Nodl
  • Examples
  • Who it's for
  • How it works
  • Pricing
  • FAQ
en
Sign in Start free

Privacy Policy for Nodl

As of: 11 June 2026
Provider / Controller: ex-nihilo GmbH, Effingergasse 18/2-3, 1160 Vienna, Austria


1. Overview

This privacy policy explains how ex-nihilo GmbH processes personal data in connection with Nodl.

Nodl is an AI-native voice-to-document platform. Users can record or upload audio. Nodl creates transcripts from it, identifies speaker segments, generates structured documents, and stores content in the user account or workspace.

Nodl stores recordings, transcripts, and documents according to the user’s or customer’s workspace settings. Users can save, export, or delete content. Depending on the plan, retention and deletion rules may be configurable. Original audio may be stored unchanged as a reference source where the user or customer uses or configures this function.


2. Controller and Contact

ex-nihilo GmbH
Effingergasse 18
1160 Vienna
Austria

Authorised representatives: Ing. Sebastian Beyer MSc., Ing. Christian Eichberger MSc.
Company register number: FN 601306z
Commercial register court: Vienna / Commercial Court of Vienna
VAT ID: ATU79273723
Email: [email protected]

Please direct privacy enquiries to: [email protected]

If a data protection officer is appointed in future or a separate privacy address is established, this privacy policy will be updated accordingly.


3. Role of ex-nihilo GmbH: Controller and Processor

ex-nihilo GmbH is the controller for processing personal data required for operation, administration, security, billing, support, website, user accounts, and communication.

For content that business customers, organisations, healthcare providers, or other professional users process in Nodl, ex-nihilo GmbH may act as processor within the meaning of Art. 28 GDPR with respect to such content where the customer determines the purposes and means of processing. In that case, a data processing agreement must be entered into where legally required.

Users or customers remain responsible for the lawfulness of content they record, upload, or have processed. This applies in particular to information for conversation partners, consents, employment law requirements, professional secrets, patient data, customer data, data subject rights, deletion obligations, and industry-specific requirements.


4. What Data Does Nodl Process?

Depending on use, Nodl processes in particular the following categories of data:

Category Examples
Account data Name, email address, password hash, language settings, login data
Contract and plan data Plan, limits, status, subscription start and end, billing status
Workspace data Workspace name, memberships, roles, settings, usage limits
Audio content Browser recordings, audio uploads, original audio, technical copies, normalised audio files
Transcripts Recording text, speaker segments, timestamps, recognised speech content
Generated documents Markdown documents, summaries, meeting notes, task lists, client summaries
AI processing data Prompts, transformer instructions, transcript excerpts, model responses, error data
Usage data Number of recordings, duration, selected output types, processing status, limit utilisation
Technical data IP address, user agent, session IDs, request logs, error logs, security events
Payment data Stripe customer ID, payment status, invoice data, tax information; no full credit card data via Nodl
Communication data Support requests, emails, security reports, feedback
Cookie and consent data Essential session cookies, cookie settings, consent records
Analytics data Only to the extent analytics is enabled and, where required, consent has been given

Audio, transcripts, and documents may contain personal data of third parties. They may also contain special categories of personal data, such as health data, political opinions, religious views, trade union membership, sexual orientation, or other sensitive information if users record or upload such content.


5. Purposes and Legal Bases

We process personal data in particular for the following purposes:

Purpose Data Legal basis
Provision of Nodl Account data, audio, transcripts, documents, workspace data Performance of contract or pre-contractual measures, Art. 6(1)(b) GDPR
Audio recording, upload, and transcription Audio, technical copies, transcript, speaker segments Performance of contract, Art. 6(1)(b) GDPR; for B2B content, possibly processing on behalf of customer
Storage of recordings, transcripts, and documents according to workspace settings Audio, transcripts, documents, metadata, possibly original audio Performance of contract, Art. 6(1)(b) GDPR; for B2B content, possibly customer instruction
Document creation with AI Transcript, prompts, output type, generated document Performance of contract, Art. 6(1)(b) GDPR; for B2B content, possibly processing on behalf of customer
User account and login Account data, session data, security data Performance of contract, Art. 6(1)(b) GDPR; legitimate interest in security, Art. 6(1)(f) GDPR
Payment and billing Contract data, Stripe IDs, invoice data Performance of contract, Art. 6(1)(b) GDPR; legal obligations, Art. 6(1)(c) GDPR
Support and communication Contact data, messages, technical information Performance of contract, Art. 6(1)(b) GDPR; legitimate interest, Art. 6(1)(f) GDPR
Security, abuse prevention, and incident response IP addresses, logs, audit events, error data Legitimate interest, Art. 6(1)(f) GDPR; legal obligations, Art. 6(1)(c) GDPR
Technically necessary cookies Session cookies, security cookies, consent data Performance of contract, Art. 6(1)(b) GDPR; legitimate interest, Art. 6(1)(f) GDPR
Analytics, where enabled Usage and device data, possibly pseudonymous IDs Consent, Art. 6(1)(a) GDPR, where required
Legal enforcement and defence Contract data, logs, communication, relevant content Legitimate interest, Art. 6(1)(f) GDPR; legal obligations, Art. 6(1)(c) GDPR

6. Special Categories of Personal Data

Nodl does not actively prompt users to enter special categories of personal data. Because Nodl processes audio and freely spoken content, such data may nevertheless be contained in recordings, transcripts, or documents.

