In short
This site sets no cookie and uses no audience measurement tool. It has a
single form, on the contact page, and
joining a meeting needs no account.
-
No account is needed to join a meeting. An account exists only to
subscribe and administer an organisation, on the portal.
-
Audio and video streams are relayed between participants, not recorded.
The server neither decodes nor re-encodes them.
-
A room's data is encrypted at rest and erased automatically once the
last participant has left.
-
No personal data leaves the European Union in the course of our
processing.
These claims can be checked in the code published under a free licence,
not only in this document. That is what open source is for.
Data controller
GEEZOT, a simplified joint-stock company under French law, 28 B rue des 3 Moulins, 77000 Melun, France, registered under number 801 928 888.
No data protection officer has been appointed: our activity does not fall
within the cases of mandatory appointment set out in article 37 of the
General Data Protection Regulation. Requests are therefore handled
directly at contact@vuisio.com, an address monitored by the team.
We act as data controller only for the processing operations described
below. When an organisation uses Vuisio for its own meetings, it decides
the purposes: it is then the controller, and we act as a processor, within
the limits of a written contract.
What we process
Eight processing operations, not one more. Each
with its purpose, its lawful basis and its retention period.
| Purpose | Data | Lawful basis | Retention |
| Serving the pages of the site and detecting abuse | IP address, date and time, page requested, response code, user agent | Legitimate interest A web server cannot answer without knowing the address asking it, nor defend itself against abuse without keeping a trace. | 14 days, through daily log rotation |
| Answering requests sent through the contact form | Name, email address, organisation, profile and expected number of hosts where given, content of the message, IP address | Consent You tick a box explicitly before sending, and you choose what you write. Nothing is pre-filled or inferred. | 3 years from the last exchange, then deletion from the server log and from the inbox |
| Answering messages addressed to us | Sending address, content of the message, any attachments | Legitimate interest Answering someone who writes to us is the normal continuation of what they started. | 3 years from the last exchange, then deletion from the mailbox and from the trash |
| Running a meeting on the video conferencing service | First name or nickname entered, technical session identifier, IP address, audio and video streams relayed without being kept | Legitimate interest Joining a meeting needs no account: the only data processed is the data without which the meeting cannot take place. | Automatic deletion once the last participant leaves. No recording is kept without an explicit action by a host. |
| Creating and managing an account and its organisation | Name, email address, hashed password, organisation, role, creation date, sign-in dates | Performance of a contract Without an account there is no subscription, no role and no organisation: this is the very data that makes the contract performable. | Erased when the account is closed. Only invoices already issued remain, under the line below |
| Managing the subscription, payment and invoicing | Company name, billing address, VAT number, plan, number of hosts, invoice history. Card details never reach us: they are entered at the payment provider | Legal obligation Performance of the contract justifies the subscription, but keeping the accounting records is a legal obligation, which prevails and imposes a far longer period than anything else here. | 10 years from the close of the financial year, under article L123-22 of the French commercial code |
| Signing you in through the identity provider you choose | Email address and IP address sent to the provider at sign-in, and the technical identifier it returns | Performance of a contract This processing only exists if you choose that way of signing in. Signing in with a password remains available and calls nobody. | The link with the provider is erased as soon as you remove that sign-in method, and at the latest when the account is closed |
| Sending you commercial messages, if you have agreed to them | Email address, date and scope of the consent, date of its withdrawal where applicable | Consent The box is separate from accepting the terms and is never pre-ticked: agreeing to the contract does not amount to agreeing to receive messages. | 3 years from the last contact, the period the French data protection authority applies to outreach. The date of the consent is kept for as long as it has effect, so that it can be proven |
The retention period of the logs is not an intention: it is what rotation
actually applies on the server, fourteen daily rotations before deletion.
That is well below the six months the French data protection authority
treats as an upper bound for security logs.
What there is not
The list of what does not exist is as informative as the list of what
does, and faster to check.
- No audience measurement tool, neither in-house nor third-party.
- No tracking pixel, no advertising network, no data broker.
- No profiling, no automated decision-making.
