Legal
Privacy Policy
HGB Mates are AI teammates ("AI mates") that join your Zoom and Microsoft Teams meetings, answer from your company's knowledge (Confluence, Jira, GitHub) and act only with a person's approval. This policy explains what personal data the service processes, why, where, and what your rights are.
Last updated: September 30, 2026 · Effective: September 25, 2026
Who is responsible
HGB Solutions Oy, Finland ("HGB", "we") provides HGB Mates.
- Your organisation's content (meetings, documents, tickets, code activity, decisions): your organisation is the controller and HGB processes it on its behalf as a processor, under a data processing agreement.
- Console accounts and service operation (sign-in, usage, billing information): HGB is the controller.
Data we process
Account data
Name and work email of the people your organisation lists as administrators, and sign-in sessions. Sign-in uses a one-time code sent by email; we store only hashes of codes and sessions, never passwords.
Meeting data
- Audio: while an AI mate is in a meeting, each participant's audio is streamed to speech recognition to produce a transcript. Audio is not recorded or stored.
- Transcript and chat: kept in the meeting session to answer questions, and discarded when the meeting ends.
- Participants: the display names the meeting platform shows.
- Results: decisions, action items, approvals and the audit log of what the AI mate did (who asked, who approved, sources used, outcome) are stored for your organisation.
Connected systems
When an administrator connects Atlassian (Jira, Confluence) or GitHub, AI mates read the content needed to answer a question (pages, tickets, pull requests, issues, releases) at the moment it is needed, and write only after approval. OAuth tokens are stored encrypted; for GitHub no long-lived token is stored.
Employee configuration
Names, roles, personas, voices and photos your administrators give their AI mates.
Usage data
Meeting minutes, AI tokens, voice and transcription seconds and tool calls, to enforce plan limits and keep costs under control.
How the AI works
- It says it is an AI. When it joins a meeting, an AI mate says, by voice and in the chat, that it is an AI (EU AI Act, Article 50). It joins as "Name (AI)".
- Listening is visible. In Zoom the host must allow it; in Microsoft Teams everyone sees a recording notice. Both show a notice to participants.
- No biometrics. Speakers are identified by the meeting platform or by the sign-in, never by voiceprints. In Microsoft Teams, the name and work email of people of the connected organisation are read from Microsoft to know who is speaking.
- People decide. The AI proposes; anything that writes to your systems (a ticket, a page, a comment, a recorded decision) waits for an authorised person's approval.
- No training on your content. We do not use your organisation's content to train AI models, and neither do our AI providers under their business terms.
Why we use it
- To provide the service: answer questions, record decisions and action items, carry out approved actions.
- To keep it secure and reliable: sign-in, audit log, abuse prevention, troubleshooting.
- To apply plans and usage limits.
- To communicate about the service: sign-in codes and important service notices.
Legal basis (GDPR)
- Contract: providing the service to your organisation (Art. 6(1)(b)).
- Legitimate interests: security, fraud prevention and service improvement (Art. 6(1)(f)).
- Legal obligations: for example accounting and tax records (Art. 6(1)(c)).
- For meeting content, your organisation determines the legal basis as controller, including informing meeting participants.
Where it is stored
The service runs on Google Cloud in the European Union: application, database and secrets in Finland (europe-north1); AI answers (Gemini on Vertex AI) in Frankfurt, Germany (europe-west3) or Finland (europe-north1); speech recognition and synthesis through Google's EU endpoints. A workspace admin can allow AI mates to use open AI models that Google serves with global routing (Vertex AI Model Garden); only for AI mates set to such a model, the conversation it answers may then be processed by Google outside the EU. This is off unless the workspace turns it on.
Service providers
We never sell personal data or share it with advertisers. We use these providers, bound by data processing agreements:
- Google Cloud (EU regions): hosting, database, AI models, speech.
- Zoom and Microsoft Teams: the meeting platforms your organisation uses; the AI mate joins their meetings (Teams only after your organisation's administrator grants access).
- Brevo (EU): sending sign-in emails.
- Atlassian and GitHub: only when your administrators connect them, and only for what they grant.
Where a provider processes data outside the EU/EEA, the transfer is protected by an adequacy decision (such as the EU–US Data Privacy Framework) or Standard Contractual Clauses.
How long we keep it
- Meeting audio: not stored.
- Transcripts and chat: only during the meeting.
- Sign-in codes: 10 minutes. Sessions: 30 days.
- Decisions, action items, audit log and usage: while your organisation uses the service; deleted within 90 days after it ends, unless the law requires longer or your organisation asks earlier.
- Accounting records: as long as Finnish law requires.
Security
- Encryption in transit (TLS) and at rest; integration tokens are additionally encrypted by the application (AES-256-GCM) with a key kept in a secrets manager.
- Least privilege: AI mates only reach the spaces, projects and repositories they are configured for.
- Only administrators use the console; sign-in by one-time email codes.
- Every action is recorded in an audit log.
- If a personal data breach affects you, we notify the supervisory authority within 72 hours and inform those affected as the GDPR requires.
Your rights
You have the right to access, correct and delete your personal data, to restrict or object to processing, and to data portability. For meeting content, send requests to your organisation (the controller); we help them answer. Write to privacy@hgb.fi; we answer within 30 days. You may also complain to the Finnish Data Protection Ombudsman (tietosuoja.fi).
Children
HGB Mates is a service for organisations and is not intended for people under 16.
Changes
We may update this policy. For material changes we notify administrators by email at least 30 days in advance and update the date above.
Contact
- Controller
- HGB Solutions Oy, Helsinki, Finland
- Website
- www.mates.hgb.fi
- Privacy questions
- privacy@hgb.fi
- Data Protection Officer
- dpo@hgb.fi
This policy is governed by Finnish and European Union law. © 2026 HGB Solutions Oy.