Legal
Last updated: July 2026
AfterTalk (“AfterTalk”, “we”, “our”, “us”) is a Polish-first call analytics platform that helps phone teams transcribe, analyse, and understand their conversations. AfterTalk is the trading name of Kacper Kądziołka, a sole proprietorship (jednoosobowa działalność gospodarcza) registered in the Central Register and Information on Economic Activity (CEIDG) of the Republic of Poland.
Registered address: ul. Czerwone Maki 31B/21, 30-392 Kraków, Poland
NIP: 6762706032 · REGON: 543141869
Contact: privacy@aftertalk.co
We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR/RODO) and applicable Polish law. We have not appointed a Data Protection Officer, as this is not currently required under Article 37 GDPR given the scale of our processing.
AfterTalk acts in two different roles depending on the type of data:
If you are an individual whose call was recorded by one of our customers and you have a question about that recording, please contact that organisation directly. AfterTalk does not have a direct relationship with you and will assist our customer in responding to your request.
Our customers are responsible for having a lawful basis to record and upload calls, and for providing any notice required by law to the people on those calls.
When you register, we collect your email address and a hashed password. We never store plain-text passwords.
You upload audio files (call recordings) to the platform. We process these to generate transcripts, sentiment scores, topic tags, and other analytics. Audio files are stored encrypted and remain associated with your project.
We collect standard server logs (IP address, browser type, pages visited, timestamps) to operate, secure, and improve the Service. Where necessary to protect the Service, we may block access from specific IP addresses and retain a record of those blocks for security and abuse prevention.
For security and abuse prevention we also keep an audit log of security-relevant events — such as sign-in attempts and administrative actions taken on an account — recording the event, the IP address and browser (user-agent) involved, and a timestamp. We retain these records for as long as needed for security and to meet our legal obligations.
We also use PostHog, an EU-hosted product analytics service, to understand how the Service is used: which pages are visited, basic device and browser information, and the referring site. When you are signed in, these events are linked to your account (user ID and email address); events from visitors who are not signed in are not linked to any profile. Our analytics runs in cookieless mode and stores no identifiers on your device (see Section 8).
Payment processing is handled by Stripe, our third-party payment provider, which acts as merchant of record for paid subscriptions. Stripe collects and processes your payment details directly under its own privacy policy; we store only transaction references and plan information, never full card numbers.
We process your data for the following purposes:
We do not sell your personal data, and we do not use your audio recordings or transcripts to train AI models shared across customers.
We use automatic speech recognition and AI/machine-learning models to generate transcripts, sentiment indicators, topic categorisation, and quality or template scores from Customer Content (“AI Output”).
This is automated processing of conversation content. AfterTalk does not itself make any automated decision that produces legal or similarly significant effects on an identifiable individual. Where AI Output is used to evaluate or make decisions about people (for example, an employee's call performance), that decision is made by our customer, who acts as controller for that purpose.
AI Output is generated probabilistically and may contain errors. See our Terms of Service for important limitations on AI Output.
AfterTalk provides automatic PII (Personally Identifiable Information) detection and anonymisation for transcripts, e.g. replacing names, phone numbers, PESEL numbers, and other identifiers with placeholders. Whether and to what extent this feature is applied depends on each customer's project configuration; the customer, as controller of Customer Content, decides how they use the Service.
AfterTalk analyses the content of transcribed conversations (e.g. topics, sentiment, quality scores). We do not create voiceprints, perform voice or speaker biometric identification, or otherwise process voice as biometric data for the purpose of uniquely identifying any individual within the meaning of Article 9 GDPR.
Default speaker labels used in transcripts (e.g. “Speaker 1”, “Agent”) are not biometric identifiers. Customers can configure their own labels, including assigning the names of specific individuals; that configuration and its legal basis form part of Customer Content, for which the customer is responsible as controller (see Section 2).
Some of our sub-processors may be located outside the European Economic Area (EEA), including in the United States. Where this is the case, we rely on one of the following safeguards required by Chapter V GDPR:
Our PII anonymisation feature (Section 6), where applied, further reduces the risk associated with any such transfer. You can request more information about the safeguards that apply to a specific transfer by emailing privacy@aftertalk.co.
We use a small number of cookies that are strictly necessary for the Service to operate:
These cookies are exempt from consent requirements under Polish law (Art. 399(3) of the Law on Electronic Communications), as they are necessary to provide a service you have explicitly requested. We do not currently use analytics, advertising, or marketing cookies. If this changes, we will ask for your consent before setting any such cookies.
Our product analytics (see Section 3) runs in cookieless mode: it does not set cookies and does not store any identifiers on your device.
Under GDPR/RODO, you have the right to:
To exercise any of these rights regarding your account data, email privacy@aftertalk.co. We will respond within 30 days. If your request relates to a call recorded by one of our customers, please contact that organisation directly. We will assist them in responding to you.
All data is transmitted over HTTPS. Audio files and transcripts are encrypted at rest. We apply access controls so that only authorised personnel can access your project data, and we conduct regular security reviews.
We use a limited number of sub-processors to operate the Service, such as cloud hosting, speech-to-text and AI analysis, email delivery, product analytics, and payment processing. Each sub-processor is contractually bound to process data only on our instructions, to apply appropriate security measures, and to comply with GDPR. A current list of sub-processors, including their location and any applicable transfer safeguard, is available on request by emailing privacy@aftertalk.co.
For Customer Content that contains personal data, we act as a processor on your behalf under a Data Processing Agreement (DPA) that reflects the requirements of Article 28(3) GDPR, including the scope and purpose of processing, confidentiality, security measures, sub-processing, and assistance with data-subject requests and deletion on termination. A copy of our DPA is available on request by emailing privacy@aftertalk.co.
We may update this policy from time to time. Material changes will be notified by email or an in-app banner at least 14 days before they take effect.
Questions about this policy or how we handle your data? Email privacy@aftertalk.co.