joyin.work
← Home

Privacy policy

Last updated: 29 September 2026

Draft: operator details marked [pending] will be filled in before publication.

This policy explains which personal data Joyin (joyin.work, the website and the iOS and Android apps) processes, why, on which legal basis, for how long, and what your rights are. It is written in two layers, as the Spanish supervisory authority (AEPD) recommends: the essentials first, the details below.

Basic information (first layer)

Controller[pending], [pending]. Contact: [email protected]. No data protection officer has been appointed.
PurposesProviding the video meeting service: host account, guest access, real-time video and audio, chat and files, recordings and AI notes if the host turns them on, invitation and reminder emails, service security.
Legal basisPerformance of a contract (use of the service), legitimate interest (security, abuse prevention), consent (push notifications; recording and transcription, decided by the host).
RecipientsProviders acting as our processors: hosting in Germany, DNS and website protection, and, only if the host turns on AI notes, AI service providers in the USA under standard contractual clauses. The full list is on the DPA page. We do not sell data and show no advertising.
RightsAccess, rectification, erasure, objection, restriction and portability. From the dashboard (“Your data”) you can download a copy or delete your account instantly; or email [email protected]. You can lodge a complaint with the AEPD (www.aepd.es).
SourceYou (account, guest name, meeting content) and the sign-in providers Google or Apple (name, email, photo) when you sign in with them.

1. Controller

Operator: [pending]

Legal form and representative: [pending]

Address: [pending]

Country: [pending]

Register and registration number: [pending]

VAT ID (USt-IdNr.): [pending]

Email: [pending]

We have not appointed a data protection officer because the processing does not require one. For any question about your data write to [email protected].

2. What we process, why and on which basis

ProcessingDataPurposeLegal basis (Art. 6 GDPR)
Host accountName, email, profile photo (if any), identifier at the sign-in provider (Google or Apple), language, sign-up date.Signing in, keeping rooms, history, recordings and settings.6(1)(b) (contract).
Guest in a meetingThe name you type when joining, device and browser, approximate country from IP, join and leave time.Showing you to the other participants, running the waiting room, the host's history.6(1)(b) (contract with the host) and 6(1)(f) (legitimate interest in running the service).
Real-time video and audioCamera, microphone and screen-share streams.Transmitting the meeting between participants.6(1)(b). Not stored, unless the host turns on recording.
Chat and filesMessages, files and links sent in the meeting, author and time.Showing them to participants during the meeting and in the host's history.6(1)(b).
RecordingVideo and audio of the main room.Letting the host and people with the link watch the meeting afterwards.Turned on by the host, who is responsible for informing participants; everyone sees the indicator. Basis: 6(1)(b) for the host; the host must have an appropriate basis towards participants.
AI transcription and notesAudio of each participant separately, transcript text, summary.Preparing the transcript and summary for the host and, if the host decides, for participants.Turned on by the host per meeting; everyone sees the “Transcribing” indicator. Audio is sent to AI service providers (see section 4) and deleted after processing.
EmailsEmail addresses of people the host invites, meeting time and link.Sending invitations, a calendar file, reminders and, where applicable, the summary.6(1)(b).
Push notifications (apps)Device token, platform, language.Notifying you when a scheduled meeting starts.6(1)(a) (consent when allowing notifications).
Contact form and requestsName, email or phone, message.Answering your request.6(1)(b) / 6(1)(f).
Rating after a callStars, room code.Measuring service quality. Not linked to your name.6(1)(f).
Technical logsIP address, device and browser type, date and time, errors.Security, abuse prevention, troubleshooting.6(1)(f).

3. Recipients and processors

We do not sell or share your data. To run the service we use providers that act as processors under contract (Art. 28 GDPR):

  • Hosting and media servers: data centre in Germany (Nuremberg). The media server (LiveKit) is operated by us on those servers; it is not a third party.
  • DNS and website protection: a content delivery network that routes website traffic (not the video).
  • AI service providers: speech recognition and summary writing, only when the host turns on transcription, and only with the audio and text of that meeting.
  • Email: our own mail server on the same infrastructure.
  • Sign-in with Google or Apple: when you sign in with them, Google or Apple pass us your name, email and photo. For that sign-in they act as independent controllers under their own policies.

Names, countries and safeguards for each provider: sub-processors list on the DPA page.

4. International transfers

Video, audio, recordings, chat and your account data are processed and stored in the European Union. There are two exceptions:

  • AI notes: if the host turns them on, the audio of that meeting and its transcript are sent to AI service providers based in the United States. The transfer relies on the European Commission's standard contractual clauses (Decision 2021/914) and, where the provider is certified, on the EU-US Data Privacy Framework. We do not use your meeting content to train AI models.
  • Website protection: the DNS and content delivery provider is based in the USA and processes website connection metadata (not the video) under the same safeguards.

You can request a copy of the safeguards by writing to [email protected].

5. Retention

DataPeriod
Host account, rooms, historyWhile the account is active. Deleted immediately when you delete the account.
Recordings3 days from recording, then deleted automatically. The host can delete earlier. Where an active paid plan exists, 30 days.
Audio for transcriptionDeleted as soon as processing finishes.
Transcript and summaryIn the host's account until the host deletes them or the account.
Meeting chat and filesWith the meeting history, until the host deletes the account.
Shared recording links7 days.
Invited guests' emailsWith the meeting they were invited to.
Technical logsUp to 90 days.
Push tokenUntil you uninstall the app or delete the account.

6. Your rights and how to exercise them

You have the right of access, rectification, erasure, objection, restriction of processing and portability. Self-service:

  • Download a copy of your data (profile, meetings, recordings and transcripts as metadata) as JSON: dashboard → Your data.
  • Delete your account and all associated data instantly: dashboard → Your data → Delete account, or in the app: Settings → Delete account.
  • Any other request: [email protected]. We answer within one month.

If you are a guest and appear in someone else's recording or transcript, the host is responsible for that recording; you can contact the host or write to us and we will help.

If you believe the processing does not comply with the law, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or with the supervisory authority of the controller's country ([pending]).

7. Minors

You must be at least 14 years old to create an account (Article 7 of the Spanish LOPDGDD); below that age the consent of a parent or guardian is required. We do not knowingly collect data of children under 14; if you believe this has happened, write to us and we will delete it.

8. Security

Video and audio are encrypted in transit (DTLS-SRTP) on every connection; the website and apps use TLS. Rooms are private and open by link only, with a waiting room at the host's discretion. Access to servers is limited to the technical staff who need it.

9. Recordings and transcripts: the host's obligations

Whoever turns on recording or transcription is responsible for informing participants and for having an appropriate legal basis, especially when health data or other special categories are involved. Joyin shows every participant the recording and transcription indicators. For professionals who need a data processing agreement: DPA.

10. Cookies

The website uses only technical cookies needed to work (host session, language, sign-in protection, room access). There are no analytics or advertising cookies, so we show no cookie banner. Details in the Cookie policy.

11. Changes

We publish any change here with its date. If a change materially affects how we process your data, we notify hosts by email.

12. Contact

Questions about this policy and your data: [email protected].

Terms · Privacy · Cookies · Legal notice · DPA
© 2026 Joyin · Built by OneDev