GDPR at RecordX
Data location
All recordings, transcripts, summaries, and account data are stored in the European Union - specifically AWS
eu-central-1 in Frankfurt, Germany. We do not copy recordings across regions. EU/EEA data stays in
the EEA for storage and primary processing.
RecordX is operated by HRD, based in Israel. Israel holds an EU adequacy decision, so operational access to EU data from Israel does not require Standard Contractual Clauses under Article 46. For any sub-processor located outside the EU/EEA that is not covered by adequacy, we rely on the appropriate Article 46 mechanism.
Your rights under GDPR
Right of access (Art. 15)
Every recording, transcript, and summary tied to your account is available for you to view and export from the app. For structured exports beyond the app, email us.
Right to rectification (Art. 16)
Update your account details from Settings. For content corrections, edit or delete the item.
Right to erasure (Art. 17)
Delete individual recordings from the app. Delete your entire account from Settings, Account, Danger Zone. All personal data is permanently deleted within 30 days.
Right to portability (Art. 20)
Export your transcripts and summaries in a machine-readable format from the app.
Right to restrict / object (Art. 18 / 21)
Contact us at security@recordx.io to restrict specific processing or object to a lawful-basis processing activity.
Right to lodge a complaint (Art. 77)
You may lodge a complaint with your local supervisory authority. In Israel, that is the Privacy Protection Authority (הרשות להגנת הפרטיות).
Lawful basis
- Performance of contract (Art. 6(1)(b)) - for account data, audio processing, transcription, summaries, and billing.
- Consent (Art. 6(1)(a)) - for recording third parties (obtained by the recording user before each call - see the Combined Agreement).
- Legitimate interests (Art. 6(1)(f)) - for fraud prevention (Recital 47 recognises this as a legitimate interest), balanced against your rights.
- Legal obligation (Art. 6(1)(c)) - for billing record retention required by tax law.
What we do not do with your data
- We do not sell personal data.
- We do not use your audio, transcripts, or summaries to train AI models.
- We do not share your content with other customers.
- We do not use third-party analytics or tracking cookies.
Sub-processors
RecordX uses vendors under data processing agreements. The main ones:
- AWS (Frankfurt) - hosting, storage, managed identity, KMS.
- Meeting-bot provider - used only when you ask RecordX to send a bot to a Google Meet, Zoom, Microsoft Teams, or Webex call.
- Payment processors (Creem, Google Play, PayPal) - for billing only; we do not store card numbers.
The full sub-processor list is available on request.
Data Processing Agreement
If you are an EU controller and need a DPA with RecordX as processor under Article 28, email legal@recordx.io with subject "DPA request". We use a standard template that references SCCs where applicable.
Data breach notification
In the event of a personal data breach as defined by Article 33, we will notify the relevant supervisory authority within 72 hours where required, and affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms (Article 34).
Data Protection contact
For all data protection questions and data subject requests, email security@recordx.io. We respond within 30 days as required by Article 12.
Related reading: Security overview, Compliance overview, SOC 2, HIPAA, Privacy Policy.