Legal

Q-Meet Privacy Policy

Version 1.1 – Effective 15 September 2026

This Privacy Policy explains how Qbim Aktiebolag (QBIM AB) ("QBIM", "we", "us") processes personal data in connection with Q-Meet and how responsibilities are divided between QBIM and the organisation using the Service.

1. About This Policy

Qbim Aktiebolag (QBIM AB), company registration number 556944-6981, provides Q-Meet. This policy applies when you use Q-Meet or participate in a meeting that a Q-Meet Customer chooses to process.

This policy complements the Q-Meet Data Processing Agreement (DPA). Where a Customer processes your personal data through Q-Meet, the Customer is normally the controller and QBIM acts as processor.

2. Our Roles Under GDPR

QBIM as Processor

Where a Customer records, uploads or otherwise processes meetings and related information through Q-Meet, the Customer normally determines the purposes of the processing. QBIM processes such information only on the Customer's behalf, according to the Customer's instructions and the applicable DPA.

QBIM as Controller

QBIM is controller for personal data processed for QBIM's own purposes, such as customer and account administration, billing and bookkeeping, operation and security, support, service communications, permitted marketing and compliance with legal obligations.

3. Personal Data That May Be Processed

  • Contact information, such as name, email address and telephone number.
  • User and authentication information, including user identifiers, IP address, user agent, device and technical account information.
  • Calendar and meeting metadata, such as meeting time, title, participants and meeting link where calendar integration is activated.
  • Audio/voice data from meetings selected for processing.
  • Transcripts and AI-generated summaries, topics, decisions, actions, follow-up points and other meeting outputs.
  • Professional, business-related and other information expressed in meetings or contained in uploaded material.
  • Operational, security, access and traffic metadata needed to operate and protect the Service.
  • Billing and purchase information, such as organisation, selected product, transaction reference, purchase/subscription status and invoice information where applicable.

Q-Meet does not use voice data for biometric identification and is not intended for emotion detection or equivalent profiling.

How Q-Meet Collects Personal Data

Q-Meet receives personal data directly from users and Customers when accounts are created, information is entered, meetings are recorded or uploaded, or support is contacted; from meetings captured through the Q-Meet app or meeting bot; from optional calendar integrations activated by the Customer; automatically from the app, device and Service through technical, operational and security logs; and from Stripe, Apple App Store or Google Play for purchase/subscription status and transaction references. Complete payment-card details are handled by the applicable payment provider or app-store operator and are not received or stored by QBIM.

4. How Q-Meet Processes Customer Meeting Content and Uses OpenAI

The Customer determines which meetings are processed. For a selected meeting, Q-Meet captures or receives audio and transcribes it. For AI-based meeting analysis, Q-Meet uses OpenAI Ireland Limited ("OpenAI") as a sub-processor. After transcription, Q-Meet may send text-based meeting information from the transcript, relevant meeting context, prompts or instructions, generated outputs and necessary technical metadata to OpenAI to produce summaries, topics, decisions, actions, follow-up points and other meeting outputs. Raw meeting audio is not sent to OpenAI for this AI-processing step.

FunctionHow it is used
Meeting capture / upload, transcription and AI analysisCore flow for meetings the Customer chooses to process. Audio is transcribed by QBIM; relevant text-based meeting information is then processed by OpenAI for AI-generated meeting outputs.
Calendar integrationOptional. May be left inactive or disabled.
Search, storage and sharingAvailable to authorised users according to the Service functionality and Customer configuration.
Email deliveryQ-Meet does not connect to the Customer's mailbox. The Service may send meeting summaries by email.
CRM / telephony integrationsNot provided as Q-Meet functionality.

Before Customer Personal Data is sent to OpenAI through the app for this processing, Q-Meet presents an in-app disclosure identifying OpenAI and the relevant data sharing and requires the user to provide the permission presented for the AI processing. If that permission is not provided, Q-Meet does not send Customer Personal Data to OpenAI for that AI processing.

OpenAI is contractually required, as a Q-Meet sub-processor, to apply data-protection safeguards that are no less protective, in relevant respects, than the obligations applicable to QBIM under the Q-Meet DPA and Article 28 GDPR. QBIM does not permit Customer Personal Data submitted to OpenAI through Q-Meet to be used for AI model training. International transfers relating to OpenAI are addressed below and in the current Q-Meet DPA and Sub-processor List.

QBIM does not independently use Customer Personal Data for marketing, profiling, independent product development, independent statistics or AI model training. OpenAI is used only to provide the AI-processing functionality described above and is not permitted by QBIM to use Q-Meet Customer Personal Data for model training. Product and quality development may use anonymised or aggregated information that no longer constitutes personal data.

5. Information When Meetings Are Recorded or Transcribed

The organisation using Q-Meet is responsible for informing meeting participants and establishing an applicable lawful basis for recording, transcription and other processing.

For digital meetings where the Q-Meet bot is used, Q-Meet appears as a participant. The bot's visibility is a technical transparency signal but does not itself constitute valid consent. The Customer/user should expressly inform participants before recording and/or transcription begins.

For physical meetings or other recordings where no bot is visible, the Customer/user must provide the information to participants before recording begins.

