iBabs Data Privacy and Information Security Factsheet

iBabs forms one ecosystem for governance decision-making. From preparing meetings to recording decisions, from live streaming sessions to publishing information for citizens—everything comes together in one platform.

In addition, iBabs offers Debrief, an optional AI-powered assistant to support transcription and minute-taking. From a privacy perspective, Debrief is fully aligned with the GDPR and the EU AI Act. The feature is disabled by default and can only be enabled at a client’s request, ensuring that users remain in full control. All AI outputs must be reviewed and approved by the client before use, and importantly, iBabs never uses customer data to train or fine-tune AI models.

Because iBabs supports organisations in essential decision-making, privacy and security are built in from the ground up. Our platform is designed according to the privacy by design principle and is fully compliant with the GDPR and other relevant laws. We work exclusively with data centres in the EU and the UK, are ISO/IEC 27001 and ISO/IEC 9001 certified and apply end-to-end encryption. This ensures your organisation’s data is and remains secure.

Application areas for secure digital meetings

iBabs is the leading platform for decision-making in the public sector. Municipalities, provinces and water boards use iBabs to securely and transparently organise council meetings, committees and consultations. Private sector organisations also rely on iBabs for their governance processes.

  • Council meetings, committees and public consultations
  • Board of directors meetings and strategic sessions
  • Annual General Meetings (AGMs)
  • Corporate governance meetings and internal training
  • Internal and external decision-making

Our platform ensures the secure handling of sensitive discussions, real-time voting and transparency through compliant digital collaboration.

Our approach to data privacy

Data privacy is a foundational element of iBabs’ service design. We understand the sensitive nature of the data involved in corporate meetings and take all necessary steps to ensure compliance with data protection laws, particularly GDPR.

Our distinctive strengths:

  • ISO/IEC 27001 certified for Information Security
  • ISO / IEC9001 certified for Quality management
  • We work in accordance with the Baseline Informatiebeveiliging Overheid (BIO) and the ISO/IEC 16175
  • Data Transfers outside the EER: Data may be transferred outside the EEA only where necessary, and always subject to appropriate safeguards such as SCCs
  • End-to-end encryption for data in transit and at rest
  • Role-based Access Controls with strict internal data segregation
  • 24/7 monitoring, regular security audits, and penetration testing

Data Controller vs Processor Roles

This depends on how you use iBabs:

ScenarioOur role
You visit our website, register for an event, or request a demo.Data Controller – We determine how your data is used.
You use our meeting management services as part of your company’s subscription.Data Processor – We follow your organisation’s instructions.

For more information, please contact us or the DPO.

Privacy & Compliance

QuestionReply
Is iBabs compliant with the GDPR?iBabs is fully compliant with GDPR. We continuously monitor regulatory changes and update our processes to remain compliant.
Do you have a Data Protection Officer (DPO)?Our DPO is part of Euronext's central governance. You can reach the DPO at [email protected].
Do you have a programme in place to address compliance with applicable data privacy legislation?iBabs has a GDPR-compliant privacy programme, centrally managed by the Group DPO.

Access Control & Data Isolation

QuestionReply
Can iBabs staff see your data?Only authorized personnel with a legitimate need may access your data, subject to your permission and under strict security protocols.

Support with DPIA requests

QuestionAnswer
Will iBabs help with a DPIA?No. When you, as data controller, wish to conduct a Data Protection Impact Assessment (DPIA), iBabs is committed to supporting you with the necessary information. As your data processor, we cannot perform the DPIA on your behalf, but we will provide the technical, organizational, and contractual details you need to complete your assessment. This note explains our role and how we can assist you.
What kind of support will I get for a DPIA?iBabs will assist you by providing the information you need, such as details of our technical and organisational measures, our hosting environment, and our sub-processors.
Can I work with iBabs to complete a DPIA?As Controller, you are responsible for completing the DPIA. iBabs will support you by answering specific questions and providing the necessary details to help you finalise your assessment efficiently.

