Summarize.One GDPR Compliance

Summarize.One is a WhatsApp assistant that summarizes and transcribes voice and text messages. It is developed and operated in Germany by Tasler IT Inh. Thomas Tasler. This page explains how Summarize.One meets the requirements of the EU General Data Protection Regulation (GDPR). All details are in our Privacy Policy.

Privacy by design

  • No message content is stored. Voice messages, texts, transcripts and summaries are only processed to create your summary and are not saved in our database.
  • No account, no password. Your WhatsApp number identifies you. We do not ask for your name, email address or postal address.
  • Minimal metadata. For billing and quality we store technical data such as message type, length and status – never the content. After 13 months it is de-linked from you.
  • Nobody reads your messages. Processing is fully automated.

Data we hold

  • Account data: WhatsApp phone number, WhatsApp profile name, country (derived from the phone number), settings, credit balance, plan and the time you accepted our terms.
  • Message metadata: type, length or duration, detected language, processing times, status, credits charged.
  • Usage events: which menu actions are used – without content and without phone number.
  • Payment data: Stripe customer ID, subscription status, purchases and invoices. Card and bank details are handled by Stripe and never reach our systems.

Where data is processed

Our database is hosted by Supabase in the EU. To provide the service we work with these processors:

  • Google (Gemini API) – creates summaries and transcripts
  • Meta (WhatsApp Business Platform) – delivers messages
  • Cloudflare – runs the assistant and the website
  • Supabase – database (EU)
  • Stripe – payments and invoices

Some of these providers may process data outside the EU, especially in the USA. Such transfers are based on the EU-US Data Privacy Framework and/or the EU Standard Contractual Clauses.

Your rights

You have the right to:

  • Access – find out which data we hold about you
  • Rectification – have incorrect data corrected
  • Erasure – have your data deleted (how to delete your data)
  • Restriction – have processing restricted
  • Data portability – receive your data in a machine-readable format
  • Object – object to processing based on our legitimate interests

To exercise your rights, write to privacy@summarize.one. You can also lodge a complaint with a supervisory authority, for example the Bavarian Data Protection Authority (www.lda.bayern.de).

Security

  • Encrypted connections (HTTPS/TLS) for all data transfers
  • Access to personal data only for the people who need it
  • No storage of message content
  • Automatic de-linking of message metadata after 13 months

If a personal data breach occurs, we notify the competent supervisory authority within 72 hours as required by the GDPR and inform affected users without undue delay if the breach is likely to result in a high risk to them.

Data processing agreements

Business customers who need a data processing agreement (DPA) can request one at info@summarize.one.

Frequently asked questions

Do you store my voice messages or summaries? No. They are processed and not stored.

Where is my data stored? Account data and metadata are stored in the EU (Supabase). Processing by our providers may take place outside the EU (see above).

How long do you keep my data? Account data until you ask us to delete it. Message metadata is de-linked from you after 13 months. Invoices are kept as long as German tax law requires (up to 10 years).

Who at Summarize.One can see my data? Only the people who operate the service, and only to the extent needed for support, billing and security. Message content is not available to anyone because it is not stored.

Do you use tracking on the website? No. We currently do not use analytics or marketing tools on our website.