Skip to main content
WAIMAKERS
About UsCareersContact
|
Start a conversation
Back to overview

Fireflies.ai

Fireflies.ai

By deploymentEU: LimitedNo training¹Retention by planProcessing: US

Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.

Rolling out Fireflies.ai safely?

We assess the actual plan, settings, data flows and governance controls, then turn the findings into a practical rollout decision.

Request an assessment

Pricing / Contract Route

Per seat/month: Pro USD10 billed annually or USD18 monthly; Business USD19 annually or USD29 monthly; Enterprise USD39 billed annually

Enterprise Features

Private Storage or separately configured BYOS, custom retention, SSO/SCIM, audit-log API and HIPAA/BAA route

Last Updated

September 10, 2026

Reviewed: 10 September 2026 - prepared by WAIMAKERS B.V.


1 Purpose

Deployment-specific review. Fireflies can support an EU meeting-recording workflow only when the organisation has a lawful basis, gives required information to participants, configures access and retention, executes the DPA and assesses US transfers. A visible meeting bot is a transparency signal; it does not by itself supply a lawful basis or satisfy all national recording rules.


2 Comparison of Fireflies.ai Tiers (EU focus)

The figures below come from Fireflies' current pricing and Enterprise plan guide.

Plan Storage and governance Public price at review date
Free 400 minutes of workspace storage; limited summaries Free
Pro 8,000 minutes per seat; exports and integrations $10/seat/month annually or $18 monthly
Business Unlimited storage, team analytics and conversation intelligence $19/seat/month annually or $29 monthly
Enterprise Private Storage, custom retention, SSO/SCIM, audit-log API, HIPAA option and super-admin controls $39/seat/month, annual only; AI credits are separate

Plan quotas are not deletion schedules. Confirm retention settings and contract terms for the purchased workspace.


3 Is Fireflies.ai GDPR-Compliant?

Data use, storage and transfers

  • ✅ Fireflies' March 2026 policy update says meeting content and personal data are not used to train AI models and vendors are contractually prohibited from training on that data.
  • ⚠️ Fireflies describes third-party handling of meeting audio, video, transcripts and summaries as zero data retention after processing. This is not a claim that Fireflies itself stores no meeting data: plan storage and customer retention settings still apply.
  • ⚠️ The DPA permits Fireflies to create de-identified data and process separate Service Data for business purposes. “No use of any customer-related data” would therefore be too broad.
  • ✅ The current DPA applies to organisations using the service, makes Fireflies a processor or subprocessor for Customer Personal Data, lists the EU-US Data Privacy Framework as the primary US transfer route and incorporates SCC Modules 2 or 3 if that framework cannot be used.
  • ⚠️ Enterprise Private Storage stores new meeting data by default in Fireflies-managed Google Cloud storage in US West (Los Angeles). Bring Your Own Storage (BYOS) is a separate, team-coordinated configuration in which the customer chooses its bucket and location. Fireflies' Private Storage guide says processing still occurs on Fireflies servers in the United States in either case; a storage location is therefore not EU-only processing.
  • ⚠️ The DPA says Customer Personal Data will be deleted or returned on the customer's instruction after termination, subject to legal retention. It does not promise one universal in-service retention period.
  • ⚠️ Data intentionally sent through an MCP connector, integration or downstream app is also governed by that recipient's terms and settings; Fireflies' vendor ZDR statement should not be extended to those independent customer-directed destinations.

Meeting-law and sensitive-data considerations

Meeting audio, video, names, voices, transcripts and inferred action items can be personal data. The controller must determine the lawful basis under Article 6 GDPR, provide Articles 13/14 information where required, apply data minimisation and respect local communications and employment law. Consent is one possible basis, but it is not automatically mandatory or valid in every employment context.

Do not label ordinary voice recordings as biometric special-category data without evidence that technical processing is used to uniquely identify a person. If a use case performs speaker identification, health discussion analysis or other high-risk profiling, reassess Articles 9 and 35 and the relevant national rules.

SOC 2 Type II and an available HIPAA/BAA route are security or sector assurances, not proof of GDPR compliance for a particular meeting.


4 EU Rollout Checklist (Practical)

  1. Define meeting types that may be recorded and prohibit categories that fail the risk assessment.
  2. Establish and document the lawful basis, participant notice and any national recording-law requirements before enabling auto-join.
  3. Execute the current DPA, verify Fireflies' DPF status or SCC fallback and assess supplementary measures for US processing.
  4. Use Enterprise when Private Storage, custom retention, central SSO/SCIM or audit evidence is required.
  5. Configure the shortest workable retention and restricted sharing defaults; test deletion and export.
  6. Review every calendar, conferencing, CRM, MCP and downstream integration separately.
  7. Complete a DPIA where the planned recording or analysis is likely to create a high risk.

5 Notes & Caveats

Open procurement questions

  • Which Fireflies and subprocessor systems process or temporarily hold meeting content, and in which countries?
  • What data remains after workspace deletion, bulk deletion or contract termination, including backups and de-identified data?
  • Does the purchased Private Storage configuration use BYOS or Fireflies-managed storage, and what region is contractually fixed?
  • Which AI features consume separate credits or introduce additional providers?
  • What evidence supports the current SOC 2 scope and any HIPAA configuration?

6 References

  • Fireflies pricing
  • Fireflies Enterprise plan
  • Fireflies Data Processing Addendum
  • Fireflies legal-policy update and ZDR explanation
  • Fireflies Private Storage
  • Fireflies security
  • GDPR, official text
  • EDPB recommendations on supplementary transfer measures

7 Disclaimer

This page is a practical procurement and data-risk overview, not legal advice. Suitability depends on the meeting purpose, lawful basis, participant information, signed terms, configured integrations, retention and the customer's assessment.

Compare related tools

CursorMistral AI

Need help navigating AI?

Start a conversation
WAIMAKERS

Learn. Lead. Make.

AI Transformation Boutique · Amsterdam

Make work exciting, make businesses unstoppable.

Who We Help

View all roles & industriesCEOs & Board MembersPE & Investment ManagersCFOs & Finance LeadersInnovation DirectorsCTOs & IT LeadersCommercial Directors

What We Do

View all servicesOur ApproachLearnTailored Training ProgrammesAI Champions ProgrammeAI Champions — Executive (London)Agentic Way of WorkingE-learningLeadMake

Company

About UsResourcesContactCareersPodcast ↗

© 2026 WAIMAKERS. All rights reserved.

Privacy PolicyCookie Policy