Ultra Premium
Buy more templates at mediumrare.shop
Ultra Premium
Buy more templates at mediumrare.shop
DSTNYIQ / LEGAL
DstnyIQ Privacy Policy
Last updated: 14 August 2026
DSTNYIQ / LEGAL
DstnyIQ Terms of Use
Last updated: 14 August 2026
1. Who we are
This policy explains how Capacit A/S (“Capacit”, “we”) handles personal data in DstnyIQ and partner-branded versions of the same service where the processing described in this policy is materially the same. Separate services may be subject to separate privacy information. Capacit A/S, CVR 42607797, Overgaden Neden Vandet 9A, 1414 Copenhagen, Denmark. Privacy contact: info@capacit.com. Where you buy DstnyIQ through a partner, your contract and first point of contact may be with that partner.
2. What DstnyIQ does
DstnyIQ joins Microsoft Teams meetings as a visible participant and records the meeting. Recordings are processed automatically using AI to produce transcripts and summaries, which are delivered to the recipients the customer organisation configures. The recorder appears in the Teams participant list the whole time it is present and can be removed from a meeting at any time by a participant with a sufficient meeting role.
3. Our role — this determines who you ask
The customer organisation decides to record. We do not.
For meeting content, the customer organisation whose Microsoft 365 tenant is connected to the service is the data controller. Capacit is a processor and acts only on that organisation’s documented instructions under a data processing agreement.
Capacit is a controller for a narrower set: business contact and account details, onboarding, licensing, usage and billing records, support correspondence, and the security and operational logs we need to run the service. For meeting content, Capacit acts as a processor — or, where the service is supplied through a partner, as the partner’s sub-processor — and acts only on documented instructions originating from the customer organisation under the applicable data processing agreement. Where a partner is involved, instructions and requests flow through the partner. We do not sell personal data and do not use it for advertising. What we do and do not do with meeting content for AI purposes is in section 7.
4. If you are a meeting participant
A participant called DstnyIQ, or a partner-branded equivalent, may have appeared in your meeting. The meeting audio is recorded, transcribed and summarised by AI, and sent to recipients chosen by the organising organisation. If you have concerns about being recorded, contact the meeting organiser or use any meeting controls made available to you. Your rights and the organiser’s legal basis depend on the circumstances of the meeting. The organisation that organised the meeting is responsible for it. This policy does not replace the privacy information that the organising organisation, as controller, is required to provide about its recording and use of meeting content. Ask them about purpose, legal basis, retention and your rights. You can also write to info@capacit.com and we will pass your request to them and confirm we have done so — we cannot decide it ourselves.
5. What we process
Meeting content (we are processor): meeting audio; transcripts and summaries generated from it; participant details such as name, email address, Microsoft Entra identifier, meeting role and join/leave times; meeting metadata such as subject, time, organiser and meeting identifiers; and records of the transparency notices sent about a meeting. Recorded speech can contain anything participants choose to say, including special category data under Article 9 GDPR. DstnyIQ is not designed to identify or profile individuals based on special category data. Such information may nevertheless be reflected in transcripts or summaries where it forms part of the meeting content.
We do not create voiceprints. DstnyIQ does not perform voice biometrics, does not generate or store biometric identifiers, and does not identify or recognise anyone from voice characteristics — including across meetings. Speaker attribution comes from the Microsoft Teams participant identity attached to the audio stream, not from analysing the voice itself. We also do not perform emotion recognition. We do not market to meeting participants. Email addresses obtained from a customer’s calendar or participant list are used only to send transparency notices about the meeting and to deliver the output the customer has configured. We do not use them to promote our services, and we do not add participants to mailing lists. Customer and account data (we are controller): business contact details; tenant, onboarding and licensing records; service configuration; usage and billing records; support correspondence; and application and security logs, which can contain technical identifiers and IP addresses.
We receive controller-side account and business contact data directly from you, from your employer or organisation, from an authorised partner, and where relevant from your organisation’s Microsoft 365 tenant.
Certain administrator, account and tenant information is necessary to provision and administer the service. If it is not provided, we may be unable to activate or support the relevant account or tenant.
6. Why, and on what basis
Where we are processor, the legal basis for meeting content is set by the customer organisation, not by us. Where we are controller, we rely on Article 6(1)(b) where processing is necessary to perform a contract with the individual concerned. Otherwise, we rely on our legitimate interests under Article 6(1)(f) for administering and supporting our business customer relationships, user accounts and service operations, including operating, securing, troubleshooting and improving the service. Our legitimate interest in improving the service relates to account, usage, diagnostic and operational data and does not permit us to use customer meeting content for model training or independent product development. We also rely on legal obligations under Article 6(1)(c) for accounting and lawful requests. We do not carry out automated decision-making with legal or similarly significant effects under Article 22 GDPR.
