HeyDiane processes recorded conversations with AI — systematic processing of potentially sensitive spoken content, including the voices of third parties who are not HeyDiane users. That combination warrants a DPIA under Art. 35 GDPR. This document is the published summary of that assessment.
Customers upload or connect audio recordings. The platform verifies the media, transcribes it with speaker detection, generates summaries, timelines and suggested actions, answers questions grounded in the transcript with playable citations, and renders documents on request. All storage and AI inference happen in the EU (see Trust Center for locations and providers). Recordings are processed once per pipeline stage; there is no continuous analysis, no advertising use, and no training of AI models on customer content.
| Risk | Assessment |
|---|---|
| Conversations contain sensitive content (health, finances, opinions) | Likely in normal use; impact high if disclosed. |
| Third-party participants are recorded without awareness | Possible; the customer controls recording. Impact medium–high. |
| Unauthorized cross-tenant access | Impact high; likelihood low (forced RLS, per-request authorization, tested denial paths). |
| Credential theft for connected cloud accounts | Impact high; likelihood low (application-level encryption, key outside DB). |
| Provider access outside the EU | Content path is EU-only; residual intra-group scenarios at infrastructure providers are covered by SCCs. Likelihood low. |
| AI output errors (wrong attribution in transcripts or summaries) | Possible; mitigated by citation validation against the actual transcript, visible speaker labels, and full user correction ability. |
The complete catalogue is the TOMs document: EU-only content path, forced tenant isolation in the database, encryption in transit / at rest / at application level for credentials, immediate and complete deletion, scrubbed metadata, audit trail, sub-processors under Art. 28 agreements with no-training guarantees from every AI provider (Mistral, Google, Microsoft Azure OpenAI).
Responsibility split: the customer, as controller, is responsible for the lawfulness of recording a conversation (information/consent of participants under applicable law); HeyDiane provides the deletion and export tooling to honor participants' rights (DPA §6).
HeyDiane makes no automated decisions with legal or similarly significant effect on data subjects. AI output is informational, visibly AI-generated, grounded in the user's own recordings, and fully editable or deletable by the user.
With the measures in place, the residual risk for data subjects is assessed as low. No prior consultation of a supervisory authority under Art. 36 is required. This assessment is revisited on every material change to providers, storage locations or AI processing, and at least annually.
Questions, objections or requests: info@heydiane.ai