Privacy Policy for Nodl
As of: 11 June 2026
Provider / Controller: ex-nihilo GmbH, Effingergasse 18/2-3, 1160 Vienna, Austria
1. Overview
This privacy policy explains how ex-nihilo GmbH processes personal data in connection with Nodl.
Nodl is an AI-native voice-to-document platform. Users can record or upload audio. Nodl creates transcripts from it, identifies speaker segments, generates structured documents, and stores content in the user account or workspace.
Nodl stores recordings, transcripts, and documents according to the user’s or customer’s workspace settings. Users can save, export, or delete content. Depending on the plan, retention and deletion rules may be configurable. Original audio may be stored unchanged as a reference source where the user or customer uses or configures this function.
2. Controller and Contact
ex-nihilo GmbH
Effingergasse 18
1160 Vienna
Austria
Authorised representatives: Ing. Sebastian Beyer MSc., Ing. Christian Eichberger MSc.
Company register number: FN 601306z
Commercial register court: Vienna / Commercial Court of Vienna
VAT ID: ATU79273723
Email: [email protected]
Please direct privacy enquiries to: [email protected]
If a data protection officer is appointed in future or a separate privacy address is established, this privacy policy will be updated accordingly.
3. Role of ex-nihilo GmbH: Controller and Processor
ex-nihilo GmbH is the controller for processing personal data required for operation, administration, security, billing, support, website, user accounts, and communication.
For content that business customers, organisations, healthcare providers, or other professional users process in Nodl, ex-nihilo GmbH may act as processor within the meaning of Art. 28 GDPR with respect to such content where the customer determines the purposes and means of processing. In that case, a data processing agreement must be entered into where legally required.
Users or customers remain responsible for the lawfulness of content they record, upload, or have processed. This applies in particular to information for conversation partners, consents, employment law requirements, professional secrets, patient data, customer data, data subject rights, deletion obligations, and industry-specific requirements.
4. What Data Does Nodl Process?
Depending on use, Nodl processes in particular the following categories of data:
| Category | Examples |
|---|---|
| Account data | Name, email address, password hash, language settings, login data |
| Contract and plan data | Plan, limits, status, subscription start and end, billing status |
| Workspace data | Workspace name, memberships, roles, settings, usage limits |
| Audio content | Browser recordings, audio uploads, original audio, technical copies, normalised audio files |
| Transcripts | Recording text, speaker segments, timestamps, recognised speech content |
| Generated documents | Markdown documents, summaries, meeting notes, task lists, client summaries |
| AI processing data | Prompts, transformer instructions, transcript excerpts, model responses, error data |
| Usage data | Number of recordings, duration, selected output types, processing status, limit utilisation |
| Technical data | IP address, user agent, session IDs, request logs, error logs, security events |
| Payment data | Stripe customer ID, payment status, invoice data, tax information; no full credit card data via Nodl |
| Communication data | Support requests, emails, security reports, feedback |
| Cookie and consent data | Essential session cookies, cookie settings, consent records |
| Analytics data | Only to the extent analytics is enabled and, where required, consent has been given |
Audio, transcripts, and documents may contain personal data of third parties. They may also contain special categories of personal data, such as health data, political opinions, religious views, trade union membership, sexual orientation, or other sensitive information if users record or upload such content.
5. Purposes and Legal Bases
We process personal data in particular for the following purposes:
| Purpose | Data | Legal basis |
|---|---|---|
| Provision of Nodl | Account data, audio, transcripts, documents, workspace data | Performance of contract or pre-contractual measures, Art. 6(1)(b) GDPR |
| Audio recording, upload, and transcription | Audio, technical copies, transcript, speaker segments | Performance of contract, Art. 6(1)(b) GDPR; for B2B content, possibly processing on behalf of customer |
| Storage of recordings, transcripts, and documents according to workspace settings | Audio, transcripts, documents, metadata, possibly original audio | Performance of contract, Art. 6(1)(b) GDPR; for B2B content, possibly customer instruction |
| Document creation with AI | Transcript, prompts, output type, generated document | Performance of contract, Art. 6(1)(b) GDPR; for B2B content, possibly processing on behalf of customer |
| User account and login | Account data, session data, security data | Performance of contract, Art. 6(1)(b) GDPR; legitimate interest in security, Art. 6(1)(f) GDPR |
| Payment and billing | Contract data, Stripe IDs, invoice data | Performance of contract, Art. 6(1)(b) GDPR; legal obligations, Art. 6(1)(c) GDPR |
| Support and communication | Contact data, messages, technical information | Performance of contract, Art. 6(1)(b) GDPR; legitimate interest, Art. 6(1)(f) GDPR |
| Security, abuse prevention, and incident response | IP addresses, logs, audit events, error data | Legitimate interest, Art. 6(1)(f) GDPR; legal obligations, Art. 6(1)(c) GDPR |
| Technically necessary cookies | Session cookies, security cookies, consent data | Performance of contract, Art. 6(1)(b) GDPR; legitimate interest, Art. 6(1)(f) GDPR |
| Analytics, where enabled | Usage and device data, possibly pseudonymous IDs | Consent, Art. 6(1)(a) GDPR, where required |
| Legal enforcement and defence | Contract data, logs, communication, relevant content | Legitimate interest, Art. 6(1)(f) GDPR; legal obligations, Art. 6(1)(c) GDPR |
6. Special Categories of Personal Data
Nodl does not actively prompt users to enter special categories of personal data. Because Nodl processes audio and freely spoken content, such data may nevertheless be contained in recordings, transcripts, or documents.
