Data Processing Agreement
GDPR Article 28 compliant processor terms. Effective April 11, 2026.
This Data Processing Agreement ("DPA") is entered into between the customer ("Controller") and CallScribe FZ-LLC ("Processor") and forms part of the Terms of Service. It applies when the Processor processes personal data on behalf of the Controller in connection with the CallScribe service.
Roles
The Controller determines the purposes and means of the processing. The Processor acts solely on documented instructions from the Controller. For audio files uploaded to CallScribe, the Controller is the CallScribe customer and the Processor is CallScribe.
Nature and Purpose of Processing
- Subject matter: transcription, diarization, sentiment analysis, and analytics of audio files.
- Duration: the term of the customer's CallScribe subscription plus 30 days for deletion.
- Data categories: audio content (may include personal data, voice biometrics), derived transcripts, speaker labels.
- Data subjects: call participants whose audio is uploaded by the Controller.
Sub-processors
The Controller authorizes the Processor to engage the following sub-processors, subject to 30-day written notice of any change:
- Hetzner Online GmbH (DE) — infrastructure hosting.
- Stripe, Inc. (US / IE) — payment processing (billing metadata only).
- Resend — transactional email.
- Sentry — error telemetry.
- Tailscale — private network overlay.
Security Measures
- Encryption at rest (AES-256 via PostgreSQL pgcrypto).
- Encryption in transit (TLS 1.3).
- Row-level security (RLS) for tenant isolation.
- Access controls: JWT-scoped authentication, rate limiting, and audit logging on all authenticated endpoints.
- Quarterly vulnerability scans; dependency updates on critical CVEs.
International Transfers
Where personal data is transferred outside the EEA or the UAE, the parties rely on the EU Standard Contractual Clauses (SCCs) and supplementary measures (end-to-end encryption). The Processor maintains a current list of transfer mechanisms available on request.
Breach Notification
The Processor will notify the Controller of a personal data breach without undue delay and in any case within 72 hours of becoming aware, providing the information required under GDPR Article 33(3).
Audit Rights
Once per 12-month period, the Controller may request a summary audit report or, at the Controller's expense, an on-site audit under reasonable notice and confidentiality terms.
Deletion on Termination
Upon termination of the Terms of Service, the Processor will delete or return all personal data within 30 days, and confirm deletion in writing on request.
Contact
Data Protection: privacy@callscribe.ae