Privacy Policy

Last updated: 24 July 2026

This Privacy Policy explains how thinkIT Limited ("thinkIT", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you use noteIT (the "Service"), including our websites, applications, APIs, meeting bots, and related emails.

We designed this policy to meet the requirements of the EU/UK General Data Protection Regulation (GDPR) and comparable privacy laws. If you use noteIT on behalf of an organisation, that organisation may act as an independent or joint controller for meeting content it captures; see Roles and responsibilities below.

1. Who we are (data controller)

For account, billing, website, and platform-operation data, the controller is:

thinkIT Limited
Product: noteIT
Website: https://thinkit.africa
Privacy / legal: we@thinkit.africa

Where an organisation customer uses noteIT to record meetings, generate notes, or manage tasks about its workforce or guests, that organisation typically determines the purposes of that meeting content and is a controller (or joint controller) for that content. thinkIT then processes that content as a processor on the organisation's documented instructions, except where we process it for our own platform security, abuse prevention, or legal obligations.

2. Roles and responsibilities

  • Organisation admins and meeting hosts must have a lawful basis to capture meetings, inform participants, honour opt-outs or exclusion requests, and configure retention consistent with their policies.
  • Users must only upload or connect content they are authorised to process (calendar, files, guest lists, recordings).
  • thinkIT provides the Service with tenant isolation, access controls, and tools for export/deletion subject to the organisation's settings and the Terms of Use.

3. Data we collect

Depending on how you use noteIT, we may process:

  • Account and profile data — name, email, password hash, organisation membership, roles, preferences, email verification status.
  • Organisation data — organisation name, domains, settings, consent text, retention settings, billing contacts where applicable.
  • Meeting and collaboration content — meeting metadata, participants, calendar event details you sync, live captions, audio/video recordings you choose to capture, transcripts, summaries, decisions, proposed actions, tasks, comments, and related files.
  • Connected service data — tokens and calendar metadata when you connect Google Calendar (or similar) via OAuth; we store what is needed to sync and schedule, not your Google password.
  • Communications — support emails, in-product notifications, and service emails (verification, notes delivery, reminders).
  • Usage and technical data — IP address, device/browser type, app logs, performance and security events. We do not put full transcript bodies in HTTP access logs.
  • Ask noteIT / knowledge queries — questions you ask, conversation history, and retrieved citations needed to answer you.

We do not create biometric voiceprints or use facial emotion recognition. Personal coaching insights, where offered, are private by default and must not be used for disciplinary decisions.

4. Purposes and legal bases (GDPR Art. 6)

PurposeExamplesTypical legal basis
Provide the ServiceAccounts, meetings, transcripts, Workboard, Ask noteIT, notificationsContract (Art. 6(1)(b)); organisation's legitimate interests / employment context as applicable
Recording & AI notesCapture audio, transcribe, summarise, extract actionsOrganisation's lawful basis (often legitimate interests or consent of participants — host responsibility); our processing under contract / processor instructions
Security & abuse preventionAuth, audit logs, fraud/misuse detectionLegitimate interests (Art. 6(1)(f)); legal obligation where required
Service emailsVerification, password reset, meeting notes, remindersContract; legitimate interests
Product improvementAggregated reliability metrics; optional feedback you send usLegitimate interests; consent where we ask for optional research use
Legal complianceRespond to lawful requests, enforce termsLegal obligation (Art. 6(1)(c)); legitimate interests

Where we rely on legitimate interests, we balance those interests against your rights and freedoms. You may object as described in Your rights.

5. Recording and transcription (consent & notice)

noteIT can join meetings (for example via a bot), capture audio, stream captions, and produce transcripts and notes. Recording is a sensitive processing activity. We require an in-product confirmation before capture starts that participants have been informed. Organisation consent text is configurable and start/stop events are audited.

Before anyone starts capture, hosts should:

  • Tell participants the meeting will be recorded and/or transcribed.
  • Explain the purpose (for example: notes, action tracking, organisational knowledge, follow-up work).
  • Identify noteIT / thinkIT as the technology provider and point to this Privacy Policy and the Terms of Use.
  • Provide a practical way to object, leave, or continue without capture when required by law or policy, and note exclusion requests where appropriate.
  • Comply with local rules (including one-party vs all-party consent jurisdictions) and workplace consultation obligations.