Users may process special categories of personal data only if they have an appropriate legal basis for doing so. This applies in particular to health data, patient data, biometric data for unique identification, political opinions, religious or philosophical beliefs, trade union membership, genetic data, data concerning sex life or sexual orientation.
For professional use, in particular in healthcare, law firms, consultancies, human resources, or other regulated sectors, the user or customer is responsible for the required legal basis, information obligations, consents, professional secrets, access rights, retention and deletion obligations, and entering into a data processing agreement where required.
For direct use by consumers, Nodl processes sensitive content only to the extent users record, upload, or knowingly provide it for processing themselves. Users should not process sensitive data of other persons if they are not authorised to do so.
7. Storage, Original Audio, and Deletion
Nodl stores recordings, transcripts, and generated documents according to the user’s or customer’s workspace settings. Users can save, export, or delete content. Depending on the plan, retention and deletion rules may be configurable.
Where users create recordings or upload audio, Nodl may store the original audio unchanged — as a reference source for comparison with transcripts and documents, where the user or customer uses or configures this function.
Nodl may additionally create technical files, such as normalised audio files, temporary processing copies, waveforms, transcript segments, or metadata. These files serve processing, playback, transcription, synchronisation, and document creation. Stored original audio remains unaffected.
Recordings, transcripts, documents, and any original audio are retained according to workspace settings and plan for as long as:
- the account or workspace exists and the applicable storage rule provides for this,
- the respective recording or document has not been deleted by the user,
- no contractual or statutory deletion has been triggered.
Users may delete recordings and documents where this function is available. After deletion, the affected content is removed from active systems within 30 days, unless statutory retention obligations, security incidents, disputes, abuse cases, or legitimate legal reasons require longer retention. In backups, content may remain until the backup cycle expires.
Nodl does not guarantee that stored content will be recognised in every legal, professional, or regulatory context or that it meets specific industry documentation obligations.
8. AI Processing
Nodl uses AI systems for:
- live transcription preview,
- batch transcription,
- speaker separation,
- generation of transcript segments and timestamps,
- transformation of transcripts into structured documents.
Under the current product design, the following providers or model families are used in particular:
| Processing | Provider / Model | Purpose |
|---|---|---|
| Transcription | Mistral / Voxtral — batch: voxtral-mini-latest; live preview: voxtral-mini-transcribe-realtime-2602 |
Live and batch transcription, speaker separation, timestamps |
| Document creation | Google / Gemini — gemini-3.1-flash-lite |
Structuring and conversion of transcripts into documents |
Audio, transcripts, prompts, and documents are not used to train own or third-party AI models. AI providers are used in the EU where possible. Zero-data-retention or comparable non-storage / non-training settings are intended where technically and contractually available. Providers may not use customer data for model training.
AI results may be incorrect. Users must review and approve results themselves. Detailed information on AI use and related obligations is provided in the AI Transparency Statement. The contractual framework is set out in the Terms of Service.
9. No Automated Decisions with Legal Effect
Nodl does not make solely automated decisions within the meaning of Art. 22 GDPR that produce legal effects concerning users or similarly significantly affect them.
Automated technical processes such as plan limits, usage counting, rate limits, spam / abuse protection, or security checks serve provision, security, and contract performance. Where such processes lead to blocking or significant restriction, users may contact support.
10. Speaker Separation, Emotions, and Biometric Data
Nodl uses speaker separation to distinguish segments of different speakers within a recording. Nodl does not identify persons by their voice, does not create permanent voiceprints, does not use speaker separation for authentication, and does not perform biometric categorisation.
Nodl is not designed as an emotion recognition system. If users express emotions or moods in a recording, such content may appear in the audio, transcript, or document. Targeted emotional classification of persons is not a purpose of Nodl.
11. Recipients and Service Providers
We may disclose personal data to service providers who support us in operating Nodl. These include in particular:
| Service provider / category | Purpose | Possible data |
|---|---|---|
| Hetzner | Hosting, storage, database, server infrastructure (Nuremberg, Germany) | Account data, content, logs, technical data |
| Mistral / Voxtral | Transcription and speaker separation | Audio, transcript and segment data, technical metadata |
| Google / Gemini | Document creation, possibly analytics after consent | Transcripts, prompts, generated documents; for analytics, usage data |
| Stripe | Payment processing, billing, invoice status | Payment and contract data, invoice data, tax data |
| Brevo | Transactional emails, possibly service communication | Email address, name, email content, technical delivery data |
| Cloudflare | CDN, DNS, attack protection, performance | IP address, request data, security logs |
| Self-hosted SigNoz / OpenTelemetry | Monitoring, error analysis, performance | Technical logs, error data, trace data |
| Legal, tax, and security advisors | Legal enforcement, compliance, incident response | Required contract, communication, and case data |
| Authorities and courts | Fulfilment of legal obligations | Required data on a case-by-case basis |
Service providers are engaged only to the extent necessary for the stated purposes. Where legally required, we enter into data processing agreements or other data protection agreements.
