Skip to main content

    Privacy Policy

    Last updated: October 4, 2026

    1. Introduction

    TANYRA ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This privacy policy describes how we collect, use and protect your information when you use our intelligent meeting analysis platform.

    This policy has been drawn up in accordance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679) and Italian privacy legislation.

    2. Data Controller

    TANYRA

    Email: [email protected]

    For any questions about the processing of your personal data, you can contact us at the addresses above.

    3. Personal Data Collected

    3.1 Data you provide directly:

    • Registration data: First name, last name, email, company
    • Audio files: Recordings of the meetings you upload for analysis
    • Feedback: Comments and ratings you provide
    • Preferences: Privacy settings and usage preferences

    3.2 Data collected automatically:

    • Technical data: IP address, browser, device
    • Usage data: Pages visited, features used, time spent
    • Cookies: Data collected through cookies (only with your consent)
    • System logs: Access and usage records for security

    3.3 Data generated by the service:

    • Transcripts: Text generated from your audio files
    • Analyses: Insights and metrics about your meetings
    • Reports: Generated documents and visualizations

    3a. Microsoft Teams, if you connect it

    If you connect your Microsoft Teams account from Settings, Tanyra accesses Microsoft 365 on your behalf, with delegated permissions: it sees only what you see, and uses it to bring in the meetings you organize. Data arrives from Microsoft Graph over an encrypted connection (HTTPS).

    What it reads

    Name and email of your Microsoft account; from your calendar, the Teams meetings you organized (title, time, meeting link); the transcript of those meetings, with the name of who spoke, if transcription was started in Teams. Meetings organized by other people don't come in. Tanyra doesn't read audio, video, chats, mail or files.

    What it keeps

    The Microsoft access tokens, readable only by Tanyra's services and never by the browser; name and email of the connected account, the Microsoft organization ID and the permissions granted; for each meeting brought in, title, date, duration, the transcript text with names and the analyses Tanyra draws from it, as for any uploaded meeting (sections 3.3 and 6); a record of Teams meetings already seen, so they're never brought in twice, and the summary of the last check with the titles of skipped meetings and the reason.

    Transcripts also concern the other people present, who appear with their Teams name: that's why Tanyra asks whoever organizes the meeting to let them know that the transcript is read by Tanyra.

    How to disconnect

    Settings → Microsoft Teams → Disconnect. Tanyra deletes the tokens and stops reading. Meetings already brought in stay among your meetings until you delete them; with data deletion (section 7) the Teams connection and record go too.

    How to withdraw consent in Microsoft

    Whoever manages Microsoft 365 in your organization can revoke the permissions given to Tanyra at any time (Microsoft Entra admin center → Enterprise apps → Tanyra → Permissions) or delete the app; turning off transcript access in Teams (“Transcript API access”) blocks reading for every app.

    The details for your organization's IT team are on the page tanyra.com/teams/admin.

    4. Legal Basis for Processing (Art. 6 GDPR)

    Performance of a contract (Art. 6.1.b)

    Provision of the meeting analysis service, account management, technical support

    Consent (Art. 6.1.a)

    Analytics cookies, marketing communications, product improvements

    Legitimate interest (Art. 6.1.f)

    Platform security, fraud prevention, analysis for improvements

    Legal obligation (Art. 6.1.c)

    Data retention for tax and accounting obligations

    5. Purposes of Processing

    Provision of the service

    Audio transcription, meeting analysis, generation of reports and insights

    Account management and support

    Authentication, profile management, technical assistance

    Product improvement

    Usage analysis for new features and optimizations

    Communications

    Service emails, product updates, marketing (only with consent)

    Security and compliance

    Fraud prevention, IT security, legal compliance

    6. Retention Period

    Retention periods:

    Audio files, transcripts and analysesUntil you or your organization delete them
    Analytics data730 days
    Account and profileUntil deletion
    Security logs365 days
    Tax data10 years (legal obligation)

    There is currently no automatic deletion after a set period: audio files, transcripts and analyses stay until you or your organization delete them. You can delete your account, along with the related data, from your privacy settings, or request deletion by writing to [email protected].

    7. Your Rights (Arts. 15-22 GDPR)

    As a data subject, you have the following rights:

    🔍 Right of access (Art. 15)

    Obtain confirmation of whether we are processing your data and receive a copy of it

    ✏️ Right to rectification (Art. 16)

    Correct inaccurate data or complete incomplete data

    🗑️ Right to erasure (Art. 17)

    Request the deletion of your data ("right to be forgotten")

    ⏸️ Right to restriction of processing (Art. 18)

    Restrict processing in certain circumstances

    📦 Right to data portability (Art. 20)

    Receive your data in a readable format and transfer it to another controller

    ❌ Right to object (Art. 21)

    Object to processing based on legitimate interest or for marketing purposes

    How to exercise your rights:

    • Go to your Privacy Dashboard to manage your data yourself
    • Contact us by email: [email protected]
    • We respond within 30 days of the request
    • The service is free of charge (except for manifestly unfounded requests)

    8. Data Security

    We implement appropriate technical and organizational measures to protect your personal data:

    End-to-end encryption for audio files
    HTTPS/TLS connections for all transfers
    Two-factor authentication available
    Regular backups and access controls
    Periodic security audits

    9. International Transfers

    Your data is processed mainly on servers in the EU. Some third-party services may involve transfers outside the EU:

    Third-party services used:

    • Google Analytics: United States (Adequacy Decision)
    • OpenAI: United States (Standard Contractual Clauses)
    • AssemblyAI: United States (Standard Contractual Clauses)

    All transfers take place with appropriate safeguards under the GDPR.

    10. Changes to this Policy

    We may update this privacy policy from time to time. We will notify you of any material changes through:

    • An email to the address associated with your account
    • A notification in the TANYRA platform
    • An update of the date at the top of this page

    11. Contact

    For privacy questions:

    Email: [email protected]

    Subject: [GDPR] + description of the request

    Response time: Within 30 days

    Complaints to the Garante Privacy

    You have the right to lodge a complaint with the Garante per la Protezione dei Dati Personali (the Italian Data Protection Authority) if you believe that the processing of your data violates the GDPR.

    Garante Privacy: www.gpdp.it

    This privacy policy complies with the GDPR (EU Regulation 2016/679) and the Italian Privacy Code (Legislative Decree 196/2003, as amended by Legislative Decree 101/2018).

    Last updated: October 4, 2026 | Version 1.0