Data Processing Addendum

Data Processing Addendum (DPA)

Last Updated: 12.05.2024

This Data Processing Addendum ("DPA") is part of the agreement between Codelio, the operator of Noteo.ai ("Processor"), and the user of the Service ("Controller"). This DPA governs the processing of Personal Data in compliance with applicable data protection regulations, including the General Data Protection Regulation (GDPR).


1. Definitions

Controller

The entity determining the purposes and means of processing Personal Data. In this case, the "Controller" is the user of the Noteo.ai platform.

Processor

The entity processing Personal Data on behalf of the Controller. In this case, the "Processor" is Codelio, operating the Noteo.ai platform.

Personal Data

Any information relating to an identified or identifiable individual, including email addresses, IP addresses, audio files, and transcriptions.


2. Scope and Applicability

This DPA applies to all Personal Data that the Controller provides to the Processor through the use of the Noteo.ai platform. The Processor processes Personal Data solely for the following purposes:

  • To provide transcription services.
  • To enable users to manage and export transcriptions.
  • To ensure compliance with legal obligations (e.g., archiving user consent).

3. Roles and Responsibilities

Controller Responsibilities

The Controller is responsible for:

  • Ensuring the lawful collection of Personal Data before sharing it with the Processor.
  • Maintaining accuracy and completeness of the Personal Data provided.
  • Complying with applicable data protection laws.

Processor Responsibilities

The Processor agrees to:

  • Process Personal Data only as instructed by the Controller.
  • Implement appropriate technical and organizational measures to safeguard Personal Data.
  • Assist the Controller in fulfilling data subject rights (e.g., deletion, access).

4. Sub-Processors

The Processor may engage sub-processors, including:

  • Firebase: Used for data storage, authentication, and other essential services.

The Processor will notify the Controller of any changes to sub-processors and ensure all sub-processors comply with data protection obligations.


5. Data Subject Rights

The Processor shall assist the Controller in responding to data subject requests, including:

  • Accessing Personal Data.
  • Rectifying inaccurate data.
  • Deleting Personal Data.
  • Exporting transcriptions in a user-friendly format.

Requests can be directed to: [email protected]


6. Data Retention

The Processor will retain Personal Data only as long as necessary to provide the Service or as required by law. The Controller may delete Personal Data at any time through the Service.


7. Security Measures

The Processor shall implement and maintain industry-standard security measures, including:

  • Data encryption during transmission and storage.
  • Regular vulnerability assessments.
  • Access controls to prevent unauthorized access.

8. Data Breach Notification

In the event of a data breach affecting Personal Data, the Processor will:

  • Notify the Controller without undue delay.
  • Provide details of the breach, including its scope, impact, and mitigation steps.
  • Cooperate with the Controller to meet any regulatory reporting obligations.

9. International Data Transfers

The Processor may transfer Personal Data to jurisdictions outside the Controller's location. Such transfers will comply with applicable data protection laws and ensure adequate safeguards are in place.


10. Termination and Deletion

Upon termination of the Service, the Processor will:

  • Delete or return all Personal Data to the Controller, as requested.
  • Retain data only if required by applicable law.

11. Governing Law

This DPA is governed by and construed in accordance with the laws of Switzerland. Any disputes arising under this DPA will be resolved in the courts of Zurich, Switzerland.

However, for users located in jurisdictions subject to specific data protection regulations, such as the General Data Protection Regulation (GDPR) in the European Union or the California Consumer Privacy Act (CCPA) in the United States, compliance with these local regulations will also apply to the processing of their Personal Data.


12. Contact Us

For questions about this DPA or data protection, contact us at:

Codelio Email: [email protected]

`;