7. AI
DstnyIQ uses AI models hosted in Microsoft Azure to transcribe audio and generate summaries. AI output can be wrong. Transcripts and summaries can mis-hear words, misattribute speech, omit material and state things that were not said. Treat them as an aid, not as a record of what was said, and verify before relying on them. Content is not used to train models. Meeting content sent for AI processing is used to return a result and is not used by us or by our providers to train or improve any model.
Microsoft’s abuse monitoring
Microsoft operates automated abuse detection on the Azure OpenAI Service. Content flagged by Microsoft’s abuse-monitoring systems may be stored and made available to authorised Microsoft personnel for human review in accordance with Microsoft’s then-current Azure service terms and privacy documentation, so that misuse of the service can be detected and prevented. Content that is not flagged is not retained for this purpose. Because our Azure OpenAI deployments are located in the European Economic Area, any Microsoft personnel who carry out such a review are also located in the European Economic Area. This monitoring is Microsoft’s own and is limited to detecting misuse.
8. Who we share with
Sub-processors. Each sub-processor is engaged under written terms imposing the same data protection obligations as apply to Capacit under the applicable data processing agreement, to the extent relevant to the sub-processor’s services. Our current sub-processors are:
Sub-processor
Purpose
Location
Microsoft (Azure)
Hosting, storage, database, key management, logging
EU
Microsoft (Azure OpenAI Service)
AI transcription and summarisation
EU
Microsoft (Azure AI Speech)
Live speech-to-text, where enabled
EU
We notify customers before adding a sub-processor, as set out in the applicable data processing agreement. Where DstnyIQ is supplied through a partner, the parties’ respective roles in relation to personal data are set out in the applicable data processing and sub-processing arrangements. Dstny does not access meeting content or outputs. Output delivery: transcripts and summaries go only to the recipients the customer organisation configures. Others: professional advisers under confidentiality; authorities where legally required, with notice to the customer or partner where lawful; and an acquirer in a merger or sale, subject to this policy continuing to apply.
9. Where data is held, and transfers
The service is hosted in Microsoft Azure in the European Union, and meeting content is stored and primarily processed in the EU. Recordings, service data and AI summarisation are currently handled in Sweden Central, and AI transcription in West Europe (Netherlands). We may change EU regions as capacity requires. Where Microsoft’s abuse-monitoring process results in human review, flagged content may be accessed by authorised Microsoft personnel located within the EEA, as described in section 7. Your Teams meeting itself runs in Microsoft’s infrastructure under your own agreement with Microsoft. Where personal data is transferred outside the EU/EEA, we rely on the European Commission’s Standard Contractual Clauses with supplementary measures, or another valid transfer mechanism. This may apply to controller-side data, such as support tooling, rather than meeting content. Request a copy of the safeguards at info@capacit.com.
10. Retention and deletion
Meeting content is the customer’s, and the customer sets the period. Recordings, transcripts and summaries are retained for the period agreed with the customer organisation in its agreement with us, and are deleted when that period ends or when the customer instructs deletion. Where nothing else is agreed, our default is up to 30 days from the date of the meeting — for the recording, the transcript and the summary alike. Deletion takes effect in active systems within 7 days of the retention period ending or of a customer’s instruction.
When a customer’s agreement ends, we delete or return their meeting content in accordance with the data processing agreement, unless we are legally required to keep it. Account, licensing and configuration records are retained for the duration of the customer relationship and thereafter only for as long as necessary to close the account, comply with legal obligations, or establish, exercise or defend legal claims. Relevant contractual and customer relationship records may generally be retained for up to three years after termination. Billing and accounting records are retained for five years from the end of the financial year to which they relate, as required by the Danish Bookkeeping Act. Operational logs and diagnostics are retained for up to 90 days.
11. Security
We protect customer data with technical and organisational measures appropriate to the risk. These include encryption in transit and at rest, identity-based access control with access limited to personnel who need it for their role, segregation of each customer’s content, integrity verification and short-lived access links for stored recordings, and centralised logging and monitoring. Our full technical and organisational measures are set out in the applicable data processing agreement, which customers may request from their provider. No system is perfectly secure. Where we act as processor or sub-processor, we notify the relevant customer or partner through which the service is supplied without undue delay after becoming aware of a personal data breach and assist with applicable notification obligations. Where we act as controller, we notify the competent supervisory authority and affected individuals where the law requires it.
