Using Dot under UK GDPR and EU GDPR

For what Dot records in your meetings, your organisation is the controller and TELLME AI LIMITED is its processor, under a data processing agreement you can have before you sign. Those roles are the same under the UK GDPR and the EU GDPR. What differs is the region you may want your data stored in.

Last checked 29 September 2026.

At a glance

Controller of meeting contentYour organisation
Processor of meeting contentTELLME AI LIMITED, company number NI710572
Controller of accounts, billing, support and this websiteTELLME AI LIMITED
Data processing agreementAvailable before you sign, from support@hidot.ai
Where meeting data is storedThe region you choose: United Kingdom (London), European Union (Frankfurt) or United States (Northern Virginia)
Processed outside that regionTranscription at European endpoints for the UK region, and the AI models in the United States for every region. What goes where
Telling the people in the meetingThe person using Dot, from the desktop app. The meeting bot, where it is switched on, announces itself
Special category dataNot asked for, and never derived
Training AI models on your meetingsNever

Controller and processor

For what Dot records in a meeting, the organisation that uses Dot is the controller. It decides what is kept and for how long, within the limits the product enforces, and who in the organisation may use Dot and in what role. TELLME AI LIMITED is its processor: we handle that content on the organisation’s behalf and under its instructions, which it gives through Dot’s settings and the data processing agreement.

For people’s accounts, billing, support conversations and the hidot.ai website, TELLME AI LIMITED is the controller, and the privacy policy sets out what we collect, why, and the lawful basis for each.

Inside an organisation, a meeting is seen by the person who recorded it and the people they share it with. Administrators cannot open somebody else’s meeting unless it is shared with them.

The data processing agreement

The data processing agreement is the detail of that arrangement: what we process, on whose instructions, and with which sub-processors. It is available before you sign anything. Ask for it at support@hidot.ai, and say which region your organisation is in. The companies that process data for us, region by region, are on the sub-processors page.

UK GDPR, EU GDPR and where the data is

Everything Dot keeps is stored in the region your organisation chooses when it is created. The United Kingdom region is London and the European Union region is Frankfurt. London is not in the European Union, so an organisation that needs its data stored in the EU should choose the EU region.

Some processing happens outside the region while a meeting is dealt with. The audio of a UK organisation’s meetings is transcribed at the transcription service’s European endpoint. And for every region, the transcript, the questions and pictures of the shared screen go to AI models from Anthropic and OpenAI in the United States; the pictures are not kept. The data residency page sets out exactly what goes where, and the privacy policy sets out our terms for international transfers.

Telling the people in the meeting

Using Dot in a meeting means asking us to transcribe a conversation other people are part of. When Dot listens in from the desktop app it runs beside the call and shows the other people on it nothing, so telling them is up to the person using it, and in many places the law requires it. Your organisation is responsible for having the right to bring Dot into the meetings it brings it into, and for any consent its own rules or its regulator require.

Where Dot’s meeting bot has been switched on for an organisation, the bot announces itself as well: a message in the chat when it joins, a notice on its video tile for the whole meeting, and an email to the people invited the first time it is added to a recurring meeting. None of that is optional or can be switched off.

For the people in your meetings, a page of their own explains what Dot is, what it keeps, and how to object.

The rights of the people in your meetings

Under data protection law people may have the right to be informed, and the rights of access, rectification, erasure, objection, restriction of processing and data portability. For what Dot recorded in a meeting, the organisation that controls the meeting decides, and we help it act. A person who does not know which organisation that is can write to support@hidot.ai, without an account, and we will tell them.

Deleting a meeting deletes its transcript, its notes and the passages the search index took from it. Erasing an organisation deletes its meetings and its records, its audit log included.

What Dot does not process

We do not ask for special categories of personal data or for criminal offence data, and Dot never derives them. It keeps no voiceprint and never works out who somebody is from their voice, and it does not score anybody’s mood, engagement or tone. What people choose to say in a meeting is in its transcript, and the organisation that controls the meeting is responsible for it. We do not sell personal data, and we do not train AI models on your meetings.

Questions

Is TELLME AI the controller or the processor of meeting data?

The processor. For what Dot records in a meeting, the organisation that uses Dot is the controller and TELLME AI LIMITED processes it on that organisation’s behalf and under its instructions. For accounts, billing, support conversations and the hidot.ai website, TELLME AI LIMITED is the controller.

Is there a data processing agreement?

Yes. The data processing agreement sets out how TELLME AI LIMITED processes meeting data for an organisation, and it is available before anything is signed. Ask for it at support@hidot.ai.

Who tells the people in a meeting that Dot is there?

The person using Dot. When Dot listens in from the desktop app it shows the other people on the call nothing, so telling them is up to that person, and in many places the law requires it. Where Dot’s meeting bot has been switched on for an organisation, the bot announces itself as well: a message in the chat when it joins, a notice on its video tile for the whole meeting, and an email to the people invited the first time it is added to a recurring meeting.

How does somebody ask for their data to be deleted?

A request about what Dot recorded in a meeting goes to the organisation that used Dot in that meeting, because it controls the data, and TELLME AI LIMITED helps it act. Anybody can also write to support@hidot.ai, with or without an account, and will be told which organisation to ask.

Does TELLME AI train AI models on our meetings?

No. TELLME AI LIMITED does not train models on customers’ meetings, does not sell personal data, and does not read meeting content except where running the service or answering a customer’s request needs it.

Which regulator can I complain to?

In the United Kingdom, the Information Commissioner’s Office (ico.org.uk). In the European Union, the data protection authority of the country where you live or work. We would appreciate the chance to put things right first, at support@hidot.ai.