Leexi on iOSLeexi on Android

Leexi Security, Privacy and Compliance

  • Where your meetings are hosted, who processes them, and which documents to share with your DPO. Verified on 16/09/2026.
Try for free
Hosted in France, public DPA, no AI training, ten named subprocessors, ISO 27001:2022. Evidence to share with your DPO, section by section.

Your meeting data is hosted in France, in the AWS Paris region. It is encrypted in transit and at rest, processed by a language model running through Azure France in a closed circuit, and never used to train AI models. The DPA is public, all ten subprocessors are named, and ISO 27001:2022 certification is held. This page brings together the evidence in the order a DPO typically requests it.

Contact our security team · View our documents

Leexi's security commitments

🇪🇺 Data location. Recordings, transcripts and meeting notes are hosted in France, in the AWS Paris region, with a Scaleway option. Learn more

🔐 Security. Encryption in transit and at rest, access controls, backups, and measures supported by ISO 27001:2022 certification (Article 5.3 of the DPA). Learn more

🇪🇺 GDPR. A public DPA, effective since 6 July 2026, applicable from the free trial. Default retention of no more than two years, with breach notification within 24 hours. Learn more

🤖 AI and data. Your meetings are not used to train models. This commitment is set out in the privacy policy, and a written attestation is provided on request. Learn more

📋 Subprocessors. Ten subprocessors, named in Article 6.1 of the DPA with their role and hosting location, kept up to date in the Trust Center. View the list

Where is Leexi data hosted?

Your recordings, transcripts and meeting notes are hosted in France, in the Paris region, on AWS infrastructure. Processing by the language model takes place through Azure France, in a closed circuit. Above a certain volume of licences, hosting with Scaleway, a French provider, is available as an option; the threshold is set in the commercial contract.

Data Location Provider
Recordings France (Paris region) Amazon Web Services
Transcripts France (Paris region) Amazon Web Services
Meeting notes France (Paris region) Amazon Web Services
Account data (name, email, company) European Union Amazon Web Services

Last verified: 16/09/2026.

The complete list of infrastructure providers, with their hosting location, appears in Article 6.1 of the DPA and in the Trust Center.

Leexi and the GDPR

Whenever a provider processes personal data on your behalf, Article 28 of the GDPR requires a written contract and sets out its contents. This contract is Leexi's DPA: it is public, version 2.0 has been in effect since 6 July 2026, and it applies from online sign-up, including the free trial.

Responsibilities

You remain the data controller; Leexi is your processor. The DPA states this in its own terms.

Leexi DPA, Article 4.2 “As a data processor, Leexi will process personal data on behalf of and according to the instructions of the Data Controller.”

You decide the purpose of the recording, the retention period and who can access the meeting notes. Leexi carries out those instructions.

Personal data processed

The scope is set out in Article 3 of the DPA.

Leexi DPA, Article 3 “Leexi collects the following personal data: surname, first name, email, telephone number, role, company name, video-conference or VOIP (audio system) conversation, together with its metadata.”

According to the same article, data subjects are the client's employees, suppliers and customers. The operations covered are collection, transfer, retention and deletion.

Client instructions

The GDPR prohibits a processor from acting outside its instructions: it “only processes personal data on documented instructions from the controller” (Article 28(3)(a)). Processing your meetings for a purpose you have not determined—for example, training a model—would be processing without instructions.

Data subject rights

The right to erasure (Article 17 of the GDPR) is exercised through you, the data controller. Leexi assists you in responding (Article 7 of the DPA). Informing participants remains your responsibility: the Leexi assistant is visible in the meeting to help you do so.

Data deletion

A recording or meeting note can be deleted from the library. At the end of the contract, you choose between returning and deleting all data (Article 11.2 of the DPA). Leexi then purges backups that are no longer needed, using reasonable anonymisation efforts.

Retention periods

Leexi DPA, Article 9.1 “By default, data is retained for a maximum of 2 years. The client may reduce this period on request or through the settings of the Leexi platform.”

For reference, the CNIL uses six months for call recordings in the workplace and one year for analysis documents. The GDPR requires retention to be limited to what is strictly necessary (Article 5(1)(e)).

Download the DPA in French · Download the DPA in English

The article-by-article details are provided on the page DPA: what the law requires and what Leexi provides. The rules for recording meetings themselves—informing participants, legal basis and retention—are on the page recording a business meeting.

How Leexi uses artificial intelligence

A meeting passes through five stages. For each stage, the provider is named in the DPA together with its hosting location.

