Legal

Data Processing Agreement

Our GDPR Art. 28 processor terms. These apply automatically whenever we process personal data on your behalf — a countersigned copy is available on request.

Effective October 1, 2026AllOnEars Inc.

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between:

  • AllOnEars Inc., a Delaware C Corporation, 3 Germay Drive, Unit 4 #3321, Wilmington, DE 19804, United States (“Processor”, “AllOnEars”, “we”); and
  • the customer identified in the account or order (“Controller”, “you”),

and applies whenever we process personal data on your behalf in connection with the AllOnEars service (the “Service”).

Where the GDPR (Regulation (EU) 2016/679) applies, you are the controller and we are the processorof “Meeting Content” (see Annex 1). Where the UK GDPR applies, references are to the UK GDPR and the ICO.

1Subject matter, duration, nature and purpose#

  • Subject matter: our processing of Meeting Content and related personal data to provide the Service.
  • Duration: the term of your subscription plus the retention/return period in section 9.
  • Nature and purpose: capturing live meeting audio; producing transcripts; generating AI context cards and summaries; scheduling recordings from connected calendars; and operating, securing and billing the Service.
  • Types of personal data and categories of data subjects: see Annex 1.

2Roles and instructions#

2.1 We process personal data only on your documented instructions, including those given through the Service’s configuration, unless required by EU/Member State law (in which case we will inform you unless legally prohibited).

2.2 The Terms, this DPA and your use of the Service constitute your complete instructions. If we believe an instruction infringes the GDPR, we will inform you.

2.3 You warrant that you have a valid lawful basis and, where required, have obtained all necessary consents and given all necessary notices to meeting participants before recording or transcribing any meeting (see Terms § “Recording consent”). We are not responsible for your lawful basis.

3Confidentiality#

We ensure that persons authorised to process personal data are bound by confidentiality obligations.

4Security (Art. 32)#

We implement appropriate technical and organisational measures, described in Annex 2, and may update them provided the level of protection is not degraded.

5Sub-processors (Art. 28(2), (4))#

5.1 You give general authorisation for us to engage the sub-processors in the named list we give you with this DPA. The categories are shown on our public Sub-processors page.

5.2 We will give at least 30 days’ notice before adding or replacing a sub-processor. You may object on reasonable data-protection grounds within that period; if we cannot resolve the objection, you may terminate the affected Service.

5.3 We impose data-protection obligations on each sub-processor no less protective than this DPA and remain liable for their performance.

6International transfers (Chapter V)#

Where personal data is transferred outside the EEA/UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK IDTA/Addendum where applicable) plus supplementary measures. The processing region for meeting recordings is set at deployment; EU-region processing is available for enterprise customers by arrangement.

7Assistance to the Controller#

7.1 Taking account of the nature of processing, we assist you with appropriate measures to fulfil your obligation to respond to data-subject requests(Art. 12–23). Account holders can also exercise access, export and erasure in-app.

7.2 We assist you with security, breach notification, data-protection impact assessments and prior consultation(Art. 32–36), taking into account the information available to us.

8Personal-data breach (Art. 33)#

We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information reasonably available to help you meet your Art. 33/34 obligations. Notify us of suspected incidents at [email protected].

9Return or deletion (Art. 28(3)(g))#

On termination, and at your choice, we will delete or return your personal data and delete existing copies within 30 days, unless retention is required by law. Deleting your account also instructs our bot provider to delete stored recordings and flushes live-session caches. Standard content retention is 365 days; Business and Enterprise customers can shorten it for their organisation in the settings. Copies in backups are deleted when the backups themselves are deleted: server copies after 14 days, and emailed encrypted copies as described in the Privacy Policy. Recordings held by our bot provider expire after 7 days.

10Audits (Art. 28(3)(h))#

We make available information necessary to demonstrate compliance and allow for audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice, no more than once per calendar year (or after a breach), subject to confidentiality and without compromising other customers’ security.

11Liability and precedence#

Liability under this DPA is subject to the limitations in the Terms. If there is a conflict, this DPA prevails over the Terms on the subject of data protection.

12Signatures#

A countersigned copy is available to customers on request at [email protected].

For the ProcessorEgemen Sariaslan, authorised signatory, AllOnEars Inc.
Signature ______________ Date __________
For the ControllerName ______________ Title ______________ Entity ______________
Signature ______________ Date __________

Annex 1Details of processing#

Categories of data subjectsThe Controller's users, meeting hosts and meeting participants; calendar owners; the Controller's staff and customers who appear in meetings.
Categories of personal dataAccount data (name, email); meeting audio; participant names; transcripts, translations and speaker labels; AI-generated cards, key facts and reports; context material the Controller adds (documents, glossary terms, notes, CRM records); calendar event data and meeting links; usage, billing and technical data (incl. IP address).
Special-category dataNot intentionally processed by us. May incidentally appear in Meeting Content; the Controller is responsible for the Art. 9 condition (see Privacy Policy § 4).
FrequencyContinuous, for the duration of the subscription.
Nature of processingCapture, transcription, AI inference, storage, retrieval, deletion.
PurposeProviding the Service as described in the Terms.
RetentionPer section 9.

Annex 2Technical and organisational measures (summary)#

  • Encryption: TLS in transit (terminated at our network-edge provider and proxied to our servers); AES-256-GCM at rest for stored OAuth tokens; database and disk protection provided by our infrastructure provider in the EU (Germany).
  • Access control: Hashed passwords and API keys; short-lived, scope-bound access tokens; per-tenant isolation and ownership checks on all resource access. Staff access to customer accounts is limited to an email allowlist, shows account and billing data but not Meeting Content, and is audit-logged.
  • Network: Reverse proxy with rate limiting; webhook signature verification; secrets kept out of source control.
  • Resilience: Nightly database backup kept on the server for 14 days; AES-256 encrypted database backup emailed on a schedule to a restricted-access mailbox; retention/erasure jobs; health checks; graceful shutdown.
  • Observability: Structured application logs with secrets masked; request logs record the path but not the query string or request body; the engine does not log transcript text unless debugging is switched on, which it is not in production. No third-party error-tracking or analytics service is used.
  • Organisational: Least-privilege access, confidentiality obligations, secret-rotation runbook, breach-response process.
Legal entity
AllOnEars Inc.
Delaware C Corporation
Registered address
3 Germay Drive
Unit 4 #3321
Wilmington, DE 19804
United States