Voice & biometric data
What happens to a voice recorded through MIHOS — and to the person it belongs to.
Last updated: 26 August 2026
MIHOS listens to real sales conversations. That is the product. It is also the part that carries the most responsibility, because the person across the table is usually not a MIHOS user, has no account with us, and never agreed to anything with us directly. This page explains what happens to their voice.
1. What gets recorded
When a rep starts a session, the application captures the audio of that conversation and produces three things: an audio recording of the meeting; a written transcript, with speakers separated; and derived analysis covering topics raised, objections, questions, talk-time balance, coaching signals and CRM field suggestions.
Recording is started deliberately by the rep, session by session. MIHOS does not run in the background, does not listen between sessions, and does not activate on a schedule. There is no setting that makes it do so.
2. Consent comes first
No recording begins without the consent of everyone in the room.
The application plays an audible announcement at the start of the session. The rep confirms on screen that every participant has agreed. The consent itself is captured in the opening seconds of the recording and kept as the proof. Recording stops on request at any moment, and the session can be deleted from the device.
Where the law requires the agreement of every participant, that obligation sits with the customer company, which controls the meeting. In Switzerland, art. 179ter of the Criminal Code makes it an offence for a participant to record a non-public conversation without the agreement of the other participants, and art. 179bis covers recording a conversation between other people. The exception in art. 179quinquies is narrow, and the FDPIC reads it as covering orders, contracts, reservations and comparable transactions rather than consultative sales conversations. MIHOS does not rely on it. In France, art. 226-1 of the Penal Code applies the same logic. Several US states apply an all-party rule of their own.
MIHOS provides the controls and the evidence trail. The customer is responsible for using them.
3. Is a voiceprint created?
No.
This question decides which laws apply, so it deserves a direct answer rather than a comfortable one.
A recording of a voice is personal data. A voiceprint is stricter: a mathematical template of the characteristics of a person's voice, kept so that the same person can be recognised again later. That is a biometric identifier under art. 5(c) of the Swiss FADP and art. 9 GDPR, and under US statutes such as the Illinois BIPA and the Texas CUBI, several of which carry a private right of action and statutory damages per violation.
MIHOS separates speakers within a single recording so that the transcript reads correctly. The vectors that make that possible exist for the duration of that one processing job and are gone when it ends. They are not written to a database, not indexed, not compared against another recording, and not attached to a name. Which speaker is the rep is determined by the account and the device that started the session, not by the sound of a voice. Other participants are labelled by the rep in the interface, or not at all.
MIHOS therefore cannot recognise the same voice across two meetings. Our transcription provider cannot do it for us either: we contract on terms that prohibit speaker enrolment and the retention of voice templates, and we will show that clause to any customer who asks.
We do not rely on the argument that a template derived from an audio recording falls outside the definition of a biometric identifier. Some statutes carve that out and some do not. We rely on not creating the template at all.
If that ever changes, this page changes first, and the written notice, written consent and published destruction schedule those laws require will be in place before the feature ships.
4. Emotions are not analysed
MIHOS does not infer, score or label the emotional state of any participant, and in particular not that of an employee. Sentiment and emotion detection features offered by our providers are switched off in our pipeline.
Inferring emotions in the workplace is a prohibited practice under art. 5(1)(f) of the EU AI Act, in force since 2 February 2025. We treat it as a design constraint rather than a policy statement: the feature is not exposed, not configurable and not sold.
What MIHOS measures is what was said and how the conversation was structured. Who spoke and for how long, which questions were asked, which objections came up, whether the playbook was followed. Not whether someone sounded stressed.
5. Synthetic voices in role play
MIHOS lets a rep replay a lost meeting against a simulated prospect. The simulation reproduces the arguments, objections and reactions recorded in the meeting. It does not clone the real person's voice.
Role play uses a generic synthetic voice. It is labelled as artificially generated in the interface and marked as such in the audio, as art. 50 of the EU AI Act requires. No participant's voice is reproduced, imitated or reused for any purpose other than the transcript and the analysis of the meeting they were in.
6. Who can hear a recording
The rep who recorded it. Their manager and any colleague their organisation has authorised. The providers listed in section 7 of our Privacy Policy, strictly to store the file or to produce the transcript and the analysis, on terms that prohibit training and hold retention to what a single request requires. And MIHOS staff, only on a named support request from the customer or during a security incident, under a time-limited procedure that is logged and visible to the customer in their audit trail.
Recordings are not sold and not shared with advertisers. They are not used to train models, ours or our providers'. There is no setting to opt into on that point, because there is nothing to opt into.
7. Where it is stored, and for how long
Audio, transcripts and analyses are stored in Switzerland, in the Zurich region. Transcription is carried out inside the European Union, by Gladia. No meeting content is stored outside Switzerland.
One honest qualification. The Zurich infrastructure is operated by Supabase, Inc. on Amazon Web Services, both United States companies. The data does not leave Switzerland, but the operator of that infrastructure is US-controlled, and physical residency is not the same thing as legal sovereignty. We say so rather than let a buyer discover it in a security review. Section 8 of the Privacy Policy sets out the safeguards that sit on top of the location itself.
Default retention: audio 90 days, transcripts 12 months, analyses 24 months. A customer can shorten any of these. Extension beyond the default is possible only where the customer documents a regulatory obligation that requires it, and it is written into the order form.
Deletion is permanent in production systems. Encrypted backups are rotated out within 35 days, after which no copy remains.
A customer can delete an individual recording at any time from the application. Withdrawal of consent by any participant triggers deletion of that recording, its transcript and its analysis.
8. If you were recorded and you are not a MIHOS customer
You have rights over that recording even though your relationship is with the company whose rep you met, not with us. You can ask for a copy, ask for it to be corrected, ask for it to be deleted, or withdraw your consent. Withdrawing consent is enough on its own. You do not have to give a reason.
Because that company decides why the recording exists, address your request to them first. You can also write to us at privacy@mihos.ai and we will route it and help them answer.
9. Recording people at work
Where MIHOS is deployed across a sales team, the employer must inform its employees before any recording, put a written internal policy in place covering the system, its retention periods and its consequences, and consult employee representatives where local law requires it.
In Switzerland, art. 26 of Ordinance 3 to the Labour Act prohibits surveillance systems intended to monitor employee behaviour. A system used for coaching has to be built and operated accordingly. That is why recording is started per session by the rep, why the product does not listen between meetings, and why there is no continuous capture mode to enable.
Under the EU AI Act, systems that monitor and evaluate the performance of workers are classified as high risk under Annex III, point 4(b). Regulation (EU) 2026/1744, in force since 27 July 2026, sets the application date for those obligations at 2 December 2027. We are building against that date.
A data protection impact assessment is required for a deployment of this kind, under art. 35 GDPR and art. 22 FADP. The obligation sits with the customer as controller. We provide a completed assessment covering the MIHOS side of the processing, available on request.
10. Security
Recordings are encrypted in transit and at rest. Access is restricted by role. Every access to meeting content is logged and visible to the customer.
11. Changes
Material changes to this page are notified to customers by email at least 30 days before they take effect.
12. Contact
MUUM Sàrl, Route de Champ-Colin 12, 1260 Nyon, Switzerland. Data protection contact: privacy@mihos.ai.


