PricingContact

Legal

Privacy Policy

Last updated: July 2026

1. Who We Are

AfterTalk (“AfterTalk”, “we”, “our”, “us”) is a Polish-first call analytics platform that helps phone teams transcribe, analyse, and understand their conversations. AfterTalk is the trading name of Kacper Kądziołka, a sole proprietorship (jednoosobowa działalność gospodarcza) registered in the Central Register and Information on Economic Activity (CEIDG) of the Republic of Poland.

Registered address: ul. Czerwone Maki 31B/21, 30-392 Kraków, Poland
NIP: 6762706032 · REGON: 543141869
Contact: privacy@aftertalk.co

We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR/RODO) and applicable Polish law. We have not appointed a Data Protection Officer, as this is not currently required under Article 37 GDPR given the scale of our processing.

2. Our Two Roles: Controller and Processor

AfterTalk acts in two different roles depending on the type of data:

  • Controller: for your account, billing, and usage data. This Policy describes how we process that data.
  • Processor: for the audio recordings, transcripts, and related content you upload (“Customer Content”). You, or the organisation you represent, remain the controller of that data, and we process it only on your instructions, as described in our Data Processing Agreement (see Section 12).

If you are an individual whose call was recorded by one of our customers and you have a question about that recording, please contact that organisation directly. AfterTalk does not have a direct relationship with you and will assist our customer in responding to your request.

Our customers are responsible for having a lawful basis to record and upload calls, and for providing any notice required by law to the people on those calls.

3. What Data We Collect

Account data

When you register, we collect your email address and a hashed password. We never store plain-text passwords.

Audio recordings and transcripts

You upload audio files (call recordings) to the platform. We process these to generate transcripts, sentiment scores, topic tags, and other analytics. Audio files are stored encrypted and remain associated with your project.

Usage data

We collect standard server logs (IP address, browser type, pages visited, timestamps) to operate, secure, and improve the Service. Where necessary to protect the Service, we may block access from specific IP addresses and retain a record of those blocks for security and abuse prevention.

For security and abuse prevention we also keep an audit log of security-relevant events — such as sign-in attempts and administrative actions taken on an account — recording the event, the IP address and browser (user-agent) involved, and a timestamp. We retain these records for as long as needed for security and to meet our legal obligations.

We also use PostHog, an EU-hosted product analytics service, to understand how the Service is used: which pages are visited, basic device and browser information, and the referring site. When you are signed in, these events are linked to your account (user ID and email address); events from visitors who are not signed in are not linked to any profile. Our analytics runs in cookieless mode and stores no identifiers on your device (see Section 8).

Billing data

Payment processing is handled by Stripe, our third-party payment provider, which acts as merchant of record for paid subscriptions. Stripe collects and processes your payment details directly under its own privacy policy; we store only transaction references and plan information, never full card numbers.

4. How We Use Your Data

We process your data for the following purposes:

  • Providing the Service: account creation, authentication, transcription, and analytics (necessary to perform our contract with you).
  • Transactional communications: account activation, billing receipts, and service notices (necessary to perform our contract with you).
  • Security and service improvement: detecting abuse, monitoring performance, and improving the platform, including through the product analytics described in Section 3 (our legitimate interest in keeping the Service safe, reliable, and useful).
  • Legal and accounting obligations: for example, retaining invoices as required by Polish law (legal obligation).

We do not sell your personal data, and we do not use your audio recordings or transcripts to train AI models shared across customers.

5. AI-Powered Analysis

We use automatic speech recognition and AI/machine-learning models to generate transcripts, sentiment indicators, topic categorisation, and quality or template scores from Customer Content (“AI Output”).

This is automated processing of conversation content. AfterTalk does not itself make any automated decision that produces legal or similarly significant effects on an identifiable individual. Where AI Output is used to evaluate or make decisions about people (for example, an employee's call performance), that decision is made by our customer, who acts as controller for that purpose.

AI Output is generated probabilistically and may contain errors. See our Terms of Service for important limitations on AI Output.

