SalesMage company Logo
Why salesmageHow it worksIntegrations
Sign inTry for free
Sign inTry for free

Legal & Compliance

Privacy Policy

Last updated: 16 August 2026

SalesMage AB ("SalesMage", "we", "us", "our") is committed to protecting your personal data. This policy explains what personal data we collect, why we collect it, who we share it with, and what rights you have.

SalesMage is a sales collaboration platform. Users create shared "deal rooms" with their customers, and can connect a Google Calendar so that a notetaker bot joins their sales meetings, records them, and produces transcripts, summaries and insights.

Data controller

SalesMage AB Nybohovsgränd 8, Stockholm, Sweden contact@salesmage.io

For personal data that we process on behalf of our business customers (for example, the personal data of participants in a customer's meetings), SalesMage acts as a data processor and the business customer is the controller. In that case the customer's own privacy notice governs, and this policy describes how we handle the data on their instructions.

1. What We Collect and Why

1.1 Website visitors

Data
Purpose
Legal basis
Data: IP address, browser and device data, pages visited
Purpose: Operating, securing and improving the website
Legal basis: Legitimate interest (Art. 6(1)(f))
Data: Contact details you submit to us
Purpose: Responding to your enquiry
Legal basis: Legitimate interest / steps prior to a contract

1.2 Account and platform use

The table below covers processing for which we are the controller. Where we act as a processor, see 1.4.2.

Data
Purpose
Legal basis
Data: Name, email address, job title, phone number, and a profile picture if you choose to upload one
Purpose: Creating and authenticating your account
Legal basis: Performance of a contract (Art. 6(1)(b))
Data: One-time passcodes sent to your email address
Purpose: Verifying your identity at sign-in and for guest access
Legal basis: Performance of a contract
Data: Organisation and team membership, role and permissions
Purpose: Access control within the platform
Legal basis: Performance of a contract
Data: Content you upload to a deal room (documents, files, comments)
Purpose: Providing the deal room functionality
Legal basis:Processor — on our customer's documented instructions (see 1.4.2)
Data: Activity records (logins, views, shares, deal room activity)
Purpose: Delivering engagement insights and securing the service
Legal basis:Login records and security logs for your own user account | Authenticating you and securing the Service | Performance of a contract / legitimate interest

1.3 Google account and calendar data

We use Google OAuth in two distinct places, and each requests only what it needs.
‍
‍Sign-in. When you log in with Google we receive your email address and basic profile information from Google. We use it to identify your account. We do not receive or store your Google password.

‍Calendar connection. If you choose to connect your calendar so meetings can be recorded, we request the following Google scopes:
‍https://www.googleapis.com/auth/calendar.events.readonly, read-only access to your calendar events, so we can show your upcoming meetings and detect which of them have a video conference link.
‍
‍https://www.googleapis.com/auth/userinfo.email, your email address, to match the calendar to your SalesMage account.

We request read-only calendar access. SalesMage cannot create, edit, or delete anything in your calendar.

The calendar authorisation is completed by our meeting-recording provider, Recall.ai (see section 2). SalesMage generates the Google consent screen link, but the resulting Google credentials are held by Recall.ai, not by SalesMage. We never see or store your Google refresh token.

From your connected calendar we receive, for each upcoming meeting, the meeting title, start and end time, the video conference URL, and an identifier. We use this only to display your meeting list and to determine whether a notetaker bot should join.

Google API Services and Limited Use
SalesMage's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs adheres to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.

Specifically:

  • We use Google Calendar data only to provide and improve the meeting-recording features described here.
  • We do not transfer it to others except as necessary to provide those features, for security purposes, or to comply with applicable law.
  • We do not use it for advertising, and we do not sell it.
  • We do not allow humans to read it except with your explicit consent, for security purposes, to comply with applicable law, or where the data has been aggregated and de-identified.

