Privacy statement
Version 1.1, September 2026. In short: we only process what is needed to coach your conversations, we sell nothing, and your data does not train AI models.
Who we are
Stiqqs is a product of Impactio BV, registered with the Dutch Chamber of Commerce under number 42002895, based in Bussum, the Netherlands.
Privacy questions: privacy@stiqqs.com.
Our role
For an organisation's conversations, knowledge and website chats, we are a processor. The organisation using Stiqqs is the controller and decides what Stiqqs is used for. We provide a data processing agreement on request.
For account data, security and billing we are the controller ourselves, based on the agreement and our legitimate interest in a secure service.
What data
Account: name, email address, organisation, role and language. If you sign in with Google, Google gives us your name, email address and profile picture. No password.
Conversations in Google Meet and Microsoft Teams: the extension reads the captions that Meet or Teams create themselves, including speaker names as shown in the captions. Also the goal of the conversation, the advice during the conversation and the summary afterwards. No audio is recorded or stored.
Phone calls in the browser (only if you start this yourself): the audio of the tab and, if you choose, your microphone goes live to speech recognition (Speechmatics or Soniox, see Sub-processors) and is not stored. Stiqqs only keeps the text, as 'Customer' and 'Me'.
Conversations at the table via the Live page: the audio of your microphone goes live to speech recognition (Speechmatics or Soniox, see Sub-processors) and is not stored. It tells the speakers apart during the conversation (speaker 1, speaker 2), without identifying who anyone is and without storing a voice profile. Stiqqs only keeps the text, as 'Me' and 'Speaker 2'. If that fails, your browser's speech recognition turns the audio into text; in Chrome, Google processes the audio for this.
Website chats (Stiqqs AI Agent): what a visitor types in the chat, the page where this happens (address and title, without query data), and name, email address and organisation if the visitor provides them. To prevent abuse and spam we store a one-way derivative (hash) of the IP address, never the address itself; a block expires after 24 hours or, if an admin blocks, after 90 days.
Knowledge: documents, website texts and examples the organisation adds itself.
Technical: IP address and session data for sign-in, error messages, and per AI call only speed and number of tokens, without content.
Special categories of personal data (such as health) do not belong in Stiqqs. If they come up in a conversation anyway, we treat them like the rest of the conversation and delete them on the same schedule.
People who are not users
Stiqqs also processes data of conversation partners and website visitors. They have no account with us. The organisation using Stiqqs informs them, for example by saying at the start of a call that an AI assistant is listening in, and by mentioning the website assistant in its own privacy statement.
Are you a conversation partner or website visitor and want to know what has been recorded about you? Contact that organisation. We help them handle your request. You can also email privacy@stiqqs.com and we will forward your question.
What for
To give advice during and after conversations, write summaries, answer questions from the organisation's knowledge and help website visitors.
Not: selling data, advertising, emotion recognition, or decisions with legal effects for anyone. Your data is not used to train AI models.
Artificial intelligence
Advice, summaries and answers are produced by a language model from Anthropic. The relevant part of the transcript or the question is sent along with the knowledge needed for the answer. Names that appear in the conversation are therefore sent as well.
Anthropic is based in the United States. The transfer is covered by the European Commission's standard contractual clauses in their data processing agreement. Anthropic does not use this data to train models and keeps it only briefly, under its terms.
Sub-processors
Supabase: database and sign-in, stored in Ireland (EU).
Vercel: hosting of the website and app, compute region Frankfurt (EU). Vercel is a US company; transfers under standard contractual clauses.
Anthropic: language model, United States; see above.
Mistral AI: language model, based in France. Only for the tasks for which Stiqqs uses Mistral instead of Anthropic. Mistral does not use this data to train models.
Resend: sending sign-in codes and invitations by email.
Speechmatics: only if you let Stiqqs listen in on a phone call in the browser. The audio goes live to their servers in the EU and is not stored there; Stiqqs only receives the text.
Soniox: instead of Speechmatics, for the same speech recognition during phone calls and conversations at the table. The audio goes live to their servers in the EU and is not stored there or used to train models; Stiqqs only receives the text. Account and billing data at Soniox may be processed outside the EU; it contains no audio or text of conversations.
Google: only if you choose to sign in with Google.
We have a data processing agreement with each sub-processor. We announce a new sub-processor on this page in advance.
Who sees what
Each organisation has its own isolated environment. Other organisations see nothing of your conversations, knowledge or website chats. This is enforced in the database itself, not only in the app.
Within your organisation, roles determine what someone sees. Your organisation's administrators see the website chats and employees' questions.
We, as operator of Stiqqs, cannot view customers' conversations, website chats or questions through the app. We only use direct database access for maintenance or incidents, never to read content.
Cookies
Only functional cookies: to keep you signed in and remember your language. No tracking or advertising cookies, no third-party analytics.
Retention
Transcripts and in-call advice: 12 months after the conversation, then deleted automatically. The summary and figures are kept until you delete them or the account ends.
Website chats and leads: 12 months after the last activity, then deleted automatically.
Knowledge and questions to the assistant: until the organisation deletes them or the account ends.
Account: until the end of the agreement, then at most 90 days.
Backups: at most 30 days. Technical logs: at most 30 days.
Security
Storage in the EU, encrypted connections, isolation per organisation in the database, passwordless sign-in with a one-time code or Google, and integration keys stored only as a hashed fingerprint.
Your rights
You have the right to access, rectification, erasure, restriction, portability and objection. Email privacy@stiqqs.com. We respond within one month.
If it concerns data your organisation manages, we ask your organisation to handle the request.
Complaints
If you are not satisfied with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl) or the authority in your country. We would like to hear from you first.
Changes
If anything material changes, we update this page, raise the version number and announce it in the app.