12. Your rights
Depending on the circumstances and the applicable legal basis, you may have the right to access your personal data, correct it, have it erased, restrict or object to processing, obtain portability, and withdraw consent where processing relies on it. Where to send the request depends on who controls the data. For meeting recordings, transcripts and summaries, that is the organisation that organised the meeting — send it to them. If you send it to us we will forward it via our partner where applicable, confirm we have done so, and assist as the applicable data processing agreement requires, but we cannot decide it ourselves. For data where we are controller — your business contact details, account records, support correspondence — write to info@capacit.com. We respond without undue delay and in any event within one month. Where permitted by law, this period may be extended by up to two further months, and we will inform you of any extension within the initial one-month period. We may need to verify your identity.
Complaints. You are welcome to contact us first, and you also have the right to lodge a complaint with a supervisory authority — in Denmark, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, dt@datatilsynet.dk, datatilsynet.dk — or with the authority where you live or work.
13. Changes
We may update this policy as the service develops. The “Last updated” date changes, and where changes are material we notify customers in advance. The current version is always at https://capacit.com/dstnyiq/privacy.
14. Contact
Capacit A/S, Overgaden Neden Vandet 9A, 1414 Copenhagen, Denmark. Privacy and data subject requests: info@capacit.com. Inappropriate AI-generated content: info@capacit.com. Security: info@capacit.com. Support: info@capacit.com.
1. Parties, acceptance, and precedence
These Terms govern use of DstnyIQ, the Microsoft Teams meeting recording and AI transcription service supplied by Capacit A/S, CVR [CVR NUMBER], Overgaden Neden Vandet 9A, 1414 Copenhagen, Denmark (“Capacit”, “we”), including where it is supplied under a partner brand. They apply to the Customer — the organisation that subscribes and connects its Microsoft 365 tenant — and to Users, the individuals it permits to use the service. By installing the app, connecting a tenant, adding the recorder to a meeting or otherwise using the service, you accept these Terms. If you accept on behalf of an organisation, you confirm you are authorised to bind it, and “you” means that organisation. Order of precedence: where a signed agreement exists between the Customer and Capacit or an authorised partner, that agreement prevails over these Terms with respect to commercial terms. In a conflict concerning personal data, the Data Processing Agreement prevails. The Data Processing Agreement forms part of the arrangement between the parties. [CONFIRM HOW THE DPA IS CONCLUDED.] Our Privacy Policy describes how we process personal data. Purchases through a partner are governed by the partner agreement for fees, subscription term and partner-provided support; these Terms otherwise continue to apply.
2. The service
DstnyIQ joins Microsoft Teams meetings as a visible participant and records them. The recorder is shown in the participant list while present and can be removed by a participant with a sufficient meeting role at any time. Recordings are processed automatically using AI to produce transcripts and summaries, delivered to the recipients the Customer configures. The Customer controls how the recorder joins meetings through its configuration of the service. We may change, improve or discontinue features. Where a change materially reduces core functionality we will give the Customer reasonable prior notice.
3. Access and licence
The Customer must have a Microsoft 365 tenant with Microsoft Teams and must complete administrator consent. Microsoft Teams itself, and the Customer’s agreement with Microsoft, are not part of this service. We grant the Customer a non-exclusive, non-transferable, non-sublicensable right to use DstnyIQ during the subscription term for its own internal business purposes, limited to the licences subscribed for. The Customer is responsible for its Users’ compliance with these Terms, for keeping credentials secure, and for its configuration choices — including who receives transcripts and summaries.
4. Recording is the Customer’s decision and responsibility
We supply the tool. The Customer decides to record, and is solely responsible for doing so lawfully. The Customer warrants that it will establish a lawful basis for recording each meeting and related processing; give required notices and obtain consent where applicable; keep transparency notices accurate, intelligible and legally sufficient; handle objections from participants; comply with obligations under the GDPR, Article 50 of the EU AI Act and applicable employment, works council, sector and confidentiality rules; carry out any required assessment; and set an appropriate retention period and instruct us accordingly. We provide transparency features to help, including a visible recorder, notices to invitees and in the meeting chat, and a configurable pre-recording notice period. Using them does not discharge the Customer’s legal obligations. The Customer indemnifies us for breach of this section under section 9.
5. Acceptable use
The Customer and its Users must not record covertly or conceal the recorder from participants; record conversations they have no right to record; use the service for unlawful monitoring of employees or in breach of employment or works council requirements; record privileged, medical or other specially protected conversations without having established that it is lawful; use output for biometric identification, emotion inference or automated evaluation of individuals in a manner prohibited by the EU AI Act; resell or sublicense the service except as agreed; reverse engineer it where unenforceable by law; probe or test its security without written consent; attempt unauthorised access; disrupt it, circumvent usage limits or impose unreasonable load; use it to store or transmit malicious, unlawful, infringing, defamatory or harassing content; or attempt to manipulate, override or bypass AI instructions, safety controls or intended behaviour. We may suspend access where we reasonably believe this section is breached, where required by law, or where there is a security risk. Where practicable we notify first and limit suspension to what is necessary.
