Skip to content
WhispaWave

Security & Privacy

Privacy is a given here, not a feature.

GDPR-compliant, processed in the EU, audio never stored, no fine print. Everything verifiable in one place.

  • GDPR-compliant
  • EU processing
  • DPA per Art. 28
  • cookie-free

How we handle your data

← Swipe

  1. 01 / 07

    Processed in the EU

    Your dictation audio stays on your device on Apple-silicon Macs. Where the cloud does the work, such as conversation mode, audio and content run through servers in Germany / the EU: no detour via the US, no US vendor in the audio and content path. If you’re bound by professional secrecy, where your data lives is part of compliance, not a side note. You never have to explain why a client call shouldn’t end up in Virginia.

  2. 02 / 07

    Audio never stored, no training

    Audio is never stored: once recognised, it’s gone. Your text stays for 24 hours, permanently or not at all — you decide; organisations set it centrally. We never train AI on your data, and neither does our AI vendor. What you dictate stays yours and never becomes raw material for someone else’s model.

  3. 03 / 07

    GDPR-compliant

    Full data-subject rights per Art. 12–22, audio and content stay in the EU, cookie-free by default. No tracking, no consent-banner theatre. Privacy isn’t a feature bolted on afterwards here; it’s the ground everything runs on. Exactly the way it should be.

  4. 04 / 07

    DPA per Art. 28

    For companies, firms and practices we provide a Data Processing Agreement per Art. 28 GDPR right on the DPA page: the contractual basis your own compliance needs. No sales call, no hurdle. So you can fold WhispaWave cleanly into your data-protection documentation.

  5. 05 / 07

    Professional secrecy (§ 203)

    Built with confidentiality professionals in mind: law, medical, tax. Exactly the professions where a leaked word has real consequences. Client and patient data stays where it belongs: with you, not in someone else’s cloud.

  6. 06 / 07

    Confidentiality mode

    For professions bound by secrecy, there’s a confidentiality mode in which WhispaWave never stores your dictations in the first place. Maximum restraint when it matters. You decide per situation how much the system keeps at all. Confidentiality as a switch you flip yourself.

  7. 07 / 07

    Offline mode

    On Apple-silicon Macs, speech recognition runs right on your device, no cloud involved. Your audio never leaves your Mac; only the recognised text goes to our EU servers for polishing. Privacy here isn’t just a promise; it’s anchored in the architecture. What never leaves your machine can’t be intercepted anywhere.

Where we stand

No window dressing: what is met today — and what isn’t yet.

  • GDPRCompliant

    Data-subject rights per Art. 12–22. Audio and content stay in the EU: dictation audio on Apple-silicon Macs on your device, everything else on EU servers. Cookie-free by default.

    Details in the privacy policy

  • No data retention at the AI vendor (Zero Data Retention)Active

    Our AI vendor does not store your inputs or outputs after processing and does not train on them — confirmed in writing, EU endpoint.

    Confirmation of 2026-08-20, sub-processor list

  • § 203 mode (professional secrecy)Available

    For law, medical and tax practices: WhispaWave then stores no dictations at all. Organisations enforce the mode centrally.

    Settings → Privacy; privacy policy section 10

  • DPA per Art. 28Available

    Data Processing Agreement for companies, firms and practices.

    Right on the DPA page — applies automatically; countersigning on request

  • ISO 27001In progress

    No certificate. An ISO 27001 information security management system has been in build-up since 09/2026; certification is planned.

    DPA § 10 and Annex 1

  • SOC 2 / HIPAANot certified

    Not certified, no programme running. We publish our technical and organisational measures instead.

    DPA § 10 and TOM annex

  • External penetration testPlanned

    Not performed yet; an external test is planned. Until then: internal security audits and continuous monitoring.

    DPA § 10

A privacy question not answered here?

Get in touch