سياسة الخصوصية
Last updated: 17 August 2026
This Privacy Policy (“Policy”) explains how Harmony Labs Limited, a company incorporated in Ireland, with its registered office at 22 Northumberland Road, Ballsbridge, Dublin 4, Ireland, D04 ED73, and its affiliates (“Harmony”, “we”, “us”) process your personal data (“Data”) when you use the Harmony platform at heyharmony.com (“Services”).
We are committed to processing Data in accordance with applicable data protection law, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Brazilian General Data Protection Law (Law No. 13.709/2018, “LGPD”), and other applicable privacy legislation.
Capitalized terms not defined here have the meanings given in the Harmony Terms of Service at heyharmony.com/terms.
1. Data controller
The data controller is Harmony Labs Limited, 22 Northumberland Road, Ballsbridge, Dublin 4, Ireland, D04 ED73. You can contact us about privacy matters at [email protected].
Where the Customer contracts with a different Harmony entity, that entity is the data controller in respect of the Data described in this Policy. Where the Customer contracts with Harmony Global Inc., 8 The Green, Ste R, Dover, Delaware 19901, United States, Harmony Global Inc. acts as the data controller. Where the Customer contracts with Harmony Brasil Ltda., Rua Iapó nº 62, Alphaville Graciosa, Pinhais/PR, CEP 83327-075, Brazil, Harmony Brasil Ltda. acts as the data controller for the purposes of the LGPD. Each entity may be contacted at the same email address.
2. What data we collect
2.1. Account data
When you create an account or are added as a User, we collect: name, email address, job title, company name, and account credentials.
2.2. Customer data
The Services process conversation data on the Customer’s behalf, including voice recordings, transcripts, AI-generated summaries, action items, scorecards, and analytics. The Customer is the data controller for this data; Harmony processes it as a data processor under the terms of the Data Processing Agreement at heyharmony.com/dpa.
2.3. Usage data
We collect aggregated data about how the Services are used, including feature adoption, system performance, and usage patterns, from which all identifiers have been irreversibly removed such that neither Harmony nor any third party can, by any means reasonably likely to be used, identify the Customer, any User, or any other individual. Usage Data does not include pseudonymized data, and Harmony will not attempt, and will not permit any third party to attempt, to re-identify it.
2.4. Technical data
We collect IP addresses, browser type, device information, operating system, and access timestamps when you use the Services.
2.5. Payment data
We collect billing information including company name, billing address, VAT or tax identification number, and payment method details. Payment processing is handled by third-party payment providers; Harmony does not store full credit card numbers.
3. Why we process your data
To provide the Services. We process Data to operate, maintain, and improve the Services, including recording, transcription, AI analysis, and workspace features. Legal basis: performance of contract (GDPR Art. 6(1)(b)).
To communicate with you. We process Data to respond to inquiries, provide support, and send service-related notices. Legal basis: performance of contract (GDPR Art. 6(1)(b)) and legitimate interest (GDPR Art. 6(1)(f)).
To improve and develop the Services. We use Usage Data and Technical Data to analyze trends, diagnose issues, and develop new features. Legal basis: legitimate interest (GDPR Art. 6(1)(f)).
To send marketing communications. Where you have consented, we may send commercial information about our products and services. Legal basis: consent (GDPR Art. 6(1)(a)). You may withdraw consent at any time.
To comply with legal obligations. We process Data as required by applicable law, including tax, accounting, and regulatory obligations. Legal basis: legal obligation (GDPR Art. 6(1)(c)).
To protect our rights. We process Data to establish, exercise, or defend legal claims. Legal basis: legitimate interest (GDPR Art. 6(1)(f)).
4. AI processing
The Services use artificial intelligence to generate transcripts, summaries, action items, scorecards, and analytics. Harmony does not use Customer Data to train AI models. Third-party AI providers used to deliver the Services are bound by contractual commitments prohibiting the use of Customer Data for model training. Harmony maintains a zero-data-retention policy with third-party AI providers.
AI Outputs are generated algorithmically and may contain inaccuracies. They should not be used as the sole basis for decisions with legal, employment, financial, or other significant consequences.
5. Who we share data with
We share Data with the following categories of recipients:
Sub-processors. Infrastructure providers, AI service providers, and other sub-processors listed at security.heyharmony.com. All sub-processors are bound by data processing agreements.
Professional advisors. Legal, accounting, and audit service providers, under appropriate confidentiality obligations.
Law enforcement and regulators. Where required by applicable law, regulation, or court order.
Corporate transactions. In connection with a merger, acquisition, or sale of assets, Data may be transferred to the successor entity.
