Privacy Policy
Read this first if you attended a meeting
If you're here because you saw "Khulasa" in a meeting participant list, or received a meeting summary, Section 9 is written for you. It explains who holds your data and how to exercise your rights.
1Who we are
LEINO SYSTEMS SOFTWARE DESIGN FZCO, a free zone company registered in IFZA, Dubai, United Arab Emirates, under licence number 87738, registered office at Building A1, Dubai Digital Park, Dubai Silicon Oasis, Dubai, UAE.
Contact: hello@leino.dev
This policy explains how we handle personal data. It applies to our website, the Khulasa platform, and our sales and support activities.
2Two different roles — and why it matters
This is the most important thing to understand about how we handle data.
We are a Processor for meeting content. When an organisation uses Khulasa to record and summarise a meeting, that organisation decides which meetings are recorded, why, who attends, and who receives the summary. They are the Controller. We only process that content on their instructions. Our obligations to them are set out in our Data Processing Addendum.
We are a Controller for our own business data. Account registration, billing, support conversations, website analytics and platform usage telemetry are ours to decide about, and this policy governs them.
If your question is about a meeting you attended, the organisation that recorded it is the right first point of contact — see Section 9.
3Data we hold as Controller
| Category | Examples | Why we process it | Lawful basis |
|---|---|---|---|
| Account data | Name, work email, job title, organisation, password hash | Create and secure accounts, authenticate users | Performance of a contract |
| Billing data | Billing contact, address, TRN, payment method token, invoices | Take payment, meet tax and accounting obligations | Contract; legal obligation |
| Support data | Emails, chat transcripts, screenshots you send us | Answer questions and resolve issues | Contract; legitimate interests |
| Usage telemetry | Log-ins, feature usage, meeting counts and durations, device and browser, IP address | Operate, secure, debug and improve the Service | Legitimate interests |
| Marketing data | Contact details, communication preferences, engagement with our emails | Send information about our products | Consent; legitimate interests |
| Website data | Cookies and similar technologies — see Section 8 | Operate the site, measure usage | Consent for non-essential cookies |
We do not sell personal data. We do not share it with advertising networks.
4Meeting content — what we do as Processor
When our customer uses the Service, we process:
- Audio captured from the meeting by the Meeting Assistant
- Transcripts produced from that audio
- Speaker attribution data derived from the audio
- Summaries, action items and insights generated from the transcript
- Participant details — names, and where the meeting platform provides them, email addresses
- Calendar metadata — meeting titles, times, invitee lists, where the customer connects a calendar
We process this only to provide the Service to our customer: transcription, translation, summarisation, action-item extraction, and delivery to the recipients the customer designates.
We do not use meeting content to train our models unless the customer has explicitly opted in, and when they do, they must confirm they have obtained the separate consent of participants for that purpose. Opt-in is off by default. See our Terms of Service Clause 7.4.
Customer Data is retained until you delete it. There is no automatic expiry by default. On deletion — whether by you, by your retention schedule, or on termination — media files are erased immediately and irrecoverably. Copies of the associated database records may persist in encrypted backups for up to fourteen days, after which they are erased, except where retention is legally required..
5Who we share data with
Sub-processors. We use third parties for hosting, speech recognition and language model inference.
Professional advisers — auditors, lawyers, accountants, under confidentiality.
Payment providers — Stripe, Inc.. We do not store full card details.
Authorities — where required by a lawful order from a UAE court, the Public Prosecution, the UAE Data Office, a police authority, or an equivalent authority elsewhere. We notify the affected customer unless legally prohibited.
Corporate transactions — in a merger, acquisition or asset sale, subject to equivalent protections.
6International transfers
We process data in France, elsewhere in the EU, and in the USA. Some sub-processors give us no choice of region, so processing may take place in any country in which they operate. Our sub-processor list states, for each provider, both the jurisdiction of the contracting entity and the region in which it processes. Where we transfer personal data outside the United Arab Emirates, we do so in accordance with Articles 22 and 23 of the PDPL
Customers on Private Cloud and On-Premise plans may elect UAE-resident or GCC-resident processing, under which meeting content is not transferred outside the chosen region.
7Security
We maintain technical and organisational measures appropriate to the risk, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access control and least-privilege administration
- Multi-factor authentication for administrative access
- Audit logging of access to meeting content
- Background-checked personnel under written confidentiality obligations
We notify affected customers of a personal data breach within 72 hours of becoming aware of it, and notify the UAE Data Office where Article 33 of the PDPL requires.
8Cookies
We use strictly necessary cookies to operate the site and keep you signed in.
9If you attended a meeting recorded with Khulasa
If a meeting you took part in was recorded using our Service, here is your position.
Who decides about your data. The organisation that ran the meeting is the Controller. They chose to record, they set the purpose, and they decide who receives the summary and for how long it is kept. We act on their instructions.
Your rights. Under the PDPL you have the right to be informed, to access your personal data, to have it corrected, to request erasure or restriction of processing, to object to processing, and to withdraw consent where consent was the basis relied on.
How to exercise them. Contact the organisation that ran the meeting — they can act on your request directly and immediately. If you don't know who to contact, or they don't respond, write to us at hello@leino.dev and we will identify the relevant customer and pass your request on, or act on it under their instruction. We will acknowledge within 10 working days.
If you don't want to be recorded. Tell the meeting host before or during the meeting. Hosts can remove the Meeting Assistant, pause capture, or stop processing at any time. You may also ask the host to delete a recording after the fact.
Complaints. You may complain to the UAE Data Office, or to the data protection authority in your own country. We'd appreciate the chance to resolve it first — hello@leino.dev.
10Your rights as a customer or user
Where we act as Controller, you may request access, correction, erasure, restriction, portability, or object to processing, and withdraw consent where we rely on it. Contact hello@leino.dev. We respond within 30 days, or tell you if we need longer.
We may need to verify your identity. Some rights are qualified — for example, we may retain data where a legal obligation requires it.
11Children
The Service is not directed at anyone under 18 and we do not knowingly collect their data. If you believe a child's data has been submitted, contact hello@leino.dev.
12Contact
hello@leino.dev