Privacy Policy

Effective date: 21 February 2026  ·  Last updated: 6 August 2026

DemandIntel ("we", "us", or "our") operates the platform available at demandintel.io (the "Platform"). This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our Platform, and sets out your rights under applicable data protection laws including:

  • The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
  • The EU General Data Protection Regulation (EU GDPR) 2016/679
  • The Protection of Personal Information Act 4 of 2013 (POPIA) - South Africa
  • US state privacy laws including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA)

Please read this policy carefully. By accessing or using the Platform you acknowledge you have read and understood this policy. If you do not agree, please discontinue use of the Platform.

1. Who We Are (Data Controller / Responsible Party)

DemandIntel is the data controller (UK/EU GDPR), responsible party (POPIA), and business (CCPA) with respect to personal information processed through the Platform.

Contact details:
Email: privacy@demandintel.io
Website: demandintel.io

For South Africa: our designated Information Officer can be reached at privacy@demandintel.io.

For EU residents: if we are required to appoint an EU representative under Article 27 GDPR, their contact details will be published here.

2. What Personal Information We Collect

2.1 Account & Identity Data

When you sign in we collect data depending on the authentication method you use:

  • Google SSO: Full name, email address, Google profile picture URL, and authentication session data. In the main Platform we also request the minimum Google Drive scopes required: read-only access to your Drive (to let you select source folders for transcript ingestion) and per-file access limited to documents and presentations the Platform itself creates on your behalf. Preview sign-in uses our managed authentication broker and does not itself grant Drive access. We do not request access to your Gmail or Google Calendar.
  • Microsoft SSO: Full name, email address, Microsoft profile picture (if available), and a Microsoft OAuth access token and refresh token (to access your OneDrive/SharePoint on your behalf for transcript ingestion and report storage). The refresh token is stored securely in our database to enable background auto-ingestion without requiring you to remain signed in
  • Email & password: Email address and a securely hashed password (we never store your password in plain text; passwords are hashed using PBKDF2-SHA256 with a unique random salt). If you enable two-factor authentication (2FA), we also store a TOTP secret and single-use backup codes, all protected at rest by our database encryption

Sales representatives: An account administrator may invite an individual sales representative to log in and access only their own performance, coaching, QA, and competency data. Reps activate their account through a secure, time-limited invitation link sent to their email address, after which they authenticate using any of the methods above (Google SSO, Microsoft SSO, or an email and password they set). We store the rep's name, email address, authentication credentials, and notification preferences for this purpose.

2.2 Professional & Client Data

The Platform processes call transcripts and related data that you or your organisation upload or link from Google Drive, Microsoft OneDrive/SharePoint, or upload directly from your device. This may include names, phone numbers, or other personal information contained in those transcripts. You are the data controller for any third-party personal information contained in transcripts; we process it solely as your data processor on your instructions.

Device uploads: Signed-in users may upload transcript files (.vtt, .srt, .txt, .json) or audio recordings (.mp3, .wav, .m4a, .mp4, .webm, .ogg, .aac, .flac) directly from their device into a private storage bucket. Uploaded audio files are transcribed by the speech-to-text sub-processors listed in section 4.1, then the transcript is analysed by the same pipeline as Drive- and dialler-sourced calls. The original uploaded file is retained for 30 days after successful processing and then deleted; the resulting transcript and analysis are retained per section 6.

Dialler integrations: When your organisation connects its sales dialler or phone system (such as Orum, Kixie, FrontSpin, Aircall, Dialpad, JustCall, Zoom Phone, Zoom Contact Center, or a dialler connected via Zapier/n8n), the Platform receives call data directly from that system. This may include call audio recordings, call transcripts, the calling representative's name, email address and agent ID, the phone numbers dialled, call timestamps, durations, dispositions, and queue or campaign names. Where the dialler provides its own transcript (for example Zoom, Aircall AI, Dialpad Ai, or JustCall AI), we ingest that transcript directly; otherwise audio recordings are transcribed by the speech-to-text sub-processors listed in section 4.1. Call data is stored in our database infrastructure (Supabase). Your dialler provider remains a separate controller/processor under your agreement with them.

