Privacy Policy

Effective Date: 7 September 2026

This Privacy Policy explains how Setten Company Limited (“Setten”, “we”, “us”, “our”) collects, uses, shares, and protects personal data when you use settenhq.com and related applications (the “Service”).

This Policy covers website visitors, account holders, workspace users, people who interact with Setten booking or collaboration features, and people whose personal data appears in content processed through the Service.

1. Our Privacy Commitments

  • We do not sell personal data.
  • We do not use advertising cookies or cross-site tracking cookies.
  • We do not train AI models on Customer Content.
  • We do not use Customer Content for biometric identification unless that feature is expressly offered and enabled with appropriate legal notices and consents.
  • We access Customer Content only with permission for support, or as needed to protect security, prevent abuse, comply with law, or enforce our Terms.
  • We publish our material service providers on the Subprocessors page.

2. Roles: Controller and Processor

2.1 Customer Content. When you or your workspace users submit content to the Service, such as files, messages, tasks, calendar data, recordings, transcripts, prompts, and outputs (“Customer Content”), Setten generally acts as a processor or subprocessor. The customer controls what is submitted, who may access it, how long it is kept, and whether recordings are made.

2.2 Setten account and service data. Setten acts as a controller for data we use for our own business and service operations, such as account administration, billing records, security logs, support correspondence, usage data, and website operation.

2.3 DPA. Where we process Customer Content as a processor or subprocessor, the Data Processing Agreement applies.

3. Personal Data We Collect

3.1 Data you provide

Category Examples
Account data Name, email address, password hash, profile details, language, time zone
Workspace data Workspace name, members, roles, permissions, invitations, settings
Billing data Plan, billing period, seat count, transaction status, billing country, partial payment details received from our merchant of record
Support data Messages, attachments, and context you provide when contacting us
Customer Content Content you or your users submit, create, upload, record, transcribe, process, or generate through the Service
Calendar and booking data Calendar events, availability, attendees, booking page submissions, names, email addresses, and details entered by guests
AI interactions Prompts, instructions, context submitted to AI Features, and resulting outputs

3.2 Data collected automatically

Category Examples
Device and log data IP address, browser, operating system, device identifiers, referring page, timestamps, request logs
Security data Sign-in attempts, session activity, audit logs, administrative actions
Usage and event data Pages and screens viewed, feature usage, clicks and other interactions, performance data, errors, plan usage counters
Cookies and local storage Session, security, functional, preference, and analytics data described in Section 12

3.3 Data from third parties

We receive data from third-party services you connect to the Service and from our merchant of record. See our Subprocessors page for provider details.

3.4 Data about non-users

Customer Content may include personal data about people who do not have Setten accounts, such as meeting participants, calendar attendees, booking guests, message correspondents, and people mentioned in workspace content. We process that data on behalf of the relevant customer. If you have a request about that data, contact the customer first. If you cannot identify the customer, contact us and we will help route the request where appropriate.

3.5 Sensitive data

The Service does not require sensitive personal data. Customer Content may nevertheless include sensitive data, and recordings may include voice, image, biometric, health, employment, or other protected information. Customers are responsible for processing sensitive data lawfully.

4. How We Use Personal Data

Purpose Data used Basis for processing
Provide and administer accounts Account, authentication, workspace data Contract; legitimate interests
Provide the Service Customer Content, workspace, calendar, booking, AI interaction data Contract; customer instructions under the DPA
Process recordings, transcripts, and AI outputs Customer Content, recordings, transcripts, prompts Contract; customer instructions under the DPA
Process subscriptions and billing Account and billing data Contract; legal obligation
Send service messages Account, workspace, usage data Contract; legitimate interests
Provide support Account, support data, relevant Customer Content when permitted Contract; legitimate interests
Secure, debug, and maintain the Service Device, log, security, usage, event data Legitimate interests; legal obligation
Understand and improve the Service Account, workspace, device, usage and event data; aggregated or de-identified information Consent where required; otherwise legitimate interests
Send marketing communications Account data and preferences Consent or legitimate interests where permitted
Comply with law and enforce rights Relevant data Legal obligation; legitimate interests

You may object to processing based on legitimate interests where applicable law gives you that right.

5. Customer Content and AI

5.1 No AI training. We do not use Customer Content to train, retrain, fine-tune, or improve generative AI or machine learning models.

5.2 Provider restrictions. We require relevant AI and transcription providers to process Customer Content only to provide the requested service output and not to train their models on it.

5.3 Human access. Setten staff do not inspect Customer Content except: (a) at your request or with your permission for support; (b) to investigate, prevent, or respond to a security incident; (c) to investigate abuse or enforce our Terms; or (d) to comply with law. Where legally permitted and appropriate, we give notice of legal or abuse-related access requests.

5.4 Product improvement. We may use usage and event data, and aggregated or de-identified information, to maintain, debug, secure, and improve the Service. We do not use Customer Content for model training.

6. Recordings

Customers decide whether to use recording, transcription, and AI-assisted meeting features. They are responsible for providing notices and obtaining consent as required by Section 9 of the Terms of Service.

