How, where, and why Akompa processes your data

Last updated: August 6, 2026

The registry below presents the main types of data processed by Akompa, the reasons they are processed, the technology service providers participating in their processing, the applicable security measures, and the territories involved. It is intended, among other things, to help professionals and organizations using Akompa Notes complete, when necessary, their privacy impact assessment.

Type of dataWhy this data is processedProviders involvedSecurityAI modelsTransit outside QuebecLong-term storage outside QuebecLong-term storage in Quebec
Audio recordings
To generate transcripts, which are then used to generate notes
storage: Amazon Web Services (Quebec), transcript generation: Modal Labs
ISO 27001, SOC 2, AES-256 encryption at rest and in transit (TLS), data processing agreement (DPA)
Akompa-controlled open-source model. Data is not used to train the model.
Yes, United States
No
Yes, max 24h
Transcripts, initial notes in processing, and note examples of a custom template
To generate notes and custom note templates
orchestration: Modal Labs, AI: OpenAI
ISO 27001, SOC 2, AES-256 encryption at rest and in transit (TLS), DPA
Various OpenAI models. Data is not used to train the models.
Yes, United States
No
No
Client identifiers (name, ID, or alias), revised notes, and transcripts
To allow you to access notes and transcripts from past sessions and organize them by client
Amazon Web Services (Quebec), Supabase (Quebec)
ISO 27001, SOC 2, AES-256 encryption at rest and in transit (TLS), DPA
none
No
No
Yes, retention depends on configuration (default 24–48 hours)

Type of dataWhy this data is processedProviders involvedSecurityAI modelsTransit outside QuebecLong-term storage outside QuebecLong-term storage in Quebec
Name, email address, and other waitlist information
Signup request management, user profile creation, secure authentication, and technical support
Amazon Web Services (Quebec), Supabase (Quebec)
ISO 27001, SOC 2, AES-256 encryption at rest and in transit (TLS), DPA
none
No
No
Yes, for the lifetime of the account
Financial information
Credit card payments
Stripe
PCI-DSS Level 1, SOC 1 & 2, AES-256 at rest, TLS 1.2, DPA
none
Yes, United States
For the term of the agreement and any period required by law (e.g., financial record keeping).
No
First name and email address
Sending emails required for the web application to function
Resend
SOC 2 Type II, AES-256 at rest, TLS in transit, DPA
none
Yes, United States
Yes
No
Name, email address, and other waitlist information
Sending optional emails to users (e.g., reminders or resource sharing), with unsubscribe available from the link at the bottom of each message
MailerLite
ISO 27001:2022, AES-256 at rest, TLS in transit, DPA
none
Yes, European Union
Yes
No
Technical metadata (browser, operating system, etc.) and masked recording of your navigation
Diagnosing technical errors and improving application stability
Sentry
SOC 2 Type 2, ISO 27001, AES-256 at rest, TLS in transit, DPA
none
Yes, United States
Yes
No
Pages viewed, actions taken in the application, and masked recording of your navigation
Understanding how the application is used in order to improve it, and reproducing reported technical problems
PostHog (European Union region)
SOC 2 Type 2, TLS in transit, DPA
OpenAI and Anthropic models, via PostHog's AI-assisted analysis features. Data is not used to train the models.
Yes, European Union
Yes
No
Name and email address, and video conversations with our team and their transcript
Receiving and sending emails (e.g., about your questions and comments), and videoconference discussions about Akompa Notes
Google Workspace
SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, AES-256 at rest, TLS in transit, DPA
Gemini, for meeting transcription and summaries and for searching emails. Data is not used to train the models.
Yes, United States
Yes
No

This registry is provided for informational purposes and does not constitute legal advice. The providers involved and the protection measures may evolve. For any questions, contact privacy@akompa.com.