Privacy Notice
Last updated: 27 September 2026
1. Privacy at a glance
What this is about
This notice describes which personal data we process when you visit the website getdiscoverify.com and when you use the Discoverify application. Discoverify is a tool that companies use to record, transcribe and analyze customer interviews.
The key points
- Servers and storage are located at Hetzner in Germany.
- Transcription with speaker separation is handled by AssemblyAI via its EU endpoint. Voice recognition runs only on our own server.
- For answers, summaries and semantic search, we use AI models via Amazon Bedrock in the EU. The data is not used to train models.
- Payments are handled by Paddle as reseller (Merchant of Record). Payment data does not reach us.
- We do not use any analytics, tracking or advertising tools. The website only sets technically necessary cookies.
2. Hosting
The website and application run on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in data centers in Germany. Hetzner processes the data on our behalf (Art. 28 GDPR) on the basis of a data processing agreement. This includes all content of the application, the database, media files and backups. The legal basis is Art. 6(1)(b) GDPR (provision of the service) and Art. 6(1)(f) GDPR (our legitimate interest in secure, reliable operation).
3. General information and mandatory information
Controller
The controller for data processing on this website and for the processing described in section 5.1 is:
Make it Nice GmbH
An der Koppel 1, 53909 Zülpich, Germany
Managing Director: Martin Förster
Phone: +49 2252 8360-200
Email: talktous@getdiscoverify.com
You conclude the contract for the use of Discoverify with Make it Nice GmbH. For data protection requests, you can reach us at the email address above or by post.
Our role as processor
We process the content that our customers store in Discoverify (recordings, transcripts, statements, people, voice profiles) on behalf of the respective customer (Art. 28 GDPR). The customer is the controller for this data. The customer decides which interviews to record and obtains the necessary consent from the interviewees. If you are an interviewee and have questions about your data, please contact the company that conducted the interview. We support our customers in fulfilling your rights. We provide our customers with a data processing agreement.
Storage period
We store personal data only for as long as necessary for the respective purpose or as required by a statutory retention obligation. After that, it is deleted or anonymized. We state specific periods for the individual processing activities.
Legal bases
We process data on the basis of Art. 6(1)(b) GDPR (contract and pre-contractual measures), Art. 6(1)(c) GDPR (legal obligations), Art. 6(1)(f) GDPR (legitimate interests, explained in each case) and, where we ask for it, Art. 6(1)(a) GDPR (consent). Access to information on your device is governed by Section 25 TDDDG (German Telecommunications Digital Services Data Protection Act).
Recipients
Personal data is only received by:
- our processors: Hetzner Online GmbH (hosting, Germany), AssemblyAI Inc. (transcription, processing in the EU), Resend (Plus Five Five, Inc.; sending login and system emails, USA) and Amazon Web Services EMEA SARL (Amazon Bedrock, processing in EU regions), see section 5,
- Paddle as reseller for ordering, payment, subscription management, taxes and invoices, see section 6,
- advisors such as tax advisors, lawyers and auditors, where necessary,
- authorities, where we are legally obliged to disclose data or where this is necessary to protect rights.
Transfers to third countries
The application processes data in Germany and, for AI features, in EU regions of Amazon Web Services. Amazon Web Services EMEA SARL belongs to a US group. Access from the USA can therefore not be completely ruled out. The parent company is certified under the EU-U.S. Data Privacy Framework; in addition, the European Commission’s Standard Contractual Clauses apply. AssemblyAI Inc. is based in the USA; we use only the EU endpoint, so that, according to AssemblyAI, audio and transcripts are processed and stored in the EU. Access from the USA cannot be ruled out here either; AssemblyAI’s data processing agreement contains the European Commission’s Standard Contractual Clauses. For sending login and system emails, we use Resend (Plus Five Five, Inc., USA). The emails are sent from the EU region (Ireland); however, Resend stores metadata, logs and API data in the USA. Resend is certified under the EU-U.S. Data Privacy Framework; in addition, the data processing agreement contains the European Commission’s Standard Contractual Clauses. Paddle.com Market Limited is based in the United Kingdom, for which an adequacy decision of the European Commission exists. For purchases from the USA, Paddle.com Inc. (USA) is the contracting party.
Withdrawal of your consent
You can withdraw any consent you have given at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
Right to object (Art. 21 GDPR)
Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. We will then no longer process the data unless we demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defense of legal claims.
Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Kavalleriestr. 2–4, 40213 Düsseldorf, Germany.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21 GDPR). To exercise them, email us at talktous@getdiscoverify.com. We respond within one month; in complex cases, this period may be extended under Art. 12(3) GDPR.
Security and encryption
We protect data with technical and organizational measures. These include: transmission only in encrypted form via TLS (recognizable by “https://”), separation of customer data at database level, server access only via SSH keys, encrypted backups and role-based access controls. Details can be found in our Trust Center.
4. Data collection on this website
Server log files
When you access the website, our web server stores technical information in log files: IP address, date and time, requested address, HTTP status, amount of data transferred, browser and operating system (user agent). We remove login tokens and search terms from the addresses before storing them. We need the logs to secure operations and detect attacks (Art. 6(1)(f) GDPR). The logs are continuously overwritten and deleted after a few days to weeks, depending on volume.
