1.Introduction
This Privacy Policy explains how Zare Lab (trading as "Cue") (“Cue”, “we”, “us”, “our”) handles personal data.
Cue is a continuous deal-intelligence platform for business-to-business sales teams. It prepares briefs before sales calls, assists the sales representative privately during calls, produces analysis and follow-up drafts afterwards, and monitors open deals in between.
We are based in the Netherlands and comply with the General Data Protection Regulation (GDPR), the Dutch GDPR Implementation Act (Uitvoeringswet AVG), and the Dutch Telecommunications Act.
Contact details
- Zare Lab (trading as "Cue")
- Het Bijsterveld 18, 5701 GW Helmond, the Netherlands
- KvK: 73183156
- VAT: NL002481375B08
- Privacy enquiries and security reports: [email protected]
2.The two roles we play. Please read this first
Whether we are the controller or the processor of your personal data depends on who you are. This decides who you should contact about your rights.
2a. Where Cue is the controller
We decide why and how personal data is processed when it relates to:
- visitors to our website;
- people who contact us or request a demo;
- our customers’ administrators and authorised users, in respect of their account, sign-in, billing, support and product-usage data;
- prospective customers we contact for our own sales and marketing;
- business contacts.
For all of the above, this policy describes what we do, and you can exercise your rights with us directly (section 11).
2b. Where Cue is the processor
When our customer uses Cue in their sales process, we process personal data on that customer’s instructions. That includes:
- transcripts and analysis of sales calls, and the personal data of everyone on those calls;
- buyer contact records, CRM data, and email and calendar metadata from the customer’s connected systems;
- in Slack, only the messages a user sends to Cue (a direct message, an @Cue mention, the /cue command) and the profile email Cue uses to match a Slack user to their Cue account. Cue does not read other Slack conversations. A question asked in Slack is stored like one asked in Cue;
- in Notion, the pages a workspace admin chooses to import into the knowledge base (their text is stored and indexed like an uploaded document), and one page of call notes per call that Cue writes into a Notion database the admin chooses. Cue reads only pages the admin has shared with it in Notion;
- when a user connects an AI assistant to Cue (for example Claude, ChatGPT or Notion AI), the deal, call, transcript and knowledge-base information that assistant asks Cue for on that user’s behalf. The assistant can only read what that user can read in Cue, cannot change anything, and the user can disconnect it at any time. What the assistant does with that information is governed by its own provider’s terms;
- information about buyer-side organisations and stakeholders gathered to support the deal;
- files the customer’s users store on a deal, such as proposals and order forms, and the text extracted from them.
Files stored on a deal
Unlike call audio, a file a user adds to a deal is stored. It is kept in private file storage in the same European region as our database (Ireland) and is never publicly reachable: it opens only through a link that expires within a minute, created for a signed-in member of the workspace that owns the deal. The user who owns the deal can add, rename and delete its files; other members of that workspace can view them. If a file is too large to attach to an email, Cue can put a download link in the email instead; anyone holding that link can download the file for 7 days. Cue extracts the text of PDF, Word, Markdown and text files so it can answer questions about that deal and update it. That text is indexed for search and read by the AI providers listed in section 8 only when that deal is asked about or updated. It is never added to the workspace’s shared knowledge base. A file is kept until it or its deal is deleted.
For this data, our customer is the controller and we are the processor. They decide what is collected, why, and for how long. Our processing is governed by a Data Processing Agreement, which is provided with every paid subscription and is available on request during a trial or pilot.
3.Recording and analysis of calls
Because this is the part of Cue that affects the most people, we set out our position plainly.
- What is processed. Cue processes the audio of online meetings (Zoom, Microsoft Teams, Google Meet) that our customer’s user joins with Cue running. The audio is streamed to our transcription provider as the call happens and is not stored. Cue keeps the transcript, the analysis derived from it, and the timing of who spoke when. Cue does not process video.
- Who must tell the participants. Our customer is responsible for informing everyone on the call that it is transcribed and analysed, and for obtaining consent where the law requires it. This is a binding obligation under our Terms and Conditions. As processor we act only on our customer’s instructions and cannot verify compliance on each call, though we will tell a customer if an instruction appears to us to infringe data protection law.
- What the software does to help. Before a user’s first call, the Cue desktop app requires them to acknowledge that responsibility, and the acknowledgement is recorded. Suggested wording for a calendar invitation or the start of a call: “This call is transcribed and analysed with Cue so I can follow up accurately. Tell me if you would rather I turn it off.”
- What other participants see. Nothing. Cue’s overlay is visible only to the user running it and shows nothing to anyone else on the call. Whether and how participants are told is the customer’s decision and obligation; the software does not make that decision for them.
- What the analysis is limited to. Cue works only from the words in the transcript and from system records: what was said, by whom, when, what was asked, and what was committed to. Its analysis may note when a buyer’s own words signal hesitation, enthusiasm or a change of position. Cue does not analyse tone of voice, facial expressions or video, and does not use biometric identification or emotion recognition from voice or face. We consider this a product principle, not only a legal one.
