GDPR: how Whisper protects your data

A plain-language explanation of how Whisper processes data under the GDPR — and why your data is never used to train AI models.

Updated: 11 June 2026

GDPR: how Whisper protects your data

Protecting data — yours and your customers' — is our top priority. Here is a plain-language summary of what happens to data inside Whisper. It is based on our Terms of Service, Privacy Policy, and Data Processing Agreement (DPA), which are binding for us.

Who is responsible for the data#

Under the GDPR, the roles are clearly split:

  • You are the data controller — you decide what data is processed and for what purpose.
  • Whisper is the data processor — it processes data on your behalf and only according to your instructions.

This relationship is governed by the Data Processing Agreement (DPA) you enter into when you create your account. The DPA is built directly on the requirements of Article 28 of the GDPR.

Your data does not train AI models#

This is the most common concern — and the answer is unambiguous: we do not use your data to train general-purpose AI models.

  • The content of your communication (emails, messages, transcripts, drafts) is not used to train, fine-tune, or improve general-purpose AI models for third parties or the public.
  • We may use data only to improve the configuration specifically for you — for example, prompt tuning and context retrieval within your workspace.
  • The same commitments apply to the AI model providers we use (e.g. Anthropic, OpenAI, Google) — data sent through their APIs is not used to train their models.

What data we process and why#

We only process data that is needed to provide the service. The exact scope is described in the appendix (Schedule 1) of our DPA:

  • Communication content — emails (body, attachments, headers), messages, voice recordings, transcripts, drafts, calendar entries.
  • Business context — data from connected systems (CRM, ERP, e-shop) that you authorize.
  • Metadata — sender and recipient, timestamps, subject lines.
  • Authorized users — name, email, job title, credentials.

The purpose is a single one: to provide you with a working service for customer support and communication. We never sell data to third parties.

Sub-processors#

To run the service, we work with carefully selected vendors (e.g. cloud infrastructure and AI model providers). Each of them is contractually bound to the same level of protection that we guarantee.

  • The current list of sub-processors is available at letswhisper.ai/subprocessors.
  • We notify you in advance about any new sub-processors, and you have the right to object.
  • When data is transferred outside the EU/EEA, we rely on appropriate safeguards (e.g. the EU-U.S. Data Privacy Framework).

Security and independent audits#

We protect data with technical and organizational measures under Article 32 of the GDPR:

  • Encryption — data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Access control — strict role-based access control (RBAC) and mandatory multi-factor authentication (MFA) for our team.
  • Minimization — we access data only when necessary for security or your explicit support request.
  • Independent security audits — to connect with Google accounts, we have successfully passed the Google CASA (Cloud Application Security Assessment) audit.
  • Backups — encrypted backups in a separate zone and regular security reviews.

You stay in control of your data#

  • Your customers' rights (access, rectification, erasure, portability…) — we help you fulfil them with the appropriate technical measures.
  • Data deletion — you can request permanent deletion of your organization and all data at any time. See Data and Privacy for details.

Back to home