Privacy Statement
Privacy Statement
Last updated: August 16, 2026
01
Who we are and scope
StandIn is operated by Komaa DigiTech (“we”, “us”). This statement explains how we handle personal data in connection with the StandIn website, account, and media-bridge service. It does not cover the content of your Teams meetings, which stays in your own Microsoft tenant (see section 5).
02
Our role: controller and processor
For your account, billing, and usage data we act as the data controller. For real-time meeting media we act only as a transient conduit and do not store it, you (or your organization) remain the controller of your meeting content and your bot identity. For chat messages relayed through the StandIn bot in Teams we act as your processor and hold only a short-lived delivery record (see section 5). Our Data Processing Agreement at standin.komaa.com/dpa applies to business customers.
03
What we collect
Account data from your sign-in provider (name, email address, and profile image via Microsoft, Google, or GitHub); subscription and billing metadata (processed by Paddle as Merchant of Record, we do not receive full card details); the bot credentials you provide (transmitted over TLS and stored server-side in our control plane, never exposed in the browser and never returned to it); operational logs, diagnostics, and usage metrics; and any information you send us for support.
04
Google API Services
StandIn offers sign-in with Google. When you choose Google sign-in, we access your basic Google account profile (name, email address, and profile image) solely to authenticate you and to create and operate your StandIn account. StandIn’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not transfer it except as needed to provide or secure the service or as required by law, and we do not use it to train generalized AI or machine-learning models.
05
What we do NOT collect or store
We do not store meeting content, no transcripts, recordings, audio, video, or memory. The media bridge only transits real-time media to the agent you operate and persists none of it. Your bot identity and meeting content remain in your own Microsoft tenant. We do not create voiceprints or other biometric identifiers, and we do not retain the voice, image, or personal data of meeting participants. The one exception is text chat: when you use the StandIn bot in Teams, chat messages sent to the bot (and the replies your agent sends back through it) are held in the StandIn database as a transient delivery record for about 24 hours after delivery to your connected agent, then deleted by an hourly sweep; inline attachments expire after 15 minutes and are purged within the following hour. This delivery record exists only so a message is not lost if your agent is briefly unreachable. We also keep the conversation routing reference (conversation identifier and Teams service address, no message content) for as long as the bot is installed in that conversation, so replies can be delivered; it is removed when the bot is removed from the conversation and at the latest 180 days after the last activity. Audio, video, transcripts, and recordings are never stored, on any lane.
06
How we use data, and legal bases
We use personal data to provide, operate, secure, bill, and support the service, to communicate with you, and to comply with law. Where the GDPR or similar laws apply, our legal bases are: performance of our contract with you; our legitimate interests in operating and securing the service; your consent where required; and compliance with legal obligations.
07
Sharing and sub-processors
We share data with service providers that help us run StandIn. Our current sub-processors are: Microsoft (Azure hosting, operational logging, Microsoft 365 email, and Microsoft Teams and Graph); Paddle (payments, as Merchant of Record); Google (product analytics, and sign-in if you choose Google); GitHub (sign-in only, if you choose GitHub); and Cloudflare (web analytics). You separately choose and control your own AI agent and model providers. We do not sell personal data. We will post material changes to this list on this page.
08
Where your data is processed
Our portal and control plane run in Microsoft Azure in the United States (West US 2), and account and billing metadata is stored in that same region; Paddle processes payment data in its own locations. Real-time meeting media transits our infrastructure in that region only in real time and is not stored. Where personal data is transferred across borders, we rely on appropriate safeguards (such as Standard Contractual Clauses) where required.
09
Data residency
StandIn currently runs in a single region (West US 2), and we do not offer self-serve region selection today. Dedicated or in-region deployment is available as part of an Enterprise engagement, scoped with you. Account and billing data locations are described in section 8.
10
Retention
We retain personal data only as long as necessary for the purposes described in this statement. Account data: for the life of your account, then deleted or anonymized within 90 days of account closure. Billing and invoice records that we hold: for the period required by applicable tax and accounting law, which in the United Arab Emirates is up to seven (7) years under corporate tax law (five (5) years for VAT records). Invoices and payment records held by Paddle as Merchant of Record are retained by Paddle under its own privacy policy for the applicable legal limitation periods. Operational logs and diagnostics: up to 90 days, then deleted or anonymized. Support correspondence: up to 24 months after the request is closed. Prospect and marketing contact data, where applicable: up to 24 months from your last interaction, or until you opt out. Chat messages relayed through the StandIn bot in Teams: held as a transient delivery record for up to 24 hours after delivery to your connected agent, then deleted; inline attachments up to 15 minutes. Real-time meeting media is never stored, and no audio, video, transcripts, or recordings are ever retained (see the “What we do NOT collect or store” section).
11
Security
We protect data with encryption in transit, secrets transmitted over TLS and stored server-side with least-privilege access, managed-identity and least-privilege access, and network controls. No method of transmission or storage is completely secure.
12
Your rights
Subject to applicable law, you may request access to, correction, deletion, export, or restriction of your personal data, and may object to certain processing. Contact supportkomaa.com; we aim to respond within 30 days. You may also have the right to complain to your local data protection authority.
13
Cookies
We use strictly necessary cookies for authentication and session management, and first-party analytics cookies (Google Analytics) to understand how the product is used. Our web analytics from Cloudflare are cookieless. We do not use advertising or cross-site tracking cookies.
14
Children
StandIn is a business service, is not directed to children, and we do not knowingly collect personal data from children.
15
Changes
We will post any changes to this statement on this page with a new “last updated” date and, for material changes, take reasonable steps to notify you.
16
Contact
Privacy questions and requests: supportkomaa.com. Operated by Komaa DigiTech.