Release notes
These notes explain, in simple words, what we changed in dembrane's legal and policy documents, and why. This is a short summary to help explain all the changes. The legal documents themselves are the ones that apply.
September 2026: the FAQ on our website
The question box on our website matches what you type to one of our written answers. From 28 September 2026 that matching is done by Jev, a model made by TypeSafe AI in the United States, which we reach through Cloudflare.
What this does and does not involve:
-
Only the question you type. We send the text of your question and our own FAQ. No name, email address, IP address or account information goes with it.
-
It picks, it does not write. The model only indicates which written answer fits. Every answer you read was written by a founder, and nothing is decided about you.
-
A transfer outside the EEA. TypeSafe runs in the United States, so your question leaves the EEA. The transfer relies on the EU Standard Contractual Clauses, and TypeSafe does not train its models on your question.
-
Nothing changes for the platform. Recordings, transcripts and analyses are not involved and stay in the EU.
The Privacy Statement names this under "Website visitors" (legitimate interest, Art. 6(1)(f) GDPR), in the list of recipients, and under "Transfers outside the EEA". Please do not put personal data in a question.
Documents changed (28 September 2026)
| Document | New version | Previous version |
|---|---|---|
| Privacy Statement | 3.0.3 | 3.0.2 |
September 2026: usage reviews
We are going to send organisations a periodic review of how they used dembrane: the number of recordings, hours, projects and reports, when the platform was used, and patterns that follow from that (for example that most of your sessions happen on a Saturday). Think of a year in review.
What this does and does not use:
-
Platform-usage data only. Counts and timestamps. Never the content of recordings, transcripts or analyses.
-
Product-related email, with an opt-out. A review goes to the users of an organisation as a product email, not as a newsletter, and every email has an opt-out link. You can object at any time.
-
Nothing is published without your say-so. A review is yours to share. dembrane does not publish it, or name your organisation with it, without your written consent.
The Privacy Statement names this use under "Users of our products" (legitimate interest, Art. 6(1)(f) GDPR). The General Terms and Conditions are unchanged: showing an organisation its own usage is part of the service (Articles 5.3 and 5.5), and naming a client publicly already requires written consent (Article 16.7).
Documents changed (September 2026)
| Document | New version | Previous version |
|---|---|---|
| Privacy Statement | 3.0.2 | 3.0.1 |
17 July 2026: AssemblyAI removal and sub-processor update
On 17 July 2026 we updated the Data Processing Agreement (DPA) and the Privacy Statement to version 3.0.1.
We did this following the migration of our transcription infrastructure:
-
AssemblyAI removed as sub-processor: we no longer use AssemblyAI for speech-to-text audio transcription.
-
Transcription via Google Cloud Vertex AI (EU): all speech-to-text audio transcription and analysis are now processed within the European Union via Google Cloud Vertex AI (
europe-west1), with platform storage and compute on DigitalOcean in Amsterdam (AMS3). -
100% EEA resident: audio and transcription data processing and storage remain entirely within the European Economic Area.
Documents changed (17 July 2026)
| Document | New version | Previous version |
|---|---|---|
| Data Processing Agreement (DPA) | 3.0.1 | 3.0 |
| Privacy Statement | 3.0.1 | 3.0 |
21 June 2026: What changed, in short
On 21 June 2026 we updated our main documents: the General Terms and Conditions, the Data Processing Agreement (DPA), the Privacy Statement, the Service Level Agreement (SLA), and the Data Policy for Participants.
We did this for three reasons:
-
to support a new and simpler way to pay;
-
to add new ways of working together (workspaces and data owners);
-
to make our wording clearer and more exact about what we do with your data.
English is now the main version
Our documents are now written in English as the official version. We may give you a Dutch translation to help you. If there is any difference between the two, the English version is the one that counts.
A new way to pay: per seat
Before, you paid for each workspace. Now, you pay for each person who uses dembrane. We call this a "seat".
-
There are three plans (we call them tiers): Innovator (you bring your own AI model), Changemaker (EU-hosted AI is included; good for most uses), and Guardian (extra compliance support and controls, for organisations with high compliance needs).
-
We removed the limits on recording and transcription hours.
-
There are no credits and no meter to watch. If you use a lot more than most people, we will contact you to agree a fair price.
-
You pay once a year by default. You can also choose to pay each month for a small extra cost.
-
The old Pilot and Pioneer plans are no longer sold. If you already have one of these, your current agreement stays the same until it renews.
For current prices, please see our pricing page.
Workspaces: keep projects separate
You can now make separate workspaces for different projects or teams. When you make a workspace, you choose if it is internal or external.
-
Internal workspace: it shares your billing, and your organisation owns the data.
-
External workspace: for work you do for another organisation. It has its own billing. You choose which organisation is the "data owner". You can invite people to watch the project for free (we call these "read-only observer seats"), and you can set a different logo.
Who is responsible for the data
This part is important for data protection (the GDPR rules).
-
The data owner is the organisation that decides why and how the data is used. In law, this role is called the "controller".
-
dembrane handles the data for the controller. In law, this role is called the "processor".
-
If you run an external workspace for another organisation, you also act as a processor for them.
-
If the data owner later makes their own account, they can take over the workspace. People who already paid for seats keep their access.
Clearer privacy and data processing
We updated the DPA and the Privacy Statement to match this new way of working.
-
We added the new roles: read-only observers, external collaborators, and the contact people at a data-owner organisation that we tell when a workspace is created.
-
We explained that the AI providers we use depend on your plan. For example, if you bring your own AI model, your data goes to your provider, not ours.
-
We changed the word "anonymised" to "de-identified". This describes what we really do. We remove details that could directly identify you, and we lower the risk that someone is re-identified. We do not promise that data can never be traced back because sometimes people share things that identify them to particular people (like using a particular catchphrase, or sharing a unique story).
Data Policy for Participants
This document explains how we handle the data of people who take part in a session. We added it to this document library, and we updated it.
-
It now names the trusted EU service providers we use (for hosting, for turning speech into text, and for AI analysis), instead of saying we do not share data with anyone.
-
We also use "de-identified" here, for the same reason as above.
Service levels (SLA)
-
We removed the old Pilot and Pioneer plans from the support list.
-
If the platform is available less than we promised in a month, you now get money back as credit on your account. We work this out from a monthly amount: your yearly price divided by twelve (or your monthly invoice, if you pay each month).
Which documents were changed
| Document | New version |
|---|---|
| General Terms and Conditions | 2.0 |
| Data Processing Agreement (DPA) | 3.0 |
| Privacy Statement | 3.0 |
| Service Level Agreement (SLA) | 1.1 |
| Data Policy for Participants | 1.1 |
We kept the older versions for reference. They are marked as replaced ("superseded").
Questions?
If you have any questions about these changes, please contact us at [email protected]. For privacy questions, you can contact [email protected].