1. Audio capture. The assistant joins the meeting and remains visible to participants, whether by videoconference, telephone or in person using the mobile app. Data concerned: the conversation's audio stream and metadata (Article 3 of the DPA).

2. Transcription. Audio is converted into text by the speech-to-text providers named in the DPA: Gladia (hosting in the EU), Eleven Labs (hosting in Europe) and Microsoft Azure (hosting in the EU). Purpose: to produce the transcript you request.

3. AI model. The language model is provided by OpenAI and run through Azure France, in a closed circuit: processing remains within a controlled perimeter in France, without exposure to third-party use. Mistral is also named in the DPA for generative AI (hosting in the EU). Purpose: to draft the meeting notes and summary, and answer questions submitted to Ask Leexi about your own meetings. None of these operations trains the models.

4. Summary and analysis. The meeting notes arrive in your library: decisions, actions and deadlines. You decide whether to share them with your team or CRM.

5. Storage. Data is retained on AWS in the Paris region, encrypted at rest, for a maximum of two years by default; you can reduce this period in the settings.

Each subprocesser in this chain is bound by obligations at least as protective as those in the DPA (Article 6.3), implementing Article 28(4) of the GDPR.

Is our customers' data used to train the models?

No. This commitment is set out in the privacy policy, under “Security and training of AI models”:

Leexi, privacy policy “We do not use this data to train or improve generalised or non-personalised AI/ML models. Any AI processing applied is strictly limited to the features you request.”

The rule applies to all accounts by default. An attestation confirming that no training takes place, in the format expected by your DPO, is provided on request at hello@leexi.ai.

The exact scope of this commitment, the models that read your meetings and what the GDPR requires are detailed on the page no AI training on your meetings.

Our subprocessors

Ten subprocessors, named in Article 6.1 of the DPA with their role and hosting location. Reproduced from the DPA:

Subprocessor Role Hosting
Amazon Web Services Infrastructure hosting EU
Microsoft Azure Transcription and generative AI EU
Google Workspace Identity provider EU
Gladia Speech-to-text EU
Eleven Labs Speech-to-text Europe
Mistral Generative AI EU
Scaleway Cloud infrastructure (hosting, storage) EU (France)
Cloudflare Perimeter security Europe / United Kingdom
Mailgun Transactional emails EU (Frankfurt, Germany)
New Relic Application performance monitoring EU

List taken from DPA version 2.0 and verified in the Trust Center on 16/09/2026.

If Leexi adds or replaces a subprocessor, you will be informed and have fifteen days to raise a reasoned objection (Article 6.2 of the DPA).

Complete list of subprocessors

How Leexi protects your data

The technical and organisational measures are committed to in Article 5.3 of the DPA: encryption, access controls, regular backups, employee training and background checks. They have been fully implemented with ISO 27001:2022 certification.

Encryption

Your data is encrypted in transit and at rest.

Access controls

Access controls are among the measures committed to under Article 5.3 of the DPA. On the user side, you decide which people in your organisation can access the meeting notes. On Leexi's side, employees are trained and their backgrounds are checked (Article 5.3).

Data isolation

Your meetings remain within your account. Ask Leexi reads your meetings to answer your questions, within the limits of your account. An audit conducted by one client does not grant access to other clients' data (Article 10.1 of the DPA).

Backups

Regular backups are among the measures in Article 5.3. At the end of the contract, backups that are no longer needed follow a deletion process, with reasonable anonymisation efforts (Article 11.2).

Monitoring

Application performance monitoring is provided by New Relic, hosted in the EU (Article 6.1 of the DPA).

Incident management

Leexi DPA, Article 5.4 “Leexi must notify the client of any personal data breach within a maximum period of twenty-four (24) hours after becoming aware of it, by email.”

The notification describes the nature of the breach, the categories and approximate number of data subjects concerned, a contact point, the likely consequences and the measures taken. This gives you the information needed for your own notification to the supervisory authority within the 72 hours required by the GDPR.

Security testing

Leexi undergoes regular audits, including audits conducted by its own clients. The audit right is contractual: you may appoint an independent auditor once in any twelve-month period, with at least 20 days' notice and a confidentiality agreement (Article 10.1 of the DPA).

All security controls are documented by domain in the Trust Center.

Certifications and audits

ISO 27001:2022. Held. The DPA uses this certification as a reference (Article 5.3). The certificate is provided on request, together with access to the Trust Center.

ISO 42001. In progress. The standard structures the AI management system.

SOC 2 Type 2. In progress (Trust Center, recorded on 16/09/2026).