6. AI output
AI output can be inaccurate. Transcripts and summaries can mis-hear words, misattribute speech, omit material and generate statements that were never made. They are an aid, not a verbatim or authoritative record of a meeting. The Customer and its Users must review AI output before relying on it, and must not treat it as a legal record, a minute, or evidence of what was said without independent verification. We are not liable for decisions taken on unverified AI output. Report inappropriate, harmful or offensive AI output to info@capacit.com with enough detail to identify it. We investigate promptly and take corrective action.
7. Customer data, IP and confidentiality
Ownership: as between the parties the Customer owns its recordings, transcripts, summaries and other content the service generates from its meetings (Customer Data). We claim no ownership. Our licence: the Customer grants us a limited licence to host, process, transmit and display Customer Data solely to provide, secure and support the service, and as the Customer instructs. We will not sell it, use it for advertising, or use it to train AI models. We may use aggregated and anonymised statistics that cannot reasonably identify any Customer or individual. Our IP: we and our licensors retain all rights in the service, software, documentation and branding. Confidentiality: each party will keep the other’s confidential information confidential and use it only for the purposes of these Terms, subject to standard exceptions. For personal data in Customer Data the Customer is controller and Capacit is processor, processing only on the Customer’s documented instructions under the Data Processing Agreement.
8. Warranties, disclaimers and liability
We will provide the service with reasonable skill and care and in accordance with any service levels expressly agreed in writing. Otherwise, to the maximum extent permitted by law, the service is provided as is. We do not warrant uninterrupted or error-free use, that it will join every meeting or capture every part of one, or that AI output will be accurate or complete. The service depends on Microsoft Teams, Microsoft Graph and Microsoft Azure, and we are not responsible for third-party platform failures outside our reasonable control. The Customer must not rely on DstnyIQ as its sole means of capturing a meeting where failure to capture would cause loss. Neither party excludes liability for death or personal injury caused by negligence, fraud, or anything that cannot lawfully be excluded. Subject to that, neither party is liable for indirect or consequential loss, loss of profit, revenue, anticipated savings, business or goodwill; and each party’s total aggregate liability is limited to [LIABILITY CAP]. [CONFIRM CARVE-OUTS.]
9. Indemnity
The Customer will defend and indemnify us against any third-party or supervisory authority claim, proceeding, fine or penalty, and resulting losses and reasonable legal costs, arising from its breach of section 4 or section 5, use of the service in breach of applicable law, or a claim that it recorded someone unlawfully or without adequate notice. We will notify the Customer of the claim, let it control the defence, and assist reasonably at its expense. Any settlement admitting our liability needs our consent. [CONFIRM WHETHER CAPACIT GIVES A RECIPROCAL IP INFRINGEMENT INDEMNITY.]
10. Term and termination
These Terms apply while the Customer uses the service. Either party may terminate for material breach not remedied within 30 days of written notice, or immediately on the other’s insolvency. On termination the Customer’s right to use the service ends, the tenant connection is disabled, and we delete or return Customer Data in accordance with the Data Processing Agreement, except where legally required to retain it. Export anything you want to keep before termination takes effect. Sections 7, 8 and 9 survive.
11. General
Governing law is Danish law, excluding conflict of law rules and the CISG. The courts of [VENUE] have exclusive jurisdiction. [CONFIRM ARBITRATION PREFERENCE AND ANY NON-DANISH CUSTOMER CARVE-OUT.] We may update these Terms; where changes are material we give reasonable notice before they take effect, and continued use after that date is acceptance. The current version is always at https://capacit.com/dstnyiq/terms. Fees are set out in the Customer’s order form or partner agreement. Capacit may assign these Terms to an affiliate or in connection with a merger, reorganisation or sale. The Customer may not assign without Capacit’s prior written consent. We may use subcontractors and sub-processors and remain responsible for their performance. Neither party is liable for failure caused by events beyond reasonable control. These Terms, together with the Data Processing Agreement and any signed agreement or order form, are the entire agreement on this subject. If a provision is unenforceable the rest stands, modified only as needed. Notices to us: info@capacit.com and Capacit A/S, Overgaden Neden Vandet 9A, 1414 Copenhagen, Denmark. To the Customer: the contact details in its account.
