Legal

Privacy Policy

Last updated 22 September 2026 · Version 1.2

How Cue handles personal data: what is collected on sales calls, where it goes, how long it is kept, and how to exercise your rights. Written to be read, and checked against what the software actually does.

1.Introduction

This Privacy Policy explains how Zare Lab (trading as "Cue") (“Cue”, “we”, “us”, “our”) handles personal data.

Cue is a continuous deal-intelligence platform for business-to-business sales teams. It prepares briefs before sales calls, assists the sales representative privately during calls, produces analysis and follow-up drafts afterwards, and monitors open deals in between.

We are based in the Netherlands and comply with the General Data Protection Regulation (GDPR), the Dutch GDPR Implementation Act (Uitvoeringswet AVG), and the Dutch Telecommunications Act.

Contact details

  • Zare Lab (trading as "Cue")
  • Het Bijsterveld 18, 5701 GW Helmond, the Netherlands
  • KvK: 73183156
  • VAT: NL002481375B08
  • Privacy enquiries and security reports: [email protected]

2.The two roles we play. Please read this first

Whether we are the controller or the processor of your personal data depends on who you are. This decides who you should contact about your rights.

2a. Where Cue is the controller

We decide why and how personal data is processed when it relates to:

  • visitors to our website;
  • people who contact us or request a demo;
  • our customers’ administrators and authorised users, in respect of their account, sign-in, billing, support and product-usage data;
  • prospective customers we contact for our own sales and marketing;
  • business contacts.

For all of the above, this policy describes what we do, and you can exercise your rights with us directly (section 11).

2b. Where Cue is the processor

When our customer uses Cue in their sales process, we process personal data on that customer’s instructions. That includes:

  • transcripts and analysis of sales calls, and the personal data of everyone on those calls;
  • buyer contact records, CRM data, and email and calendar metadata from the customer’s connected systems;
  • in Slack, only the messages a user sends to Cue (a direct message, an @Cue mention, the /cue command) and the profile email Cue uses to match a Slack user to their Cue account. Cue does not read other Slack conversations. A question asked in Slack is stored like one asked in Cue;
  • in Notion, the pages a workspace admin chooses to import into the knowledge base (their text is stored and indexed like an uploaded document), and one page of call notes per call that Cue writes into a Notion database the admin chooses. Cue reads only pages the admin has shared with it in Notion;
  • when a user connects an AI assistant to Cue (for example Claude, ChatGPT or Notion AI), the deal, call, transcript and knowledge-base information that assistant asks Cue for on that user’s behalf. The assistant can only read what that user can read in Cue, cannot change anything, and the user can disconnect it at any time. What the assistant does with that information is governed by its own provider’s terms;
  • information about buyer-side organisations and stakeholders gathered to support the deal;
  • files the customer’s users store on a deal, such as proposals and order forms, and the text extracted from them.

Files stored on a deal

Unlike call audio, a file a user adds to a deal is stored. It is kept in private file storage in the same European region as our database (Ireland) and is never publicly reachable: it opens only through a link that expires within a minute, created for a signed-in member of the workspace that owns the deal. The user who owns the deal can add, rename and delete its files; other members of that workspace can view them. If a file is too large to attach to an email, Cue can put a download link in the email instead; anyone holding that link can download the file for 7 days. Cue extracts the text of PDF, Word, Markdown and text files so it can answer questions about that deal and update it. That text is indexed for search and read by the AI providers listed in section 8 only when that deal is asked about or updated. It is never added to the workspace’s shared knowledge base. A file is kept until it or its deal is deleted.

For this data, our customer is the controller and we are the processor. They decide what is collected, why, and for how long. Our processing is governed by a Data Processing Agreement, which is provided with every paid subscription and is available on request during a trial or pilot.

If you were on a sales call with a company that uses Cue and want to know what was kept, correct it, or have it deleted, please contact that company directly: they control the data. If you do not know who to contact, write to [email protected] and we will identify the relevant customer and pass your request on. We cannot act on their data without their instruction, but we will not ignore you.