Setten does not provide participant notice on the customer’s behalf unless a specific product feature expressly says otherwise. If you were recorded through Setten, contact the person or organisation that hosted the recording. If you cannot identify them, contact us and we will help route the request where appropriate.

7. Sharing Personal Data

We share personal data only as described below:

  • Workspace users and administrators. Content is shared within a workspace according to workspace permissions and administrator settings.
  • Subprocessors and service providers. We share personal data with service providers that help us operate and improve the Service. See our Subprocessors page for details.
  • Third-party integrations. If you connect an integration, data is shared as needed to provide that integration.
  • Merchant of record. Checkout, payment, tax, refund, and chargeback data is processed by our merchant of record as an independent controller.
  • Legal, safety, and enforcement. We may disclose data where required by law, to respond to lawful requests, to protect rights and safety, to investigate abuse or security incidents, or to enforce our Terms.
  • Business transfers. Data may be transferred in connection with a merger, acquisition, financing, reorganisation, or sale of assets, subject to appropriate confidentiality and continuity protections.
  • Professional advisers. We may share data with lawyers, auditors, accountants, insurers, and other advisers under confidentiality obligations.

We do not sell personal data or share it for cross-context behavioural advertising.

8. International Transfers

Setten is established in Vietnam and uses providers in the locations listed on the Subprocessors page. Personal data may be processed outside your country. Where transfer safeguards are required, we use appropriate mechanisms such as adequacy decisions, contractual commitments, transfer assessments, the DPA, and Standard Contractual Clauses where applicable.

9. Retention and Deletion

We keep personal data only as long as needed for the purposes described in this Policy, unless a longer period is required for legal, security, dispute, or enforcement reasons.

Data Retention
Customer Content Until deleted by the customer or while the workspace exists
Deleted Customer Content Removed from active systems on deletion; purged from encrypted backups within 90 days
Content after paid access ends Retained for 30 days for export, then deleted from active systems and purged from encrypted backups within 90 days
Account data For the life of the account, then deleted or anonymised within 30 days of account closure unless needed for legal, security, or billing reasons
Billing and transaction records Up to 10 years where required for tax, accounting, and compliance
Security and audit logs Up to 12 months
Consent confirmations and recording audit events Up to 3 years, unless kept longer as Customer Content, required by law, or needed for dispute, security, or enforcement reasons
Support correspondence Up to 3 years after the matter is closed
Marketing preferences Until changed, plus suppression records as needed to honour opt-outs

Aggregated or de-identified information that does not identify an individual may be kept indefinitely.

10. Security

We maintain technical and organisational measures appropriate to the risk, including encryption in transit, access controls, least-privilege staff access, password hashing, logging and monitoring, encrypted backups, incident response processes, and contractual security obligations for subprocessors.

No service can be guaranteed completely secure. You are responsible for protecting your devices, credentials, integrations, and workspace permissions.

Report security concerns to security@settenhq.com.

11. Your Rights

Depending on your location and the data involved, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal data; withdraw consent; opt out of marketing; and complain to a supervisory authority.

You can exercise many rights directly in the Service. Otherwise, contact hi@settenhq.com or security@settenhq.com. We may need to verify your identity.

If your data is in a customer’s workspace and we process it as a processor or subprocessor, we will normally refer your request to that customer or the relevant controller and assist them as required.

12. Cookies and Similar Technologies

We and our service providers use cookies and similar technologies, including local storage, for authentication, security, preferences, and analytics.

Technology Purpose Duration
Analytics cookies Recognise your browser and understand how you use the Service Up to one year
Local storage Store information used for analytics Until cleared

We do not use advertising cookies or cookies to track your activity across unrelated websites.

You can block or delete cookies and local storage through your browser settings. Blocking necessary cookies may prevent some features of the Service from working. Your rights to withdraw consent or object to processing are described in Section 11.

13. Children

The Service is not for children. You must be at least 18 years old to use it. We do not knowingly collect personal data from children under 18. If you believe a child has provided personal data to us, contact us and we will take appropriate action.

14. Regional Disclosures

14.1 EEA, UK, and Switzerland. Where GDPR, UK GDPR, or Swiss data protection law applies, the legal bases in Section 4 apply, international transfers are handled as described in Section 8, and you have the rights described in Section 11.

14.2 United States. Residents of states with comprehensive privacy laws may have rights to know, access, correct, delete, or export personal data and to opt out of sale, sharing, or targeted advertising. We do not sell personal data or share it for cross-context behavioural advertising.

14.3 Other regions. You may have additional rights under local law. Nothing in this Policy limits rights that cannot lawfully be limited.

15. Changes to This Policy

We may update this Policy from time to time. If a change is material, we will give at least 30 days’ notice by email or in-product notice before it takes effect, unless the change is required by law or needed for security or abuse prevention.

16. Contact

Setten Company Limited
14 Tôn Thất Tùng, Thanh Khê, Đà Nẵng, Vietnam
Business registration number: 0402340870
Email: hi@settenhq.com
Security and privacy: security@settenhq.com
Website: settenhq.com