Data Portability, Retention & Deletion

QuestionAnswer
Can we export our data if we stop using your services?You can export your data at any time, and iBabs assists with complete data retrieval prior to contract termination.
How long is data retained after contract termination?Data is retained in accordance with our documented retention schedule, based on your instructions as client. This schedule is enforced through automated workflows and regularly reviewed.
Is there an automated data deletion policy?Our retention schedules are enforced through automated workflows and periodic reviews.

Sub-Processors & Vendors

QuestionReply
Do you use sub-processors?We maintain a vetted, documented list. Clients are notified of sub-processor changes and have the right to object under our DPA. This list can be found online, through the Euronext Corporate Solutions webpage.
How do you ensure sub-processors meet your standards?All sub-processors are bound by contractual DPAs, undergo due diligence, and are required to comply with equivalent security controls.

iBabs Platform and Data Privacy

QuestionAnswer
Who is responsible for personal data processed in the iBabs platform?The organisation using iBabs is the Data Controller. iBabs only acts as a Data Processor, following the client’s instructions.
What personal data is processed by iBabs?Data may include user profile information (e.g. name, email), platform usage data (e.g. IP address, login times), and meeting content such as documents, chat, and audio/video from streamed sessions. The Controller can also upload content to the platform, for which they are solely responsible.
Does iBabs handle uploaded files?Some features rely on automated file processing, such as:
- File conversion (e.g. Word to PDF);
- Audio to text transcription (either uploaded by the client or recorded through iBabs Stream);
- Temporary encrypted storage of source files during processing.

All intermediate files are encrypted, access is restricted to engineers for troubleshooting only, and access is logged. No active content review is performed, and files are auto deleted after processing.
What is iBabs Stream?iBabs Stream is an optional feature that allows clients to broadcast or record meetings, typically for transparency or public access purposes. When enabled, it may involve the processing of video, audio, chat, and participant data. iBabs processes this data strictly on instruction from the Data Controller.
Does iBabs offer any AI-supported features?  Yes. iBabs offers Debrief, an optional AI-powered assistant. From a privacy perspective, Debrief is fully aligned with the GDPR and the EU AI Act. The feature is disabled by default and can only be activated at the client’s request. Users retain full control: all AI outputs must be reviewed and approved by the client before use. iBabs does not use customer data to train or fine-tune AI models.
Does iBabs use personal data for its own purposes?iBabs only processes data to deliver the platform services. Data is not used for marketing or analytics beyond platform performance.
Where is the data stored?Personal data is primarily stored and processed within the EEA. iBabs Stream data is hosted in AWS Ireland and Microsoft Azure West Europe.
Are international data transfers compliant with the GDPR?Any transfer outside the EEA is safeguarded by Standard Contractual Clauses (SCCs) or equivalent mechanisms.
How is platform data secured?Data is encrypted at rest and in transit (AES-256 and TLS 1.2), with strict access controls, regular security audits, and ISO/IEC 27001 certification.
Can users exercise their privacy rights via iBabs?As a Data Processor, iBabs redirects all data subject requests to the client organisation (Data Controller), who defines the purpose of the processing.

iBabs Debrief: Technical details

QuestionAnswer
What is iBabs Debrief?An AI-powered transcription and minutes assistant, integrated within iBabs. It helps secretaries and board assistants create transcripts, decision and action lists, and meeting minutes. Users always maintain full control and can validate and edit all AI outputs themselves before they are stored or shared.
Which technology is used?iBabs Debrief runs on Microsoft Azure in Europe. Key components include: OpenAI Whisper (speech-to-text), PyAnnote (speaker diarization), and GPT models (text generation). The frontend is a React application; the backend uses Azure Container Apps, Logic Apps, and Functions.
How is data processed and secured?Audio recordings are uploaded to a secure Azure environment via a SAS link. Files are automatically scanned, encrypted (AES-256 at rest, TLS 1.2+ in transit), and deleted after processing. Each user edit creates a new, securely stored version.
Are customer data used to train AI models?No. Customer data are never used for training or fine-tuning AI models. Only open-source and publicly available datasets from the vendors are used for the base models.
Who has access to the data?Only the customer can view and manage the full transcripts and minutes. iBabs staff have access solely if strictly necessary for troubleshooting, and always under strict security protocols.
What are the limitations?The maximum supported audio file size is 1 GB. During peak usage, processing time may take up to about 30 minutes.
Does iBabs Debrief comply with laws and regulations?Yes. iBabs Debrief is designed in line with the GDPR and the EU AI Act. This includes informing users when they are interacting with AI, requiring manual validation of outputs, and implementing appropriate safeguards for privacy, transparency, and auditability.

