Phonotheca

Data governance statement

Written for research ethics committees, university procurement, and the researcher filling in the form. Everything here applies on every plan, including Free.

Who is the controller and who is the processor

Your institution is the data controller for the recordings you upload. Phonotheca is a processor, acting only on your documented instructions, under a data processing agreement that carries the Article 28 obligations.

We do not decide what your recordings are for, we do not use them for any purpose of our own, and we do not acquire rights over them by receiving them. The people in your interviews are your research participants and never our users.

Where the data is

In the European Union, at every step. Application servers run in Frankfurt, the database is in Frankfurt (eu-central-1), and uploaded audio is stored in Frankfurt. Transcription runs on AssemblyAI’s EU endpoint in Dublin, Ireland.

Nothing in the normal operation of the service moves a recording outside the EU, and there is no plan tier at which this changes. You do not have to ask for it, be quoted for it, or reach an account manager to get it.

Who else touches it

Our sub-processors, what each receives, and where it runs. We give notice before this list changes.

  • AssemblyAI, transcription, EU endpoint (Dublin, Ireland). Receives interview audio and returns the transcript. The transcript is deleted from AssemblyAI once it lands in your workspace.
  • Vercel, hosting and file storage, EU (fra1, Frankfurt). Runs the application and stores uploaded audio.
  • Neon, database, EU (eu-central-1, Frankfurt). Holds accounts, transcripts, tags, and usage records.
  • Brevo, transactional email. Receives an email address to send a sign-up confirmation. Never receives recordings or transcripts.
  • Creem, merchant of record for payments. Receives billing details and is the seller on your invoice. Never receives recordings or transcripts.

Exactly one sub-processor beyond our own infrastructure receives your audio, and that is AssemblyAI. No human at Phonotheca or at any sub-processor listens to a recording as part of transcribing it.

Retention and deletion

Content stays until you delete it. Deleting an interview or a project removes its audio and its transcript. Deleting your account removes your content and your account data.

The transcript is removed from the transcription sub-processor once it has landed in your workspace, so the copy that exists after processing is the one in your archive.

Two things outlive an interview. Usage records are content-free, holding a duration and dates and never audio or text, so an allowance cannot be reset by deleting and re-uploading. They are deleted with the account. Payment records are kept for as long as tax law requires, which Creem handles as merchant of record.

Training

Phonotheca does not train any model on your recordings, transcripts, or tags, and does not sell or share them. We build no models and derive no dataset from customer content.

The DPA

We sign a data processing agreement, also called a DPA, covering the Article 28 obligations, the sub-processor list above, and the standard contractual clauses where they apply. Write to support@phonotheca.com and we will send it for signature. There is no sales call attached to this and no plan requirement.

Certifications, stated plainly

Phonotheca holds no SOC 2 report, no ISO 27001 certificate, no HIPAA BAA, and no FedRAMP authorisation. If your process requires one of those from the vendor itself, we do not currently meet it, and we would rather you learn that here than three weeks into a review.

Our infrastructure and transcription providers publish their own audits and certifications, which cover their part of the pipeline rather than ours.

Wording you can paste

For a participant information sheet or consent form, where the study uses a third-party transcription service.

Interview recordings will be transcribed using Phonotheca, a transcription and analysis service operating under a data processing agreement with [INSTITUTION]. Recordings are processed and stored within the European Union and are not used to train any artificial intelligence model. Only the research team will have access to the full data.

For an ethics application or data management plan.

Audio will be transcribed by Phonotheca (operated by Adesia S.R.L., Italy), acting as data processor under a signed data processing agreement. Application, storage, and database are located in Frankfurt, Germany, and speech-to-text processing runs on AssemblyAI’s EU endpoint in Dublin, Ireland. No recording is transferred outside the EU in normal operation. The transcript is deleted from the transcription sub-processor once it has been retrieved. Customer recordings and transcripts are not used to train models. The sub-processor list and retention terms are published at phonotheca.com/data-governance.

If your committee asks a question these do not answer, write to support@phonotheca.com and we will answer it in writing so you can attach the reply.

If you are in the United States

US review forms ask who transcribes the recording and what happens to it afterwards, rather than which country it sits in. Those questions are answered on the US research data page, along with the data classification levels this is and is not appropriate for.

Who we are

Phonotheca is operated by Adesia S.R.L., Via Napoli 23, 65121 Pescara PE, Italy, VAT IT02467940686. The privacy notice covers account data, lawful bases, your rights, and breach notification in full.