-
No form other than the contact page, and that one asks only for what
serves to answer you.
-
No third-party anti-bot service: the form check is a proof of work
computed by your browser, from a challenge issued by our own server.
-
No collection of data relating to minors as far as we know; the service
is not intended for under-fifteens acting on their own.
Commercial outreach
We identify organisations likely to be interested in Vuisio from public
directories of establishments, and we contact their generic professional
addresses. This processing rests on legitimate interest, within the
framework the French data protection authority sets for
business-to-business outreach. Any objection sent to contact@vuisio.com is carried out without condition and without delay.
The case of the voice
Vuisio offers real-time voice anonymisation. It computes no voiceprint and
therefore does not constitute processing of biometric data within the
meaning of article 9 of the Regulation.
The distinction matters, because it decides which regime applies. Biometric
data, under the Regulation, results from specific technical processing
that allows a person to be uniquely identified. Extracting a voice
template to recognise a speaker would be one. That is not what Vuisio
does.
Our anonymisation module applies an acoustic transformation to the audio
stream, packet by packet, as the server relays it. It distorts the timbre
according to a setting chosen by the user. It compares nothing, models
nothing and identifies nobody. Nothing is extracted, nothing is stored,
and the transformation does not outlive the packet it handles.
Two practical consequences worth stating rather than assuming:
-
Anonymising a meeting and anonymising a recording are two separate
operations. A recording can be anonymised while the meeting is heard
normally.
-
If the transformation cannot be applied, the voice concerned is
excluded from the recording rather than written in the
clear, and the hosts are told. It is then for them to authorise the
non-anonymised recording explicitly, or to stop.
The behaviour described here is that of the anonymizer
module, whose code is published under a free licence.
Who receives this data
Eight providers, three of them outside the European Economic Area. None of them is allowed to use your data on its own account.
The American providers are buttons, not requirements
Google, Microsoft and Meta appear in this table only because you
can choose to sign in with them. It is a shortcut
on offer, never a condition of access.
If you sign in with a password, they are contacted at no point and
receive nothing: not your address, not your IP address, not even
the fact that you opened the sign-in page. Their logo is a file
served from our domain, not a script loaded from theirs.
No function of the service requires them. Creating an account,
subscribing, running a meeting, administering an organisation: all
of it works without them. They come into play on a click, and only
on yours.
| Provider | Role | Country | Transfer safeguard |
| Scaleway SAS | Hosting of the site and of the service's servers | France | Not applicable, inside the EEA |
| Gandi SAS Verifiable: the domain's MX records point to spool.mail.gandi.net. | Receiving email sent to @vuisio.com addresses | France | Not applicable, inside the EEA |
| IONOS SE | Mailboxes those messages are forwarded to | Germany | Not applicable, inside the EEA |
| Google LLC Optional. This provider is only contacted if you click its button yourself: it then receives your email address and your IP address, and nothing else. If you do not choose it, it is never called and receives nothing. | Optional. Identity provider, only if you choose that way of signing in | United States | Adequacy decision of 10 July 2023, active participation in the Data Privacy Framework checked on 10 August 2026 |
| Microsoft Corporation Optional. This provider is only contacted if you click its button yourself: it then receives your email address and your IP address, and nothing else. If you do not choose it, it is never called and receives nothing. | Optional. Identity provider, only if you choose that way of signing in | United States | Adequacy decision of 10 July 2023, active participation in the Data Privacy Framework checked on 10 August 2026 |
| Meta Platforms, Inc. Optional. This provider is only contacted if you click its button yourself: it then receives your email address and your IP address, and nothing else. If you do not choose it, it is never called and receives nothing. | Optional. Identity provider, only if you choose that way of signing in | United States | Adequacy decision of 10 July 2023. On the register on 10 August 2026 with the status "Active, re-certification under review": the programme removes organisations that withdraw or fail to re-certify, and this one is still listed |
| Mollie B.V. Card details are entered at Mollie and never pass through our servers. | Collecting subscription payments and handling payment methods | Netherlands | Not applicable, inside the EEA |
| SUPER PDP | Accredited platform for issuing and receiving electronic invoices | France | Not applicable, inside the EEA |
Outside this list, no data is disclosed to any third party, save for a
request from a French judicial authority that we would be legally bound to
answer.
