AI and software solutions
AI

On-premises AI and data protection: where should meeting recordings be processed?

Meeting recordings are personal data. Cloud versus on-premises AI, explained with the Transify example and a practical checklist.

Muhammed Göktuğ Temiz · 8 min read
Contents (9)
  1. Why is a meeting recording sensitive?
  2. Where does data travel in a cloud service?
  3. When is the cloud not enough?
  4. What does an on-premises install change?
  5. The two models compared
  6. The price of running it yourself
  7. A checklist, whichever model you choose
  8. How to decide
  9. Frequently asked questions

Every company that wants to summarise meetings with AI eventually faces the same question: where do these recordings go? A sales call mentions a client by name, a management meeting covers pricing strategy, an HR conversation touches an employee's personal circumstances. That is why we offer our own product, Transify AI, both as a cloud service and as an on-premises install. This article explains the difference between the two models and what to look at when deciding.

#Why is a meeting recording sensitive?

Under Türkiye's Personal Data Protection Law No. 6698 (KVKK), as under the GDPR, any information that makes a person identified or identifiable is personal data. A meeting recording holds many kinds at once:

  • Participants' voices, names and often their image
  • What is said about people's opinions, performance or personal circumstances
  • Third parties mentioned in the meeting: clients, candidates, suppliers
  • Information that isn't personal data but still needs protecting: prices, contract terms, product plans

Once a recording is processed with AI, the transcript and the summary are added to that list; what needs protecting is not just the audio file but every output produced from it.

#Where does data travel in a cloud service?

When you use a cloud-based AI service, your data doesn't stay only on that service's server; it also goes to the model providers the service relies on, its sub-processors. We think this should be stated plainly. The sub-processors listed in the privacy policy of Transify's cloud version are:

Sub-processorUsed for
OpenAISpeech recognition (Whisper) and translation; data is processed temporarily on the provider's servers
MiniMaxAI analysis: summary, decisions, action items
Supabase / PostgreSQLDatabase hosting
ResendTransactional email

The safeguards of the cloud version are written in the policy too: all communication is encrypted with HTTPS/TLS, passwords are stored as bcrypt hashes, access logs are kept and media files are deleted automatically after processing. Retention periods: media files 30 days by default (24 hours can be chosen on the Pro and Team plans), transcript text 30 days.

For many teams this is enough: general team meetings, training recordings, interviews and videos that will be published anyway. The cases where it isn't enough are just as clear.

#When is the cloud not enough?

  • Cross-border transfer: If the sub-processors' servers are abroad, this is a transfer of personal data abroad under Article 9 of the KVKK and is subject to separate conditions.
  • Sector rules: In areas such as finance, healthcare and the public sector there may be additional regulations and contract terms limiting data leaving the organisation.
  • Client contracts: A confidentiality agreement with your client may prohibit sharing call recordings with third parties.
  • Trade secrets: Even where it is legally permitted, you may not want the content of certain meetings to leave the company.

#What does an on-premises install change?

With an on-premises install the service runs on your own servers. Transify's enterprise installation has four steps:

  1. Server preparation: A Linux or Windows virtual machine, installed with Docker or directly on the server. At least 8 CPU cores and 32 GB of RAM are recommended; if the models are to run in-house, an analysis server with a GPU is needed.
  2. Database: PostgreSQL set-up, a backup routine and integration with your company's single sign-on (SSO).
  3. AI pipeline: Speech recognition, translation and analysis run inside your company network; using external APIs is optional.
  4. Admin panel: Usage and support are tracked from one panel; the admin dashboard is included.

The result: data stays in Türkiye or the region you choose, on your own infrastructure. You decide who can access which recording through role-based permissions and follow it in the audit log.

