Privacy policy
Last updated: 11 September 2026
This policy explains how FelixRay Pty Ltd (ABN [ABN]) ("we", "us") handles information when an organisation, such as a local council, uses Teams Notetaker ("Notetaker") at https://notetaker.felixray.com.
Our role
Notetaker is used by organisations ("customers"). When a council uses Notetaker, the council remains responsible for its own obligations under the privacy law that applies to it, for example the Privacy and Personal Information Protection Act 1998 (NSW) or the Privacy and Data Protection Act 2014 (Vic). We handle the information on the council's behalf, as its contracted service provider, and only in line with our agreement with the council and this policy. We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth), and with any state privacy principles our customer agreements bind us to.
What Notetaker handles
Meeting information, processed and not stored. To create notes, Notetaker reads, for meetings the council has not excluded:
- the meeting title, date and time, and the names and email addresses of the organizer and invitees
- either the Microsoft 365 Copilot meeting recap (if the council uses the Copilot option), or the meeting transcript, which includes speaker names and what was said (if the council uses an Azure OpenAI option)
- the notes generated from it.
This information is held in memory only while the notes email is being prepared, then discarded. It is not written to our databases, logs or backups.
Administration information, stored. We store:
- the names, email addresses and Microsoft Entra identifiers of council staff who sign in to the Notetaker admin portal
- council settings, such as the sender mailbox, an optional records mailbox and notices
- seat assignments, which record the Microsoft Entra identifiers of organizers who have a Notetaker seat
- an activity log of metadata, such as "notes sent", the time, the identifier of the person involved, which notes option was used, and a short reference code for the meeting. The log contains no meeting content.
- subscription details: plan, number of seats, dates, and marketplace or purchase-order references.
Support information. This is what you send us when you ask for help.
We use only essential cookies, to keep council admins signed in to the admin portal. We don't use advertising or tracking cookies.
How we collect it
We collect this information:
- from Microsoft 365, through the Microsoft Graph permissions a council administrator approves
- from council administrators in the admin portal
- from the Microsoft commercial marketplace when a council buys through it
- directly from you when you contact us.
How we use it
We use the information only to:
- create meeting notes and email them to the meeting's organizer (and to a council records mailbox, if the council sets one)
- manage subscriptions and seats
- keep the service secure and investigate problems
- provide support.
We don't sell personal information, use it for advertising, or use it to train artificial intelligence models.
How notes are generated
Each council chooses one of three options:
- Microsoft 365 Copilot recap. Notes come from the recap that Microsoft 365 Copilot creates inside the council's own Microsoft 365 tenant. Notetaker never downloads the transcript.
- Azure OpenAI hosted in Australia. The transcript is sent to our Azure OpenAI service. It uses a regional deployment in an Australian Azure region, and our service checks this automatically. Microsoft states that prompts and outputs are not used to train its models and are not shared with OpenAI.
- The council's own Azure OpenAI. The transcript is sent to an Azure OpenAI service in the council's own Azure subscription. Notetaker checks that it is in an Australian region and uses a regional deployment.
Notes are generated by AI and can contain mistakes. They are sent to the organizer to review. They are not official minutes.
Where information is held
Notetaker runs in Microsoft Azure data centres in Australia: Australia East and Australia Southeast. Meeting content stays in the council's Microsoft 365 tenant, except while our service is processing it in Australia. Notes emails are sent from the council's own mailbox.
There are two limited exceptions, and neither involves meeting content:
- Teams chat messages. When staff use the Notetaker app in Teams, its chat messages are relayed by Microsoft Azure Bot Service, which is a global Microsoft service. These messages contain command text, meeting titles and dates, the organizer's email address and a reference code. They never contain transcripts, recaps or notes. A council can choose not to offer the Teams app to staff, and notes are then delivered by email only.
- Marketplace billing. If a council buys through the Microsoft marketplace, Microsoft handles the purchaser's name, email and organisation under Microsoft's own terms.
Our service providers are:
- Microsoft (Azure hosting, storage and Azure OpenAI in Australia; Azure Bot Service for Teams chat messages; marketplace billing)
- Microsoft 365, which is the council's own tenant.
How long we keep it
| Information | How long we keep it |
|---|---|
| Transcripts, Copilot recaps and generated notes | Not stored. Held in memory only while an email is prepared. |
| Activity log (metadata) | 365 days, then deleted automatically |
| Settings, seats, admin details | While the council is subscribed |
| After cancellation | Deleted 30 days after cancellation, or straight away if a council admin chooses Delete all Notetaker data |
| Subscription records | As long as tax and accounting laws require (no meeting content) |
Emails that Notetaker has already delivered are held in the council's own mailboxes. They are managed under the council's own records and retention policies.
Security
We protect information by:
- encrypting it in transit (TLS) and at rest (Azure Storage encryption)
- hosting it only in Australia
- using managed identities, so no AI service keys are stored in our code
- requesting only the Microsoft Graph permissions Notetaker needs
- letting Notetaker send email only from the council's own mailbox, a restriction the council sets in Exchange Online
- requiring Microsoft Entra sign-in with administrator roles for the admin portal
- verifying webhook calls
- keeping activity logs
- running an automatic check that blocks AI services outside Australia.
Access, correction and complaints
Notes emails and meeting records belong to the council. To access or correct information in them, please contact the council. We will help councils respond to requests.
For questions or complaints about how Notetaker handles information, contact our privacy officer at felix@felixray.com. We aim to respond within 30 days.
If you are not satisfied, you can complain to one of these regulators:
- the Office of the Australian Information Commissioner (oaic.gov.au)
- for NSW councils, the Information and Privacy Commission NSW (ipc.nsw.gov.au)
- for Victorian councils, the Office of the Victorian Information Commissioner (ovic.vic.gov.au).
Data breaches
If we become aware of a data breach involving a council's information, we will tell the council promptly, and within the time set in our agreement with it. We will give the council the information it needs to assess the breach and meet its own notification duties. For NSW councils, that includes the Mandatory Notification of Data Breach scheme. Where the law requires, we will also notify affected people and regulators.
Changes and contact
We will post changes to this policy on this page and tell customers about significant changes.
FelixRay Pty Ltd, [registered address]. Email: felix@felixray.com.