Desktop Application Privacy Policy

Desktop Application Privacy Policy

Desktop Application Privacy Policy

Desktop Application Privacy Policy

Desktop Application Privacy Policy

Desktop Application Privacy Policy

Pamela AI Holding B.V. | Last updated: June 2025

Pamela AI Holding B.V. | Last updated: June 2025

1. Introduction and Contact Details

This privacy policy aims to transparently and comprehensively inform data subjects about the way Pamela AI Holding B.V. (hereinafter: "Pamela", "we", or "us") processes personal data, in accordance with the General Data Protection Regulation (GDPR), applicable Dutch implementing laws, and other relevant data protection legislation within the European Economic Area (EEA).

Pamela is based in the Netherlands and provides an AI-powered software solution that records conversations through system audio or microphone (without bot participation), transcribes, analyzes, and generates automated summaries and insights. We respect the privacy of our users and handle personal data with the utmost care.

For questions or requests, please contact: privacy@trypamela.ai

2. Data Protection Officer (DPO)

Pamela has appointed a Data Protection Officer responsible for monitoring privacy compliance. You can reach the DPO via: privacy@trypamela.ai

3. Definitions

The terms used in this policy carry the same meanings as those defined in Article 4 of the GDPR.

4. Scope

This policy applies to any processing of personal data by or under the responsibility of Pamela, whether automated or included in (or intended to be included in) a filing system.

5. Purposes of Processing

Pamela processes personal data solely for specific, explicit, and legitimate purposes, including:

  • Providing transcription, analysis, and summarization services via the Pamela software;

  • Optimizing the user experience and improving software performance;

  • Customer support, including responding to inquiries and complaints;

  • Internal administration, security, and compliance with legal obligations;

  • Profiling and speech analysis (such as tone or sentiment recognition) based solely on explicit consent;

  • Ensuring the security of our infrastructure and services.

6. Legal Bases

Pamela processes personal data on at least one of the following legal bases:

  • Performance of a contract to which the data subject is party;

  • Compliance with a legal obligation to which Pamela is subject;

  • Legitimate interests pursued by Pamela or a third party, provided such interests are not overridden by the rights and freedoms of the data subject;

  • Your explicit, informed, and unambiguous consent.

7. Source of Personal Data

Personal data processed by Pamela is collected directly from you, your employer, or generated through your use of our software.

8. Categories of Personal Data

Depending on your use of our services, we may process the following categories of personal data:

  • Identification data (e.g., name, email address, IP address, device, guests);

  • Audio data and transcripts;

  • Technical metadata and user interaction data;

  • Special categories of personal data voluntarily discussed during calls (e.g., health or sensitive information).

9. Sensitive Data

Pamela is not intended for processing medical, legal, or other regulated and/or sensitive data. If users voluntarily disclose sensitive data, such data is processed passively without classification. Pamela strongly advises against using the tool for high-risk or regulated scenarios.

10. Sharing with Third Parties

We engage third parties for data processing to support our services. These entities act as processors under Pamela’s responsibility and process data solely based on our instructions:

  • Deepgram (speech recognition)

  • Supabase (database and authentication)

  • Gemini (LLM)

  • Amazon Web Services (hosting and infrastructure)

All processors hold up-to-date security certifications such as ISO 27001 and/or SOC
2. Pamela itself does not currently hold formal certifications but maintains GDPR-compliant practices and adheres to industry best practices.

Processing outside the EEA is carried out only with appropriate safeguards in accordance with Article 46 GDPR.

11. Data Retention

Personal data is retained no longer than necessary for the purposes for which it was collected:

  • Account data: up to 30 days after account termination;

  • Audio recordings: Pamela does not store audio recordings, we stream and transcribe live;

  • Transcripts: default retention is 90 days unless otherwise agreed.
    After expiration, data is deleted or anonymized.

12. Data Subject Rights

You have the following rights under the GDPR:

  • Right of access to your data;

  • Right to rectification or completion;

  • Right to erasure (‘right to be forgotten’);

  • Right to restrict processing;

  • Right to data portability;

  • Right to object to processing;

  • Right not to be subject to solely automated decision-making.

To exercise these rights, contact privacy@trypamela.ai. We will respond within one month upon verifying your identity.

13. Refusal or Limitation of Requests

Pamela may deny or limit a request in specific cases, including:


  • Where necessary for national or public security;

  • For the prevention, investigation, or prosecution of criminal offenses;

  • In the context of ongoing legal proceedings;

  • Where requests are excessive or repetitive.

14. Complaints

If you are dissatisfied with our response, you may file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) via www.autoriteitpersoonsgegevens.nl.

15. Data Security

Pamela implements appropriate technical and organizational measures, including:

  • Encryption of data at rest and in transit;

  • Role-based access control (RBAC);

  • Audit logging and monitoring;

  • Hosting exclusively in AWS data centers within the EU;

  • Confidentiality obligations for staff and contractors;

  • Regular security audits and staff training.

16. Profiling and Speech Analysis

Speech analysis (e.g., tone recognition) is performed only with the user’s explicit consent. No decisions with legal or significant effects are made solely based on automated processing. Users may opt out at any time.

17. Use in Sensitive Contexts

Pamela is intended for general business use, such as sales, coaching, or project communication. It is not suitable for medical, legal, or other critical decision-making contexts. Use beyond this scope is at your own risk. Pamela disclaims liability for such uses.

18. Liability

Pamela’s output (e.g., transcripts and summaries) is generated via automated processing. While we strive for high accuracy, we do not guarantee error-free or complete results. Use of this output for decision-making is entirely at the user’s own risk. Pamela is not liable for damages resulting from the use of such data, including unintended processing of sensitive information.

19. Changes

We reserve the right to amend this privacy policy in response to legal or service changes. Please review this policy regularly.

Last updated: June 2025

Your meetings, fully captured. Zero effort.

AI-powered notes, summaries, and insights - all without bots or invites. Pamela works quietly in the background, so you don’t have to.

Your meetings, fully captured. Zero effort.

AI-powered notes, summaries, and insights - all without bots or invites. Pamela works quietly in the background, so you don’t have to.

Your meetings, fully captured. Zero effort.

AI-powered notes, summaries, and insights - all without bots or invites. Pamela works quietly in the background, so you don’t have to.

Your meetings, fully captured. Zero effort.

AI-powered notes, summaries, and insights - all without bots or invites. Pamela works quietly in the background, so you don’t have to.