#The two models compared

CloudOn-premises
Where is data processed?On the servers of the service and its sub-processorsOn your own servers, in your own network
Getting startedAn account is enough; nothing to installNeeds a server, installation and training
HardwareNoneServer (and a GPU if models run in-house) on your side
Maintenance and updatesHandled by the providerYours, or ours under a service agreement (SLA)
Best forGeneral meetings, small and mid-sized teams, a quick startSensitive data, sector rules, client confidentiality agreements

#The price of running it yourself

An on-premises install is not automatically “more secure”; it moves the responsibility to your side. Before deciding, take these into account:

  • Hardware: Running models on your own servers needs GPUs; the server has to be bought or rented and its capacity planned for your level of use.
  • Operations: Updates, backups, monitoring and access management become your job, or that of the team you contract. An internal server with no backups and no patches is riskier than a well-run cloud service.
  • Model currency: In the cloud, models are refreshed by the provider; on-premises, moving to a new version is a planned piece of work.

If you don't have a team to take on the server side, we can run it with you through our maintenance, hosting and server management service. For the general pros and cons of running your own server, see shared hosting vs VPS.

#A checklist, whichever model you choose

  1. Inform participants: Say at the start that the meeting is being recorded and will be processed with AI, and cover this processing in your privacy notice.
  2. Know the sub-processors: Ask in writing which companies and which countries the service sends data to.
  3. Set retention periods: Separately for the audio file, the transcript and the summary. “Indefinitely” is not an answer.
  4. Limit access: Not everyone should reach every recording; look for role-based permissions and access logs.
  5. Plan for deletion requests: When a participant asks for their data to be erased (KVKK Article 11), you must be able to find and delete the recording, transcript and summary.
  6. Ask about model training: Make it clear in the contract whether your data is used to train models.
  7. Have an exit plan: Find out up front how you get your data back and how it is deleted when you leave the service.

#How to decide

Three questions usually settle it: Whose data is in these recordings, and how sensitive is it? Is there a rule or contract limiting data leaving the organisation or the country? Do we have the capacity to run a server securely? If the answer to either of the first two is a firm “yes”, on-premises is a serious option; if not, starting with the cloud service and moving when the need arises is more reasonable.

To install Transify in your company, or to build a similar system on your own servers that works with your documents, conversations and customer data, see our AI solutions. Another example with a lot of personal data: online booking systems for clinics. For the technical side of the product: the asynchronous job pipeline.

Frequently asked questions

What is an on-premises AI installation?

Running the AI models, the database and the application on the company's own servers and network rather than in a cloud service; the data being processed stays on the company's infrastructure.

Does a meeting recording count as personal data?

Yes. Participants' voices, names and opinions, and information about people mentioned in the meeting, are personal data; so are the transcript and summary produced from the recording.

What does an on-premises Transify install require?

A Linux or Windows server (installed with Docker or directly); at least 8 CPU cores and 32 GB of RAM are recommended and a PostgreSQL database is set up; if the models are to run in-house, an analysis server with a GPU is needed.

How long are recordings kept in the cloud version?

According to Transify's privacy policy, media files are deleted automatically after 30 days by default (24 hours can be chosen on the Pro and Team plans), and transcript text is kept for 30 days.

  • on-premises ai
  • self-hosted ai
  • kvkk ai compliance
  • meeting recording privacy
  • data residency turkey
  • sub-processors
AuthorMuhammed Göktuğ Temiz

Muhammed Göktuğ Temiz is the founder of Averis Soft. He builds corporate websites, booking platforms, admin panels, e-commerce and mobile apps, running the work end to end from analysis and design through development, launch and server management. He works with Next.js, React, Node.js, Flutter and Docker; the Connect2Taxi booking platform for the Dutch market, İstanbul Sivasspor's club website with its admin panel and an appointment system for clinics are among his projects.

About usLinkedInGitHub
Blog

AI and more articles

All articles

Transcribing meeting recordings: how we built Transify's asynchronous job pipeline

A 500 MB meeting recording can't be processed in one HTTP request. How we designed queuing, job status, webhooks and signature checks in Transify.

Extracting summaries, decisions and action items from meetings: how we designed the AI analysis

A transcript alone doesn't get work done. How Transify extracts the summary, decisions, action items and owners as structured data.

Chatbots for small businesses: where they help and where they don't

Where AI assistants genuinely help small and medium-sized businesses, their limits, choosing a channel and a step-by-step set-up plan.
Contact

Let's bring your next project to life.

Tell us briefly about your project or book an online call; we'll get back to you within 24 hours.

WhatsApp