SiteMinutes · Legal
Privacy Policy
Version 1.0Effective 25 September 2026Draft
Contents
- 1. Who we are
- 2. Two roles: our own data, and our customers' data
- 3. What we collect
- 4. Why we use it (purposes and legal bases)
- 5. Who processes it for us (sub-processors)
- 6. Payments
- 7. International transfers
- 8. How long we keep it
- 9. Meeting participants and recording consent
- 10. Security
- 11. Your rights
- 12. Children
- 13. Accessibility of this policy
- 14. Changes to this policy
- 15. Contact
Draft — to be reviewed by a qualified legal practitioner before publication.
Version 1.0 · Effective 25 September 2026
This Privacy Policy explains how SiteMinutes handles personal information when you use the SiteMinutes apps for iPhone, iPad and Mac, the web app at siteminutes.app and the website siteminutes.com (together, the Service).
It is written for everyone whose information passes through the Service: our customers and their users, and the people whose names, e-mail addresses or voices appear in meetings recorded with SiteMinutes. It is designed to meet the information requirements of the major privacy laws, including South Africa's POPIA, the EU and UK GDPR (Articles 13 and 14), US state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA), Canada's PIPEDA, Australia's Privacy Act (Australian Privacy Principles), and the data protection laws of Kenya, Nigeria and other countries. Section 11 sets out the rights that apply where you live.
In short: we collect what we need to run the Service; recordings stay on your device except for a temporary copy used to write minutes; we do not sell or share personal information for advertising; we do not use your content to train AI; and you can ask us to see, correct, export or delete your information.
1. Who we are
The Service is operated by Water en Skaafsels, trading as SiteMinutes, a business registered in Namibia under [Namibian registration number] ("SiteMinutes", "we", "us", "our"). Water en Skaafsels also runs a separate kitchen-design business under its own name, with its own privacy notice; SiteMinutes customer data is kept in SiteMinutes' own systems and is not used for that business. Both businesses use the same payment-gateway merchant account, but SiteMinutes payments carry their own references.
| Address | 16 Plover Street, Swakopmund, Erongo, 13001, Namibia |
| Privacy contact | help@siteminutes.com |
| Telephone | +264 81 127 8404 |
| Information Officer (for South African data subjects, POPIA) | Martin Bosman |
| Data Protection Officer | Not appointed; our processing does not require one. The privacy contact above handles all requests. |
| EU / UK representative (GDPR Art. 27) | [If required: name and address — to be appointed before the Service is offered to people in the EU or UK] |
2. Two roles: our own data, and our customers' data
SiteMinutes plays two different roles, and your rights depend on which one applies.
- We decide (controller / responsible party / business) for account, billing, support and website information: who signs up, who pays, who asks for help, and how the Service is used and secured.
- Our customer decides (we are the processor / operator / service provider) for everything the customer puts into the Service: projects, meetings, recordings, transcripts, minutes, attendance lists, actions, plans and documents. The customer is usually a company (for example an architecture practice) and is the controller (GDPR), responsible party (POPIA) or business (CCPA) for that content. We process it only on the customer's instructions, under our Data Processing Addendum.
If you attended a meeting that was recorded or minuted with SiteMinutes and you want to see, correct or delete what was recorded about you, please contact the company that ran the meeting first. We will help them respond, and we will pass on any request we receive directly.
3. What we collect
3.1 Account information
- Name, e-mail address and password (the password is stored only as a salted hash by our authentication provider; we never see it).
- Company name, country, and optional company details (address, registration number, VAT number, telephone, billing e-mail).
- Your role in the company (owner, admin or member), invitations you send or receive, and whether you are the billing owner.
- The version of our Terms of Service and this Privacy Policy you accepted, and when.
3.2 Meeting content (customer content)
- Audio recordings. Recordings are made and kept on your device. A temporary copy is uploaded to our servers only when you tap "Create minutes", so it can be transcribed. That copy is deleted as soon as the minutes have been written, and in any event within 7 days (an automatic clean-up job runs every day).
- Transcripts and minutes: the text transcript produced from the audio, the draft and final minutes, the review-chat messages you exchange with the AI assistant about the minutes, and the minutes' version history.
- Attendance and people: names, companies, roles, e-mail addresses and attendance status of people in meetings and in a project's people register. These are often people who are not SiteMinutes users (see section 3.7 and section 9).
- Project records: projects, meeting agendas, quick marks, actions, contract instructions, snag pins and their text.
- Plans and documents that you upload to a project (PDFs and images), stored in project storage.
- Photos taken in a meeting stay on your device in the current version and are not uploaded, apart from their captions if you add them to the minutes.
3.3 Billing information
- Plan, number of seats, billing period, prices, currency, payment references, payment status and the amounts charged.
