This Data Processing Agreement ("DPA") forms part of the Terms of Service between AI Meeting Companion ("Processor") and the customer ("Controller") and governs processing of personal data on behalf of the Controller.
1. Definitions
Terms used here have the meaning given in Regulation (EU) 2016/679 ("GDPR") and, where applicable, the UK GDPR and the California Consumer Privacy Act, as amended.
2. Subject matter and duration
Processor processes personal data on the Controller's behalf as necessary to provide the AI Meeting Companion service. This DPA applies for as long as Processor processes personal data on behalf of Controller.
3. Nature, purpose and categories
- Purpose: providing AI-assisted meeting preparation, transcription, summarisation, and task management.
- Data subjects: Controller's authorised users and the meeting attendees they record or describe.
- Personal data: account identifiers, meeting metadata, free-form notes and transcripts, decisions, action items, audio submitted for transcription.
- Special categories: not intentionally collected; Controller must avoid uploading special-category data without an appropriate legal basis.
4. Processor obligations
Processor shall:
- process personal data only on documented instructions from the Controller (the Service configuration and these Terms constitute such instructions);
- ensure persons authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational measures (Annex II);
- assist the Controller in fulfilling its obligations under Articles 32-36 GDPR;
- at the Controller's choice, delete or return personal data after the end of services;
- make available all information necessary to demonstrate compliance and allow for audits as set out in clause 7.
5. Subprocessors
Controller authorises Processor to engage the subprocessors listed in Annex I. Processor will notify Controller of changes and the Controller may object on reasonable data protection grounds within 30 days.
6. International transfers
Transfers outside the EEA/UK rely on the Standard Contractual Clauses (Module 2 or 3 as applicable), the UK International Data Transfer Addendum, and supplementary measures where required.
7. Audits
Once per year and at Controller's expense, Controller (or an independent auditor bound by confidentiality) may audit Processor's compliance with this DPA, provided that third-party SOC 2 / ISO 27001 reports (where available) shall be deemed to satisfy the audit obligation.
8. Personal data breach
Processor shall notify Controller without undue delay and, in any case, within 72 hours of becoming aware of a personal data breach, providing the information required by Article 33(3) GDPR.
9. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service.
Annex I — Subprocessors
- Hosting & database — Lovable / Cloud.
- AI inference — large language model gateway provider.
- Email — transactional email provider.
- Payments — Paddle.
- Analytics — first-party product analytics.
Annex II — Security measures
- TLS 1.2+ in transit, AES-256 at rest.
- Row-Level Security to isolate Controller data.
- Principle of least privilege and audit logging for production access.
- Regular dependency scanning and security patching.
- Backups with point-in-time recovery and tested restoration.
- Incident response plan with 72-hour breach notification.
© 2026 BAE VIEW LLC. All rights reserved.