6. Where your data is processed
Customer Data is stored in the United States. Harmony does not currently offer a choice of storage region, and does not currently offer storage of Customer Data within the European Union or the European Economic Area.
Certain processing takes place elsewhere. Conversational AI processing is performed on infrastructure located within the European Union. Transcription is performed by a sub-processor located in France. Other sub-processors may process Data in further jurisdictions to deliver specific features. The current list of sub-processors and their processing locations is maintained at security.heyharmony.com.
Where Data is transferred outside the EEA, we rely on:
(a) European Commission adequacy decisions for countries with an adequate level of data protection;
(b) Standard Contractual Clauses approved by the European Commission; or
(c) other valid transfer mechanisms recognized under applicable law.
Where the LGPD applies, international transfers comply with Article 33 of the LGPD and applicable ANPD regulations. You may request a copy of the applicable transfer safeguards by contacting [email protected].
7. Data retention
We retain Data for as long as necessary to provide the Services and fulfill the purposes described in this Policy. Specifically:
Account data is retained for the duration of the Customer’s subscription and deleted or irreversibly anonymized within 90 days following termination, in accordance with the Data Processing Agreement.
Customer data is retained for the duration of the subscription. Following termination or expiry of the Agreement, Harmony will make Customer Data available for export for 30 days and will permanently delete all Customer Data no later than 90 days after termination or expiry, except where retention is required by applicable law. A documented deletion request is actioned within 30 days.
Usage data may be retained indefinitely in anonymized, aggregated form.
Marketing data is retained until you withdraw consent or unsubscribe.
8. Your rights
Under applicable data protection law, you may have the following rights:
(a) Right of access, to obtain confirmation of whether we process your Data and a copy of it.
(b) Right to rectification, to correct inaccurate or incomplete Data.
(c) Right to erasure, to request deletion of your Data where there is no compelling reason to continue processing.
(d) Right to restrict processing, to limit how we use your Data in certain circumstances.
(e) Right to data portability, to receive your Data in a structured, machine-readable format.
(f) Right to object, to object to processing based on legitimate interest, including direct marketing.
(g) Right to withdraw consent, where processing is based on consent, at any time.
To exercise any of these rights, contact us at [email protected]. We will respond within the timeframe required by applicable law (typically 30 days under the GDPR, and 15 days for confirmation and access requests under the LGPD).
You have the right to lodge a complaint with your local data protection supervisory authority. In Ireland this is the Data Protection Commission; in Brazil it is the Autoridade Nacional de Proteção de Dados (ANPD).
8.1. Additional rights under the LGPD (Brazil)
Where the LGPD applies, you additionally have the right to: (a) anonymization, blocking, or deletion of Data that is unnecessary, excessive, or processed in breach of the LGPD; (b) information about the public and private entities with which we have shared your Data; (c) information about the possibility of denying consent and the consequences of doing so; and (d) review of decisions taken solely on the basis of automated processing.
8.2. Additional rights under United States state privacy laws
Where a United States state privacy law applies, you may additionally have the right to opt out of the sale or sharing of personal information and of targeted advertising, and the right to appeal a refusal to act on a request. Harmony does not sell personal information and does not use Customer Data for targeted advertising.
9. Cookies
The Services use cookies and similar technologies. We use the following types:
Essential cookies are necessary for the Services to function and cannot be disabled. Legal basis: performance of contract (GDPR Art. 6(1)(b)) or legitimate interest (GDPR Art. 6(1)(f)).
Analytical cookies help us understand how the Services are used. Legal basis: consent (GDPR Art. 6(1)(a)).
Functional cookies remember your preferences and settings. Legal basis: consent (GDPR Art. 6(1)(a)).
You can manage cookie preferences through your browser settings. Disabling cookies may affect the functionality of the Services.
10. Third-party meeting participants
When the Services record and transcribe meetings, third-party participants (individuals who are not Users) may have their voice and statements processed. The Customer is responsible for providing notice and obtaining any required consent from participants before recording, as described in the Acceptable Use Policy at heyharmony.com/aup.
Third-party participants may exercise their data subject rights by contacting the Customer (as data controller) or Harmony at [email protected].
11. Children
The Services are not directed at individuals under 16 years of age. We do not knowingly collect Data from children. If we become aware that we have collected Data from a child, we will take steps to delete it promptly.
12. Changes to this policy
We may update this Policy from time to time. Changes take effect 30 days after notice is provided by email or through the Services. The current version is always available at heyharmony.com/privacy.
13. Contact
For any questions about this Policy or your Data, contact us at [email protected].