Security & Privacy
Privacy is a given here, not a feature.
GDPR-compliant, processed in the EU, audio never stored, no fine print. Everything verifiable in one place.
- GDPR-compliant
- EU processing
- DPA per Art. 28
- cookie-free
How we handle your data
← Swipe
Where we stand
No window dressing: what is met today — and what isn’t yet.
- GDPRCompliantCompliant
Data-subject rights per Art. 12–22. Audio and content stay in the EU: dictation audio on Apple-silicon Macs on your device, everything else on EU servers. Cookie-free by default.
Details in the privacy policy
- No data retention at the AI vendor (Zero Data Retention)ActiveActive
Our AI vendor does not store your inputs or outputs after processing and does not train on them — confirmed in writing, EU endpoint.
Confirmation of 2026-08-20, sub-processor list
- § 203 mode (professional secrecy)AvailableAvailable
For law, medical and tax practices: WhispaWave then stores no dictations at all. Organisations enforce the mode centrally.
Settings → Privacy; privacy policy section 10
- DPA per Art. 28AvailableAvailable
Data Processing Agreement for companies, firms and practices.
Right on the DPA page — applies automatically; countersigning on request
- ISO 27001In progressIn progress
No certificate. An ISO 27001 information security management system has been in build-up since 09/2026; certification is planned.
DPA § 10 and Annex 1
- SOC 2 / HIPAANot certifiedNot certified
Not certified, no programme running. We publish our technical and organisational measures instead.
DPA § 10 and TOM annex
- External penetration testPlannedPlanned
Not performed yet; an external test is planned. Until then: internal security audits and continuous monitoring.
DPA § 10
Documents & proof
The binding legal texts: always viewable, no request needed.
A privacy question not answered here?
Get in touch