- The billing owner's e-mail address, which is passed to the payment provider.
- We never receive or store card numbers. Card details are entered on the payment provider's own secure page (see section 6).
3.4 Support and help
- Support tickets and the messages exchanged on them.
- Help assistant: the questions you type into the in-app help assistant are sent to our AI provider to produce an answer. Our server does not store the conversation; it is kept only in your browser or app while the help panel is open. If you choose "Submit a ticket", the conversation is attached to the ticket. We keep a count of help questions per user for one hour to enforce a fair-use limit. Please do not share passwords, payment-card details or other highly sensitive information in the help assistant or in support tickets.
3.5 Usage and technical information
- AI usage records: for every AI call (transcription, drafting, editing, help), the workspace, meeting, kind of call, model, audio length, number of tokens and estimated cost. These records do not contain the audio, transcript or minutes.
- Technical logs kept by our hosting providers: IP address, device and browser type, time, requested address, and error messages. Our own functions are written not to log transcripts, minutes, API keys or payment secrets.
- Country from your IP address: when you set up a company, we pre-fill the billing country from the country our web host detects for your connection. You can change it.
- Location: the Service does not collect your device location. If a future version offers location features (for example to stamp a site visit), they will be off until you switch them on.
3.6 Cookies and local storage
We only use cookies and browser storage that are needed to sign you in and remember your display preference. We use no advertising cookies and no analytics or tracking tools. See our Cookie Policy.
3.7 Where the information comes from
- From you, when you create an account, use the apps, pay or contact us.
- From your company or colleagues, when they invite you, add you to a project's people register or record a meeting you attend. This is how we receive the names, companies, roles, e-mail addresses and spoken words of meeting participants who are not users.
- Generated by the Service, such as transcripts and draft minutes produced by AI from a recording, and usage records.
- From our providers: payment results from PayGate, and the country of your connection from our web host.
3.8 Sensitive information
SiteMinutes is not designed to collect sensitive or special categories of information (for example health, religion, ethnicity, sexual orientation, trade-union membership, criminal matters, government identity numbers or precise location). Such information may be spoken in a meeting; customers should avoid recording it unless they have a lawful basis. We do not use recordings to identify people by their voice: no voiceprints or other biometric identifiers are created. We do not use sensitive information to infer characteristics about anyone.
3.9 Do you have to give us information?
Account information is needed to create an account and provide the Service; without it we cannot provide it. Billing information is needed to buy a paid plan. Everything else is optional or depends on how you use the Service.
4. Why we use it (purposes and legal bases)
| Purpose | Information | Legal basis (GDPR / UK GDPR) and justification (POPIA s11) |
|---|---|---|
| Create and run your account, sign you in, keep workspaces separate | Account information | Performance of our contract with you (Art. 6(1)(b)) |
| Record, transcribe and write minutes; sync and store your projects | Customer content | On the customer's instructions as processor / operator; the customer's own lawful basis applies |
| Take payments, manage seats, prevent fraud, keep accounting records | Billing information | Contract (Art. 6(1)(b)); legal obligation — tax and accounting records (Art. 6(1)(c)) |
| Answer support tickets and help questions | Support and help information | Contract; legitimate interest in helping users (Art. 6(1)(f)) |
| Keep the Service secure, prevent abuse, fix errors, control AI costs | Usage and technical information | Legitimate interest in a secure, reliable and affordable service (Art. 6(1)(f)) |
| Tell you about changes to the Service, these terms, your trial or your plan | Account information | Contract; legitimate interest |
| Marketing e-mails about SiteMinutes | Name, e-mail address | Consent, or where the law allows, legitimate interest for similar services you already use — always with an opt-out |
| Comply with the law and protect our rights | Any, as needed | Legal obligation; legitimate interest in establishing or defending legal claims |
Where we rely on legitimate interests, we have balanced them against your rights and expectations; you can ask us for details, and you can object (section 11).
We do not sell personal information, we do not share it for cross-context behavioural advertising, we do not use it for targeted advertising, and we do not use customer content to train AI models (ours or anyone else's). We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. The AI writes a draft that a person reviews (see the AI & Recording Policy).