- Practice role-play calls. When a representative uses Cue’s role-play feature to rehearse a call, their voice audio is streamed to Google to generate the synthetic practice buyer’s voice in real time. The audio is streamed and not stored by Cue; the role-play transcript is stored like any call.
4.Personal data we process as controller
| Category | Examples |
|---|---|
| Identity and contact data | Name, business email address, job title, employer, phone number |
| Account data | User ID, role and workspace, sign-in identifiers from Google or Microsoft, or a one-time email sign-in link. Cue does not store passwords. |
| Billing data | Billing contact, company address, VAT number, plan and invoices, once billing is enabled. Card details are handled by our payment provider; we never hold full card numbers. |
| Usage and product telemetry | Features used, overlay interactions, error and performance logs, device and browser type, operating system, IP address |
| Support and communications | Emails, demo and onboarding notes, feedback |
| Marketing data | Contact preferences. The website sets no tracking cookies (section 13). |
We do not knowingly collect special categories of personal data (Article 9 GDPR) as controller, and we ask that you do not send them to us.
5.Where the data comes from
Most personal data we hold as controller comes directly from you: you request a demo, sign in, email us, or use the product.
We also obtain some personal data indirectly:
- From our customers. When an administrator adds a colleague to their workspace, we receive that person’s name and work email from them.
- From public and commercial business sources. For our own B2B sales and marketing we may obtain business contact details from professional networks, company websites and public registers.
- From service providers. Email and payment providers return data about deliveries and transactions.
Where we obtain your business contact details indirectly and use them to contact you, we will say at first contact where we got them, and you may object at any time (section 11).
6.Why we process personal data, and on what legal basis
| Purpose | Data used | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Providing the Service and administering accounts | Identity, account, usage | Performance of a contract (6(1)(b)); legitimate interests where the contract is with your employer (6(1)(f)) |
| Sign-in, access control, fraud and abuse prevention | Account, usage, IP | Legitimate interests: securing the Service (6(1)(f)) |
| Billing, invoicing, collections | Billing, identity | Contract (6(1)(b)); legal obligation (6(1)(c)) |
| Customer support and onboarding | Contact, support, usage | Contract (6(1)(b)); legitimate interests (6(1)(f)) |
| Product improvement, debugging, reliability and security engineering | Usage, telemetry, error logs | Legitimate interests: improving and securing a service you rely on (6(1)(f)) |
| Measuring and improving the quality of AI outputs | Aggregated and de-identified usage data; identifiable data only where strictly necessary, with safeguards, and never to train foundation models for other customers | Legitimate interests (6(1)(f)) |
| Direct marketing to existing customers about similar services | Contact | Legitimate interests (6(1)(f)), with an opt-out in every message |
| Direct marketing to new prospects | Contact | Consent (6(1)(a)) or legitimate interests (6(1)(f)), depending on the channel and applicable law |
| Complying with tax, accounting and other legal obligations | Billing, identity, correspondence | Legal obligation (6(1)(c)) |
| Establishing, exercising or defending legal claims | As relevant | Legitimate interests (6(1)(f)); legal obligation (6(1)(c)) |
| Corporate transactions (financing, merger, acquisition) | As relevant, minimised | Legitimate interests (6(1)(f)) |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interest does not override your rights and freedoms. You can ask us for a summary of that assessment, and you can object (section 11).
7.Automated decision-making and profiling
Cue produces deal-health scores, risk flags, detected signals and recommended actions. These are generated automatically from evidence in transcripts and connected systems. Our position:
- They are decision support for a human sales professional, not automated decisions in the sense of Article 22 GDPR. They produce no legal effects concerning any individual, and we do not use them to make decisions about individuals.
- Cue does not send an email to a buyer without a user’s own action. Where a customer connects a CRM, Cue writes the call summary and captured fields to it after each call; every write records the previous value so it can be reviewed and corrected.
- A signal detected on a call carries the transcript passage it came from, a health score shows the factors behind it, and a user can dismiss or correct a signal. We built this deliberately: intelligence that cannot be audited or corrected should not be trusted.
- Cue is not designed to evaluate the individual performance of employees for HR decisions. If a customer configures it in a way that approaches that, they are responsible for the additional obligations that follow, including any works-council consultation.
8.Who we share personal data with
We do not sell personal data. We share it only as described here.
Service providers (sub-processors)
These providers run parts of Cue on our behalf. This list is the current one; we update it here before adding a provider, and customers with a Data Processing Agreement are notified.
| Provider | Function | Location |
|---|---|---|
| Supabase | Database and file storage | Ireland (EU) |
| Fly.io | Hosting for live-call processing and background jobs | Frankfurt, Germany (EU) |
| Vercel | Hosting for the web application | Dublin, Ireland (EU) |
| Cloudflare | DNS and network security for the website | Global network (EU and US) |
| Deepgram | Speech-to-text transcription of call audio | United States |
| Anthropic | AI models: live-call classification, answers, analysis | United States |
| AI models: briefs and deal updates; realtime voice for the practice buyer | United States | |
| OpenAI | AI models for briefs, analysis and drafts; text embeddings for search | United States |
| Merge | AI model gateway that routes requests to OpenAI models | United States |
| Tavily | Web research for pre-call briefs and deal monitoring | United States |
| Resend | Transactional email: sign-in links and invitations | United States |
Our commitments on AI providers. We use these providers’ business APIs, whose terms do not permit the provider to train its models on data submitted through our account, and we prefer zero-retention or short-retention configurations where a provider offers them. Live transcript text is sent to them as the basis for answers and analysis; it is not used to train foundation models for other customers.
