Privacy policy

September 24, 2026 version

Geremy.ai, an artificial intelligence application for creating minutes and analyzing meetings, attaches the utmost importance to the protection of privacy and personal data. This privacy policy explains how we collect, use, disclose, process and protect the personal information of Geremy.ai users.

Geremy.ai is a service provided by Stellar Quantum SAS – Hamadryade Bât. 2, 55 allée Camille Claudel, 84000 Avignon, France.

Collecting and using information

When using Geremy.ai to record meetings, the Customer is responsible for informing all participants and, where applicable, for obtaining their consent, for the recording and transcription of their voices and statements. It is up to the Customer to determine the legal basis applicable to its context: performance of the contract, legitimate interest, task carried out in the public interest, or consent.

2. Processing audio recordings

3. Data use and artificial intelligence

4. User account creation and management

We need certain information to create your account:

5. Creating and managing reports

When you create a report, we record:

The user can enter optional additional information (objectives, agenda, list of participants) to enhance the report. This information can be modified or deleted at any time.

6. Service support

To help you if you have any problems, we use:

7. Statistical analysis and customization

Data storage and security

Data retention and deletion

Deletion on request

The Customer may at any time request the permanent deletion of his Account and all his data (reports, preferences, profile information), through either of two channels:

Deleting a report or content from the customer area results in its erasure from our production servers within a maximum of twenty-four hours.

Default retention times

Confidentiality

Stellar Quantum undertakes to:

This obligation remains in effect during and after the term of use of the Service. All Stellar Quantum personnel are bound by a contractual obligation of confidentiality.

Data transfer and disclosure

Meeting content — recordings, transcripts and reports — is processed exclusively within the European Union and is not disclosed to any third party, except as required by law.

Our own processing — billing and management of the commercial relationship — relies on service providers established in the European Union, which have no access to any meeting content.

Disclosure on court order

In the event of a request from a competent judicial authority (rogatory commission, examining magistrate, public prosecutor, judicial police, or foreign order via international mutual assistance), Stellar Quantum will:

User rights

You have the following rights concerning your personal data:

You may request the permanent deletion of your Account and all your data at any time, through either of the two channels described above, with the exception of billing data, which is retained in accordance with legal obligations.

To exercise these rights: rgpd@geremy.ai or support@geremy.ai

You can also lodge a complaint with the CNIL: www.cnil.fr

RGPD compliance

Cookies and similar technologies

Definitions

Types of cookies used

You can accept or refuse non-essential cookies via the “Manage my cookies” link in the footer, and change your choice at any time. The deactivation of certain cookies may affect the operation of the site. Details of the cookies placed are set out in our Cookie Policy.

Modifications and contact

Geremy.ai reserves the right to modify this policy at any time. Users will be informed of any significant changes.

Data protection contact: rgpd@geremy.ai
Address: Stellar Quantum SAS, Hamadryade Bât. 2, 55 allée Camille Claudel, 84000 Avignon

APPENDIX: Data Processing Agreement (DPA)

In accordance with Article 28 of Regulation (EU) 2016/679 (RGPD)

Preamble

The present agreement is concluded between Stellar Quantum SAS (“Subcontractor”) and the Customer within the meaning of the Terms and Conditions of Sale (“Data Controller”). The Data Controller retains control of the data it processes via the application.

Article 1 – Purpose, duration and termination

Subject: Audio transcription and report generation using artificial intelligence.

Duration: For the entire period of use of the services.

End: At the end of the trial or subscription period, the data is kept for two (2) years to enable the Data Controller to consult the data or take out a new subscription. At the end of this period, the data will be permanently deleted after thirty (30) days’ prior notice.

Before the end of the term, the Data Controller may retrieve its reports using the Service’s export functions; failing this, the data is deleted.

Deletion on request: The Data Controller may request the deletion of his Account and data at any time. Deletion takes place within 72 hours for a request handled by support, or within one week of validation for a request made from the customer area, this period allowing an accidental or fraudulent request to be cancelled. Billing data is kept in accordance with legal accounting and tax obligations.

Article 2 – Processed data

Identification data: surname, first name, e-mail, telephone (optional), SSO data.

Audio recordings: voice, processed solely for transcription purposes and automatically deleted once the report has been produced.

Transcripts and reports generated.

Connection data: logs (12 months maximum).

Persons concerned: Users and participants of recorded meetings.

Article 3 – Subcontractor’s obligations

The Subcontractor undertakes to process the data only in accordance with the instructions of the Data Controller.

The Subcontractor guarantees data confidentiality.

The Subcontractor implements appropriate security measures.

The Subcontractor assists the Data Controller with requests to exercise rights.

The Subcontractor shall notify any data breach within 48 hours.

The Subcontractor deletes the data at the request of the Data Controller — within 72 hours via support, or one week after validation from the customer area — or upon expiry of the two (2) year retention period after the end of the trial period or subscription.

The Subcontractor undertakes never to use the data to train AI models (permanent opt-out, active monitoring).

The Subcontractor guarantees strict partitioning of each account.

The Subcontractor informs the Data Controller if an instruction appears to it to be contrary to the RGPD.

Upon request, the Subcontractor provides its security white paper and the processing description sheet; this communication constitutes demonstration of compliance with the present agreement.

Article 4 – Security

Hosted in the European Union, encryption in transit (TLS 1.2 minimum, TLS 1.3 preferred) and at rest (AES-256), role-based access control, continuous monitoring and regular security testing.

Article 5 – Subsequent subcontractors

The Data Controller generally authorizes the use of subsequent subcontractors. The Subcontractor will inform of any changes.

Article 6 – Transfers

No data transfer outside the European Union.