GDPR check

Is Trint GDPR compliant? What universities should check

Trint is a UK company that transcribes audio and video with its own AI. This page sets out what Trint publicly documents about where recordings are stored, its contract terms, subprocessors and AI training, and what that means for universities handling research interviews.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

Trint is a UK company with an appointed EU representative, ISO 27001:2022 certification and a contractual statement that it does not use customer data to train its AI models. It offers a US tenant and an EU tenant on Amazon Web Services; its help centre ties EU storage to Enterprise accounts in Europe. Trint processes voiceprint data, which it describes as special category biometric data, when speaker identification is used. Whether it suits a research project depends on the tenant, the contract and how speaker features are configured.

Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers interview transcription with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data

What Trint documents publicly

Everything in this table comes from Trint's own pages and documents, read on 7 October 2026. Numbers in brackets refer to the sources at the end of the page.

TopicWhat the vendor statesSource
Company and establishmentTrint Limited, registered in England and Wales (company number 09225083), London. Trint has appointed IT Governance Europe Limited as its EU representative under the GDPR. Platform privacy policy dated 4 August 2026.[1]
Where recordings and transcripts are storedPlan-dependent Two tenants. US tenant: AWS US regions and MongoDB Atlas in the USA. EU tenant: AWS EU regions, MongoDB Atlas in Ireland and Auth0 in Frankfurt and Ireland. The help centre says transcripts are stored in us-east-1 "or if you have an Enterprise account in Europe, in eu-west-1 (Dublin)". The privacy policy's processing table separately says transcription data "is stored in the USA" under Standard Contractual Clauses.[1] [3] [4]
Data processing agreementDocumented Data processing terms in clause 8 and Annex A of the Terms and Conditions. Enterprise customers have a separately negotiated Enterprise Agreement that applies instead. Customers get 30 days to object to new subprocessors.[2]
SubprocessorsListed in the privacy policy, split by tenant, with locations and certifications. No third-party speech recognition provider is named. Anthropic (USA) is listed globally for first name, last name, email and IP address for internal use. Coralogix (Sweden) receives transcription metadata for observability.[1]
International transfersTrint relies on adequacy (for example, the EEA) or on contracts approved for use in the UK, and on the EU Standard Contractual Clauses where data is stored in the USA. The terms say AI-related processing of customer personal data will occur within the UK, the EEA or locations with adequate protection. The European Commission recognises the UK as adequate under the GDPR, renewed in December 2025.[1] [2] [6]
AI training on customer contentDocumented The terms state that Trint "does not use customer data to train or improve its AI models". The help centre says Trint relies on publicly available datasets. Trint's security FAQs say it does not use OpenAI or other third-party AI models for external processing. The terms also grant Trint a licence to use non-personally identifiable content "in aggregate and blinded formats" for benchmarking and research analyses.[2] [5] [12]
Retention and deletionOriginal uploads are kept for 30 days; transcripts and playback media until the user deletes them. Enterprise content is deleted within six months of contract end, and secure deletion can be requested monthly. Database backups may keep content metadata, including filename and an excerpt, for up to a year.[3] [5]
Security certificationsDocumented ISO 27001:2022 certified, and Cyber Essentials certified according to the security page. AES-256 encryption at rest and TLS in transit.[4] [7]
Institution controlsPlan-dependent SAML SSO on Enterprise plans. Admin dashboard, workspace permissions and roles. The security FAQs say Trint "does not currently provide MFA" and recommend Enterprise customers use SSO. Trint has an education page; education pricing was not found in public documentation (checked 7 October 2026).[5] [8]

Trint deserves credit for a level of public detail that many vendors do not offer: a dated subprocessor list split by tenant, a clear no-training clause in the contract, a named EU representative, an independent ISO 27001 certificate, and security FAQs that explain backups, deletion verification and penetration testing. It is also open about voiceprints: the privacy policy describes voiceprint data as biometric personal data that can identify a speaker [1].

What this means for research and teaching

Validemic's analysis

Interview content is often special category data. Participants in qualitative research talk about their health, beliefs, political views or sexuality. Those are special categories under Article 9(1) GDPR [9], and a transcript does not lose that status. Voice recordings are personal data in every case.

Speaker identification needs its own decision. Trint processes voiceprint data at the direction of the account holder [1], and the terms make the customer responsible for a lawful basis and any required consents from speakers [2]. Biometric data used to uniquely identify a person falls under Article 9 GDPR [9]. For most research interviews, speaker labels can be added without voiceprints. If voiceprints are wanted, the participant information sheet and consent form should say so explicitly, and the ethics application should cover it.

