Scribe is built with privacy and security at its core. We are fully GDPR-compliant, store all data within the European Union, and follow industry best practices for data protection.
All customer data is stored and processed within the European Union. Our database, file storage, and AI processing pipelines are configured to use EU-based infrastructure. No customer data is transferred outside the EU without explicit consent and appropriate safeguards (Standard Contractual Clauses).
Scribe is fully compliant with the General Data Protection Regulation (GDPR). We process personal data under the following legal bases:
We use the following third-party services to provide Scribe. Data Processing Agreements (DPAs) are in place with all subprocessors.
| Provider | Purpose | Data Processed | Region | DPA |
|---|---|---|---|---|
| Prisma (Prisma Data) | Database connection pooling and edge access | All application data (via Prisma Accelerate) | EU (Frankfurt) | In place |
| Cloudflare | File storage (R2) and CDN | Audio/video files, attachments | EU (Western Europe) | In place |
| AssemblyAI | Speech-to-text transcription | Audio files for transcription | EU | In place |
| Anthropic | AI summaries and content extraction | Transcript text (no audio) | EU | In place |
| SendGrid (Twilio) | Transactional email delivery | Email addresses, message content | EU | In place |
| OAuth authentication (optional) | Email, name, account ID | EU/US | In place | |
| PyAnnote (self-hosted) | Speaker voice recognition | Audio clips, speaker embeddings | EU | Pending |
| Recall.ai | Meeting bot recording | Meeting metadata, audio/video streams | EU/US | In place |
| Inngest | Background job orchestration | Job metadata, event payloads | US | In place |
| Vercel | Application hosting, deployment, and web analytics | Request logs, edge metadata, pageview analytics | Global (edge) | In place |
| PostHog | Product analytics and session replay | Usage events, pageviews, session recordings | EU | In place |
| PartyKit (Cloudflare) | Real-time document collaboration | Document edits, presence data | EU | In place |
Under GDPR, you have the following rights regarding your personal data. We respond to all requests within 30 days.
We retain your data for as long as your account is active and you need the service. Upon account deletion or request:
For compliance inquiries, data subject requests, or security concerns:
Happenings Group A/S
Klostergade 56B, St.
8000 Aarhus C, Denmark
VAT NO. DK40979956
Email: support@happenings.dk
Effective as of March 7, 2026