Services you connect
Data reaches these because you instructed us to send it or read from it. Once it is in those systems, their own privacy terms apply:
- Google Workspace (sign-in, Google Calendar, Gmail)
- Microsoft 365 (Outlook Calendar, Outlook Mail)
- HubSpot
- Salesforce
- Slack
- Notion
- AI assistants a user connects to Cue (for example Claude, ChatGPT or Notion AI)
Others
We may also disclose personal data to professional advisers (lawyers, accountants, auditors) under a duty of confidence; to competent authorities where legally required; and to an acquirer or investor in the context of a corporate transaction, subject to confidentiality and data minimisation.
9.International transfers
We host and store personal data in the European Economic Area: our database is in Ireland and our application servers are in Frankfurt and Dublin.
Some of our providers, in particular for transcription and AI models, are established in or process data in the United States. Where that happens we rely on one or more of:
- an adequacy decision by the European Commission, including the EU-US Data Privacy Framework where the recipient is certified;
- the European Commission’s Standard Contractual Clauses, combined with a transfer impact assessment and supplementary measures such as encryption in transit and at rest and access minimisation;
- another lawful transfer mechanism under Chapter V GDPR.
You may request a copy of the relevant safeguards at [email protected].
10.How long we keep personal data
| Data | Retention |
|---|---|
| Account and user data | For the life of your account, then 90 days after termination, unless you ask us to delete it sooner |
| Customer data processed on behalf of a customer (transcripts, analysis, deal records) | Until you delete it. Deleting a deal deletes its calls, transcripts and analysis. On termination, available for export for 30 days, then deleted |
| Call and practice audio | Not stored. Streamed for transcription or buyer voice generation and discarded |
| Files stored on a deal, and the text extracted from them | Until the file or its deal is deleted. Deleting either removes the stored file and its extracted text |
| Billing and invoicing records | 7 years, as required by Dutch tax law (once billing is enabled) |
| Support correspondence | 3 years after the case is closed |
| Marketing contact data | Until you object or unsubscribe, then a minimal suppression record so we do not contact you again |
| Security and audit logs | 12 months |
Cue does not yet offer a configurable retention period per workspace. If you need one, tell us and we will apply it for you. Where we no longer need personal data but cannot delete it immediately, for example because it sits in a backup, we isolate it and delete it on the normal backup cycle.
11.Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data, where the conditions are met;
- restrict processing in certain circumstances;
- data portability: receive data you provided in a structured, machine-readable format, and have it transmitted to another controller where technically feasible;
- object to processing based on legitimate interests, on grounds relating to your particular situation, and at any time and without reason to direct marketing;
- withdraw consent where we rely on it, without affecting processing carried out before withdrawal;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (section 7).
How to exercise them. Email [email protected]. We respond within one month, extendable by two months for complex requests, and will tell you if we need the extension. We may ask for information to verify your identity and will not ask for more than is necessary. Exercising your rights is free unless a request is manifestly unfounded or excessive.
If we are the processor (section 2b), we will forward your request to the responsible customer and support them in answering it. Please contact them first where you can.
Complaints. We would prefer to resolve any concern with you directly, so please contact us first. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl). If you live or work in another EU or EEA country, you may complain to your local authority instead.
12.Security
Customers trust us with material that would embarrass them if it leaked. Our measures include:
- encryption in transit (TLS) everywhere, and encryption at rest by our hosting providers;
- credentials for the services you connect (calendar, email, CRM, Slack, Notion) are encrypted with a key held separately from the database, and access tokens Cue issues to AI assistants are stored only as one-way hashes;
- role-based access within a workspace, and least-privilege access for our own staff;
- a recorded history of every field Cue writes to a connected CRM, with the previous value;
- dependency scanning and automated checks on every code change, regular backups, and an incident response process.
No system is perfectly secure. If a personal data breach occurs, we will notify the Autoriteit Persoonsgegevens within 72 hours where required, and affected customers without undue delay so they can meet their own obligations.
If you believe you have found a security vulnerability, please report it to [email protected]. We will acknowledge your report and will not pursue action against good-faith researchers who follow responsible disclosure.
14.Children
Cue is a business tool. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe we have, contact [email protected] and we will delete it.
15.Changes to this policy
We may update this policy as our product, our providers or the law change. The date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will notify workspace administrators by email or by notice in the product before it takes effect.
16.Contact
- Zare Lab (trading as "Cue")
- Het Bijsterveld 18, 5701 GW Helmond, the Netherlands
- KvK: 73183156
- VAT: NL002481375B08
- Email: [email protected]
- Web: cuelive.app