Data we process
- Account and organization information.
- Analysis request metadata.
- Transcripts, recordings and uploaded files.
- Reports, evidence banks and coaching sheets.
- Billing and status information.
Purpose of processing
- Provide conversation analysis and improvement recommendations.
- Manage client requests and report delivery.
- Support billing, request status and client support.
- Maintain security and access control.
- Improve the agreed service where permitted by the client and applicable law.
Controller and processor roles
In most client engagements, the client determines the purpose and lawful basis for submitting personal data, and Second Listener processes that data for the agreed analysis service. Specific agreements may define these roles differently. Clients remain responsible for ensuring that recording, sharing and processing are lawful under their own policies and applicable law.
Retention and deletion
Retention should be agreed with the client. Highly confidential material should be retained only as long as necessary for the agreed analysis and delivery unless a longer period is explicitly agreed or legally required. Clients may request deletion or anonymization according to the agreed engagement terms and applicable law.
Practical GDPR / privacy safeguards
- Use the client portal rather than open email where possible.
- Limit access to authorized client users and JJ Comms Group reviewers.
- Separate original submissions from anonymized training examples.
- Avoid uploading privileged or high-sensitivity material unless authorized.
- Record confidentiality level and reuse permissions at intake.
- Apply human review before sending sensitive analysis outputs.