Transfers outside the European Union
One case of transfer exists, it is not mandatory, and only you trigger it: signing in through an American identity provider. Simply not choosing it is enough for no data to leave the Union.
There is no implicit transfer either: your browser contacts no domain
other than ours while you read this site. No remote typeface, no
third-party video player, no content delivery network.
Signing in with a password remains available and does everything:
no third-party provider is needed to create an account, subscribe
or run a meeting. The third-party sign-in buttons are a
convenience, never a requirement.
Until you click, nothing leaves. Those providers' logos are files
served from our own domain, not scripts loaded from theirs:
displaying the sign-in page tells them nothing, not even that you
visited.
How we checked these transfers
A transfer outside the European Economic Area is only lawful if it
rests on a ground from chapter V of the Regulation. We rely here on
the adequacy decision of 10 July 2023, which only covers companies
actually listed in the Data Privacy Framework register. We
therefore checked each of them, one by one, rather than assuming
it.
The check takes a minute and can be reproduced, and we would rather
you redid it than took our word for it.
-
Open the official register of the programme, kept by the United
States Department of Commerce: dataprivacyframework.gov/list.
- Type the company name into the search field.
-
Read the EU-U.S. Data Privacy Framework line and
its status. Only "Active" covers a transfer.
Checked on 10 August 2026: Google LLC and Microsoft Corporation
come back "Active". Meta Platforms comes back "Active,
re-certification under review", a status that still covers the
transfer but which we will check again before every update of this
page.
What this check changed
Apple was in our initial plan for identity providers. The search
finds it neither among active nor among inactive participants,
across four variants of its name. With no applicable adequacy,
its transfer would have had to rest on standard contractual
clauses and a transfer impact assessment. We dropped it rather
than add it, which is why this page does not mention it anywhere
else.
Security
The measures described here are not intentions: they are in the code and
in the server configuration.
-
All traffic is encrypted in transit, with a permanent redirect to HTTPS
and an HSTS policy.
-
A room's data stored on the server is encrypted at rest with AES-256-GCM.
-
A room's data expires automatically once the last participant leaves,
with no intervention.
-
The application allows no resource to be loaded from outside its own
domain, which makes third-party script injection ineffective.
-
The server does not decode video: it relays packets. The attack surface
tied to transcoding does not exist.
No certification and no external security audit has been obtained to date.
We therefore do not claim any. The day that changes, it will be written
here, dated, with the report.
Your rights
You have the rights of access, rectification, erasure, restriction,
objection and portability set out in articles 15 to 22 of the Regulation.
Send your request to contact@vuisio.com. We answer within one month, extendable by two months if the request is
complex, in which case we tell you before the deadline rather than after.
One honest caveat on exercising those rights: because the service works
without an account, we usually have no way of linking a piece of data to a
person. A request for access covering a past meeting will therefore run
into the fact that nothing is left to disclose. That is a direct
consequence of how the product is designed, not an evasion.
If our answer does not satisfy you, you may lodge a complaint with the
French data protection authority, Commission nationale de l'informatique
et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris CEDEX 07,
France, or online at cnil.fr. If you live in another member state, you may also complain to your own
national authority.
If you host Vuisio yourself
This page does not concern you, except for the part about the vuisio.com
site.
When you install Vuisio on your own infrastructure, no data passes through
our servers and we have access to nothing. The software does not phone
home: there is no telemetry, no usage reporting and no online licence
check.
You are then the sole data controller. The settings that concern you, in
particular the retention period and the encryption key for room data, are
described in the operations documentation.
Changes to this document
This page describes a state, at a date, the one shown at the top.
It will change when the product changes. A change that widened the
collection, added a recipient or lengthened a retention period will be
announced before it takes effect, not noticed afterwards. A change that
narrows the collection will simply be applied.
We would rather have a short, exact document than a long, unverifiable
one. If you find a claim here that the code contradicts, write to us: it
is a mistake to correct, not a debate to open.