Users may process special categories of personal data only if they have an appropriate legal basis for doing so. This applies in particular to health data, patient data, biometric data for unique identification, political opinions, religious or philosophical beliefs, trade union membership, genetic data, data concerning sex life or sexual orientation.

For professional use, in particular in healthcare, law firms, consultancies, human resources, or other regulated sectors, the user or customer is responsible for the required legal basis, information obligations, consents, professional secrets, access rights, retention and deletion obligations, and entering into a data processing agreement where required.

For direct use by consumers, Nodl processes sensitive content only to the extent users record, upload, or knowingly provide it for processing themselves. Users should not process sensitive data of other persons if they are not authorised to do so.


7. Storage, Original Audio, and Deletion

Nodl stores recordings, transcripts, and generated documents according to the user’s or customer’s workspace settings. Users can save, export, or delete content. Depending on the plan, retention and deletion rules may be configurable.

Where users create recordings or upload audio, Nodl may store the original audio unchanged — as a reference source for comparison with transcripts and documents, where the user or customer uses or configures this function.

Nodl may additionally create technical files, such as normalised audio files, temporary processing copies, waveforms, transcript segments, or metadata. These files serve processing, playback, transcription, synchronisation, and document creation. Stored original audio remains unaffected.

Recordings, transcripts, documents, and any original audio are retained according to workspace settings and plan for as long as:

  • the account or workspace exists and the applicable storage rule provides for this,
  • the respective recording or document has not been deleted by the user,
  • no contractual or statutory deletion has been triggered.

Users may delete recordings and documents where this function is available. After deletion, the affected content is removed from active systems within 30 days, unless statutory retention obligations, security incidents, disputes, abuse cases, or legitimate legal reasons require longer retention. In backups, content may remain until the backup cycle expires.

Nodl does not guarantee that stored content will be recognised in every legal, professional, or regulatory context or that it meets specific industry documentation obligations.


8. AI Processing

Nodl uses AI systems for:

  • live transcription preview,
  • batch transcription,
  • speaker separation,
  • generation of transcript segments and timestamps,
  • transformation of transcripts into structured documents.

Under the current product design, the following providers or model families are used in particular:

Processing Provider / Model Purpose
Transcription Mistral / Voxtral — batch: voxtral-mini-latest; live preview: voxtral-mini-transcribe-realtime-2602 Live and batch transcription, speaker separation, timestamps
Document creation Google / Gemini — gemini-3.1-flash-lite Structuring and conversion of transcripts into documents

Audio, transcripts, prompts, and documents are not used to train own or third-party AI models. AI providers are used in the EU where possible. Zero-data-retention or comparable non-storage / non-training settings are intended where technically and contractually available. Providers may not use customer data for model training.

AI results may be incorrect. Users must review and approve results themselves. Detailed information on AI use and related obligations is provided in the AI Transparency Statement. The contractual framework is set out in the Terms of Service.


9. No Automated Decisions with Legal Effect

Nodl does not make solely automated decisions within the meaning of Art. 22 GDPR that produce legal effects concerning users or similarly significantly affect them.

Automated technical processes such as plan limits, usage counting, rate limits, spam / abuse protection, or security checks serve provision, security, and contract performance. Where such processes lead to blocking or significant restriction, users may contact support.


10. Speaker Separation, Emotions, and Biometric Data

Nodl uses speaker separation to distinguish segments of different speakers within a recording. Nodl does not identify persons by their voice, does not create permanent voiceprints, does not use speaker separation for authentication, and does not perform biometric categorisation.

Nodl is not designed as an emotion recognition system. If users express emotions or moods in a recording, such content may appear in the audio, transcript, or document. Targeted emotional classification of persons is not a purpose of Nodl.


11. Recipients and Service Providers

We may disclose personal data to service providers who support us in operating Nodl. These include in particular:

Service provider / category Purpose Possible data
Hetzner Hosting, storage, database, server infrastructure (Nuremberg, Germany) Account data, content, logs, technical data
Mistral / Voxtral Transcription and speaker separation Audio, transcript and segment data, technical metadata
Google / Gemini Document creation, possibly analytics after consent Transcripts, prompts, generated documents; for analytics, usage data
Stripe Payment processing, billing, invoice status Payment and contract data, invoice data, tax data
Brevo Transactional emails, possibly service communication Email address, name, email content, technical delivery data
Cloudflare CDN, DNS, attack protection, performance IP address, request data, security logs
Self-hosted SigNoz / OpenTelemetry Monitoring, error analysis, performance Technical logs, error data, trace data
Legal, tax, and security advisors Legal enforcement, compliance, incident response Required contract, communication, and case data
Authorities and courts Fulfilment of legal obligations Required data on a case-by-case basis

Service providers are engaged only to the extent necessary for the stated purposes. Where legally required, we enter into data processing agreements or other data protection agreements.