12. Contact
For support, legal, privacy, security and inappropriate AI-generated content:
Support
info@capacit.com
Legal, Privacy & Security
info@capacit.com
Inappropriate AI-generated content
info@capacit.com
1. Who we are
This policy explains how Capacit A/S (“Capacit”, “we”) handles personal data in DstnyIQ and partner-branded versions of the same service where the processing described in this policy is materially the same. Separate services may be subject to separate privacy information. Capacit A/S, CVR 42607797, Overgaden Neden Vandet 9A, 1414 Copenhagen, Denmark. Privacy contact: info@capacit.com. Where you buy DstnyIQ through a partner, your contract and first point of contact may be with that partner.
2. What DstnyIQ does
DstnyIQ joins Microsoft Teams meetings as a visible participant and records the meeting. Recordings are processed automatically using AI to produce transcripts and summaries, which are delivered to the recipients the customer organisation configures. The recorder appears in the Teams participant list the whole time it is present and can be removed from a meeting at any time by a participant with a sufficient meeting role.
3. Our role — this determines who you ask
The customer organisation decides to record. We do not.
For meeting content, the customer organisation whose Microsoft 365 tenant is connected to the service is the data controller. Capacit is a processor and acts only on that organisation’s documented instructions under a data processing agreement.
Capacit is a controller for a narrower set: business contact and account details, onboarding, licensing, usage and billing records, support correspondence, and the security and operational logs we need to run the service. For meeting content, Capacit acts as a processor — or, where the service is supplied through a partner, as the partner’s sub-processor — and acts only on documented instructions originating from the customer organisation under the applicable data processing agreement. Where a partner is involved, instructions and requests flow through the partner. We do not sell personal data and do not use it for advertising. What we do and do not do with meeting content for AI purposes is in section 7.
4. If you are a meeting participant
A participant called DstnyIQ, or a partner-branded equivalent, may have appeared in your meeting. The meeting audio is recorded, transcribed and summarised by AI, and sent to recipients chosen by the organising organisation. If you have concerns about being recorded, contact the meeting organiser or use any meeting controls made available to you. Your rights and the organiser’s legal basis depend on the circumstances of the meeting. The organisation that organised the meeting is responsible for it. This policy does not replace the privacy information that the organising organisation, as controller, is required to provide about its recording and use of meeting content. Ask them about purpose, legal basis, retention and your rights. You can also write to info@capacit.com and we will pass your request to them and confirm we have done so — we cannot decide it ourselves.
5. What we process
Meeting content (we are processor): meeting audio; transcripts and summaries generated from it; participant details such as name, email address, Microsoft Entra identifier, meeting role and join/leave times; meeting metadata such as subject, time, organiser and meeting identifiers; and records of the transparency notices sent about a meeting. Recorded speech can contain anything participants choose to say, including special category data under Article 9 GDPR. DstnyIQ is not designed to identify or profile individuals based on special category data. Such information may nevertheless be reflected in transcripts or summaries where it forms part of the meeting content.
We do not create voiceprints. DstnyIQ does not perform voice biometrics, does not generate or store biometric identifiers, and does not identify or recognise anyone from voice characteristics — including across meetings. Speaker attribution comes from the Microsoft Teams participant identity attached to the audio stream, not from analysing the voice itself. We also do not perform emotion recognition. We do not market to meeting participants. Email addresses obtained from a customer’s calendar or participant list are used only to send transparency notices about the meeting and to deliver the output the customer has configured. We do not use them to promote our services, and we do not add participants to mailing lists. Customer and account data (we are controller): business contact details; tenant, onboarding and licensing records; service configuration; usage and billing records; support correspondence; and application and security logs, which can contain technical identifiers and IP addresses.
We receive controller-side account and business contact data directly from you, from your employer or organisation, from an authorised partner, and where relevant from your organisation’s Microsoft 365 tenant.
Certain administrator, account and tenant information is necessary to provision and administer the service. If it is not provided, we may be unable to activate or support the relevant account or tenant.
6. Why, and on what basis
Where we are processor, the legal basis for meeting content is set by the customer organisation, not by us. Where we are controller, we rely on Article 6(1)(b) where processing is necessary to perform a contract with the individual concerned. Otherwise, we rely on our legitimate interests under Article 6(1)(f) for administering and supporting our business customer relationships, user accounts and service operations, including operating, securing, troubleshooting and improving the service. Our legitimate interest in improving the service relates to account, usage, diagnostic and operational data and does not permit us to use customer meeting content for model training or independent product development. We also rely on legal obligations under Article 6(1)(c) for accounting and lawful requests. We do not carry out automated decision-making with legal or similarly significant effects under Article 22 GDPR.