Participants who believe a recording should not proceed should raise that with the host or organisation admin. Organisation admins can set retention for recordings versus transcripts independently where the Service supports it.

6. AI processing

To transcribe audio and draft notes, summaries, and answers, we use subprocessors that provide AI services (currently including OpenAI under our server-side API keys). Audio and text snippets necessary for a job may be transmitted to those providers to produce outputs that are stored back in your organisation's tenant.

  • We do not operate a shared "master brain" that trains one customer's model on another customer's meetings.
  • Ask noteIT retrieves content you are permitted to see (for example meetings you hosted or joined) and synthesises answers with citations; chat threads are stored per user.
  • AI outputs can be wrong or incomplete. Treat them as assistance and verify important decisions.

7. Sharing and processors

We do not sell personal data. We share data only with:

  • Service providers (processors) — hosting, storage, email delivery, AI transcription/summarisation, error monitoring, and similar infrastructure under contracts that require confidentiality and GDPR-appropriate terms.
  • Connected apps you authorise — e.g. Google Calendar OAuth; their use of data is also governed by their policies.
  • Organisation administrators — who manage members, retention, and access within your tenant.
  • Professional advisers and authorities — where required by law or to protect rights, safety, and the Service.
  • Successors — in a merger, acquisition, or restructuring, subject to continued protection consistent with this policy.

8. International transfers

noteIT may process data in countries outside your own, including where our subprocessors operate. Where GDPR applies to a transfer from the EEA/UK to a third country, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs), UK addenda where required, and supplementary measures as needed. Contact us for more detail on current subprocessors and transfer mechanisms.

9. Retention

We keep personal data only as long as needed for the purposes above, including:

  • Account data — for the life of the account, then a short wind-down period unless a longer legal hold applies.
  • Recordings, transcripts, and notes — according to organisation retention settings and deletion/export requests, subject to backups and legal holds.
  • Security and audit logs — for a limited period appropriate to investigate incidents and demonstrate compliance.

Organisation admins and authorised users may request export or deletion via product tools or by emailing we@thinkit.africa.

10. Security

We apply technical and organisational measures appropriate to the risk, including tenant isolation by organisation, access control (RBAC), hashed passwords, secure session cookies, encrypted transport, and signed storage access. No method of transmission or storage is perfectly secure; please use strong credentials and report suspected incidents promptly to we@thinkit.africa.

11. Your rights (GDPR)

If the GDPR (or UK GDPR) applies to you, you may have the right to:

  • Access — obtain confirmation and a copy of personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion in certain circumstances.
  • Restriction — limit processing in certain circumstances.
  • Portability — receive data you provided in a structured, commonly used format where processing is based on contract or consent and is automated.
  • Object — object to processing based on legitimate interests, including profiling of that kind.
  • Withdraw consent — where processing is based on consent, without affecting prior lawful processing.
  • Complain — lodge a complaint with a supervisory authority (for example your local EU/EEA DPA or the UK ICO). We encourage you to contact us first so we can help.

To exercise rights, email we@thinkit.africa with enough detail to verify your identity and locate the data. If your data is held because your employer or another organisation uses noteIT, we may need to route the request to that organisation as controller.

12. Cookies and similar technologies

We use essential cookies and similar storage for authentication, security (including CSRF protection), and keeping you signed in. These are required to operate the Service. If we introduce optional analytics or marketing cookies, we will update this policy and obtain consent where required.

13. Children

noteIT is built for workplace and professional use. It is not directed at children under 16 (or the higher age required in your country). We do not knowingly collect personal data from children. If you believe a child has provided data, contact we@thinkit.africa and we will take appropriate steps.

14. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Material changes may also be notified in-product or by email where appropriate. Continued use after the effective date means you acknowledge the updated policy.

15. Contact

Privacy, data-subject requests, and security notices:

we@thinkit.africa
thinkIT Limited — thinkit.africa

Related: Terms of Use

Home