Notetaker integrations: When your organisation connects a meeting notetaker (such as Fireflies, Google Gemini for Google Meet, Microsoft Copilot for Teams, Granola, tl;dv, Read.ai, Fathom, or Otter), the Platform pulls the meeting transcript directly from that provider's API. We prefer provider-supplied transcripts and only download the audio/video recording as a fallback when no transcript is available. You control which call types are ingested (Discovery, Demo, Outbound, etc.) through the ingestion filter in Settings - meetings outside that filter are never pulled. Where the DemandIntel Recorder has already captured the same meeting for the same representative in the same time window, the notetaker copy is automatically suppressed to avoid duplicate ingestion. The notetaker provider remains a separate controller/processor under your agreement with them.

DemandIntel Recorder (browser extension and desktop app): Where your organisation enables it, an individual sales representative may install the DemandIntel Recorder to capture the audio of their own sales calls (for example on Google Meet, Microsoft Teams, Zoom, or a softphone) directly from their device. When active, the Recorder captures the representative's microphone and the tab/system audio of the other party, buffers the recording locally on the representative's device in short encrypted chunks, and uploads those chunks to the Platform's private storage bucket. Only representatives whose account administrator has issued a pairing code and who have approved recording analysis (see "Representative approval" below) can upload. The Recorder does not capture video, screen contents, keystrokes, or any other application data, and it does not run in the background outside of an active call. Local buffer chunks are deleted from the device as soon as they are successfully uploaded (or, for any chunks that fail to upload, within 24 hours). The uploaded audio is then handled on the same terms as any other device upload: transcribed by the speech-to-text sub-processors listed in section 4.1, retained for 30 days as the original file and per section 6 for the resulting transcript and analysis. Your organisation is responsible for configuring the Recorder in a manner that is lawful in the jurisdictions where its representatives and call participants are located (including any two-party consent requirements) - see the Terms of Service section 4.

Representative approval: For connected dialler sources and the DemandIntel Recorder, an individual sales representative's calls are only transcribed and analysed after that representative approves recording analysis in their own settings. Calls received before approval are held unprocessed for up to 14 days and then deleted (see section 6). Consent changes are recorded in an audit log.

2.3 Usage & Technical Data

  • Access request information (email, organisation name)
  • Pages visited, features used, and actions taken on the Platform
  • Browser type, device type, and operating system
  • IP address and approximate location (country/region)
  • Session tokens and authentication state stored in your browser's local storage
  • Server-side product events (page-level signup, checkout started/completed) used for marketing pipeline reporting

2.4 Communications

If you contact us by email or complete a request-access form, we retain the contents of that communication and any personal information you include.

3. How We Use Your Personal Information

PurposeLegal basis (UK/EU GDPR & POPIA)CCPA category
Authenticate your account and provide the PlatformPerformance of a contract (Art. 6(1)(b) GDPR; s. 11(1)(a) POPIA)Identifiers; Internet activity
Process call transcripts and generate reportsPerformance of a contract; legitimate interests (Art. 6(1)(f); s. 11(1)(f) POPIA)Professional information; Inferences
Manage access requests and grant/deny platform accessLegitimate interests; pre-contractual stepsIdentifiers
Maintain security, prevent fraud and abuseLegitimate interests; legal obligationIdentifiers; Internet activity
Improve and develop the PlatformLegitimate interests (anonymised or aggregated where possible)Internet activity
Product analytics, session replay, and feature-usage measurementLegitimate interests (Art. 6(1)(f)); anonymised or aggregated where possibleInternet activity; Inferences
Comply with legal and regulatory obligationsLegal obligation (Art. 6(1)(c); s. 11(1)(c) POPIA)Any relevant category
Provide support, coaching, account management, and identify additional services that may benefit you (authorised DemandIntel staff may review your account's performance data, reports, and analytics; all such access is logged)Legitimate interests (Art. 6(1)(f); s. 11(1)(f) POPIA); performance of a contractProfessional information; Inferences

4. Sharing Your Personal Information

We do not sell, rent, or trade your personal information. We share it only as described below:

4.1 Sub-processors / Service Providers

  • Supabase - database, authentication, and serverless functions. Data may be stored in the EU or USA (subject to appropriate transfer safeguards). See Supabase's privacy policy at supabase.com/privacy.
  • Google LLC - OAuth authentication and Google Drive integration (including Google Docs and Google Slides files the Platform creates on your behalf via the Drive file-level scope). Data is processed under your Google account terms. See Google's privacy policy.
  • Microsoft Corporation - OAuth authentication (Microsoft SSO), OneDrive and SharePoint integration for transcript ingestion and report storage, Microsoft Teams notifications (via incoming webhook or, for Microsoft-signed users, the Microsoft Graph API to post messages to a team/channel you select), and Microsoft Teams Phone integration (the Microsoft Graph CallRecords API is used to pull PSTN call records and recordings for transcription and analysis using application-only credentials authorised by a Microsoft 365 global admin granting tenant-wide consent on first connect - DemandIntel does not act on behalf of any individual Microsoft user for Teams Phone). Data is processed under your Microsoft account terms. See Microsoft's privacy statement.
  • Anthropic PBC - AI model provider for call transcript analysis and report generation. Transcript data is sent to Anthropic's API for processing; Anthropic does not use customer data for training. See Anthropic's privacy policy.
  • Trigger.dev Ltd - background task orchestration for report generation and call ingestion workflows. See Trigger.dev's privacy policy.
  • Netlify Inc. - web application hosting and content delivery. See Netlify's privacy policy.
  • Resend Inc. - transactional email delivery for account credentials, password resets, invitations, login confirmations, and automated knowledge/report emails sent from our automated assistant "Eriqa" at eriqa@demandintel.io (replies are not monitored and bounce to no-reply@demandintel.io). See Resend's privacy policy.
  • OpenAI, L.L.C. - AI model provider used for the in-product and marketing chat assistant ("Eriqa") and, as a last-resort fallback, to transcribe call recordings (speech-to-text) when the primary transcription providers are unavailable. Chat messages you send to Eriqa and any audio processed on the fallback path are handled by OpenAI; OpenAI does not use this data to train its models under its API terms. See OpenAI's privacy policy.
  • Groq, Inc. - AI inference provider used as the primary engine to transcribe call recordings (speech-to-text) via the Whisper model. Audio recordings are sent to Groq's API for transcription; Groq does not use customer data for training. See Groq's privacy policy.
  • AssemblyAI, Inc. - speech-to-text provider used as a fallback to transcribe call recordings (including speaker separation / diarisation) when the primary transcription provider is unavailable. Audio recordings are sent to AssemblyAI's API in the United States for transcription; AssemblyAI does not use customer data for training. See AssemblyAI's privacy policy.
  • Slack Technologies, LLC - team messaging used to notify the DemandIntel support team when a chat with Eriqa is escalated or a lead is captured. See Slack's privacy policy.
  • Firecrawl, Inc. - public website crawling and scraping service used to build the client context profile when you add or refresh a customer record. Only the customer's own public website URLs are sent to Firecrawl; no transcript or call data is ever shared with this sub-processor. See Firecrawl's privacy policy.
  • Stripe, Inc. - payment processing for subscriptions, trials, and credit top-ups. When you start a trial or purchase a subscription, your name, email address, billing address, and payment card details are collected and processed by Stripe; we do not store full card numbers on our infrastructure. See Stripe's privacy policy.
  • Attio, Inc. - customer relationship management (CRM) system used to manage our sales and marketing pipeline. We store your name, email address, company domain, the marketing pipeline stage you are in, your selected plan, and engagement events (such as page views and email opens) so we can follow up appropriately. See Attio's privacy policy.
  • Instantly.ai - cold-email outbound and sequencing tool used for marketing outreach. We send your name, email address and company domain when you become a marketing-qualified lead so we can send relevant outreach. You can opt out at any time using the unsubscribe link in any email. See Instantly's privacy policy.
  • Notetaker providers (optional). Where your organisation connects a meeting notetaker, transcript and meeting metadata is pulled from that provider's API. The active notetaker sub-processors are: Fireflies AI, Inc. (policy), Google LLC for Gemini / Meet artifacts (policy), Microsoft Corporation for Copilot / Teams artifacts (policy), Granola, Inc. (policy), tl;dv GmbH (policy), Read AI, Inc. (policy), Fathom Video, Inc. (policy), and AISense, Inc. (Otter.ai) (policy). Each notetaker provider remains a separate controller/processor under your agreement with them.