7. AI
DstnyIQ uses AI models hosted in Microsoft Azure to transcribe audio and generate summaries. AI output can be wrong. Transcripts and summaries can mis-hear words, misattribute speech, omit material and state things that were not said. Treat them as an aid, not as a record of what was said, and verify before relying on them. Content is not used to train models. Meeting content sent for AI processing is used to return a result and is not used by us or by our providers to train or improve any model.
Microsoft’s abuse monitoring
Microsoft operates automated abuse detection on the Azure OpenAI Service. Content flagged by Microsoft’s abuse-monitoring systems may be stored and made available to authorised Microsoft personnel for human review in accordance with Microsoft’s then-current Azure service terms and privacy documentation, so that misuse of the service can be detected and prevented. Content that is not flagged is not retained for this purpose. Because our Azure OpenAI deployments are located in the European Economic Area, any Microsoft personnel who carry out such a review are also located in the European Economic Area. This monitoring is Microsoft’s own and is limited to detecting misuse.
8. Who we share with
Sub-processors. Each sub-processor is engaged under written terms imposing the same data protection obligations as apply to Capacit under the applicable data processing agreement, to the extent relevant to the sub-processor’s services. Our current sub-processors are:
Sub-processor
Purpose
Location
Microsoft (Azure)
Hosting, storage, database, key management, logging
EU
Microsoft (Azure OpenAI Service)
AI transcription and summarisation
EU
Microsoft (Azure AI Speech)
Live speech-to-text, where enabled
EU
We notify customers before adding a sub-processor, as set out in the applicable data processing agreement. Where DstnyIQ is supplied through a partner, the parties’ respective roles in relation to personal data are set out in the applicable data processing and sub-processing arrangements. Dstny does not access meeting content or outputs. Output delivery: transcripts and summaries go only to the recipients the customer organisation configures. Others: professional advisers under confidentiality; authorities where legally required, with notice to the customer or partner where lawful; and an acquirer in a merger or sale, subject to this policy continuing to apply.
9. Where data is held, and transfers
The service is hosted in Microsoft Azure in the European Union, and meeting content is stored and primarily processed in the EU. Recordings, service data and AI summarisation are currently handled in Sweden Central, and AI transcription in West Europe (Netherlands). We may change EU regions as capacity requires. Where Microsoft’s abuse-monitoring process results in human review, flagged content may be accessed by authorised Microsoft personnel located within the EEA, as described in section 7. Your Teams meeting itself runs in Microsoft’s infrastructure under your own agreement with Microsoft. Where personal data is transferred outside the EU/EEA, we rely on the European Commission’s Standard Contractual Clauses with supplementary measures, or another valid transfer mechanism. This may apply to controller-side data, such as support tooling, rather than meeting content. Request a copy of the safeguards at info@capacit.com.
10. Retention and deletion
Meeting content is the customer’s, and the customer sets the period. Recordings, transcripts and summaries are retained for the period agreed with the customer organisation in its agreement with us, and are deleted when that period ends or when the customer instructs deletion. Where nothing else is agreed, our default is up to 30 days from the date of the meeting — for the recording, the transcript and the summary alike. Deletion takes effect in active systems within 7 days of the retention period ending or of a customer’s instruction.
When a customer’s agreement ends, we delete or return their meeting content in accordance with the data processing agreement, unless we are legally required to keep it. Account, licensing and configuration records are retained for the duration of the customer relationship and thereafter only for as long as necessary to close the account, comply with legal obligations, or establish, exercise or defend legal claims. Relevant contractual and customer relationship records may generally be retained for up to three years after termination. Billing and accounting records are retained for five years from the end of the financial year to which they relate, as required by the Danish Bookkeeping Act. Operational logs and diagnostics are retained for up to 90 days.
11. Security
We protect customer data with technical and organisational measures appropriate to the risk. These include encryption in transit and at rest, identity-based access control with access limited to personnel who need it for their role, segregation of each customer’s content, integrity verification and short-lived access links for stored recordings, and centralised logging and monitoring. Our full technical and organisational measures are set out in the applicable data processing agreement, which customers may request from their provider. No system is perfectly secure. Where we act as processor or sub-processor, we notify the relevant customer or partner through which the service is supplied without undue delay after becoming aware of a personal data breach and assist with applicable notification obligations. Where we act as controller, we notify the competent supervisory authority and affected individuals where the law requires it.