No AI or ML training on Google user data. SalesMage does not use, transfer, or sell Google user data, whether raw, aggregated, anonymised or derived, to create, train, fine-tune, or improve any foundational or generalised machine learning or artificial intelligence model. None of the third-party AI services we use is permitted to do so either, and we enforce that contractually and through the technical routing controls described in section 3.

1.4 Our role under the GDPR

1.4.1 Where we act as controller

We are the controller of personal data that we process for our own purposes. This includes: (a) account and user data (name, work email address, job title, password credentials and login history); (b) billing and payment data; (c) website, marketing and support data, including cookies and analytics; and (d) security, audit and abuse-prevention logs.

Our legal bases for this processing are the performance of our contract with you (Art. 6(1)(b) GDPR) for data necessary to provide and administer your account, our legitimate interests (Art. 6(1)(f) GDPR) in securing, improving and marketing the Service, and our legal obligations (Art. 6(1)(c) GDPR) in respect of accounting and tax records. Where we rely on legitimate interests, you may object as described in section 6.

1.4.2 Where we act as processor

We are a processor, and our customer is the controller, of all personal data contained in customer content. This includes meeting recordings, audio and video, transcripts, summaries, AI-generated output derived from them, CRM data synchronised into the Service, and deal room content.

The SalesMage user who scheduled or uploaded a recording, and the organisation on whose behalf that user acts, determines the purposes and means of that processing. We process such data only on documented instructions from that customer, under the data processing terms set out in our Terms and Conditions, which meet the requirements of Art. 28 GDPR. We do not determine the purposes of that processing and do not state a separate legal basis for it; the customer is responsible for establishing a legal basis for the recording and for informing meeting participants.

If you are a meeting participant and wish to exercise your rights in relation to a recording, please contact the organisation that scheduled the meeting. If you contact us instead, we will forward your request to that organisation.

1.5 Deal room guests and invited users

When one of our customers invites a customer or colleague to a deal room, we process that person's email address and their activity in the room on the inviting customer's instructions, as a processor.

Meetings are not visible to deal room guests by default. A recording only becomes visible to a buyer or guest if the SalesMage user explicitly shares it into the deal room.

1.6 Marketing and job applications

Data
Purpose
Legal basis
Data:Email address, name, company
Purpose:Product updates and marketing emails
Legal basis: Consent, or legitimate interest for existing customers (soft opt-in)
Data:Public professional profile data (e.g. LinkedIn)
Purpose:Business contact and recruitment
Legal basis: Legitimate interest
Purpose:CV, application materials
Legal basis:Assessing your application
Data:Steps prior to a contract / legitimate interest

You can unsubscribe from marketing at any time using the link in any email, or by writing to contact@salesmage.io.

1.7 Cookies and analytics

We use cookies that are strictly necessary for the site and the product to work, including the cookie that keeps you signed in. We ask for your consent before setting any analytics or marketing cookies, and you can decline without losing access to the Service. Details are in our Cookie Policy. If we introduce a third-party analytics provider, we will name it in the table in section 3 and update this policy before it goes live.

2. Recall.ai and Meeting Recording

SalesMage uses Recall.ai (operated by Hyperdoc Inc., 2261 Market Street #4339, San Francisco, CA 94114, USA) to connect to your Google Calendar and to record and transcribe meetings. Recall.ai acts as our sub-processor and is bound by a data processing agreement.

What Recall.ai does for us:
Holds the Google Calendar authorisation.
When you connect your calendar, the Google consent flow completes at Recall.ai. Recall.ai stores the Google credentials and keeps your calendar in sync.
‍Reads your upcoming calendar events and passes us the title, times, and video conference link for each one.
‍Sends a bot into the meeting. For meetings marked for recording, Recall.ai's bot joins the call as a visible participant named "Salesmage Notetaker" and captures audio and video. Supported platforms are Zoom, Google Meet, Microsoft Teams, Cisco Webex and GoToMeeting.
‍Produces a transcript of the recording, with speaker attribution and timestamps.
‍Notifies us when a recording and transcript are ready, so we can retrieve them.