6. GDPR/RODO Compliance, PII Anonymisation & Voice Data

AfterTalk provides automatic PII (Personally Identifiable Information) detection and anonymisation for transcripts, e.g. replacing names, phone numbers, PESEL numbers, and other identifiers with placeholders. Whether and to what extent this feature is applied depends on each customer's project configuration; the customer, as controller of Customer Content, decides how they use the Service.

AfterTalk analyses the content of transcribed conversations (e.g. topics, sentiment, quality scores). We do not create voiceprints, perform voice or speaker biometric identification, or otherwise process voice as biometric data for the purpose of uniquely identifying any individual within the meaning of Article 9 GDPR.

Default speaker labels used in transcripts (e.g. “Speaker 1”, “Agent”) are not biometric identifiers. Customers can configure their own labels, including assigning the names of specific individuals; that configuration and its legal basis form part of Customer Content, for which the customer is responsible as controller (see Section 2).

7. International Data Transfers

Some of our sub-processors may be located outside the European Economic Area (EEA), including in the United States. Where this is the case, we rely on one of the following safeguards required by Chapter V GDPR:

  • the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework (Art. 45 GDPR), for recipients certified under that framework; or
  • the European Commission's Standard Contractual Clauses (Art. 46 GDPR), together with appropriate supplementary measures, for other recipients.

Our PII anonymisation feature (Section 6), where applied, further reduces the risk associated with any such transfer. You can request more information about the safeguards that apply to a specific transfer by emailing privacy@aftertalk.co.

8. Cookies

We use a small number of cookies that are strictly necessary for the Service to operate:

  • at and rt, authentication tokens that keep you signed in.
  • NEXT_LOCALE: remembers your preferred language (English or Polish).

These cookies are exempt from consent requirements under Polish law (Art. 399(3) of the Law on Electronic Communications), as they are necessary to provide a service you have explicitly requested. We do not currently use analytics, advertising, or marketing cookies. If this changes, we will ask for your consent before setting any such cookies.

Our product analytics (see Section 3) runs in cookieless mode: it does not set cookies and does not store any identifiers on your device.

9. Data Retention

  • Audio files: retained for as long as your project exists, and deleted within 30 days of project deletion.
  • Transcripts and analytics: retained for the lifetime of your account, and deleted upon account deletion.
  • Account data: retained until you delete your account or request erasure.
  • Billing records: retained for 5 years, as required by Polish accounting law.

10. Your Rights

Under GDPR/RODO, you have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate data;
  • request erasure (“right to be forgotten”);
  • object to processing, or request its restriction;
  • receive your data in a portable, machine-readable format; and
  • lodge a complaint with the Polish data protection authority (Urząd Ochrony Danych Osobowych, “UODO”).

To exercise any of these rights regarding your account data, email privacy@aftertalk.co. We will respond within 30 days. If your request relates to a call recorded by one of our customers, please contact that organisation directly. We will assist them in responding to you.

11. Data Security & Sub-processors

All data is transmitted over HTTPS. Audio files and transcripts are encrypted at rest. We apply access controls so that only authorised personnel can access your project data, and we conduct regular security reviews.

We use a limited number of sub-processors to operate the Service, such as cloud hosting, speech-to-text and AI analysis, email delivery, product analytics, and payment processing. Each sub-processor is contractually bound to process data only on our instructions, to apply appropriate security measures, and to comply with GDPR. A current list of sub-processors, including their location and any applicable transfer safeguard, is available on request by emailing privacy@aftertalk.co.

12. Data Processing Agreement

For Customer Content that contains personal data, we act as a processor on your behalf under a Data Processing Agreement (DPA) that reflects the requirements of Article 28(3) GDPR, including the scope and purpose of processing, confidentiality, security measures, sub-processing, and assistance with data-subject requests and deletion on termination. A copy of our DPA is available on request by emailing privacy@aftertalk.co.

13. Changes to This Policy

We may update this policy from time to time. Material changes will be notified by email or an in-app banner at least 14 days before they take effect.

14. Contact

Questions about this policy or how we handle your data? Email privacy@aftertalk.co.

Polish-first AutoQA for phone teams.
From recording to insight in minutes.

PricingContactPrivacyTerms

Copyright © Aftertalk 2026