5. Who processes it for us (sub-processors)
We use a small number of carefully chosen service providers. Each receives only what it needs, under a written contract that requires it to protect the information and use it only to provide its service to us.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Supabase, Inc. | Database, sign-in, file storage, server functions | All account, billing and stored customer content | EU — Frankfurt, Germany (AWS eu-central-1) |
| Vercel, Inc. | Hosts the web app and website | Web requests, technical logs; pages pass through it | Functions in Frankfurt (fra1); content delivered from Vercel's worldwide edge network |
| OpenAI, L.L.C. | Speech-to-text (model whisper-1) | The temporary audio copy, attendee names and project terms as a spelling hint | United States |
| Anthropic, PBC | Claude AI: writes and edits the draft minutes; answers help questions | The transcript and meeting details needed for the minutes; help questions with basic plan information (no e-mail addresses) | United States |
| PayGate (Pty) Ltd / DPO Group (a Network International company) | Card payments (PayWeb3 and VCS Recurring) | Amount, reference, the billing owner's e-mail; card details are entered directly on its page | South Africa |
| Apple Inc. | Distributes the iPhone, iPad and Mac apps (App Store, TestFlight) | Apple's own account and download data; crash reports and feedback only if you choose to share them | Worldwide (Apple's own privacy policy applies) |
The AI providers' own terms (as at September 2026) say that data sent through their business APIs is not used to train their models by default. OpenAI states that its audio transcription endpoint keeps no abuse-monitoring log or stored copy of the audio; OpenAI may keep other API inputs and outputs for up to 30 days for abuse monitoring. Anthropic deletes API inputs and outputs within 30 days, but may keep them for up to 2 years if they are flagged for a usage-policy violation. We will update this list at least 30 days before we add or replace a sub-processor (see the Data Processing Addendum).
We may also disclose information to professional advisers under confidentiality, to a buyer or successor if the business is sold (who must honour this policy), or when the law requires it (for example a valid court order). We will tell the affected customer about a legal demand for its content unless the law forbids us.
6. Payments
Card payments are processed by PayGate (DPO Group), which is certified to PCI DSS Level 1. You type your card details on PayGate's or VCS's own secure page, not on ours. We receive only the result (approved or declined), the amount, a transaction reference and, for recurring payments, a subscription reference. We check every result directly with PayGate before a plan is activated.
7. International transfers
Our servers are in the European Union (Frankfurt). Our AI providers are in the United States, and our payment provider is in South Africa. Your information may therefore be transferred outside Namibia, South Africa or your own country, to countries whose laws may differ from yours.
We protect those transfers by:
- choosing providers bound by written data processing terms that include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum and the Swiss equivalents where they apply, or by relying on an adequacy decision or recognised certification (for example the EU–US Data Privacy Framework, where a provider is certified);
- sending the AI providers only what the task needs, for as short a time as possible, under terms that forbid training on it;
- for South Africa, relying on section 72 of POPIA: the recipients are subject to binding agreements that give protection substantially similar to POPIA, and the transfers are needed to perform the contract with our customer (see our POPIA Notice & PAIA summary);
- for Kenya, Nigeria and other countries with transfer rules, using the same contractual safeguards and, where required, the transfer mechanisms those laws recognise; and
- for Canada and Australia, remaining accountable for information we transfer to providers, which are contractually required to protect it to a comparable standard.
You can ask us for a copy of the relevant safeguards (commercial terms may be redacted).
8. How long we keep it
In short: customer content is kept while the customer's workspace exists; the temporary audio copy is deleted after the minutes are written (at most 7 days); billing records are kept for 7 years; and workspaces that stop paying are never deleted for non-payment for at least 12 months. Full details are in the Data Retention & Deletion Policy.
9. Meeting participants and recording consent
SiteMinutes records meetings. The person recording — on behalf of our customer — must tell everyone present that the meeting is being recorded and why, before recording starts. The app shows this reminder every time ("Tell everyone the meeting is being recorded"). Our customer is responsible for having a lawful basis, and where required the consent of every participant, for recording the meeting and for processing their names and e-mail addresses. Some countries and states require the consent of all participants before a conversation may be recorded. See the AI & Recording Policy.
If you took part in a meeting and want to exercise your rights, contact the company that recorded it, or contact us and we will pass your request on.
10. Security
We protect information with encryption in transit (TLS) and at rest, strict per-company separation enforced in the database (row level security), secrets kept in an encrypted vault, least-privilege access, logging and daily backups, organised along the lines of recognised frameworks such as ISO/IEC 27001 and SOC 2. No system is perfectly secure; we will tell affected customers, individuals and regulators about a personal-information breach as the law requires. See the Security Overview.
11. Your rights
11.1 Rights everyone has with us
Wherever you live, you can ask us to:
- tell you whether we hold information about you and give you a copy (access / right to know);
- correct inaccurate or incomplete information;
- delete information we no longer have a reason to keep;
- give you your information in a structured, commonly used, machine-readable format, or send it to another provider (portability) — workspace owners can also export projects and minutes themselves;
- stop using it for direct marketing, at any time;
- object to or restrict processing based on our legitimate interests; and
- withdraw consent where we rely on consent (this does not affect earlier processing).
We will not discriminate against you, charge you more or give you a worse service for using your rights.