Where processing happens. We use Recall.ai's EU infrastructure (eu-central-1) for calendar sync, recording and transcription, so meeting media is processed within the EU. Recall.ai's provider, Hyperdoc Inc., is established in the United States and its personnel may access data from there for support and operations. That access is a transfer to a third country and is covered by the EU Standard Contractual Clauses, see section 3.
‍
What we retrieve and store ourselves. As soon as a recording and transcript are ready, we download them to our own AWS S3 storage in the eu-north-1 (Stockholm) region. Once stored with us, the recording video and transcript live in our EU infrastructure and are served to you from there.
What we do not send to Recall.ai.

We do not send Recall.ai your deal room documents, comments, or any other platform content. The only data we send is what is needed to identify you and schedule a recording: your account email address, which Recall.ai uses as your identifier, and, when you schedule a bot for a meeting link yourself, that meeting URL together with an internal numeric user identifier.
‍
Disconnecting. You can disconnect your calendar at any time from the Calendar page in the app. When you do, we instruct Recall.ai to delete your calendar user record, which revokes their access to your Google Calendar, and we discard our cached Recall.ai session token for you. Recordings already stored with SalesMage are not deleted by disconnecting an integration. To have them deleted, follow the procedure in section 6 (Your rights); for how long we keep them if you take no action, see section 4 (Retention). You can also revoke SalesMage's and Recall.ai's access directly from your Google Account permissions page at https://myaccount.google.com/permissions.

We do not sell personal data. We share it only with service providers who process it on our behalf under a data processing agreement, and with authorities where the law requires it.

3. Who We Share Data With, and International Transfers

Our sub-processors

Provider
Purpose
Personal data involved
Location
Provider: Recall.ai (Hyperdoc Inc.)
Purpose: Calendar sync, meeting recording, transcription
Personal data involved: Calendar events, meeting audio/video, transcripts, participant names, your email address
Location: EU processing region (eu-central-1); provider established in the USA
Provider: Amazon Web Services (AWS)
Purpose: Hosting, database, file and recording storage
Personal data involved: All platform data
Location: EU, eu-north-1 (Stockholm)
Provider: Google LLC
Purpose: OAuth sign-in and calendar authorisation
Personal data involved: Email, profile, calendar events
Location: USA
Provider: OpenRouter
Purpose: Gateway routing meeting transcripts and deal room content to large language models to generate summaries, chapters, action items and insights. Prompt logging off, Zero Data Retention enforced, no training on submitted data
Personal data involved: Meeting transcripts, deal room content, participant names, meeting title and start time
Location: USA
Provider: Model inference endpoints reached through OpenRouter
Purpose: Running the models named in "AI processing" below. Restricted by allowlist to endpoints operating under Zero Data Retention, so submitted data is neither stored nor used for training
Personal data involved: The prompt content listed above, for the duration of the request only
Location: Varies by endpoint; see "AI processing"
Provider: Email delivery provider
Purpose: Transactional and marketing email
Personal data involved: Name, email address
Location: EU/USA

International transfers

Some of our providers are established outside the EU/EEA, principally in the United States. Where personal data is transferred outside the EU/EEA, we rely on:

  • EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) supplemented by technical and organisational measures such as encryption in transit and at rest; and
  • the EU–US Data Privacy Framework, where the receiving provider is certified under it.

You can obtain a copy of the safeguards in place by writing to contact@salesmage.io.

AI processing

Meeting transcripts and deal room content are sent to large language models in order to generate summaries, chapters, action items and answers in the deal room assistant. We use OpenRouter as a gateway to reach those models rather than contracting with each model host directly.

‍Which models we call. We call a fixed, named set of models: openai/gpt-oss-120b for meeting summaries, chapters, action items and deal room context, and openai/gpt-4o-mini for the deal room assistant's streaming replies. No model is chosen dynamically at runtime, and requests are routed only to inference endpoints on an allowlist we maintain.

