Dactylo Privacy Policy

Last updated: July 15, 2026

General overview

Dactylo is a SaaS tool for generating meeting reports from audio files, developed and operated by Magic LEMP, a French company whose registered office is located at 40 Rue de la Gare, 94110 Arcueil, France.

This Privacy Policy transparently describes how we collect, use, store and protect the personal data of Dactylo service users, in accordance with the General Data Protection Regulation.

Data collected and retention

We collect only the data strictly necessary to provide and improve the Dactylo service.

  • Account data (email address, credentials, preferences) is retained for the duration of the contract, then deleted 30 days after termination.
  • Recording data (audio, transcriptions) is retained for the duration of the contract, with the option to delete it immediately at any time.
  • Connection data (connection logs and service usage statistics) retained for 12 months for analysis and security.

Google and Microsoft calendar integration

Dactylo offers optional integration with Google Calendar and Microsoft Outlook Calendar. It allows the user to (i) enable automatic transcription of certain meetings scheduled in their calendar, (ii) view upcoming meetings in Dactylo, and (iii) schedule new meetings (with a Google Meet video conference link) directly from Dactylo, while viewing participants' availability (free/busy).

Enabling this integration relies exclusively on the user's explicit consent (via Google or Microsoft's OAuth authorization screen). The user may revoke it at any time, either by disconnecting their calendar in Dactylo or from their Google account security settings (myaccount.google.com/permissions).

As part of this integration, Dactylo accesses only the calendar data strictly necessary for the described features to work:

  • Reading events: title, start and end date and time, list of participants, description, video conference link — to display upcoming meetings and identify those eligible for automatic transcription;
  • Creating and managing events: only for meetings the user explicitly creates from Dactylo (invitations are sent to participants by Google Calendar);
  • Availability (free/busy): only busy intervals from consulted calendars, without access to the content of the corresponding events, to help choose a meeting slot.

OAuth access tokens associated with this integration are stored encrypted at rest. Calendar data and tokens are deleted when the user disconnects their calendar or deletes their account.

For automatic meeting recording, Dactylo relies on the provider Recall.ai, acting as a processor within the meaning of the GDPR, which is entrusted with synchronizing events from the connected calendar. Apart from this processor strictly necessary for the service, data from Google and Microsoft calendars is never sold, never used for advertising purposes, never used to train AI models, and never shared with third parties. No human accesses this data except upon explicit user request (support), legal obligation or security imperative.

Dactylo's use of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

Dactylo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Purposes of processing

Personal data collected is processed for the following purposes:

  • Providing automatic transcription and reformulation of audio files
  • Generating, storing and delivering the reports requested by the user
  • Improving the quality, performance and reliability of the service
  • Ensuring security, maintenance and technical monitoring of the platform
  • Communicating with you regarding your account, subscription or the service
  • Complying with our legal and regulatory obligations

We never use user content to train our models.

Legal basis for processing

Processing of your data is based on the following legal grounds:

  • Performance of a contract: access to and use of the service.
  • Legitimate interest: improving service quality, limited and justified analysis.
  • Compliance with legal obligations: such as invoice retention.

Processing modes

The Dactylo service offers two processing options, adapting to needs and preferences regarding performance and data protection:

Secure Mode

In this mode, all artificial intelligence (AI) processing is performed via an open-source model running on a Scaleway instance located entirely within the European Union (EU). The main characteristics of this mode include:

  • User data never leaves Scaleway's infrastructure.
  • No international transfer of data is performed; it remains strictly hosted in the EU.
  • No third-party provider has access to submitted content.

This mode ensures optimal data sovereignty and protection.

Performance Mode

For enhanced performance and analysis quality, Dactylo uses Google Cloud services under Performance Mode. This mode has the following specifics:

  • Processing: Data may be transferred to servers located outside the EU, including in the United States.
  • Protection guarantees: These international transfers are governed by Standard Contractual Clauses approved by the European Commission, and benefit from the EU-US Data Privacy Framework safeguards.
  • Role of Google Cloud: Google acts as a processor in accordance with the GDPR. A Data Processing Addendum (DPA) is in place to ensure legal and technical compliance.
  • Enhanced confidentiality: With a paid quota, Google does not reuse your data to train its models.
  • Security and legal compliance: Certain data may be temporarily logged for abuse detection or compliance with legal obligations.

Users are free to choose between these two modes according to their preferences regarding performance and data protection. This flexibility allows the service to be adapted to different privacy and performance requirements.

Data hosting

Data is hosted exclusively within the European Union by our provider:

Scaleway SAS, whose servers are located in France (EU).

Scaleway acts as a processor within the meaning of the GDPR and guarantees security measures compliant with European standards.

Data security

Magic LEMP implements appropriate technical and organizational measures to ensure the confidentiality, integrity and availability of data:

  • Encryption of communications (HTTPS/TLS)
  • Restricted server access and secure authentication
  • Ongoing review of compliance and security incidents.

User rights

To exercise your rights (access, rectification, erasure, restriction, portability), contact contact@dactylo.tech. You may also lodge a complaint with the CNIL.

Compliance with the European Artificial Intelligence Regulation (AI Act)

We use AI models classified as GPAI (General-Purpose AI).

We guarantee:

  • transparency regarding the use of AI
  • no training on your data
  • responsible and non-discriminatory use
  • human oversight at all times
  • prohibition on submitting sensitive or prohibited data

Our models do not fall under the "high-risk AI" category.

Cookies and measurement tools

The Dactylo site uses cookies strictly necessary for the operation of the service (authentication, session, security). No advertising or third-party tracking cookies are placed without your prior consent.

Changes to this policy

We may update this Privacy Policy to reflect legal, technical or functional changes. Any material change will be notified visibly on our website or by email.

Contact

For any question regarding this policy or your personal data: contact@dactylo.tech