate. Our sub-processor list states, for each provider, both the jurisdiction of the contracting entity and the region in which it processes. Where we transfer personal data outside the United Arab Emirates, we do so in accordance with Articles 22 and 23 of the PDPL

Customers on Private Cloud and On-Premise plans may elect UAE-resident or GCC-resident processing, under which meeting content is not transferred outside the chosen region.

7Security

We maintain technical and organisational measures appropriate to the risk, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access control and least-privilege administration
  • Multi-factor authentication for administrative access
  • Audit logging of access to meeting content
  • Background-checked personnel under written confidentiality obligations

We notify affected customers of a personal data breach within 72 hours of becoming aware of it, and notify the UAE Data Office where Article 33 of the PDPL requires.

8Cookies

We use strictly necessary cookies to operate the site and keep you signed in.

9If you attended a meeting recorded with Khulasa

If a meeting you took part in was recorded using our Service, here is your position.

Who decides about your data. The organisation that ran the meeting is the Controller. They chose to record, they set the purpose, and they decide who receives the summary and for how long it is kept. We act on their instructions.

Your rights. Under the PDPL you have the right to be informed, to access your personal data, to have it corrected, to request erasure or restriction of processing, to object to processing, and to withdraw consent where consent was the basis relied on.

How to exercise them. Contact the organisation that ran the meeting — they can act on your request directly and immediately. If you don't know who to contact, or they don't respond, write to us at hello@leino.dev and we will identify the relevant customer and pass your request on, or act on it under their instruction. We will acknowledge within 10 working days.

If you don't want to be recorded. Tell the meeting host before or during the meeting. Hosts can remove the Meeting Assistant, pause capture, or stop processing at any time. You may also ask the host to delete a recording after the fact.

Complaints. You may complain to the UAE Data Office, or to the data protection authority in your own country. We'd appreciate the chance to resolve it first — hello@leino.dev.

10Your rights as a customer or user

Where we act as Controller, you may request access, correction, erasure, restriction, portability, or object to processing, and withdraw consent where we rely on it. Contact hello@leino.dev. We respond within 30 days, or tell you if we need longer.

We may need to verify your identity. Some rights are qualified — for example, we may retain data where a legal obligation requires it.

11Children

The Service is not directed at anyone under 18 and we do not knowingly collect their data. If you believe a child's data has been submitted, contact hello@leino.dev.

12Contact

hello@leino.dev