This Privacy Policy explains how Setten Company Limited (“Setten”, “we”, “us”, “our”) collects, uses, shares, and protects personal data when you use settenhq.com and related applications (the “Service”).
This Policy covers website visitors, account holders, workspace users, people who interact with Setten booking or collaboration features, and people whose personal data appears in content processed through the Service.
1. Our Privacy Commitments
- We do not sell personal data.
- We do not use advertising cookies or cross-site tracking cookies.
- We do not train AI models on Customer Content.
- We do not use Customer Content for biometric identification unless that feature is expressly offered and enabled with appropriate legal notices and consents.
- We access Customer Content only with permission for support, or as needed to protect security, prevent abuse, comply with law, or enforce our Terms.
- We publish our material service providers on the Subprocessors page.
2. Roles: Controller and Processor
2.1 Customer Content. When you or your workspace users submit content to the Service, such as files, messages, tasks, calendar data, recordings, transcripts, prompts, and outputs (“Customer Content”), Setten generally acts as a processor or subprocessor. The customer controls what is submitted, who may access it, how long it is kept, and whether recordings are made.
2.2 Setten account and service data. Setten acts as a controller for data we use for our own business and service operations, such as account administration, billing records, security logs, support correspondence, usage data, and website operation.
2.3 DPA. Where we process Customer Content as a processor or subprocessor, the Data Processing Agreement applies.
3. Personal Data We Collect
3.1 Data you provide
| Category | Examples |
|---|---|
| Account data | Name, email address, password hash, profile details, language, time zone |
| Workspace data | Workspace name, members, roles, permissions, invitations, settings |
| Billing data | Plan, billing period, seat count, transaction status, billing country, partial payment details received from our merchant of record |
| Support data | Messages, attachments, and context you provide when contacting us |
| Customer Content | Content you or your users submit, create, upload, record, transcribe, process, or generate through the Service |
| Calendar and booking data | Calendar events, availability, attendees, booking page submissions, names, email addresses, and details entered by guests |
| AI interactions | Prompts, instructions, context submitted to AI Features, and resulting outputs |
3.2 Data collected automatically
| Category | Examples |
|---|---|
| Device and log data | IP address, browser, operating system, device identifiers, referring page, timestamps, request logs |
| Security data | Sign-in attempts, session activity, audit logs, administrative actions |
| Usage and event data | Pages and screens viewed, feature usage, clicks and other interactions, performance data, errors, plan usage counters |
| Cookies and local storage | Session, security, functional, preference, and analytics data described in Section 12 |
3.3 Data from third parties
We receive data from third-party services you connect to the Service and from our merchant of record. See our Subprocessors page for provider details.
3.4 Data about non-users
Customer Content may include personal data about people who do not have Setten accounts, such as meeting participants, calendar attendees, booking guests, message correspondents, and people mentioned in workspace content. We process that data on behalf of the relevant customer. If you have a request about that data, contact the customer first. If you cannot identify the customer, contact us and we will help route the request where appropriate.
3.5 Sensitive data
The Service does not require sensitive personal data. Customer Content may nevertheless include sensitive data, and recordings may include voice, image, biometric, health, employment, or other protected information. Customers are responsible for processing sensitive data lawfully.
4. How We Use Personal Data
| Purpose | Data used | Basis for processing |
|---|---|---|
| Provide and administer accounts | Account, authentication, workspace data | Contract; legitimate interests |
| Provide the Service | Customer Content, workspace, calendar, booking, AI interaction data | Contract; customer instructions under the DPA |
| Process recordings, transcripts, and AI outputs | Customer Content, recordings, transcripts, prompts | Contract; customer instructions under the DPA |
| Process subscriptions and billing | Account and billing data | Contract; legal obligation |
| Send service messages | Account, workspace, usage data | Contract; legitimate interests |
| Provide support | Account, support data, relevant Customer Content when permitted | Contract; legitimate interests |
| Secure, debug, and maintain the Service | Device, log, security, usage, event data | Legitimate interests; legal obligation |
| Understand and improve the Service | Account, workspace, device, usage and event data; aggregated or de-identified information | Consent where required; otherwise legitimate interests |
| Send marketing communications | Account data and preferences | Consent or legitimate interests where permitted |
| Comply with law and enforce rights | Relevant data | Legal obligation; legitimate interests |
You may object to processing based on legitimate interests where applicable law gives you that right.
5. Customer Content and AI
5.1 No AI training. We do not use Customer Content to train, retrain, fine-tune, or improve generative AI or machine learning models.
5.2 Provider restrictions. We require relevant AI and transcription providers to process Customer Content only to provide the requested service output and not to train their models on it.
5.3 Human access. Setten staff do not inspect Customer Content except: (a) at your request or with your permission for support; (b) to investigate, prevent, or respond to a security incident; (c) to investigate abuse or enforce our Terms; or (d) to comply with law. Where legally permitted and appropriate, we give notice of legal or abuse-related access requests.
5.4 Product improvement. We may use usage and event data, and aggregated or de-identified information, to maintain, debug, secure, and improve the Service. We do not use Customer Content for model training.
6. Recordings
Customers decide whether to use recording, transcription, and AI-assisted meeting features. They are responsible for providing notices and obtaining consent as required by Section 9 of the Terms of Service.