6. Purposes, Legal Bases and Retention Where QBIM Is Controller

PurposeTypical dataLegal basisRetention principle
Customer/account administrationContact, organisation, account and authentication dataPerformance of contract; legitimate interests where the agreement is with an employer/organisationFor the active relationship and a reasonable period afterwards where needed for administration, claims or security.
Billing, purchases and accountingBilling details, purchase/subscription status, transaction references and invoice/accounting dataPerformance of contract; legal obligationFor the periods required by accounting, tax and other applicable law.
Security and operationsIP address, device/technical information, login, operational and security logsLegitimate interests; legal obligation where applicableFor periods reasonably required for security, troubleshooting, fraud prevention and operation.
Support and troubleshootingContact details, support correspondence, diagnostics and voluntarily provided informationPerformance of contract; legitimate interestsFor the duration of the case and a reasonable follow-up period.
Service communicationsAccount/contact data and service statusPerformance of contract; legitimate interestsWhile the account/customer relationship is active and as reasonably needed afterwards.
Permitted marketingContact details and communication preferencesLegitimate interests or consent where requiredUntil objection/opt-out or withdrawal of consent, subject to limited suppression records.

Where QBIM acts as processor for Customer meeting content, the Customer determines the lawful basis and retention within the framework of the DPA.

7. Data Location and International Transfers

Q-Meet's primary application data, meeting audio, transcripts and backups are primarily processed and stored within the EU/EEA. Transcription is operated by QBIM within its primary hosting environment.

Certain authentication, network/security and email-delivery functions may involve processing outside the EU/EEA. AI-based text processing is performed by OpenAI Ireland Limited (OpenAI), and processing outside the EU/EEA, including the United States, may occur. Exact sub-processors, processing regions and international data flows are described in the current Q-Meet DPA and Q-Meet Sub-processor List.

Where personal data is transferred outside the EU/EEA, QBIM uses a valid mechanism under Chapter V GDPR. Where an applicable adequacy decision exists, the transfer may rely on that decision. Otherwise, appropriate safeguards such as the European Commission Standard Contractual Clauses (SCC) and relevant supplementary measures are used.

8. Payments and App Stores

Q-Meet purchases may be processed through Stripe for web checkout, Apple App Store or Google Play, depending on the purchase channel. These providers may process billing, transaction, store-account and purchase/subscription information and may act as processors or independent controllers for their respective processing under their own terms. QBIM does not receive or store complete payment-card credentials where those details are handled directly by the payment provider or app-store operator.

9. Retention of Customer Meeting Content

Customer Personal Data processed in Q-Meet is normally retained for as long as the Customer uses the Service and the information is required for the selected functionality, unless the Customer deletes it earlier.

Operational backups have a rolling technical retention of 7 days. If the customer relationship ends, Customer Personal Data in primary systems is deleted no later than 30 days after termination, unless continued retention is required by law. Backup copies are progressively deleted no later than 90 days after termination. Temporary technical working copies are cleared according to applicable operational and lifecycle routines.

10. Return, Export and Deletion

When a Customer agreement ends, the Customer may, in accordance with the DPA, request return or deletion of Customer Personal Data processed by QBIM on the Customer's behalf. Return is provided in an existing and technically available standard format. Remaining copies are then deleted according to the periods stated in the DPA unless continued retention is required by law.

QBIM also manages deletion by relevant sub-processors in accordance with applicable agreements and retention processes. The Customer may request written confirmation once the deletion process has been completed.

11. Security

QBIM applies appropriate technical and organisational measures to protect personal data, including encryption, access control, confidentiality requirements, customer isolation, logging, backup and recovery routines, vulnerability management, patch processes and secure development practices. More detailed information is provided in the applicable DPA and its TOM appendix.

QBIM also performs recurring external attack-surface scanning and other security controls.

12. Cookies and Similar Technologies

Q-Meet websites and applications may use cookies or similar technologies for essential functionality, authentication, security, preferences, analytics and marketing. Where consent is legally required for non-essential technologies, they are activated only after the applicable consent has been obtained.

13. Your Rights

Where QBIM acts as controller, you may, depending on the circumstances and applicable GDPR conditions, have rights to information, access, rectification, erasure, restriction, portability, objection to certain processing and withdrawal of consent where processing is based on consent.

Where the information is processed by QBIM only on behalf of a Customer, you should normally contact that Customer as controller. QBIM assists the Customer in accordance with the DPA and GDPR.

14. Personal Data Breaches

Where QBIM processes personal data on behalf of a Customer, QBIM notifies the Customer of a relevant Personal Data Breach without undue delay in accordance with the applicable DPA and GDPR. Further information is provided as it becomes available.

15. Complaints

You have the right to lodge a complaint with a competent data-protection supervisory authority. In Sweden, the supervisory authority is Integritetsskyddsmyndigheten (IMY).

16. Business Use and Children

Q-Meet is intended for business, organisational and professional use and is not knowingly offered directly to persons under 18 years of age.

17. Changes to This Policy

QBIM may update this Privacy Policy when Q-Meet, processing activities, service-provider categories or applicable law change. Material changes will be communicated through an appropriate channel where required and the current version will show its effective date.

18. Contact

Qbim Aktiebolag (QBIM AB)
Company registration number: 556944-6981
Västra Torggatan 18
652 24 Karlstad
Sweden
Phone: +46 (0)54 87 07 25

The same email address may be used for data-protection and incident-related questions.