# Noota

## Kurzbeschreibung
**"Boost your team with AI Agents" / "Automatically record, transcribe, and summarize meetings with AI notetaker…"**


**Noota** is a European SaaS platform for Conversation Intelligence, AI Meeting Notes, transcription, meeting summaries, email agents, telephony, knowledge search, and recruiting/sales workflows. The tool records meetings or calls, transcribes conversations, creates structured summaries, follow-up emails, reports, and makes meeting, call, and email knowledge searchable.

## Claim
Boost your team with AI Agents” / “Automatically record, transcribe, and summarize meetings with AI notetaker…

## Geeignet für
- API Integration
- Audio / Voice
- Automation / Workflows
- Data Extraction / Document Analysis
- Email / Communication
- Productivity & Planning
- Project Management
- Sales / Sales
- Knowledge Management / Internal Search

## Kernfunktionen
- Meeting Minutes
- Transcription
- Translation
- Summarization

## Preismodell
- **free:** Free entry for individuals; includes unlimited recording & transcription, monthly AI notes minutes, limited storage, email automation, Chrome extension, as well as iOS/Android app.
- **subscription:** **Pro **For individuals and small teams; includes everything in Free plus more AI Notes minutes, Team Workspace up to a limited team size, unlimited integrations, and AI Agents.


**Business** For fast-growing companies; includes everything in Pro plus unlimited recording, paid unlimited seats, unlimited AI features, Custom Templates, Zapier & API, Analytics, and AI Infrastructure.
- **other:** **Enterprise **Custom offer for larger teams; includes everything from Business plus unlimited usage, payment by invoice, custom integration, SSO, dedicated support, and business telephony.


**Business Telephony / Phone** Add-on module for VoIP telephony, domestic calls, local numbers from multiple countries, iOS/Android calling, click-to-call in the browser, and a bring-your-phone option depending on country regulations.


**API / Zapier / AI Agents** Advanced automation for workflows, integrations, CRM/ATS synchronization, follow-ups, analytics, and knowledge base queries.

## DSGVO und Datenschutz
**Gesamteinschätzung:** Conditional

**On-Prem / local hosting: partial**

An on-premise/self-hosting option is mentioned on the website: companies can request an 'on premise configuration'. However, no specific technical, contractual, or product-related details are provided on the website.

**Private Cloud / data center: partial**

Noota describes isolated environments for development, testing, and production in European data centers, as well as enterprise infrastructure on Google Cloud Platform. However, a dedicated customer-specific private cloud option is not clearly described on the website.

**EU SaaS / managed: covered**

The website clearly describes Noota as an operated cloud service with storage in EU data centers or European data centers. This means an EU SaaS/managed operating model is explicitly covered.

**Hybrid: indirect / not available**

There are references to 'Text-only' and requestable on-premise configurations, but no clearly described hybrid operating model in which parts of the processing run internally and other parts run as EU SaaS. Not specifically stated on the website.

**DPA / Data Processing Agreement: covered**

The contractual terms explicitly include a 'Data Protection Agreement' and regulate roles under the GDPR as well as the use of subprocessors. A separate DPA download is not clearly indicated on the website, but the existence of a DPA in the contractual framework is documented.

**No training: partial**

The website states that data is not used to train generalized AI models, and also notes for Google-related data that it is not processed for non-personalized AI/ML model development. However, a generally worded, comprehensive contractual assurance for all product data and models is not fully detailed on the website.

**Open source / transparency path: indirect / not available**

No clear information was found on the website regarding open-source components, open models, or self-hostable open-source building blocks. A certain transparency path exists only indirectly through the mention of on-premise, data deletion, retention controls, and export/switching options are not specifically described on the pages found.

**Data processing**

According to the website, customer data is processed encrypted in transit and at rest; TLS 1.2/1.3, 256-bit AES, and Google Cloud Platform with Google KMS are mentioned. The environments are said to be isolated from one another and hosted in European data centers. In addition, Noota mentions configurable retention periods and an organization-wide 'Text-only' option in which no audio or video is stored.