What we do to prevent training and retention.

  • Prompt and completion logging is switched off on our OpenRouter account.
  • Zero Data Retention is enforced, so requests are only routed to endpoints that do not store request data. An endpoint that does not retain data cannot train on it.
  • Every request additionally carries a data-policy restriction (data_collection: "deny") and has provider fallback disabled, so a request cannot be served by, or silently fail over to, an endpoint that collects submitted data.
  • We do not run a self-hosted or offline copy of any model. All inference happens at the hosted endpoints described above.

Google data and AI. Meeting transcripts are produced from the audio of the call itself, not from any Google API. The only Google Calendar data that can appear in a model prompt is the meeting's title and start time, included so a summary can be labelled correctly. No Google user data, raw or derived, is used to train or improve any AI or ML model. See section 1.3.
‍
Automated output. Model output is generated automatically. It can be inaccurate or incomplete and should not be treated as a verbatim record of a meeting. It does not produce legal effects concerning you, and we do not use it for automated decision-making within the meaning of Art. 22 GDPR.

4. How Long We Keep Data

Data
Retention
Data: Account data
Retention: For as long as your account is active, then deleted or anonymised within 90 days of closure
Data: Deal room content
Retention: For as long as the deal room exists, or until you delete it
Data: Meeting recordings, transcripts and AI output
Retention: Until you delete the meeting, or until your account is closed
Data: Calendar event data
Retention: Held only while your calendar connection is active; removed when you disconnect
Data: Website and analytics data
Retention: Up to 26 months
Data: Marketing contact data
Retention: Until you unsubscribe
Data: Job applications
Retention: Up to 24 months after the recruitment process concludes, unless you object
Data: Data we must keep by law (e.g. accounting records)
Retention: For the period required by Swedish law

5. Security

We apply technical and organisational measures appropriate to the risk, including:

  • Encryption of data in transit (TLS) and at rest;
  • Access control within the platform, so meetings and deal room content are only visible to the people the owner has shared them with;
  • Storage of production credentials in a managed secrets service;
  • Separate, per-user session tokens for the calendar integration, which expire and are re-issued rather than being held indefinitely.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Swedish Authority for Privacy Protection (IMY) within 72 hours and, where the risk is high, notify you directly.
‍
Where we act as a processor, we will notify the affected customer without undue delay after becoming aware of a personal data breach affecting their data, and will assist them in meeting their own notification obligations. The customer, as controller, is responsible for any notification to a supervisory authority or to data subjects.

6. Your Rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you and receive a copy;
  • Rectify inaccurate or incomplete data;
  • Erase your data ("right to be forgotten"). You can close your account from within the Service. To have an individual meeting recording and its transcript deleted, email us and we will remove it;
  • Restrict or object to processing based on legitimate interest, including profiling;
  • Data portability, receive your data in a structured, machine-readable format. We currently handle export requests manually, so please allow us the full response period below;
  • Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
  • Lodge a complaint with a supervisory authority. In Sweden this is Integritetsskyddsmyndigheten (IMY), https://www.imy.se.

To exercise any of these, email contact@salesmage.io. We respond within one month.
‍
If your data was uploaded to SalesMage by one of our business customers, for example if you attended a meeting recorded by one of our users, we will forward your request to that customer, who is the controller of that data.

7. Children

The Service is not directed at anyone under 18, and we do not knowingly collect personal data from children.

8. Changes to This Policy

We may update this policy. When we do, we will revise the "Last Updated" date above, and for material changes affecting how we use your data we will notify you by email or in the product before the change takes effect.

9. Contact

SalesMage AB
Company registration number (organisationsnummer): 559530-1192Registered office: Stockholm, Nybohovsgränd 8,  Sweden
Email: contact@salesmage.io

SALESMAGE © 2026 · Org.nr 559530-1192 · Stockholm, Sweden

Terms and ConditionsPrivacy Policy