12. Transfers to Third Countries
We prefer processing within the EU or European Economic Area. Hosting, storage, and database operation are provided via Hetzner in Nuremberg, Germany. For Mistral/Voxtral and Google Gemini, EU processing is intended where technically and contractually available.
Some providers, such as Cloudflare, Google, Stripe, or Brevo, may be internationally organised companies. Access or transfers outside the EU/EEA may occur. In such cases, we rely, where required, on adequacy decisions, standard contractual clauses, supplementary safeguards, or other permissible transfer mechanisms under the GDPR.
13. Cookies and Analytics
Nodl currently uses in principle only technically necessary cookies and comparable technologies required for login, session management, security, consent management, and provision of the website.
Google Analytics is intended as a future analytics solution. Where Google Analytics is enabled and consent is required for it, Google Analytics will be used only after prior consent. Users may withdraw consent given at any time with effect for the future.
Marketing or retargeting cookies are not currently used. A newsletter is not currently offered.
14. Retention Periods and Deletion
We store personal data only for as long as necessary for the respective purposes, statutory obligations exist, or legitimate interests justify retention.
For Nodl, the following periods apply as an initial reasonable retention standard:
| Data category | Retention period |
|---|---|
| Account data | For as long as the account exists; deletion from active systems generally within 30 days after account deletion, unless statutory obligations prevent this |
| Original audio | According to workspace settings and plan for as long as account/workspace exists and the recording is not deleted; after user deletion, removal from active systems generally within 30 days |
| Normalised audio files and technical audio derivatives | For as long as required for playback, processing, or traceability; at latest upon deletion of the recording from active systems, unless required for security/dispute |
| Temporary processing files | Generally up to 7 days, maximum 30 days, unless required for error analysis or incident response |
| Transcripts and speaker segments | For as long as account/workspace exists and the recording or document is not deleted; after deletion, generally within 30 days from active systems |
| Generated documents | For as long as account/workspace exists and the document is not deleted; after deletion, generally within 30 days from active systems |
| Workspace and membership data | For as long as workspace or membership exists; thereafter generally 30 days, unless statutory obligations prevent this |
| Usage and limit data | During the contract term; thereafter generally 24 months for billing, abuse prevention, and product/support traceability |
| App and error logs | Generally 30 days |
| Security logs and incident data | Generally 12 months; longer in the case of a specific security incident, abuse, or legal dispute until resolved |
| Audit events for admin and security purposes | Generally 24 months; longer where there is a specific reason until resolved |
| Support communication | Generally 24 months after closure of the request; longer for ongoing contract, security, or legal matters |
| Payment, invoice, and accounting data | Generally 7 years under Austrian tax and company law retention obligations; longer where legally required or proceedings are pending |
| Consent and cookie settings | Generally 12 months or until withdrawal/reset, where technically required |
| Google Analytics data, if enabled | According to periods configured in the consent banner or in Google Analytics, typically maximum 14 months |
| Backups | Rolling backups generally up to 35 days; thereafter overwritten. During restore operations, already deleted data may temporarily reappear technically and will be deleted again. |
Statutory retention obligations, legitimate legal interests, abuse cases, security incidents, outstanding claims, or legal disputes may require longer retention.
15. Security
We implement technical and organisational measures to protect Nodl and personal data. These include in particular access restrictions, role-based permissions, transport encryption, secure authentication, monitoring, backups, logging, security reviews, and incident response processes.
Users are responsible for secure passwords, confidential credentials, lawful account use, and appropriate internal access rights.
16. Data Subject Rights
Data subjects have the following rights under the GDPR in particular:
- access to processed personal data,
- rectification of inaccurate data,
- erasure of personal data,
- restriction of processing,
- data portability,
- objection to processing based on legitimate interests,
- withdrawal of consent given with effect for the future,
- complaint to a data protection supervisory authority.
Please direct requests to [email protected].
Where we process data as processor for a customer, we will forward data subject requests to the respective customer where appropriate or handle them according to their instructions.
17. Right to Lodge a Complaint
Data subjects may lodge a complaint with a data protection supervisory authority. In Austria, this is in particular:
Austrian Data Protection Authority
Barichgasse 40-42
1030 Vienna
Austria
Website: https://www.dsb.gv.at
18. Obligation to Provide Data
Provision of certain data is required to use Nodl. Without account data, we cannot provide an account. Without audio or uploads, we cannot generate transcripts or documents. Without payment data, paid plans cannot be billed.
Provision of other content is voluntary. Users decide themselves what content they record or upload.
19. Changes to This Privacy Policy
We may amend this privacy policy when Nodl, service providers used, data processing, legal bases, or legal requirements change.
The current version will be made available on the website or in the app. We will inform users appropriately of material changes.