app.klang.ai — 62/100 (Μέτριος κίνδυνος απορρήτου)
Τελευταία ανάλυση
Το περιεχόμενο της αναφοράς (περίληψη, ευρήματα, αποσπάσματα) δημιουργήθηκε στα αγγλικά και δεν έχει μεταφραστεί.
Klang AI AB · klang.ai
Λεπτομέρειες αναφοράς
Μέτριος κίνδυνος απορρήτουKlang AI collects potentially sensitive audio and video content, shares it with multiple AI providers, and reserves the right to use your uploaded data to improve its own algorithms without offering an opt-out — though it does keep most processing in the EU and enforces zero data retention with its AI sub-processors.
Klang AI AB, a Swedish AI transcription and meeting-recording service, processes a broad range of personal data including potentially sensitive content from audio/video files. The policy is commendably transparent about its sub-processors and has zero data retention agreements with LLM and Speech AI providers. However, it claims the right to use uploaded content to improve its own algorithms without a clear opt-out, collects credit card numbers directly (despite using Stripe), and transfers data to at least one US provider (ElevenLabs) without describing transfer safeguards. Retention is capped at three months post-account termination, which is relatively strong.
Αξιολόγηση ανά κατηγορία
Ανάλυση της πολιτικής σε βασικούς τομείς συμμόρφωσης. Καλό = ισχυρό, μέτριο = μικτό, κακό = ανησυχητικό.
Collects credit/debit card numbers directly despite using Stripe as a payment provider, and broadly defines collectible data to include any personal information in uploaded audio, video, or text files.
Clearly lists all sub-processors by name, purpose, and location; explicitly states zero data retention agreements with AI providers; structured policy with a useful summary.
Extensive sub-processor list is disclosed with detail, but data flows to at least one US provider (ElevenLabs) without transfer safeguards, and integration partners like Slack, Dropbox, HubSpot are also US-based.
ElevenLabs (USA) receives audio data for speech AI, and multiple integration partners are US-based, yet the policy is completely silent on SCCs, adequacy decisions, or any other Chapter V safeguard.
Third-party LLM and Speech AI providers are contractually barred from training on or retaining user data, but Klang itself reserves the right to use uploaded content to improve its own algorithms with no opt-out mechanism.
GDPR rights (access, rectification, erasure, restriction, portability, objection) are listed with supervisory authority links, but there is no automated self-service mechanism — users must email support@klang.ai.
Βασικά ευρήματα
Σημαντικές ρήτρες, ζητήματα ή θετικές πρακτικές (κρίσιμα πρώτα)
Algorithm improvement on user data without opt-out
Section 2 states: 'Uploaded content which may include personal information can be used to improve our services and algorithm.' This means Klang can use potentially sensitive audio/video content to train or refine its own models. No opt-out is offered, and the legal basis for this processing is unclear — it is not separately listed in Section 3's legal bases. For an AI transcription service handling meeting recordings, this is a significant concern.
US data transfer without documented safeguards
ElevenLabs, Inc. is listed as a Speech AI provider based in the USA. Audio data is shared with ElevenLabs for transcription and speaker identification. The policy does not mention Standard Contractual Clauses, an EU-US Data Privacy Framework certification, or any other GDPR Chapter V transfer mechanism. This is a compliance gap that could expose Klang to enforcement risk.
Credit/debit card numbers collected directly
Section 1 lists 'debit/credit card numbers' as personal information collected. Since Klang uses Stripe as its payment provider, full card numbers should never reach Klang's servers. Collecting and storing card numbers would create unnecessary security risk and likely violates PCI DSS and the data minimization principle.
Sensitive data processing consent mechanism is vague
Section 1 acknowledges processing 'potentially sensitive information contained within text or files (such as audio and video)' and says this is done 'with your consent or as otherwise permitted by applicable law.' However, the policy does not describe how consent is obtained — whether at upload, at account creation, or via a separate mechanism. For a service whose core function involves processing audio/video of meetings, this lack of specificity is concerning.
Zero data retention agreements with AI sub-processors are a strong positive
The policy explicitly states that LLM providers (Scaleway, Mistral, Microsoft Ireland, AWS Europe, Berget AI) and Speech AI providers (ElevenLabs, Pyannote) operate under zero data retention agreements where 'Data is not used for training and is not retained after processing' and 'Audio data is not used for training and is deleted immediately after processing.' This is above-average transparency for an AI service.
Short retention cap is notable
Section 6 states: 'No purpose in this notice will require us keeping your personal information for longer than three (3) months past the termination of the user's account.' This is a relatively short and clearly defined retention period, which is positive for GDPR compliance.
Περίληψη για τον χρήστη
Your meeting recordings and transcriptions could be used to train Klang's own algorithms, and some of your data flows to a US-based speech AI company with no explained legal safeguard — but third-party AI providers contractually cannot retain or train on your data.
Στάση συμμόρφωσης
Klang AI demonstrates partial GDPR compliance: it identifies legal bases, lists sub-processors with specificity, and caps retention. However, it has gaps around international transfer safeguards, lacks a clear opt-out for its own algorithm improvement processing, and collects payment card data that it likely should not be storing directly. No DPA reference or DPIA mention is made.
