The EU-US Data Privacy Framework, explained for vendor reviews
Solomon Amos · 7 Sep 2026 · 10 min read
Regulatory evidence
Fireflies takes notes, manages tasks, and automates workflows across meetings, email, chat, CRM, and your
For each regulation, how many of the requirements it places on your vendors Fireflies.ai’s public evidence reaches. Open one for every item with its date and source.
Answers the vendor publishes to questions buyers ask, quoted with the link to where it says so.
Where data is hosted or processed
Where is data stored? Where are the servers located?
“At Fireflies.ai, we provide flexible and secure data management options tailored to your organization’s needs, ensuring the highest levels of security, compliance, and performance: Default Data Management By default, your data is securely stored and processed in our US-based cloud infrastructure, designed for reliability and adherence to industry standards: - Servers : Hosted on the Google Cloud Platform (GCP), kn...”
Regions named: USas of 21 Sep 2026Source
Encryption
What data is encrypted? What encryption is used?
“All user data, including meeting transcripts, audio recordings, calendar events, emails, and user settings, are encrypted end-to-end both at rest and in transit using industry-standard encryption. We take snapshots of User Metadata (calendar events, emails, user settings) every 4 hours for backup purposes but not for User Content - transcripts, audio recordings, and derivatives. Metadata snapshots are retained for...”
as of 21 Sep 2026Source
Use of customer data to train models
Does Fireflies use my data for training purposes? Does Fireflies share my data with third parties?
“No . We don’t use your data for training purposes. No , Fireflies does not share your data with third parties.We prioritize your privacy and have signed a Business Associate Agreement (BAA) with OpenAI and other third-party ASR (Automatic Speech Recognition) vendors. The BAA enforces: - Zero Data Retention Policy : Vendors cannot store or retain your data. - Restricted Acces s: Vendors are prohibited from accessin...”
as of 21 Sep 2026Source
Data retention and deletion
Does Fireflies access my data? Can I delete or remove my data?
“No . We follow the principle of least privilege, strictly granting access to sensitive data on a need-to-know basis, with monitoring and auditing. If greater access is needed, for example, during a support request, you must first grant permission. Yes. You can delete the data from the user dashboard or by contacting the support team. Once deleted, it is impossible to recover the meeting data.”
as of 21 Sep 2026Source
Data retention and deletion
What is the data retention policy? When the data is deleted from the platform is it still stored somewhere within Fireflies.ai?
“Once you delete a meeting record on the Fireflies Dashboard, it is wiped from our system and no longer accessible. If you need to do a bulk wipe you can just reach out to our account manager and we can delete the data. You are in control of what is retained.”
as of 21 Sep 2026Source
Solomon Amos · 7 Sep 2026 · 10 min read
CertReports Research · 18 Sep 2026 · 12 min read
This maps third-party obligations to the vendor evidence that may support them. It is not legal advice and never a statement that a vendor or its customers comply; confirm scope and sufficiency with your counsel or auditor. “No public evidence” means nothing public was found at the last check. Citations link to the official text.