4.4 Pseudonymisation Controls (Regulated Industries)

Account administrators can enable per-account pseudonymisation of transcripts under Settings → Privacy & Compliance. When enabled:

  • Standard - Email addresses, phone numbers, payment card numbers, IBAN, NI/SSN, postcodes, URLs, IP addresses and dates of birth are replaced with stable tokens before any transcript is sent to AI sub-processors.
  • Strict - In addition, person names and organisations are replaced with stable tokens. Designed for regulated industries pursuing ISO 27001 / SOC 2 readiness.
  • The original (unredacted) value can be configured to be kept, quarantined in a service-role-only encrypted vault, or shredded (irreversibly discarded) after redaction.
  • All un-masking events (where an authorised user reveals the original value behind a token) are recorded in an append-only audit log retained for at least 90 days. The log is visible to the account owner and DemandIntel administrators.
  • Detection runs entirely inside our own infrastructure - no additional third-party sub-processor is introduced by enabling these controls.

4.2 Legal Requirements

We may disclose personal information if required by law, court order, or to protect the rights, property, or safety of DemandIntel, our users, or the public.

4.3 Business Transfers

If DemandIntel undergoes a merger, acquisition, or asset sale, personal information may be transferred. We will notify you via email and/or prominent notice on the Platform before such a transfer.

5. International Data Transfers

Personal information may be transferred to and processed in countries outside your home country, including the United States. Where we transfer data outside the UK or EEA, we rely on one of the following safeguards:

  • An adequacy decision by the UK Secretary of State or the European Commission
  • Standard Contractual Clauses (SCCs) approved by the relevant authority
  • Other lawful transfer mechanisms permitted under applicable law

South Africa: Where we transfer personal information outside South Africa, we ensure the recipient is subject to a law, binding corporate rules, or binding agreement that provides an adequate level of protection substantially similar to POPIA.

6. Data Retention

We retain personal information for as long as necessary to provide the Platform and fulfil the purposes described in this policy, unless a longer retention period is required by law.

  • Account data - retained while your account is active and for up to 12 months after account closure or access revocation, unless you request earlier deletion.
  • Transcript and report data - retained for the duration of your contract and deleted upon termination or on request.
  • Call recordings (dialler integrations and DemandIntel Recorder) - audio recordings ingested from connected diallers or captured by the DemandIntel Recorder are stored for the duration of your contract and deleted upon termination or on request, alongside the transcript they produced. Local buffer chunks on a representative's own device are held only until successful upload and, if upload fails, are automatically discarded from the device within 24 hours.
  • Unapproved representatives' calls - where a representative has not approved recording analysis, their calls are held unprocessed (not transcribed or analysed) and automatically deleted after 14 days, or immediately where the representative declines.
  • Access request data - retained for 6 months from the date of the request.
  • Legal hold - data may be retained longer where required by legal obligation or dispute resolution.

7. Cookies and Local Storage

The Platform uses browser local storage to maintain your authentication session and theme preference. This storage is strictly necessary for the Platform to function and does not require consent under the ePrivacy Directive / PECR.

Saved answers: When you save an answer from the Ask me anything dashboard, the answer and its associated client name are stored locally in your browser under the key di_ama_saved_v1. This data stays on your device, is not transmitted to our servers, and can be removed at any time by clearing your browser's local storage.

Analytics cookies: The Platform does not set any third-party analytics or session-replay cookies. Marketing pipeline events are captured server-side from explicit actions (signup, checkout) and tied to your email address only. You can request deletion at any time by contacting us at privacy@demandintel.io.

Google's and Microsoft's authentication scripts may set their own cookies governed by their respective cookie policies.

