Legal · Effective 31 July 2026

Privacy policy

Written to be read, not to be survived.

Last updated: 31 July 2026

This policy explains what data Lisan (operated by LISAN AI - FZE) collects across the Lisan platform, why, and the control you have over it. Individual products may publish product-specific policies on their own sites; this page covers the platform-wide rules that all of them inherit.

Controller and processor

For account data, website data, support conversations, and product-usage data, LISAN AI - FZE is the controller. For personal data you place inside a workspace, for example records about your colleagues, customers, shareholders, or employees, you decide why and how that data is used and we process it on your instructions to provide the service. If you need a signed data processing agreement for procurement or diligence, write to support@lisan.com and we will provide one.

What we collect

  • Account data: your name, email, and workspace membership, so you can sign in and collaborate.
  • Your content: documents, notes, transcripts, and records you create or sync are stored in your workspace so the products can do their job. Content you keep local (for example, local-only files in desktop apps) never reaches us.
  • Operational logs: basic request and error logs to keep the services running and secure.

What we do not do

We do not sell your data. We do not show third-party advertising. We do not train AI models on your private content.

AI features

AI features process only what you point them at: the page you ask about, the meeting you invite the notetaker to, the document you submit for checking or translation. Where products let you bring your own AI provider accounts, those interactions are governed by that provider's terms.

Where your data lives

That depends on the deployment you chose: Lisan's cloud by default, your own self-hosted server, or your premises entirely. On sovereign deployments, your content stays inside your infrastructure by design.

Lisan's managed cloud runs on Amazon Web Services infrastructure in the United States (region us-east-1). If your organization requires data residency in a specific country, that is what the self-hosted and on-premises deployments are for, and we will scope it with you.

Subprocessors

We use a deliberately short list of subprocessors, and we name them rather than asking you to write in for the list:

  • Amazon Web Services, Inc. (United States) - cloud hosting, storage, and backups for the managed platform.
  • Stripe, Inc. (United States) - subscription payments, invoicing, and tax identifiers. Card details go to Stripe directly; we never receive full card numbers.
  • Resend (Plus Five Five, Inc.) (United States) - delivery of transactional email such as sign-in codes, notifications, and billing notices.
  • Microsoft Ireland Operations Limited (Azure OpenAI Service) - the AI models behind our AI features. Azure OpenAI does not use customer prompts or outputs to train models.
  • Amazon Web Services, Inc. (Amazon Bedrock) - additional AI models used by some AI features, under the same no-training-on-customer-data terms.

AI subprocessors receive only what you point an AI feature at: the page you ask about, the document you submit, the meeting you invite the notetaker to. They do not receive your workspace wholesale. Where a product lets you connect your own AI provider account, that traffic goes to your provider under your agreement with them, not ours.

We will publish changes to this list here before a new subprocessor starts processing customer personal data. If you have a signed agreement with us that requires advance notice of subprocessor changes, that notice period applies.

International transfers

Because the managed platform is hosted in the United States, personal data you place in it is transferred out of the country you are in. For customers and individuals in the GCC, the EEA, and the United Kingdom, we rely on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where the UK GDPR applies) as the transfer mechanism in our data processing agreement, together with encryption in transit and at rest. Where local law requires a specific mechanism or in-country residency instead, the self-hosted and on-premises deployments let you keep the data where the law needs it.

How long we keep it

We keep account data for as long as the account exists. Workspace content is kept until you delete it or ask us to delete the account, since it is the reason the products work. Operational logs are kept for a rolling operational window and then rotated out. When content is deleted it is removed from the live service; encrypted backup copies containing it expire through the normal backup rotation rather than being individually rewritten, and are not restored into the live service except to recover from an incident.

Deletion and your rights

Depending on where you are, you may have rights to access, correct, export, delete, or restrict the personal data we hold about you, and to object to certain processing. You can export your content in open formats from inside the products at any time. For access, correction, or deletion of an account and its data, write to support@lisan.com and we will respond within the period the applicable law allows. If your data was put into a workspace by an organization using Lisan, that organization decides what happens to the record, so they are usually the right first contact; tell us and we will point you to them and help.

Contact

Questions about this policy: support@lisan.com.