11.2 How to make a request
E-mail help@siteminutes.com with "Privacy request" in the subject. We will confirm receipt, may ask for information to verify your identity (we will not ask for more than we need), and answer within 30 days, or sooner where the law requires (the CCPA allows 45 days, extendable once). If we need longer, we will tell you why. Requests are free unless they are clearly unfounded or excessive. An authorised agent may make a request for you with your written permission. If we refuse a request, we will explain why and how you can appeal to us (by replying to our answer) and complain to a regulator.
Where we act for a customer (section 2), we will refer your request to that customer and help them answer it.
11.3 Rights in specific jurisdictions
| Where you are | Main law | Your additional rights and notes | Regulator |
|---|---|---|---|
| South Africa | Protection of Personal Information Act 4 of 2013 (POPIA) | Access (s23), correction and deletion (s24), objection (s11(3)), no solely automated decisions (s71), to be told of a security compromise (s22). See our POPIA Notice | Information Regulator — POPIAComplaints@inforegulator.org.za; +27 (0)10 023 5200; inforegulator.org.za |
| Namibia | Constitution, Article 13 (privacy); Data Protection Bill not yet in force (September 2026) | We give you the same rights as in 11.1 and will update this policy when a law comes into force | None yet; contact us |
| European Union / EEA | GDPR | Access, rectification, erasure, restriction, portability (Arts. 15–20); objection, including to legitimate-interest processing (Art. 21); not to be subject to solely automated decisions (Art. 22) | Your local data protection authority (list at edpb.europa.eu) |
| United Kingdom | UK GDPR and Data Protection Act 2018 | As for the EU | Information Commissioner's Office — ico.org.uk |
| Switzerland | Federal Act on Data Protection (revFADP) | Access, correction, deletion, portability, objection | Federal Data Protection and Information Commissioner — edoeb.admin.ch |
| United States — California and other states with privacy laws (e.g. Colorado, Connecticut, Virginia, Utah, Texas, Oregon) | CCPA / CPRA and similar state laws | Right to know / access, delete, correct, portability; to opt out of sale or sharing and of targeted advertising and profiling — we do not sell or share personal information and do not use it for targeted advertising or profiling, so there is nothing to opt out of, and we treat Global Privacy Control signals as an opt-out; to limit the use of sensitive personal information — we use it only as needed to provide the Service; non-discrimination; appeal a refusal | California Privacy Protection Agency (cppa.ca.gov) or your state Attorney General |
| Canada | PIPEDA (and provincial laws where they apply) | Access and correction; withdraw consent (subject to legal or contractual limits); be told about transfers outside Canada (section 7) | Office of the Privacy Commissioner of Canada — priv.gc.ca |
| Australia | Privacy Act 1988, Australian Privacy Principles | Access (APP 12) and correction (APP 13); overseas disclosure notice (APP 8, section 7); dealing with us anonymously or under a pseudonym is not practicable for an account (APP 2) | Office of the Australian Information Commissioner — oaic.gov.au |
| Kenya | Data Protection Act, 2019 | To be informed, access, object, correction and deletion of false or misleading data, portability | Office of the Data Protection Commissioner — odpc.go.ke |
| Nigeria | Nigeria Data Protection Act, 2023 | Access, rectification, erasure, restriction, portability, objection, withdraw consent | Nigeria Data Protection Commission — ndpc.gov.ng |
| Other countries (including other African countries with data protection laws, such as Botswana, Ghana, Mauritius, Rwanda, Uganda, Zambia and Zimbabwe) | Local data protection law | We respect the rights your local law gives you; contact us | Your local data protection authority |
Please contact us first so we can try to resolve any concern. You always have the right to complain to a regulator.
12. Children
The Service is for businesses and professionals and is not intended for anyone under 18. We do not knowingly collect personal information from children as users, and the Service is not directed at children under 13 (for the purposes of the US Children's Online Privacy Protection Act) or under 16. If a child's information has been included in a meeting record, the customer who recorded it is responsible for it. If you believe we hold a child's information without a lawful basis, contact us and we will delete it.
13. Accessibility of this policy
We write this policy in plain language and publish it as an accessible web page that works with screen readers and can be printed or saved as PDF. If you need it in another format (for example large print or read aloud), contact us.
14. Changes to this policy
We will post any change here with a new version number and effective date. If a change materially affects how we use personal information, we will tell account holders by e-mail or in the app at least 30 days before it takes effect, unless the change is required sooner by law, and ask for consent where the law requires it. Earlier versions are available on request.
15. Contact
Water en Skaafsels, trading as SiteMinutes (registered in Namibia, [Namibian registration number]), 16 Plover Street, Swakopmund, Erongo, 13001, Namibia · help@siteminutes.com · +264 81 127 8404.