Audits & Control

QuestionReply
Can clients audit iBabs controls?Upon request and in accordance with the terms of our Data Processing Agreement (DPA).

Information Security statement

QuestionAnswer
Is iBabs ISO-certified?Yes. iBabs is ISO 9001:2015 and ISO/IEC 27001:2022 certified and complies with ISO 27002. Our management system is focused on continuous improvement of quality, information security, and customer satisfaction.
Does iBabs have an information security policy?Yes. The policy is reviewed annually, actively communicated, and tested through internal audits.
How does iBabs handle personnel and screening?New employees are screened (including a certificate of conduct), sign a confidentiality agreement, and are trained in information security and risks such as social engineering.
How are company assets managed?All equipment is provided with full disk encryption and antivirus. Issuance, use, and disposal of equipment are recorded.
How is system access managed?Access is based on the “least privilege” principle. Permissions are reviewed quarterly. Access is revoked immediately upon termination of employment. Use of personal login, strong passwords, MFA, and automatic session time-outs.
How is data encrypted?TLS 1.2+ during transmission, AES-256 at rest. Each tenant has its own encryption key. Apps use https, certificate pinning, and local encryption.
Where is physical hosting located?In Microsoft Azure West Europe (NL), with failover to North Europe (IE). Security complies with Azure Security Standards.
Is iBabs tested for vulnerabilities?Yes. Regular internal and external scans and penetration tests are conducted. Patches are applied promptly. Annual external pentests are performed by Radically OpenSecurity and Crystalbox.
Can iBabs scale the platform’s capacity?Yes. iBabs scales flexibly via Azure. Performance and capacity are monitored daily.
How is iBabs’ network secured?Through subnets and VNETs, secured with NSG, WAF, firewalls, and IDS. 24/7 monitoring and secure connections with MFA.
Does iBabs use secure software development practices?Yes. The OWASP Top 10 forms the basis. Developers receive annual secure coding training. Development, test, and production environments are strictly separated. All changes are reviewed and documented before deployment.
How does iBabs handle security incidents?Policies are in place for detection, investigation, notification, and remediation. These are tested at least twice per year.
How does iBabs notify customers in case of a breach?Users are informed in accordance with legislation and contractual obligations. Transparency is central.
How does iBabs manage continuity and backups?Daily backups are made (retention 30 days). Annual disaster recovery and failover tests are conducted.
What are the RPO and RTO objectives?RTO: 60 minutes. RPO: maximum of 5 seconds data loss.
Is 24/7 support available?Yes. iBabs provides 24/7 access to support. SLA reports are available via our knowledge base.
What responsibilities do users have themselves?Users are responsible for securing their accounts (strong passwords, 2FA, IP restrictions, API secret). Additional settings are available, such as camera, snapshot, Entra ID integration, etc.

Customization & Flexibility

QuestionReply
Can we configure how long data is stored or how it’s processed?Absolutely. We offer custom retention settings, user roles, and data access configurations tailored to your policies.
Does iBabs support multilingual or jurisdictional settings?Our tools are multilingual, and our privacy setup accommodates cross-border and sector-specific compliance.

Global Reach, European Roots

iBabs is headquartered in Hoorn, Netherlands, operated by iBabs B.V., and part of the Euronext N.V. Group—Europe’s leading market infrastructure provider. Our infrastructure and privacy practices are aligned with:

  • EU GDPR
  • UK GDPR
  • Dutch compliance laws
  • Participation in EU–U.S. and UK Data Privacy Frameworks
  • AI Act
  • iBabs also supports the public sector with secure and compliant digital meeting solutions for government bodies, municipalities, and related entities.

Ready for iBabs?

Is privacy critical for your organisation and do you want a partner that handles your data with care? iBabs is built on security and reliability so your meetings always meet the highest standards.

Contact our team for more information or request a free demo.