Meeting recording privacy information

This page explains how personal information is processed when an AuditBot meeting bot records and transcribes a meeting. Read it with the notice delivered in the meeting, which states the controller, purpose, recording mode and seven-day media limit.

Controller for this meeting

The audit firm named in your meeting notice

Use the privacy contact in that notice or ask the meeting organiser.

Who is responsible

The audit firm named in your meeting notice is the controller. It decides why the meeting is processed, whether Audio Bot or Video Bot is necessary, and the lawful basis for that processing.

AuditBot Ltd acts as a processor on the controller's documented instructions. AuditBot supplies the meeting bot, transcription and derived meeting outputs. The controller remains responsible for responding to attendees and exercising data protection judgement.

Information we process

  • Meeting audio and the words spoken by participants.
  • Participant video and shared-screen content only when the organiser selects Video Bot. Audio Bot does not request participant video or screen recording.
  • Participant names, account identifiers, attendance and speaker timing supplied by the meeting platform.
  • The transcript and derived meeting content, such as summaries, key points, action items and agenda analysis.
  • Meeting metadata such as the title, platform and start and end times.

This information comes directly from participants and from the meeting platform. AuditBot's minimum flow must not be used for meetings involving special category, criminal offence, legally privileged or other restricted information.

Purpose and lawful basis

The exact purpose is stated in the meeting notice. The controller instructs AuditBot to create an accurate and traceable record for that stated professional purpose.

The controller states that it relies on legitimate interests under UK GDPR. It must document the interest, show that recording is necessary and proportionate, consider a less intrusive method, and balance its interest against each participant's rights and freedoms. Selecting Video Bot requires an additional explanation of why audio alone is insufficient.

How long information is kept

Meeting audio and video

Raw meeting audio and video remain available for seven days. A controller can record a reason to store a copy for 30, 90, 180 or 365 additional days. The stored copy is deleted at the final stated time.

Transcript and derived content

AuditBot keeps the transcript and derived content as part of the meeting record. The raw-media time limit does not delete them.

Who receives the information

Information is available to authorised people at the controller who need it for the stated purpose. AuditBot uses service providers to support recording, transcription, hosting and AI processing. The controller should confirm that its contract with AuditBot and AuditBot's subprocessor terms provide the required data protection safeguards before enabling Meeting Bot.

Specialist services support the meeting bot, short-term raw-media processing, speaker identification, transcription and generation of the authorised outputs. EU data residency is a requirement for this feature. The controller should review AuditBot's current subprocessor, processing-location and international-transfer information before enabling Meeting Bot.

Your rights and objections

Depending on the circumstances, you may ask the controller for access to your personal information, correction, erasure or restriction. You may object at any time to processing based on legitimate interests. These rights are not absolute, and the controller must assess and respond to each request under data protection law.

To object during a meeting, tell the organiser or use the contact below. Removing AuditBot from the meeting stops further recording. The controller decides how to handle the objection and information already collected.

Contact the controller

Use the objection route in the meeting notice or contact the meeting organiser.

You may also complain to the UK Information Commissioner's Office. Visit the ICO complaints page.

Legal sources

This layered notice follows the transparency topics in UK GDPR Articles 13 and 14 and the ICO's guidance on the right to be informed, legitimate interests and the right to object. The controller must review it with its own policies, legitimate interests assessment and contractual arrangements before use.

Last updated 11 August 2026.