Cookies and local storage
We only use technically necessary cookies and storage (Section 25(2) No. 2 TDDDG). No consent is required for this.
- Session cookie “discoverify_session”: keeps you logged in after login. It can only be read by the server (httpOnly), is only transmitted in encrypted form and expires after 30 days at the latest or when you log out.
- Language choice “dv_locale”: remembers whether you use the website and application in German or English. The cookie is only set when you actively choose a language (the website’s language switcher or language suggestion, the language setting in the application); after login, it takes over the language stored in your account. It contains only the value “de” or “en” and expires after one year.
- Display (local storage): your choice between light, dark or system theme. The value stays in your browser.
- Sign-in flow “discoverify_oidc_state” or “discoverify_teams_oauth”: only during a sign-in with Microsoft or Google, or while connecting to Microsoft Teams. They contain random values that protect the flow, can only be read by the server (httpOnly) and expire after a few minutes.
- Recording buffer (IndexedDB): during an on-site recording, the application stores audio chunks in your browser until they have been uploaded. They are deleted afterwards.
You can delete cookies and local storage in your browser at any time. Without the session cookie, login is not possible.
Inquiries by email or phone
If you contact us by email or phone, we process your details to handle your inquiry (Art. 6(1)(b) GDPR for contract-related inquiries, otherwise Art. 6(1)(f) GDPR). We delete the data once the inquiry has been dealt with and no retention obligation applies.
No analytics or advertising tools
We do not use web analytics, tracking, advertising pixels or social media plugins on this website or in the application. We serve fonts from our own server.
5. Use of the Discoverify application
5.1 Account and login
For an account, we process your email address, name (optional), role and membership of a workspace. You log in via magic link: we send you a link by email that is valid for 15 minutes and works only once. To protect against misuse, we count login attempts per email address (at most 5 in 15 minutes). After login, we store a session for at most 30 days. The legal basis is Art. 6(1)(b) GDPR; we base the prevention of misuse on Art. 6(1)(f) GDPR (protection of accounts). We delete account data when the account is deleted or the contract ends, unless a retention obligation applies.
Sign-in with Microsoft or Google. Alternatively, you sign in with your Microsoft or Google account (OpenID Connect), including at sign-up. There is no Discoverify password involved. We request only “openid email profile” from the provider and receive a signed ID token containing your email address, your name, the identifier of your account at the provider (Microsoft: object ID and the tenant ID of your organization; Google: account ID and, where applicable, the Workspace domain) and whether the provider has verified the email address. Of this, we store the link between your Discoverify account and the provider account (provider, issuer, account ID and the email address at the time of linking); we use the name only as the contact name when you sign up. We notify you by email of every new link. Here, too, we limit the number of login attempts. The legal basis is Art. 6(1)(b) GDPR, and Art. 6(1)(f) GDPR for the prevention of misuse. We delete the link together with your account. The sign-in at the provider itself is the provider’s responsibility and is governed by its privacy policy (Microsoft, Google). In the process, the provider learns that you are signing in to Discoverify.
5.2 Interviews, transcription and analysis (on behalf of the customer)
Customers upload audio, video or transcripts or record conversations in the browser. From these, the application generates transcripts, separates the speakers, extracts statements and answers questions with quotes. This involves processing voices, conversation content, names and metadata such as date, company and segment. Transcription and speaker separation are handled by AssemblyAI (see section 5.3). This processing is carried out on behalf of the customer, see section 3.
5.3 Transcription via AssemblyAI (EU)
To convert speech to text and separate the speakers, we send the audio data of an interview to AssemblyAI Inc., 169 Madison Ave STE 38365, New York, NY 10016, USA, as our subprocessor (Art. 28 GDPR). The data processed is the audio recording (voice and conversation content) and the resulting transcript with timestamps and speaker labels. We use only AssemblyAI’s EU endpoint; according to AssemblyAI, the data is processed and stored there in the EU (AWS region Dublin). After transcription, we request deletion of the audio at AssemblyAI. We store the transcript in the customer’s database at Hetzner. As with our other processors, the legal basis is Art. 6(1)(b) GDPR (provision of the service) or the customer’s instruction as controller. For the connection to the USA, see “Transfers to third countries”.
5.4 Voice profiles (biometric data)
So that Discoverify can recognize people in other recordings, the application computes mathematical features from the voice (voice embeddings) and combines them into a voice profile for each named person. These are biometric data within the meaning of Art. 9 GDPR. The voice features are computed exclusively on our server, not at AssemblyAI; voice profiles never leave it and are not part of the export. As controller, the customer requires the explicit consent of the persons concerned (Art. 9(2)(a) GDPR). Voice profiles can be deleted at any time. If a profile or a person is deleted, the application also removes the associated voice features in the interviews and remembers that this person should no longer be recognized. Voice features of unnamed speakers are deleted together with the respective interview.
