Skip to content
Talkenda
Try now

Talkenda Data Processing Agreement

Version:
2026-09-13.1
Effective from:
September 13, 2026

This Agreement (DPA) supplements the Talkenda service contract and governs processing on the Customer’s behalf under Article 28 of Regulation (EU) 2016/679 (GDPR). Annexes A–C form an integral part of this DPA.

§1. Parties, roles and formation

  1. Processor: NeuroCodeLab Maciej Śnieżyński, a Polish sole trader registered in CEIDG, NIP 7123295462, REGON 361253253, ul. Franciszka Klimczaka 13/102, 02-797 Warszawa, Poland, kontakt@talkenda.com. The Customer is the entity identified in the account and order, represented by the duly authorised person accepting this DPA.
  2. The Customer is either the controller of entrusted data or a processor acting for its own controller. In the latter case it ensures authority to appoint a subprocessor and passes on that controller’s applicable instructions; Talkenda then acts as a subprocessor. “Customer” covers both situations without granting powers beyond its mandate.
  3. This DPA is concluded electronically by acceptance of the supplied version and applies from entrustment until return or deletion is completed. It does not authorise processing for the Processor’s own purposes. The Privacy Policy describes account, billing and security data processed by the Processor as a separate controller.

§2. Subject matter and instructions

  1. The subject matter is provision of meeting-note functions within the scope and duration in Annex A. Documented instructions include the contract, this DPA, settings and authorised in-app actions, and additional lawful instructions sent to kontakt@talkenda.com. The Customer may determine purposes, data categories, individuals, access, retention and cessation of processing.
  2. The Processor processes data only on documented Customer instructions, including for international transfers, unless Union or Member State law requires otherwise. It informs the Customer of that requirement before processing unless the law prohibits notice on important public-interest grounds.
  3. If the Processor considers an instruction to infringe data-protection law, it promptly informs the Customer and may suspend only the disputed operation pending clarification. It does not independently change processing purposes. Operations beyond the agreed service require agreement on scope and any cost before execution.

§3. Customer obligations

  1. The Customer is responsible for lawful collection, the basis for recording and further use, transparency notices, User authority and content minimisation. For Article 9 or 10 GDPR data, it ensures the additional legal basis and safeguards required by law. It does not instruct emotion recognition, biometric identification across meetings or unlawful surveillance.
  2. The Customer assesses the suitability of the Service and Annex B measures for its risks, particularly for professional secrecy, systematic monitoring or special-category data. The Processor supplies available information for that assessment and does not transfer its own GDPR obligations to the Customer.

§4. Confidentiality and security

  1. The Processor grants access only to authorised persons bound by contractual or statutory confidentiality, to the extent necessary for their duties. Permissions are reviewed and withdrawn when no longer needed. Confidentiality continues after the relationship ends.
  2. The Processor implements risk-appropriate measures under Article 32 GDPR, considering the state of the art, costs, nature, scope, context, purposes and risks to individuals. It maintains the measures in Annex B, evaluates their effectiveness and addresses identified weaknesses. Technical changes must not materially reduce the agreed protection level.
  3. Human access to content for support requires the Customer’s express case-specific permission. Necessary security or legally required access may occur without that permission. Operator, purpose, scope, time and case reference are logged before access. Recordings, transcripts and notes are not used to train or fine-tune models.

§5. Subprocessing

  1. The Customer grants general authorisation to appoint the providers listed in Annex C. The Processor contracts with them on substantially the same data-protection duties, particularly sufficient technical and organisational safeguards, and remains responsible to the Customer for the subprocessor’s performance.
  2. At least 30 days before data is entrusted to a new or replacement subprocessor, the Processor notifies the account email of the entity, purpose, scope and location. During that period the Customer may raise a substantiated data-protection objection. The parties seek a solution without starting the disputed subprocessing of that Customer’s data.
  3. If no reasonable solution exists, the Customer may end the affected service before the new subprocessing starts and receive a prorated refund of the prepaid unused period. Publishing a new list without notice does not replace this procedure. For downstream changes, the Processor passes on received information and exercises available rights in the chain.