Confirm the storage tenant. The EU tenant is the main reason many European DPOs look at Trint. Because the help centre links EU storage to Enterprise accounts in Europe, and one privacy policy table still describes US storage for transcription data, ask Trint to confirm in the contract which tenant your institution will use and where transcription processing takes place.

Transfers are simpler than for US vendors. EU-to-UK transfers benefit from the UK adequacy decision [6]. If you use the US tenant, or a subprocessor in the US receives personal data, Trint relies on Standard Contractual Clauses.

DPIA likelihood. AI transcription of interviews with special category content, particularly with vulnerable participants or at scale, will often meet the criteria for a data protection impact assessment under Article 35 GDPR [9]. Our DPIA screening tool gives a first view.

Accounts. Without end-user MFA, institutions that care about account security will want Enterprise SSO, so that their own identity provider enforces multi-factor authentication.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask Trint before approving it

  1. Will our institution be on the EU tenant, and can that be written into the contract?
  2. Where does transcription processing take place for EU tenant customers, given the privacy policy's reference to storage in the USA?
  3. Which speech recognition models do you use, and do any third parties process audio?
  4. What personal data does Anthropic receive, and does any customer content reach it?
  5. Can voiceprints and automatic speaker identification be switched off for all our users?
  6. What does "aggregate and blinded" use of content mean in practice, and can we exclude research data from it?
  7. Can backup retention of metadata, including excerpts, be shortened for our data?
  8. Which transfer mechanism applies to each subprocessor outside the UK and EEA?
  9. Can we see the ISO 27001 certificate, its scope and the latest penetration test summary?
  10. Is there an education agreement for institution-wide use?

The EU AI Act angle

The EU AI Act, Regulation (EU) 2024/1689, applies alongside the GDPR [10]. For a university using a transcription service, three points matter.

Sources

  1. Trint Platform Privacy Policy, dated 4 August 2026, retrieved 7 October 2026
  2. Trint Terms & Conditions, updated 4 August 2026, retrieved 7 October 2026
  3. Data Security, Trint Support Hub, retrieved 7 October 2026
  4. Data Security and Compliance Standards | Trint, retrieved 7 October 2026
  5. Trint Information Security FAQs (PDF), retrieved 7 October 2026
  6. European Commission: Adequacy decisions, retrieved 7 October 2026
  7. Compliance, Trint Support Hub, retrieved 7 October 2026
  8. Access Management, Trint Support Hub, retrieved 7 October 2026
  9. Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 9 and 35, retrieved 7 October 2026
  10. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 3(39), 4, 5(1)(f), 113 and Annex III, retrieved 7 October 2026
  11. Regulation (EU) 2026/1744 (Digital Omnibus on AI), retrieved 7 October 2026
  12. Artificial Intelligence, Trint Support Hub, retrieved 7 October 2026

About this page

We read Trint's privacy policy, terms, security page, support hub articles and security FAQs on 7 October 2026, and the European Commission's adequacy page on the same day. EUR-Lex was partly unavailable on that date, so the legal texts were read from the Official Journal copies published by the EU Publications Office. Trint's pricing pages did not load, so plan names and prices are not covered here. "Not found" means we could not find the information in public documentation; it does not mean the vendor lacks it.

This page describes public documentation and gives our own analysis. It is not legal advice and it is not a statement that the tool is or is not GDPR compliant, which depends on your contract, configuration and use. If you work for Trint and see an error, please contact us and we will correct it.

Frequently asked questions

Can I use Trint for research interviews under GDPR?

Trint documents several things DPOs look for: data processing terms, an EU storage tenant, ISO 27001 certification and a contractual commitment not to train its AI on customer data. Whether it fits a given study depends on the plan, the storage tenant and the ethics approval, so check with your DPO first.

Where does Trint store recordings?

Trint runs a US tenant and an EU tenant on Amazon Web Services. Its help centre says transcripts are stored in the US East region or, for an Enterprise account in Europe, in Dublin (eu-west-1). One table in the privacy policy says transcription data is stored in the USA, so ask Trint to confirm the location in writing.

Does Trint use my recordings to train AI?

Trint's Terms and Conditions say it does not use customer data to train or improve its AI models, and its help centre says it relies on publicly available datasets. The terms do grant Trint a licence to use non-personally identifiable content in aggregate and blinded form for benchmarking and research analyses.

Does Trint sign a DPA?

Data processing terms are built into Trint's Terms and Conditions (clause 8 and Annex A) for self-serve customers. Enterprise customers sign a separately negotiated Enterprise Agreement, which then applies instead.

Is Trint covered by the UK adequacy decision?

Trint Limited is registered in England and Wales. The European Commission lists the United Kingdom as providing adequate protection under the GDPR, renewed in December 2025, so EU-to-UK transfers do not need extra transfer tools. Onward transfers to the US rely on Trint's Standard Contractual Clauses.