🛡️ Enterprise Security & Transparency

Privacy Policy

Effective Date: August 29, 2026 • Version 2.4

Our Core Privacy Pledge

Your voice and thoughts belong to you. deHertz does not sell your data, and we never use your audio recordings or transcripts to train public or commercial AI models. Your memories remain confidential, securely encrypted, and under your exclusive control.

1. Introduction & Scope

deHertz Technologies FZ-LLC ("deHertz", "we", "our", or "us") operates the deHertz memory ecosystem, comprising the deHertz wearable hardware pendant, companion mobile applications (iOS & Android), and web management dashboard (collectively, the "Service").

This Privacy Policy explains what personal information, voice recordings, and metadata we collect, how they are stored, processed, and safeguarded, and your legal rights under international data protection standards including the GDPR, CCPA, and UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL).

2. Information We Collect

  • Account & Identity Information: Your full name, work email address, hashed credentials, job title, and company organization details.
  • Audio & Voice Captures: Voice recordings captured via the paired deHertz pendant device, mobile device microphone fallback, or direct audio imports explicitly initiated by you.
  • Transcripts & Cognitive Intelligence: Full-text transcripts, AI-generated overviews, key takeaways, speaker attributions, tasks, reminders, commitments, opportunities, and personal daily digests.
  • Hardware & Device Diagnostics: Unique hardware identifiers (Device MAC, BLE IDs), battery telemetry, firmware versions, and sync timestamps.
  • Connected Cloud Integrations: OAuth authentication tokens for authorized third-party services (e.g., Google Calendar for meeting synchronisation and Google Drive for personal audio backups).

3. How We Process & Utilize Data

We process your data strictly to deliver the core functionality of the deHertz platform:

  • Transcribing speech into searchable text using privacy-preserving models.
  • Extracting structured action items, meeting schedules, and follow-up opportunities.
  • Delivering automated push notifications for scheduled reminders and morning briefings.
  • Enabling semantic search and conversational memory retrieval across your history.
  • Synchronizing recordings across your personal devices and authorized team workspaces.

4. Third-Party Processing & AI Architecture

To maintain peak accuracy with zero compromise on privacy, our architecture separates audio transcription from language reasoning:

Speech Transcription

Processed on dedicated infrastructure using Whisper models. Raw audio is never forwarded to public consumer platforms.

Summary & Reasoning

Handled primarily by our own self-hosted language model on infrastructure we control. Where a fallback provider is used, it operates under enterprise API terms that contractually prohibit training on your content. We do not send your data to providers whose terms permit training on submitted content.

5. Google User Data & Limited Use

deHertz offers optional integrations with Google Sign-In, Google Drive, and Google Calendar. These are entirely optional; the Service works fully without connecting a Google account, and you can disconnect at any time from Settings, which revokes our access immediately.

What Google data we access

  • Google Sign-In: your name, email address, and profile photo, used solely to create and authenticate your account.
  • Google Drive: write-only. If you enable personal backup, we upload copies of your own recordings into a deHertz folder in your Drive. We do not read, list, or index any other file in your Drive.
  • Google Calendar: used to create events you schedule from within deHertz.

Who we share, transfer, or disclose Google user data to

We do not sell, rent, or trade Google user data, and we do not share it with any third party for advertising, analytics, or profiling. Google user data is disclosed only in these cases:

  • To Google itself, when carrying out an action you requested — for example creating a calendar event or uploading a backup to your Drive.
  • To our infrastructure providers acting strictly as data processors on our instructions and bound by contract: Microsoft Azure (encrypted storage, hosted in-region) and MongoDB Atlas (application database). They have no right to use the data for their own purposes.
  • Where legally compelled, in response to a valid, binding legal order — and we will notify you unless prohibited from doing so.
  • To you, whenever you export or share your own data.

Google user data is never sent to any third-party artificial intelligence or machine-learning service. Our AI features operate exclusively on audio you record with deHertz and the transcripts derived from it. Data obtained through any Google API is architecturally separated from the AI pipeline and is never used as input to it.

How we protect sensitive data

  • Encryption in transit: all traffic between the apps, our API, and Google is carried over TLS 1.2 or higher. We do not accept unencrypted connections.
  • Encryption at rest: recordings and backups are stored encrypted using AES-256 managed by Microsoft Azure.
  • Credential handling: OAuth tokens are stored encrypted, never written to logs, and held only as long as the integration is connected. Disconnecting deletes them. On mobile devices, session credentials are held in the iOS Keychain and Android Keystore.
  • Access control: every request is authenticated and scoped to your own organisation. Access to production systems is restricted to authorised personnel on a least-privilege basis, and is logged.
  • Minimisation: we request the narrowest OAuth scopes that make each feature work, and we do not retain Google data we have no active use for.

Limited Use commitment

deHertz's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data to develop, improve, or train generalized artificial intelligence or machine-learning models, and we do not transfer it to any third party that does.

6. Recording Consent & Legal Responsibility

Important: You are solely responsible for ensuring compliance with recording and wiretapping laws in your jurisdiction.

Laws governing the recording of in-person or telephonic conversations vary globally (such as two-party or all-party consent states in the US, and consent provisions in the UAE and EU). You must inform participants whenever legally required and obtain necessary authorizations prior to capturing audio.

7. Data Retention, Export & Deletion

You maintain total ownership of your data at all times:

  • Granular Deletion: You can delete any individual recording or transcript directly inside the mobile app or web console at any time.
  • 1-Click Account Deletion: You can permanently purge your entire account and all cloud-stored audio and transcripts via Settings → Delete Account.
  • Data Portability: Export your notes, action items, and transcripts anytime in structured formats (JSON / Text).

8. Contact & Data Protection Officer

For privacy inquiries, GDPR data requests, or compliance questions:

Data Protection Officer: deHertz Technologies FZ-LLC

Email: info@dehertz.com / privacy@dehertz.com

Phone / WhatsApp: +971 58 549 9548

Location: Dubai Internet City, Dubai, United Arab Emirates