§6. Locations and transfers

  1. The primary meeting-content infrastructure comprises OVHcloud hosting in Frankfurt, Germany (DE2 region), and Talkenda’s own model processing in Poland. The Processor’s own equipment is not a separate subprocessor. The remote model stage uses a private encrypted connection. This does not mean every account, calendar or payment provider processes data solely in the EEA.
  2. A transfer of entrusted data outside the EEA, including access from such a country, requires documented instructions or appropriate Customer authorisation and compliance with GDPR Chapter V. The Processor identifies the country, recipient, transfer basis and necessary supplementary measures. A general statement about global operations is not itself a transfer basis.
  3. An export recipient, meeting platform or external MCP client selected by the Customer is subject to its instructions and relationship with that recipient. The Processor limits disclosure to the authorised scope and does not treat selection of an integration as waiving Chapter V requirements. The Customer should assess the recipient’s terms and location before connecting.

§7. Assistance and individual rights

  1. Taking account of the nature of processing, the Processor assists the Customer by appropriate measures in fulfilling GDPR Chapter III rights. It informs the Customer without undue delay of a direct request concerning entrusted data and does not substantively respond without instructions unless legally required. Available functions include export, correction and deletion of content and access revocation.
  2. The Processor assists with Articles 32–36 GDPR, including impact assessment, regulatory consultation and breach handling, taking into account processing and available information. Standard information and mandatory cooperation are included in the Service. Exceptional work may be priced separately, but lack of a price agreement does not suspend an urgent legal obligation.

§8. Personal data breaches

  1. Upon becoming aware of a breach of entrusted personal data, the Processor informs the Customer without undue delay; the operational target is initial notice within 24 hours of awareness. It does not wait for the investigation to finish. Notice is sent to the account email or an agreed incident address.
  2. As information becomes available, notice describes the breach, categories and approximate numbers of individuals and records, likely consequences, measures taken or proposed and a contact for follow-up. Missing information is provided in phases without undue delay. The Processor preserves evidence, mitigates effects and assists with notifications; the relevant controller decides on notices to authorities and individuals, without prejudice to the Processor’s own legal duties.

§9. Information and audit

  1. The Processor makes available information needed to demonstrate Article 28 GDPR compliance, allows audits and inspections by the Customer or its authorised independent auditor, and contributes to them. Documentation and a remote review may be used first where sufficient for the audit purpose.
  2. An ordinary audit is arranged with at least 14 days’ notice during working hours, protecting other customers’ data and security secrets. Organisational restrictions do not apply to an urgent breach, substantiated suspicion of non-compliance or an authority’s request. The absence of certification does not replace audit rights; the parties agree proportionate scope and documentation.

§10. Return, deletion and precedence

  1. When processing services end, the Customer chooses return or deletion; after return the Processor deletes remaining copies unless retention is legally required. Return uses available export or agreed secure delivery. Without instructions the Processor requests a choice and deletes after 30 days; this does not override an earlier deletion instruction or shorter retention.
  2. Active-system deletion is performed without undue delay, at most 30 days after a valid request or the chosen return period ends. Backups containing the data are subject to separate access restrictions and deleted no later than 30 days after active-system deletion. Disaster recovery must reapply previous deletion instructions. A legally required retention exception requires identification of scope and basis, with continued protection.
  3. The Processor confirms completion on request. This DPA prevails over the Terms on protection of entrusted data and does not limit liability to individuals or authorities’ powers. Changes must be documented and may not unilaterally weaken protection of existing entrusted data.

