How Inwista Handles Your Data: GDPR, EU Servers and Sensitive Recordings
Uploading audio or video to an AI service is an unusual act of trust. A transcription tool doesn't see your polished output — it hears the raw material: the unguarded interview, the internal meeting, the HR conversation, the research subject who was promised confidentiality.
So the questions people ask before uploading are exactly the right ones: Where are the files stored? Who can access them? Is my data used to train AI models?
This article answers all three plainly, explains what GDPR means in practice when you use Inwista, and — because honesty is the policy here — is equally plain about where your responsibility sits and what no AI service can take off your hands.
The three questions, answered
Where are the files stored?
Everything uploaded to Inwista is stored on secure servers within the EU/EEA, on established, professional cloud infrastructure with high standards for security, access control and operations. That geography is not a detail: it means the processing sits squarely under European data-protection law, including GDPR — with none of the third-country transfer questions that follow tools processing your audio elsewhere.
One layer deeper, and worth knowing: the speech model Inwista uses runs on our own closed servers in the EU — your recordings aren't round-tripped through a third-party AI provider's API to be transcribed.
Who can access the content?
Only you — and any people you yourself grant access through team and project functions. Stored content is protected with AES-256 encryption, on every plan.
Is my data used to train AI models?
The governing principle is purpose limitation: your data is used only for the purpose you uploaded it for — transcribing it and running the features you choose on it. Your recordings are your material, not our training set.
You own it. You delete it.
Deletion is in your hands, not ours to gatekeep: you can delete projects, files and texts yourself, at any time. When you delete content, it's removed from our systems in line with established secure-deletion routines. No requests, no tickets, no retention you didn't choose.
What GDPR means in practice here
Regulation-speak translated to the three things that actually touch your workflow:
→ Purpose limitation. Your data is used only for the purpose you uploaded it for. Full stop.
→ Data minimisation and control. You choose what to upload, you have full visibility into your own data, and you can delete it whenever you want.
→ Accountability and documentation. In GDPR's role-division, you are the data controller and Inwista operates as the data processor — following the applicable requirements for security, routines and agreements that role carries.
That controller/processor split matters beyond vocabulary: it means decisions about what gets recorded, whether participants were informed, and how long transcripts should live are yours — which is precisely where the next two sections point.
The Data Processing Agreement
For organisations that need formal GDPR documentation, Inwista offers a Data Processing Agreement (DPA) as part of the Enterprise plan. The DPA sets out roles, responsibilities and the processing basis between your organisation and Randi Labs AS — and it exists for exactly the audiences that ask for it: the public sector, larger organisations, and anyone with internal privacy and information-security requirements to satisfy.
For everyone else: the same fundamental principles — data ownership, secure storage, purpose limitation — apply on every plan. The DPA is the formal supplement for organisations whose compliance frameworks require the paperwork, not a higher tier of actual protection.
Sensitive recordings — the honest section
Inwista is used daily on professional, internal and partly sensitive material, and it's built for that. But here's the sentence this article refuses to soften: no automated AI service removes the need for professional judgment.
You are responsible for the content you upload, and for assessing whether the service suits your specific purpose. Inwista is a professional tool — it does not replace legal, organisational or professional responsibility. In practice, for organisations, that judgment looks like a short checklist:
- Put the DPA in place if your compliance framework calls for one (Enterprise).
- Decide retention before you need it — who deletes transcripts, and when, should be a routine, not a discovery.
- Use access deliberately — grant team and project access to the people who need it, and only them.
- Handle consent where it lives: with you. Informing participants that a meeting or interview is recorded and transcribed is the recorder's obligation under GDPR — no tool can do it for you, and no tool should pretend to.
- Escalate the special cases. Working with especially sensitive material, or carrying specific setup requirements? Contact us first and let's clarify the right configuration — that conversation is free and the alternative isn't.
(For the workflow side of sensitive multi-voice recordings — HR cases, legal documentation, research interviews — see transcribing with speaker labels.)
Why this is a deliberate stance
We don't believe trust is built through vague formulations or marketing gloss. It's built through clear answers to real questions — which is why this article is open about limitations and about the user's role, not only about our safeguards.
It's also why the security layer isn't a paywall: EU/EEA processing and AES-256 encrypted storage apply on every plan, including the free one. A tool many people use precisely to meet accessibility law shouldn't create a data-protection problem while solving a compliance one — on any tier.
Questions about privacy, data security or using Inwista in your organisation are always welcome — that door is open by design.
Inwista's free plan lets you run the whole workflow on your own material — upload, transcribe, structure, edit and export. Current limits and plan details are on the pricing page.
Try Inwista with your own material →
Frequently asked questions
Where is my data stored? On secure servers within the EU/EEA, on established professional cloud infrastructure — placing all processing under European data-protection law, including GDPR. The Norwegian NB-Whisper model additionally runs on Inwista's own closed EU servers.
Who can see my files and transcripts? Only you, plus any collaborators you explicitly grant access through team and project functions. Stored content is protected with AES-256 encryption on every plan.
Is my data used to train AI models? Purpose limitation governs: your data is used solely for the purpose you uploaded it for — your transcription and the features you run. It isn't repurposed as training material.
Can I delete my data? Yes, at any time, yourself — projects, files and texts. Deleted content is removed from our systems under established secure-deletion routines.
How do we get a Data Processing Agreement? The DPA is part of the Enterprise plan — contact us and we'll put the formal documentation in place. It's the standard route for public-sector bodies and organisations with internal privacy requirements.
Is the free plan less secure than the paid ones? No — EU/EEA processing, AES-256 encrypted storage and the same data-ownership principles apply on every plan. Paid tiers add capacity and features, not basic protection.
Can we upload recordings containing personal or sensitive information? The service is built for professional material, and many users work with exactly that. The responsibility for assessing suitability, informing participants and setting retention sits with you as controller — and for especially sensitive material, contact us first to clarify the right setup.
This article describes Inwista's data-handling practices in general terms and is not legal advice; for your organisation's specific obligations as data controller, consult your privacy officer or counsel.