12. Your rights
Depending on the circumstances and the applicable legal basis, you may have the right to access your personal data, correct it, have it erased, restrict or object to processing, obtain portability, and withdraw consent where processing relies on it. Where to send the request depends on who controls the data. For meeting recordings, transcripts and summaries, that is the organisation that organised the meeting — send it to them. If you send it to us we will forward it via our partner where applicable, confirm we have done so, and assist as the applicable data processing agreement requires, but we cannot decide it ourselves. For data where we are controller — your business contact details, account records, support correspondence — write to info@capacit.com. We respond without undue delay and in any event within one month. Where permitted by law, this period may be extended by up to two further months, and we will inform you of any extension within the initial one-month period. We may need to verify your identity.
Complaints. You are welcome to contact us first, and you also have the right to lodge a complaint with a supervisory authority — in Denmark, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, dt@datatilsynet.dk, datatilsynet.dk — or with the authority where you live or work.
13. Changes
We may update this policy as the service develops. The “Last updated” date changes, and where changes are material we notify customers in advance. The current version is always at https://capacit.com/dstnyiq/privacy.
14. Contact
Capacit A/S, Overgaden Neden Vandet 9A, 1414 Copenhagen, Denmark. Privacy and data subject requests: info@capacit.com. Inappropriate AI-generated content: info@capacit.com. Security: info@capacit.com. Support: info@capacit.com.
1. Parties, acceptance, and precedence
These Terms govern use of DstnyIQ, the Microsoft Teams meeting recording and AI transcription service supplied by Capacit A/S, CVR [CVR NUMBER], Overgaden Neden Vandet 9A, 1414 Copenhagen, Denmark (“Capacit”, “we”), including where it is supplied under a partner brand. They apply to the Customer — the organisation that subscribes and connects its Microsoft 365 tenant — and to Users, the individuals it permits to use the service. By installing the app, connecting a tenant, adding the recorder to a meeting or otherwise using the service, you accept these Terms. If you accept on behalf of an organisation, you confirm you are authorised to bind it, and “you” means that organisation. Order of precedence: where a signed agreement exists between the Customer and Capacit or an authorised partner, that agreement prevails over these Terms with respect to commercial terms. In a conflict concerning personal data, the Data Processing Agreement prevails. The Data Processing Agreement forms part of the arrangement between the parties. [CONFIRM HOW THE DPA IS CONCLUDED.] Our Privacy Policy describes how we process personal data. Purchases through a partner are governed by the partner agreement for fees, subscription term and partner-provided support; these Terms otherwise continue to apply.
2. The service
DstnyIQ joins Microsoft Teams meetings as a visible participant and records them. The recorder is shown in the participant list while present and can be removed by a participant with a sufficient meeting role at any time. Recordings are processed automatically using AI to produce transcripts and summaries, delivered to the recipients the Customer configures. The Customer controls how the recorder joins meetings through its configuration of the service. We may change, improve or discontinue features. Where a change materially reduces core functionality we will give the Customer reasonable prior notice.
3. Access and licence
The Customer must have a Microsoft 365 tenant with Microsoft Teams and must complete administrator consent. Microsoft Teams itself, and the Customer’s agreement with Microsoft, are not part of this service. We grant the Customer a non-exclusive, non-transferable, non-sublicensable right to use DstnyIQ during the subscription term for its own internal business purposes, limited to the licences subscribed for. The Customer is responsible for its Users’ compliance with these Terms, for keeping credentials secure, and for its configuration choices — including who receives transcripts and summaries.
4. Recording is the Customer’s decision and responsibility
We supply the tool. The Customer decides to record, and is solely responsible for doing so lawfully. The Customer warrants that it will establish a lawful basis for recording each meeting and related processing; give required notices and obtain consent where applicable; keep transparency notices accurate, intelligible and legally sufficient; handle objections from participants; comply with obligations under the GDPR, Article 50 of the EU AI Act and applicable employment, works council, sector and confidentiality rules; carry out any required assessment; and set an appropriate retention period and instruct us accordingly. We provide transparency features to help, including a visible recorder, notices to invitees and in the meeting chat, and a configurable pre-recording notice period. Using them does not discharge the Customer’s legal obligations. The Customer indemnifies us for breach of this section under section 9.
5. Acceptable use
The Customer and its Users must not record covertly or conceal the recorder from participants; record conversations they have no right to record; use the service for unlawful monitoring of employees or in breach of employment or works council requirements; record privileged, medical or other specially protected conversations without having established that it is lawful; use output for biometric identification, emotion inference or automated evaluation of individuals in a manner prohibited by the EU AI Act; resell or sublicense the service except as agreed; reverse engineer it where unenforceable by law; probe or test its security without written consent; attempt unauthorised access; disrupt it, circumvent usage limits or impose unreasonable load; use it to store or transmit malicious, unlawful, infringing, defamatory or harassing content; or attempt to manipulate, override or bypass AI instructions, safety controls or intended behaviour. We may suspend access where we reasonably believe this section is breached, where required by law, or where there is a security risk. Where practicable we notify first and limit suspension to what is necessary.