**Conclusion**

For EU/EEA users, it is positive that Noota documents EU data residency, GDPR relevance, a DPA in the contractual framework, and statements that customer data is not used for model training. However, the website documentation is not sufficient for an unreservedly positive assessment, because subprocessors are not specifically listed and several statements regarding certifications and hosting locations appear contradictory. Therefore, overall 'conditional'.

**Sources**

- [https://www.noota.io/](https://www.noota.io/)
- [https://www.noota.io/privacy](https://www.noota.io/privacy)
- [https://www.noota.io/security](https://www.noota.io/security)
- [https://www.noota.io/terms-conditions-app](https://www.noota.io/terms-conditions-app)
- [https://www.noota.io/en/chatgpt-data-privacy-guide](https://www.noota.io/en/chatgpt-data-privacy-guide)
- [https://www.noota.io/fr/securite](https://www.noota.io/fr/securite)
- [https://www.noota.io/es/security](https://www.noota.io/es/security)

Noota's website documents several building blocks relevant for the EU/EEA region: explicit GDPR references, EU data centers, a data processing agreement included in the contractual framework, as well as statements that customer data is not used to train general models. At the same time, important points remain incompletely or inconsistently documented: the exact server location is described partly as EU data centers in France, Belgium, and the Netherlands, and partly as exclusively in France; a specific list of subprocessors is not provided on the website; relevant certifications are presented partly as being in preparation and partly as already existing. From the perspective of a user in the European region, GDPR-compliant use is therefore only reliably supportable under certain conditions and after conducting one's own contractual review.

**Positive**

Positive are the statements regarding EU data residency, isolated environments in European data centers, encryption, customizable retention periods, an organization-wide 'text-only' option, a DPA included in the contractual framework, and the statement that data is not used to train generalized AI models. An on-premise configuration is also mentioned for companies.

**Negative**

Negative is that several key points are not clearly and consistently documented on the website: a specific list of subprocessors is not provided, the server locations are described inconsistently, an explicit and easily findable separate DPA download is not provided, and there are contradictory statements regarding ISO 27001 and SOC 2 between 'ongoing/in preparation' and 'certified'. This leaves documentation risk for a reliable EU/EEA assessment.

**Server location**

The website mentions EU/European locations. The security page refers to European data centers in France, Belgium, and the Netherlands, as well as Google Cloud Platform with Google KMS. Other subpages, however, state that all data is hosted on servers in France. This confirms EU data residency, but the exact production location is described inconsistently on the website.

## Hosting und Daten
- **On-Prem / lokales Hosting:** teilweise / indirekt
- **Private Cloud / Rechenzentrum:** teilweise / indirekt
- **EU SaaS / Managed:** abgedeckt
- **Hybrid:** unknown
- **AVV / DPA:** abgedeckt
- **Kein Training auf Kundendaten:** teilweise / indirekt
- **Open-Source / Transparenz-Pfad:** unknown

## Standort
**Land:** France

**Taxonomie:** France

NOOTA, 13 Rue Sainte Ursule, 31000 Toulouse, France. Toulouse Trade and Companies Register: 888965951

## Vorteile
- Meeting recording, transcription, and automatic summaries
- No-bot recording and bot recording possible
- Telephony, email agent, and meeting knowledge base in one platform
- EU data centers in France, Belgium, and the Netherlands documented
- No training with customer data according to the security page
- Data Protection Agreement included in the Terms
- API/Zapier, CRM/ATS integrations, SSO in Enterprise
- Custom retention for Business/Enterprise and text-only option for organizations

## Nachteile
- Processing meetings may include personal and confidential conversational data; consent, information obligations, and recording rules must be implemented in an organizationally sound manner
- The security page states “actively preparing” for ISO 27001 and SOC 2 Type II; a completed certification cannot be reliably inferred from this
- The DPA is included in the Terms, but a separate detailed list of subprocessors was not reliably found in the research
- Google Cloud Platform as infrastructure; despite EU data centers, subprocessors, access possibilities, and transfer mechanisms should be reviewed
- Some texts contain linguistic inaccuracies, which makes careful proofreading necessary for compliance documents

## Quellen
- Offizielle Website: https://www.noota.io/

## Letzter Datenstand
2026-05-04

## Originalseite
https://kifox.ai/en/ki-tools/noota-en/