Μεταφορές ΕΕ
Most processing stays within the EU/EEA (Scaleway in France, Mistral in France, Microsoft Ireland, AWS Europe, Berget AI in Sweden, Pyannote in France). However, ElevenLabs Inc. is US-based, and the policy is silent on transfer mechanisms such as Standard Contractual Clauses or an adequacy decision. This is a compliance gap under GDPR Chapter V.
Εντοπισμένα σήματα
Συγκεκριμένα δεδομένα και πρακτικές που εντοπίστηκαν στο κείμενο
Αποσπάσματα αποδείξεων
Απευθείας αποσπάσματα από την πολιτική που υποστηρίζουν αυτά τα ευρήματα
Uploaded content which may include personal information can be used to improve our services and algorithm.
LLM Model providers, we work with the following AI providers who have strong data protection policies and zero data retention agreements. Your data can be shared with these to perform LLM requests. Data is not used for training and is not retained after processing.
No purpose in this notice will require us keeping your personal information for longer than three (3) months past the termination of the user's account.
ElevenLabs, Inc., USA
debit/credit card numbers
When necessary, with your consent or as otherwise permitted by applicable law, we process the following categories of sensitive information: any potentially sensitive information contained within text or files (such as audio and video) that are submitted to the service.
Λείπει ή ασαφές
- No description of international transfer safeguards (SCCs, DPF, BCRs) for US-based sub-processors
- No opt-out mechanism for Klang's own algorithm improvement using uploaded content
- No explanation of how consent for sensitive data processing is obtained in practice
- No reference to a Data Processing Agreement (DPA) for B2B customers
- No mention of Data Protection Impact Assessment (DPIA) despite processing sensitive audio/video at scale
- No automated self-service portal for exercising GDPR rights
- No details on cookie categories or tracking technologies (referenced to separate Cookie Notice)
Ερωτήσεις προς υποβολή
- What specific transfer mechanism (SCCs, EU-US DPF certification, etc.) do you rely on when sharing audio data with ElevenLabs in the United States?
- How exactly is consent for processing sensitive audio/video content obtained — is it at upload time, in the sign-up flow, or elsewhere?
- Can users opt out of having their uploaded content used to improve Klang's own algorithms, and if not, what is the legal basis for this processing under GDPR?
- Do you actually collect and store full debit/credit card numbers on your own servers, or does Stripe handle all card data via tokenization?
- What does 'improve our services and algorithm' entail — does this involve training machine learning models on user-uploaded audio/video content?
- Is a Data Protection Impact Assessment available for the processing of sensitive audio/video content at scale?
Κοινοποίηση αυτής της ανάλυσης
Οποιοσδήποτε με αυτόν τον σύνδεσμο μπορεί να δει το αποτέλεσμα παραπάνω.
Δημιουργήθηκε από το DentroChat
100% ευρωπαϊκό AI chat για όλους
Συνομιλήστε με AI, εργαστείτε με αρχεία, δημιουργήστε εικόνες και αναζητήστε στο διαδίκτυο. Τα δεδομένα παραμένουν στην Ευρώπη.
Άλλες πολιτικές απορρήτου που αναλύθηκαν
Προβολή όλωνcursor.com
62/100
Μέτριος κίνδυνος απορρήτουCursor (Anysphere) promises not to use your code inputs for AI training by default and doesn't sell your data, but it collects a sweeping range of personal and usage data, ships it to the US with vague transfer safeguards, and leaves key details like retention periods and legal bases unspecified.
Προβολή αναφοράς →eustella.com
62/100
Μέτριος κίνδυνος απορρήτουΗ eustella κάνει ισχυρές υποσχέσεις απορρήτου — χωρίς πώληση δεδομένων, χωρίς κοινοποίηση σε τρίτους, χωρίς εκπαίδευση AI στα δεδομένα σας, και όλη η επεξεργασία παραμένει στην ΕΕ — αλλά αυτό είναι διαφημιστικό κείμενο, όχι δεσμευτική πολιτική απορρήτου, και κρίσιμες λεπτομέρειες για τη συλλογή δεδομένων, την περίοδο διατήρησης, τους υπο-επεξεργαστές και τα δικαιώματα χρηστών απουσιάζουν από το παρεχόμενο κείμενο.
Προβολή αναφοράς →lhv.com
62/100
Μέτριος κίνδυνος απορρήτουLHV Bank collects a sweeping range of personal and financial data, shares it widely with fraud prevention agencies and payment intermediaries, and relies heavily on legitimate interest for marketing and analytics — but it does cover GDPR rights and uses manual review for profiling decisions.
Προβολή αναφοράς →cake.com
62/100
Μέτριος κίνδυνος απορρήτουCAKE.com provides standard EU data rights and transfer safeguards but collects highly intrusive workplace surveillance data—like screenshots, background location, and app usage—on behalf of employers, who act as the data controllers for their employees.
Προβολή αναφοράς →