Setten does not provide participant notice on the customer’s behalf unless a specific product feature expressly says otherwise. If you were recorded through Setten, contact the person or organisation that hosted the recording. If you cannot identify them, contact us and we will help route the request where appropriate.
7. Sharing Personal Data
We share personal data only as described below:
- Workspace users and administrators. Content is shared within a workspace according to workspace permissions and administrator settings.
- Subprocessors and service providers. We share personal data with service providers that help us operate and improve the Service. See our Subprocessors page for details.
- Third-party integrations. If you connect an integration, data is shared as needed to provide that integration.
- Merchant of record. Checkout, payment, tax, refund, and chargeback data is processed by our merchant of record as an independent controller.
- Legal, safety, and enforcement. We may disclose data where required by law, to respond to lawful requests, to protect rights and safety, to investigate abuse or security incidents, or to enforce our Terms.
- Business transfers. Data may be transferred in connection with a merger, acquisition, financing, reorganisation, or sale of assets, subject to appropriate confidentiality and continuity protections.
- Professional advisers. We may share data with lawyers, auditors, accountants, insurers, and other advisers under confidentiality obligations.
We do not sell personal data or share it for cross-context behavioural advertising.
8. International Transfers
Setten is established in Vietnam and uses providers in the locations listed on the Subprocessors page. Personal data may be processed outside your country. Where transfer safeguards are required, we use appropriate mechanisms such as adequacy decisions, contractual commitments, transfer assessments, the DPA, and Standard Contractual Clauses where applicable.
9. Retention and Deletion
We keep personal data only as long as needed for the purposes described in this Policy, unless a longer period is required for legal, security, dispute, or enforcement reasons.
| Data | Retention |
|---|---|
| Customer Content | Until deleted by the customer or while the workspace exists |
| Deleted Customer Content | Removed from active systems on deletion; purged from encrypted backups within 90 days |
| Content after paid access ends | Retained for 30 days for export, then deleted from active systems and purged from encrypted backups within 90 days |
| Account data | For the life of the account, then deleted or anonymised within 30 days of account closure unless needed for legal, security, or billing reasons |
| Billing and transaction records | Up to 10 years where required for tax, accounting, and compliance |
| Security and audit logs | Up to 12 months |
| Consent confirmations and recording audit events | Up to 3 years, unless kept longer as Customer Content, required by law, or needed for dispute, security, or enforcement reasons |
| Support correspondence | Up to 3 years after the matter is closed |
| Marketing preferences | Until changed, plus suppression records as needed to honour opt-outs |
Aggregated or de-identified information that does not identify an individual may be kept indefinitely.
10. Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit, access controls, least-privilege staff access, password hashing, logging and monitoring, encrypted backups, incident response processes, and contractual security obligations for subprocessors.
No service can be guaranteed completely secure. You are responsible for protecting your devices, credentials, integrations, and workspace permissions.
Report security concerns to security@settenhq.com.
11. Your Rights
Depending on your location and the data involved, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal data; withdraw consent; opt out of marketing; and complain to a supervisory authority.
You can exercise many rights directly in the Service. Otherwise, contact hi@settenhq.com or security@settenhq.com. We may need to verify your identity.
If your data is in a customer’s workspace and we process it as a processor or subprocessor, we will normally refer your request to that customer or the relevant controller and assist them as required.
12. Cookies and Similar Technologies
We and our service providers use cookies and similar technologies, including local storage, for authentication, security, preferences, and analytics.
| Technology | Purpose | Duration |
|---|---|---|
| Analytics cookies | Recognise your browser and understand how you use the Service | Up to one year |
| Local storage | Store information used for analytics | Until cleared |
We do not use advertising cookies or cookies to track your activity across unrelated websites.
You can block or delete cookies and local storage through your browser settings. Blocking necessary cookies may prevent some features of the Service from working. Your rights to withdraw consent or object to processing are described in Section 11.
13. Children
The Service is not for children. You must be at least 18 years old to use it. We do not knowingly collect personal data from children under 18. If you believe a child has provided personal data to us, contact us and we will take appropriate action.
14. Regional Disclosures
14.1 EEA, UK, and Switzerland. Where GDPR, UK GDPR, or Swiss data protection law applies, the legal bases in Section 4 apply, international transfers are handled as described in Section 8, and you have the rights described in Section 11.
14.2 United States. Residents of states with comprehensive privacy laws may have rights to know, access, correct, delete, or export personal data and to opt out of sale, sharing, or targeted advertising. We do not sell personal data or share it for cross-context behavioural advertising.
14.3 Other regions. You may have additional rights under local law. Nothing in this Policy limits rights that cannot lawfully be limited.
15. Changes to This Policy
We may update this Policy from time to time. If a change is material, we will give at least 30 days’ notice by email or in-product notice before it takes effect, unless the change is required by law or needed for security or abuse prevention.
16. Contact
Setten Company Limited
14 Tôn Thất Tùng, Thanh Khê, Đà Nẵng, Vietnam
Business registration number: 0402340870
Email: hi@settenhq.com
Security and privacy: security@settenhq.com
Website: settenhq.com