3.Recording and analysis of calls

Because this is the part of Cue that affects the most people, we set out our position plainly.

  • What is processed. Cue processes the audio of online meetings (Zoom, Microsoft Teams, Google Meet) that our customer’s user joins with Cue running. The audio is streamed to our transcription provider as the call happens and is not stored. Cue keeps the transcript, the analysis derived from it, and the timing of who spoke when. Cue does not process video.
  • Who must tell the participants. Our customer is responsible for informing everyone on the call that it is transcribed and analysed, and for obtaining consent where the law requires it. This is a binding obligation under our Terms and Conditions. As processor we act only on our customer’s instructions and cannot verify compliance on each call, though we will tell a customer if an instruction appears to us to infringe data protection law.
  • What the software does to help. Before a user’s first call, the Cue desktop app requires them to acknowledge that responsibility, and the acknowledgement is recorded. Suggested wording for a calendar invitation or the start of a call: “This call is transcribed and analysed with Cue so I can follow up accurately. Tell me if you would rather I turn it off.”
  • What other participants see. Nothing. Cue’s overlay is visible only to the user running it and shows nothing to anyone else on the call. Whether and how participants are told is the customer’s decision and obligation; the software does not make that decision for them.
  • What the analysis is limited to. Cue works only from the words in the transcript and from system records: what was said, by whom, when, what was asked, and what was committed to. Its analysis may note when a buyer’s own words signal hesitation, enthusiasm or a change of position. Cue does not analyse tone of voice, facial expressions or video, and does not use biometric identification or emotion recognition from voice or face. We consider this a product principle, not only a legal one.
  • Practice role-play calls. When a representative uses Cue’s role-play feature to rehearse a call, their voice audio is streamed to Google to generate the synthetic practice buyer’s voice in real time. The audio is streamed and not stored by Cue; the role-play transcript is stored like any call.

4.Personal data we process as controller

CategoryExamples
Identity and contact dataName, business email address, job title, employer, phone number
Account dataUser ID, role and workspace, sign-in identifiers from Google or Microsoft, or a one-time email sign-in link. Cue does not store passwords.
Billing dataBilling contact, company address, VAT number, plan and invoices, once billing is enabled. Card details are handled by our payment provider; we never hold full card numbers.
Usage and product telemetryFeatures used, overlay interactions, error and performance logs, device and browser type, operating system, IP address
Support and communicationsEmails, demo and onboarding notes, feedback
Marketing dataContact preferences. The website sets no tracking cookies (section 13).

We do not knowingly collect special categories of personal data (Article 9 GDPR) as controller, and we ask that you do not send them to us.

5.Where the data comes from

Most personal data we hold as controller comes directly from you: you request a demo, sign in, email us, or use the product.

We also obtain some personal data indirectly:

  • From our customers. When an administrator adds a colleague to their workspace, we receive that person’s name and work email from them.
  • From public and commercial business sources. For our own B2B sales and marketing we may obtain business contact details from professional networks, company websites and public registers.
  • From service providers. Email and payment providers return data about deliveries and transactions.

Where we obtain your business contact details indirectly and use them to contact you, we will say at first contact where we got them, and you may object at any time (section 11).

6.Why we process personal data, and on what legal basis

PurposeData usedLegal basis (Art. 6 GDPR)
Providing the Service and administering accountsIdentity, account, usagePerformance of a contract (6(1)(b)); legitimate interests where the contract is with your employer (6(1)(f))
Sign-in, access control, fraud and abuse preventionAccount, usage, IPLegitimate interests: securing the Service (6(1)(f))
Billing, invoicing, collectionsBilling, identityContract (6(1)(b)); legal obligation (6(1)(c))
Customer support and onboardingContact, support, usageContract (6(1)(b)); legitimate interests (6(1)(f))
Product improvement, debugging, reliability and security engineeringUsage, telemetry, error logsLegitimate interests: improving and securing a service you rely on (6(1)(f))
Measuring and improving the quality of AI outputsAggregated and de-identified usage data; identifiable data only where strictly necessary, with safeguards, and never to train foundation models for other customersLegitimate interests (6(1)(f))
Direct marketing to existing customers about similar servicesContactLegitimate interests (6(1)(f)), with an opt-out in every message
Direct marketing to new prospectsContactConsent (6(1)(a)) or legitimate interests (6(1)(f)), depending on the channel and applicable law
Complying with tax, accounting and other legal obligationsBilling, identity, correspondenceLegal obligation (6(1)(c))
Establishing, exercising or defending legal claimsAs relevantLegitimate interests (6(1)(f)); legal obligation (6(1)(c))
Corporate transactions (financing, merger, acquisition)As relevant, minimisedLegitimate interests (6(1)(f))

Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interest does not override your rights and freedoms. You can ask us for a summary of that assessment, and you can object (section 11).

7.Automated decision-making and profiling

Cue produces deal-health scores, risk flags, detected signals and recommended actions. These are generated automatically from evidence in transcripts and connected systems. Our position:

  • They are decision support for a human sales professional, not automated decisions in the sense of Article 22 GDPR. They produce no legal effects concerning any individual, and we do not use them to make decisions about individuals.
  • Cue does not send an email to a buyer without a user’s own action. Where a customer connects a CRM, Cue writes the call summary and captured fields to it after each call; every write records the previous value so it can be reviewed and corrected.
  • A signal detected on a call carries the transcript passage it came from, a health score shows the factors behind it, and a user can dismiss or correct a signal. We built this deliberately: intelligence that cannot be audited or corrected should not be trusted.
  • Cue is not designed to evaluate the individual performance of employees for HR decisions. If a customer configures it in a way that approaches that, they are responsible for the additional obligations that follow, including any works-council consultation.

8.Who we share personal data with

We do not sell personal data. We share it only as described here.

Service providers (sub-processors)

These providers run parts of Cue on our behalf. This list is the current one; we update it here before adding a provider, and customers with a Data Processing Agreement are notified.

ProviderFunctionLocation
SupabaseDatabase and file storageIreland (EU)
Fly.ioHosting for live-call processing and background jobsFrankfurt, Germany (EU)
VercelHosting for the web applicationDublin, Ireland (EU)
CloudflareDNS and network security for the websiteGlobal network (EU and US)
DeepgramSpeech-to-text transcription of call audioUnited States
AnthropicAI models: live-call classification, answers, analysisUnited States
GoogleAI models: briefs and deal updates; realtime voice for the practice buyerUnited States
OpenAIAI models for briefs, analysis and drafts; text embeddings for searchUnited States
MergeAI model gateway that routes requests to OpenAI modelsUnited States
TavilyWeb research for pre-call briefs and deal monitoringUnited States
ResendTransactional email: sign-in links and invitationsUnited States

Our commitments on AI providers. We use these providers’ business APIs, whose terms do not permit the provider to train its models on data submitted through our account, and we prefer zero-retention or short-retention configurations where a provider offers them. Live transcript text is sent to them as the basis for answers and analysis; it is not used to train foundation models for other customers.

Services you connect

Data reaches these because you instructed us to send it or read from it. Once it is in those systems, their own privacy terms apply:

  • Google Workspace (sign-in, Google Calendar, Gmail)
  • Microsoft 365 (Outlook Calendar, Outlook Mail)
  • HubSpot
  • Salesforce
  • Slack
  • Notion
  • AI assistants a user connects to Cue (for example Claude, ChatGPT or Notion AI)

Others

We may also disclose personal data to professional advisers (lawyers, accountants, auditors) under a duty of confidence; to competent authorities where legally required; and to an acquirer or investor in the context of a corporate transaction, subject to confidentiality and data minimisation.

9.International transfers

We host and store personal data in the European Economic Area: our database is in Ireland and our application servers are in Frankfurt and Dublin.