5.5 AI features via Amazon Bedrock (EU)
For summaries, the extraction of statements, answers to questions and semantic search, we send text excerpts from transcripts to AI models that we use via Amazon Bedrock: Claude by Anthropic and an embedding model by Cohere. The provider is Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, as our processor. We use only EU inference profiles; processing therefore stays in AWS regions within the EU. We do not send audio to Bedrock. According to AWS, inputs and outputs are not shared with the model providers and are not used to train models. AWS may temporarily store inputs for abuse detection. We store the results (statements, summaries, answers) in the customer’s database.
5.6 Access via MCP (Claude Code, Claude Desktop)
Users can create personal access tokens to query their archive from Claude applications. We store only a hash of the token, its name and technical timestamps. Every call is logged without content (tool name and parameter names, no search terms) in order to detect misuse and enforce limits (Art. 6(1)(b) and (f) GDPR). The answers go to the user’s Claude application; their processing there is subject to the terms of the respective provider. Tokens can be revoked at any time.
5.7 Logs and usage data
The application logs security-relevant events (e.g. deletions and MCP calls) with IDs and counters, without conversation content. For limits, we count requests per workspace. Log entries are deleted after 30 days at the earliest. The legal basis is Art. 6(1)(f) GDPR (traceability and security).
5.8 Emails via Resend
We only send emails that are necessary for the service, mainly login links and system messages. We do not send newsletters or promotional emails. For sending, we use Resend, operated by Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA, as our processor (Art. 28 GDPR). The sender is login@mail.getdiscoverify.com. The data processed is your email address, the content of the email including the login link, and technical delivery data such as time and delivery status. The emails are sent from the AWS region eu-west-1 (Ireland); Resend stores metadata and logs in the USA (see “Transfers to third countries”). As with our other processors, the legal basis is Art. 6(1)(b) GDPR (login and provision of the service). A login link is valid for only 15 minutes and can be used only once.
5.9 Backups
We back up the database daily in encrypted form. Backups are automatically deleted after 30 days. Deleted data therefore also disappears from the backups after this period at the latest.
5.10 Import from Microsoft Teams (on behalf of the customer)
Users can import interviews from their own Microsoft Teams meetings. The source is the customer’s Microsoft 365 environment. Microsoft is not our processor for this: the customer stores its meetings with Microsoft itself, and Discoverify retrieves data from there at the user’s request. Processing at Microsoft is governed by the customer’s contract with Microsoft.
- Approval: Before users of a workspace can import, a workspace admin links the customer’s Microsoft 365 organization with Discoverify once. An administrator of the Microsoft 365 organization must also grant the required permissions. Workspace admins can revoke the approval at any time.
- Connection: The user signs in to Microsoft and grants Discoverify delegated access on their behalf (read profile, calendar, online meetings and their transcripts and recordings). Discoverify receives a short-lived access token whose validity is set by Microsoft, and no refresh token. We store the token in encrypted form and delete it as soon as no further import by this user is pending, when the user disconnects or the approval is revoked, and at the latest in the daily clean-up run after the token has expired.
- Meeting selection: To show the selection, Discoverify reads the user’s calendar events from the last 30 days (subject, start, end, Teams link) and checks, for online meetings the user organized, whether a recording or transcript exists. This list is not stored in the database, only held briefly in memory.
- Import: Only for meetings the user explicitly selects, and only after the user has confirmed that the participants were informed about the recording and its analysis in Discoverify, Discoverify downloads the Teams transcript with the speaker names from Teams, if available, and, if the user chose “re-transcribe recording”, also the recording. After that, the data is processed like an upload: the recording is transcribed via AssemblyAI in the EU (section 5.3), and speaker names from Teams appear only as suggestions. Discoverify does not delete anything in Microsoft 365; the import is an independent copy.
- Import record: For each meeting, we store a record with the meeting ID, title, date, company, type of import, status and the IDs of the transcript and recording, so that the same meeting is not imported twice. This record is deleted together with the imported interview, and at the latest with the user account or the workspace.
This processing is carried out on behalf of and on the instructions of the customer (Art. 28 GDPR, see section 3); insofar as it concerns the identifier of the Microsoft account and the prevention of misuse, it is based on Art. 6(1)(b) and (f) GDPR.
6. Payment provider Paddle
Ordering, payment, subscription management, taxes and invoices are handled by Paddle.com Market Limited, 30 Old Bailey, London EC4M 7AU, United Kingdom (for purchases from the USA, Paddle.com Inc.), as reseller (Merchant of Record). For this purpose, Paddle processes your payment and billing data as an independent controller; Paddle’s privacy policy applies. From Paddle, we receive customer and subscription IDs, the selected plan, the subscription status, billing periods and amounts and, where applicable, your email address in order to activate your subscription (Art. 6(1)(b) GDPR). We never receive card data. We retain billing-relevant data in accordance with the statutory periods (Art. 6(1)(c) GDPR, up to 10 years).
On the pricing page and in the billing settings, the application loads Paddle.js from Paddle’s servers in order to display prices in your currency and open the checkout. In doing so, your IP address is transmitted to Paddle. Paddle may use its own cookies or local storage in the checkout, for example for fraud prevention.
7. Changes
We update this notice when the service or the legal situation changes. The version published here applies.