12. Transfers to Third Countries

We prefer processing within the EU or European Economic Area. Hosting, storage, and database operation are provided via Hetzner in Nuremberg, Germany. For Mistral/Voxtral and Google Gemini, EU processing is intended where technically and contractually available.

Some providers, such as Cloudflare, Google, Stripe, or Brevo, may be internationally organised companies. Access or transfers outside the EU/EEA may occur. In such cases, we rely, where required, on adequacy decisions, standard contractual clauses, supplementary safeguards, or other permissible transfer mechanisms under the GDPR.


13. Cookies and Analytics

Nodl currently uses in principle only technically necessary cookies and comparable technologies required for login, session management, security, consent management, and provision of the website.

Google Analytics is intended as a future analytics solution. Where Google Analytics is enabled and consent is required for it, Google Analytics will be used only after prior consent. Users may withdraw consent given at any time with effect for the future.

Marketing or retargeting cookies are not currently used. A newsletter is not currently offered.


14. Retention Periods and Deletion

We store personal data only for as long as necessary for the respective purposes, statutory obligations exist, or legitimate interests justify retention.

For Nodl, the following periods apply as an initial reasonable retention standard:

Data category Retention period
Account data For as long as the account exists; deletion from active systems generally within 30 days after account deletion, unless statutory obligations prevent this
Original audio According to workspace settings and plan for as long as account/workspace exists and the recording is not deleted; after user deletion, removal from active systems generally within 30 days
Normalised audio files and technical audio derivatives For as long as required for playback, processing, or traceability; at latest upon deletion of the recording from active systems, unless required for security/dispute
Temporary processing files Generally up to 7 days, maximum 30 days, unless required for error analysis or incident response
Transcripts and speaker segments For as long as account/workspace exists and the recording or document is not deleted; after deletion, generally within 30 days from active systems
Generated documents For as long as account/workspace exists and the document is not deleted; after deletion, generally within 30 days from active systems
Workspace and membership data For as long as workspace or membership exists; thereafter generally 30 days, unless statutory obligations prevent this
Usage and limit data During the contract term; thereafter generally 24 months for billing, abuse prevention, and product/support traceability
App and error logs Generally 30 days
Security logs and incident data Generally 12 months; longer in the case of a specific security incident, abuse, or legal dispute until resolved
Audit events for admin and security purposes Generally 24 months; longer where there is a specific reason until resolved
Support communication Generally 24 months after closure of the request; longer for ongoing contract, security, or legal matters
Payment, invoice, and accounting data Generally 7 years under Austrian tax and company law retention obligations; longer where legally required or proceedings are pending
Consent and cookie settings Generally 12 months or until withdrawal/reset, where technically required
Google Analytics data, if enabled According to periods configured in the consent banner or in Google Analytics, typically maximum 14 months
Backups Rolling backups generally up to 35 days; thereafter overwritten. During restore operations, already deleted data may temporarily reappear technically and will be deleted again.

Statutory retention obligations, legitimate legal interests, abuse cases, security incidents, outstanding claims, or legal disputes may require longer retention.


15. Security

We implement technical and organisational measures to protect Nodl and personal data. These include in particular access restrictions, role-based permissions, transport encryption, secure authentication, monitoring, backups, logging, security reviews, and incident response processes.

Users are responsible for secure passwords, confidential credentials, lawful account use, and appropriate internal access rights.


16. Data Subject Rights

Data subjects have the following rights under the GDPR in particular:

  • access to processed personal data,
  • rectification of inaccurate data,
  • erasure of personal data,
  • restriction of processing,
  • data portability,
  • objection to processing based on legitimate interests,
  • withdrawal of consent given with effect for the future,
  • complaint to a data protection supervisory authority.

Please direct requests to [email protected].

Where we process data as processor for a customer, we will forward data subject requests to the respective customer where appropriate or handle them according to their instructions.


17. Right to Lodge a Complaint

Data subjects may lodge a complaint with a data protection supervisory authority. In Austria, this is in particular:

Austrian Data Protection Authority
Barichgasse 40-42
1030 Vienna
Austria
Website: https://www.dsb.gv.at


18. Obligation to Provide Data

Provision of certain data is required to use Nodl. Without account data, we cannot provide an account. Without audio or uploads, we cannot generate transcripts or documents. Without payment data, paid plans cannot be billed.

Provision of other content is voluntary. Users decide themselves what content they record or upload.


19. Changes to This Privacy Policy

We may amend this privacy policy when Nodl, service providers used, data processing, legal bases, or legal requirements change.

The current version will be made available on the website or in the app. We will inform users appropriately of material changes.

Related documents

  • → Terms
  • → AI Transparency
  • → Security
  • → Subprocessors
Nodl for: Doctors Dental practices Racing mind Journaling Interviews Coaches & consultants
© 2026 ex-nihilo GmbH. All rights reserved.
About Pricing Demo Articles Imprint Privacy Terms

Are you sure?