Some of our providers, in particular for transcription and AI models, are established in or process data in the United States. Where that happens we rely on one or more of:

  • an adequacy decision by the European Commission, including the EU-US Data Privacy Framework where the recipient is certified;
  • the European Commission’s Standard Contractual Clauses, combined with a transfer impact assessment and supplementary measures such as encryption in transit and at rest and access minimisation;
  • another lawful transfer mechanism under Chapter V GDPR.

You may request a copy of the relevant safeguards at [email protected].

10.How long we keep personal data

DataRetention
Account and user dataFor the life of your account, then 90 days after termination, unless you ask us to delete it sooner
Customer data processed on behalf of a customer (transcripts, analysis, deal records)Until you delete it. Deleting a deal deletes its calls, transcripts and analysis. On termination, available for export for 30 days, then deleted
Call and practice audioNot stored. Streamed for transcription or buyer voice generation and discarded
Files stored on a deal, and the text extracted from themUntil the file or its deal is deleted. Deleting either removes the stored file and its extracted text
Billing and invoicing records7 years, as required by Dutch tax law (once billing is enabled)
Support correspondence3 years after the case is closed
Marketing contact dataUntil you object or unsubscribe, then a minimal suppression record so we do not contact you again
Security and audit logs12 months

Cue does not yet offer a configurable retention period per workspace. If you need one, tell us and we will apply it for you. Where we no longer need personal data but cannot delete it immediately, for example because it sits in a backup, we isolate it and delete it on the normal backup cycle.

11.Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data, where the conditions are met;
  • restrict processing in certain circumstances;
  • data portability: receive data you provided in a structured, machine-readable format, and have it transmitted to another controller where technically feasible;
  • object to processing based on legitimate interests, on grounds relating to your particular situation, and at any time and without reason to direct marketing;
  • withdraw consent where we rely on it, without affecting processing carried out before withdrawal;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (section 7).

How to exercise them. Email [email protected]. We respond within one month, extendable by two months for complex requests, and will tell you if we need the extension. We may ask for information to verify your identity and will not ask for more than is necessary. Exercising your rights is free unless a request is manifestly unfounded or excessive.

If we are the processor (section 2b), we will forward your request to the responsible customer and support them in answering it. Please contact them first where you can.

Complaints. We would prefer to resolve any concern with you directly, so please contact us first. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl). If you live or work in another EU or EEA country, you may complain to your local authority instead.

12.Security

Customers trust us with material that would embarrass them if it leaked. Our measures include:

  • encryption in transit (TLS) everywhere, and encryption at rest by our hosting providers;
  • credentials for the services you connect (calendar, email, CRM, Slack, Notion) are encrypted with a key held separately from the database, and access tokens Cue issues to AI assistants are stored only as one-way hashes;
  • role-based access within a workspace, and least-privilege access for our own staff;
  • a recorded history of every field Cue writes to a connected CRM, with the previous value;
  • dependency scanning and automated checks on every code change, regular backups, and an incident response process.

No system is perfectly secure. If a personal data breach occurs, we will notify the Autoriteit Persoonsgegevens within 72 hours where required, and affected customers without undue delay so they can meet their own obligations.

If you believe you have found a security vulnerability, please report it to [email protected]. We will acknowledge your report and will not pursue action against good-faith researchers who follow responsible disclosure.

13.Cookies and similar technologies

Our website and web application set only strictly necessary cookies: a session cookie once you sign in, and your display preferences, stored in your browser. We do not use analytics, advertising or tracking cookies, and we do not load third-party trackers. Because no non-essential cookies are set, there is no cookie banner to accept.

The Cue desktop application stores a sign-in token and your preferences locally on your device. These are necessary for it to function.

14.Children

Cue is a business tool. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe we have, contact [email protected] and we will delete it.

15.Changes to this policy

We may update this policy as our product, our providers or the law change. The date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will notify workspace administrators by email or by notice in the product before it takes effect.

16.Contact

  • Zare Lab (trading as "Cue")
  • Het Bijsterveld 18, 5701 GW Helmond, the Netherlands
  • KvK: 73183156
  • VAT: NL002481375B08
  • Email: [email protected]
  • Web: cuelive.app

Questions about this document: [email protected]