Annex A. Scope, individuals, data and retention

  1. Purpose: providing notes and collaboration functions on Customer instructions. Operations: receiving and storing audio, collecting captions and metadata, transcription, separating and assigning speakers within a meeting, generating notes and tasks, text and vector indexing, search, editing, export, authorised sharing and deletion. Duration: service use and the limited return or deletion period in §10.
  2. Individuals: Users, Customer employees and contractors, external participants, clients, business partners, candidates and other people mentioned in submitted content. Data: voice, speech content, speaker names, email, organisation names, calendar data, meeting time and link, speaking times, transcripts, notes, tasks and permission metadata. Scope depends on Customer material and instructions.
  3. Content may incidentally or deliberately include health or other Article 9 and 10 GDPR data; these are not required for the product to work. The Customer minimises them and ensures lawfulness. Talkenda does not create persistent voice profiles for cross-meeting identification or make decisions about individuals based on content.
  4. Audio retention: Free up to 30 days, Pro up to 180 days, Power and Team up to 365 days. Free history: 30 days; paid-plan transcripts and notes: until deletion or service end. Moving to Free applies shorter retention to earlier data too. Moving to trash is not immediate deletion: trash is emptied after 30 days and the Customer may request earlier permanent deletion. A shorter Customer instruction and §10 take precedence.

Annex B. Technical and organisational measures

  1. Transport and infrastructure: HTTPS for user connections; private service connections; an encrypted tunnel to the own model node in Poland; no public port for that node. Recordings are stored outside the public directory and served after permission checks. Full disk encryption at rest and ISO 27001 or SOC 2 certification are not represented.
  2. Access and separation: individual accounts, authenticated sessions, owner and team permission filtering, and revocable links and tokens. Account and protected-link passwords are stored as salted scrypt hashes; plaintext passwords are not stored. Integrations require separate authorisation; Google sign-in alone does not grant calendar access.
  3. Operational controls: restricted administrative access, logged manual reads with purpose and case, service-secret checks, request and password-attempt limits, file-type and path checks, processing-state monitoring, and review of updates and incidents. Meeting content is not automatically attached to support requests.
  4. Continuity: jobs and processing state are stored in the database, allowing retry after a process failure. The VPS infrastructure has daily OVHcloud Premium automated backups rotating seven daily restore points. Backups are stored on separate servers within the same data centre; they are not backups in an independent location. No recovery time or recovery of changes made after the last successful backup is guaranteed. Manual operational copies have separate retention and remain subject to the access and deletion restrictions in §10. The Processor undertakes to periodically test recoverability and the effectiveness of safeguards and to adapt them to the risk of data loss under Article 32 GDPR.

Annex C. Subprocessors and separate integrations

  1. OVH sp. z o.o. (OVHcloud), ul. Powstańców Śląskich 9, 53-332 Wrocław, Poland — hosting for application, database, files and logs; scope includes account data and meeting content. The primary location of hosting and VPS backups is Frankfurt, Germany (DE2). The company belongs to the France-based OVHcloud group. Processing terms and downstream subprocessors are available in the provider’s contractual documentation: https://www.ovhcloud.com/pl/terms-and-conditions/contracts/. The Customer may obtain current location and processing-chain information at kontakt@talkenda.com; changes are subject to §5–6. OVHcloud’s public list also includes group entities in Canada and the United Kingdom authorised to support this service category. Hosting in Germany does not imply access solely by EEA personnel; any transfer outside the EEA is subject to §6. Current list: https://contract.eu.ovhapis.com/1.0/pdf/OVH_Sub_processors-pl.pdf.
  2. Speech, speaker, embedding and summary models run on Talkenda’s own infrastructure in Poland. Using software or downloading weights does not itself make the model author a content recipient. Moving to an external inference service requires the §5–6 procedure before data is sent.
  3. Google handles selected sign-in and authorised calendar access; Stripe handles enabled payments. They do not receive audio or transcripts for those functions. The Privacy Policy describes roles and transfers for their own account, security and payment purposes. They are not generally authorised to receive meeting content. Meeting platforms, selected export recipients and MCP clients operate under the Customer’s chosen relationship; availability of an integration does not itself entrust all content to them as subprocessors.
Download the Data Processing Agreement (.md)

The downloaded file contains the same immutable document version shown on this page.