NIS2. Compliance being finalised. NIS2, not ISO 27001, creates the legal security obligation for “essential” and “important” entities; ISO 27001 is one way of meeting it.

EU AI Act. Leexi aligns with the European AI Regulation, particularly on transparency: the assistant is visible in the meeting and participants are informed. The commitment appears in Annex 1.1 of version 2.0 of the general terms and conditions.

Client audits. The annual audit right is set out in Article 10.1 of the DPA.

Important to know before submitting the dossier: Leexi currently holds neither SecNumCloud qualification nor its own HDS certification. For sensitive public-sector or health data, this point must be assessed on a case-by-case basis before any commitment.

Compliance documents

  • DPA, version 2.0 dated 6 July 2026: French version, English version. Accepted upon sign-up, including the free trial.
  • Privacy policy: leexi.ai/fr/politique-de-confidentialite. Contains the no-training commitment.
  • General terms and conditions, version 2.0 dated 6 July 2026: terms_of_service_fr.pdf. Commitment regarding the European AI Regulation in Annex 1.1.
  • List of subprocessors: Article 6.1 of the DPA and Trust Center, kept up to date.
  • ISO 27001:2022 certificate: provided on request at hello@leexi.ai, together with access to the Trust Center.
  • No-training attestation: available on request at hello@leexi.ai, covering the scope expected by your DPO (transcripts, logs, embeddings).
  • Record of processing activities: the obligation under Article 30 of the GDPR, which the DPA states is maintained in Article 14.3. Available on request.

Frequently asked questions

Where are my meetings stored?

In France. Your recordings, transcripts and meeting notes are hosted in the Paris region on AWS infrastructure. Above a certain volume of licences, hosting with Scaleway, a French provider, is available as an option.

Does Leexi use my data to train its models?

No. The privacy policy excludes the training and improvement of generalised or non-personalised models, and limits all AI processing to the features you request. The rule applies to all accounts by default, and an attestation is provided on request for your records.

Which subprocessors have access to the data?

The ten subprocessors named in Article 6.1 of the DPA, each with its role and hosting location, all in the EU, Europe or the United Kingdom. You are notified of any addition and have fifteen days to object (Article 6.2).

Can I request deletion of my data?

Yes. A recording or meeting note can be deleted from the library. At the end of the contract, you choose between returning and deleting all data (Article 11.2 of the DPA), and unnecessary backups are purged. The right to erasure is exercised through you, the data controller, and Leexi assists you in responding.

Is Leexi GDPR compliant?

Leexi fulfils the obligations that Article 28 of the GDPR imposes on a processor, and each can be verified through documentation: a public DPA with documented instructions, ten named subprocessors with a right to object, security measures supported by ISO 27001:2022, breach notification within 24 hours, retention limited to a maximum of two years, return or deletion at the end of the contract, and an annual audit right.

Does data leave the European Union?

Not for storage and processing, which remain in France. A transfer outside the EU is possible only to a country recognised as adequate by the European Commission or under standard contractual clauses (Article 6.4 of the DPA). AWS remains a company governed by US law and theoretically subject to the Cloud Act: for a strict sovereignty requirement, the Scaleway option meets the need, and Article 15 of the DPA commits Leexi to notifying you of any request from an authority in a third country.

How long are recordings retained?

A maximum of two years by default. You can reduce this period on request or in the platform settings (Article 9.1 of the DPA). For reference, the CNIL uses six months for call recordings in the workplace.

A question about security or compliance?

Write to hello@leexi.ai. This is the channel for obtaining a countersigned copy of the DPA, the no-training attestation, the ISO 27001:2022 certificate or the record of processing activities.

The DPA applies from the free trial: you can test Leexi on a real meeting while your DPO reviews it.

Sources

Texts taken from primary sources on 2 and 16 September 2026.

  • Leexi, Data Processing Agreement, version 2.0 effective from 6 July 2026, dpa_fr.pdf
  • Leexi, Privacy Policy, section “Security and training of AI models”, leexi.ai/fr/politique-de-confidentialite
  • Leexi, General terms and conditions of sale and use, version 2.0 effective 6 July 2026
  • Leexi, Trust Center, trust.leexi.ai, accessed 16 September 2026
  • GDPR, Articles 5, 17, 28, 30 and 32, text published by the CNIL
  • European Regulation on Artificial Intelligence, Article 50

This page describes the applicable framework. It does not constitute legal advice.

Try Leexi for free

Recommended Articles

Ready to boost your productivity with Leexi?

Leexi AI Notetaker takes notes for you

Discover here