DemandIntel Recorder extension storage: Where a representative installs the DemandIntel Recorder browser extension, the extension uses browser-managed local storage on that representative's own device to hold: a stable per-install device identifier (di_recorder_device_id), the pairing token issued by the Platform when the extension is paired to their account, the current recording policy for their organisation, and short encrypted audio buffer chunks queued for upload. Buffer chunks are deleted from the device once uploaded (or, if upload fails, within 24 hours). No transcript, meeting content, or personal data of call participants is stored on the device outside of these buffer chunks. Uninstalling the extension clears all of the above from the device.

8. Security

We implement industry-standard technical and organisational measures to protect personal information against accidental loss, unauthorised access, disclosure, alteration, and destruction - including TLS encryption in transit, access controls, and regular security reviews.

No method of transmission over the internet or electronic storage is 100% secure. If you become aware of a security incident affecting your account, please notify us immediately at privacy@demandintel.io.

9. Your Rights

9.1 UK and EU Residents (UK GDPR / EU GDPR)

You have the right to:

  • Access the personal data we hold about you (Art. 15)
  • Rectification of inaccurate or incomplete data (Art. 16)
  • Erasure ("right to be forgotten") in certain circumstances (Art. 17)
  • Restriction of processing in certain circumstances (Art. 18)
  • Data portability - receive your data in a structured, machine-readable format (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)
  • Withdraw consent at any time where processing is based on consent (Art. 7(3))
  • Lodge a complaint with the Information Commissioner's Office (ICO) in the UK at ico.org.uk, or your local EU supervisory authority

9.2 South African Residents (POPIA)

Under POPIA you have the right to:

  • Be notified when we collect personal information about you
  • Access and request a copy of your personal information
  • Request correction or deletion of your personal information
  • Object to the processing of your personal information
  • Submit a complaint to the Information Regulator of South Africa at inforegulator.org.za

To submit a request under PAIA (Promotion of Access to Information Act) for access to records we hold, please contact our Information Officer at privacy@demandintel.io.

9.3 California Residents (CCPA / CPRA)

California residents have the right to:

  • Know what personal information we collect, use, disclose, and sell/share
  • Delete personal information we have collected about you (subject to certain exceptions)
  • Correct inaccurate personal information
  • Opt out of the sale or sharing of personal information - We do not sell or share personal information for cross-context behavioural advertising.
  • Limit use of sensitive personal information (we do not use or disclose sensitive PI beyond purposes permitted under CPRA)
  • Non-discrimination - we will not discriminate against you for exercising your privacy rights

To exercise CCPA rights, submit a verifiable consumer request to privacy@demandintel.io. We will respond within 45 days (extendable by a further 45 days with notice). You may designate an authorised agent to make a request on your behalf.

Shine the Light: California residents may also request information about personal information disclosed to third parties for their own direct marketing purposes (Cal. Civ. Code § 1798.83). We do not disclose personal information for direct marketing by third parties.

9.4 All Users - Exercising Your Rights

To exercise any of the rights above, please contact us at privacy@demandintel.io. We will respond within the timeframe required by applicable law (generally 30 days for UK/EU/POPIA, 45 days for CCPA). We may need to verify your identity before processing your request. We will not charge a fee unless your request is manifestly unfounded or excessive.

10. Children's Privacy

The Platform is not directed to individuals under the age of 18 (or the applicable digital age of consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately at privacy@demandintel.io and we will delete it promptly.

11. Third-Party Links and Integrations

The Platform integrates with Google and Microsoft services and may contain links to third-party websites. This policy does not cover those third parties. We encourage you to review their privacy policies before sharing personal information with them.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by prominent notice on the Platform at least 30 days before the changes take effect (or such longer period as required by law). The updated policy will display the revised "Last updated" date at the top. Your continued use of the Platform after the effective date constitutes acceptance of the revised policy.

13. Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:

Email: privacy@demandintel.io
Website: demandintel.io

If you are a UK resident and are not satisfied with our response, you may escalate your complaint to the Information Commissioner's Office (ICO).

If you are an EU resident, you may contact your local data protection authority. A full list is available at edpb.europa.eu.

If you are a South African resident, you may contact the Information Regulator of South Africa.