6. AI output
AI output can be inaccurate. Transcripts and summaries can mis-hear words, misattribute speech, omit material and generate statements that were never made. They are an aid, not a verbatim or authoritative record of a meeting. The Customer and its Users must review AI output before relying on it, and must not treat it as a legal record, a minute, or evidence of what was said without independent verification. We are not liable for decisions taken on unverified AI output. Report inappropriate, harmful or offensive AI output to info@capacit.com with enough detail to identify it. We investigate promptly and take corrective action.
7. Customer data, IP and confidentiality
Ownership: as between the parties the Customer owns its recordings, transcripts, summaries and other content the service generates from its meetings (Customer Data). We claim no ownership. Our licence: the Customer grants us a limited licence to host, process, transmit and display Customer Data solely to provide, secure and support the service, and as the Customer instructs. We will not sell it, use it for advertising, or use it to train AI models. We may use aggregated and anonymised statistics that cannot reasonably identify any Customer or individual. Our IP: we and our licensors retain all rights in the service, software, documentation and branding. Confidentiality: each party will keep the other’s confidential information confidential and use it only for the purposes of these Terms, subject to standard exceptions. For personal data in Customer Data the Customer is controller and Capacit is processor, processing only on the Customer’s documented instructions under the Data Processing Agreement.
8. Warranties, disclaimers and liability
We will provide the service with reasonable skill and care and in accordance with any service levels expressly agreed in writing. Otherwise, to the maximum extent permitted by law, the service is provided as is. We do not warrant uninterrupted or error-free use, that it will join every meeting or capture every part of one, or that AI output will be accurate or complete. The service depends on Microsoft Teams, Microsoft Graph and Microsoft Azure, and we are not responsible for third-party platform failures outside our reasonable control. The Customer must not rely on DstnyIQ as its sole means of capturing a meeting where failure to capture would cause loss. Neither party excludes liability for death or personal injury caused by negligence, fraud, or anything that cannot lawfully be excluded. Subject to that, neither party is liable for indirect or consequential loss, loss of profit, revenue, anticipated savings, business or goodwill; and each party’s total aggregate liability is limited to [LIABILITY CAP]. [CONFIRM CARVE-OUTS.]
9. Indemnity
The Customer will defend and indemnify us against any third-party or supervisory authority claim, proceeding, fine or penalty, and resulting losses and reasonable legal costs, arising from its breach of section 4 or section 5, use of the service in breach of applicable law, or a claim that it recorded someone unlawfully or without adequate notice. We will notify the Customer of the claim, let it control the defence, and assist reasonably at its expense. Any settlement admitting our liability needs our consent. [CONFIRM WHETHER CAPACIT GIVES A RECIPROCAL IP INFRINGEMENT INDEMNITY.]
10. Term and termination
These Terms apply while the Customer uses the service. Either party may terminate for material breach not remedied within 30 days of written notice, or immediately on the other’s insolvency. On termination the Customer’s right to use the service ends, the tenant connection is disabled, and we delete or return Customer Data in accordance with the Data Processing Agreement, except where legally required to retain it. Export anything you want to keep before termination takes effect. Sections 7, 8 and 9 survive.
11. General
Governing law is Danish law, excluding conflict of law rules and the CISG. The courts of [VENUE] have exclusive jurisdiction. [CONFIRM ARBITRATION PREFERENCE AND ANY NON-DANISH CUSTOMER CARVE-OUT.] We may update these Terms; where changes are material we give reasonable notice before they take effect, and continued use after that date is acceptance. The current version is always at https://capacit.com/dstnyiq/terms. Fees are set out in the Customer’s order form or partner agreement. Capacit may assign these Terms to an affiliate or in connection with a merger, reorganisation or sale. The Customer may not assign without Capacit’s prior written consent. We may use subcontractors and sub-processors and remain responsible for their performance. Neither party is liable for failure caused by events beyond reasonable control. These Terms, together with the Data Processing Agreement and any signed agreement or order form, are the entire agreement on this subject. If a provision is unenforceable the rest stands, modified only as needed. Notices to us: info@capacit.com and Capacit A/S, Overgaden Neden Vandet 9A, 1414 Copenhagen, Denmark. To the Customer: the contact details in its account.
12. Contact
For support, legal, privacy, security and inappropriate AI-generated content:
Support
info@capacit.com
Legal, Privacy & Security
info@capacit.com
Inappropriate AI-generated content
info@capacit.com