Data Processing Agreement
Last updated: April 12, 2026
This Data Processing Agreement (DPA) applies to the processing of personal data by IronMemo on behalf of the Customer under the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Definitions
"Controller" means the Customer who determines the purposes and means of processing. "Processor" means IronMemo, which processes personal data on behalf of the Controller. "Data Subject" means an identified or identifiable natural person. "Personal Data" means any information relating to a Data Subject. "Processing" means any operation performed on Personal Data.
Scope and Purpose
This DPA covers the processing of personal data contained in meeting recordings, transcriptions, and AI-generated outputs. Processing is performed solely for the purpose of providing the IronMemo service as described in the Terms of Service.
Data Processing Details
Types of data processed: audio/video recordings, transcripts, speaker names, meeting metadata. Categories of data subjects: employees and meeting participants of the Controller. Processing operations: transcription, AI summarization, action item extraction, storage, and deletion per retention settings.
Security Measures
IronMemo implements appropriate technical and organizational measures including: AES-256 encryption at rest, TLS 1.3 in transit, role-based access control, regular security assessments, incident response procedures, and employee security training. Full details are available at /security.
Sub-processors
IronMemo engages the following categories of sub-processors: cloud infrastructure providers (Amazon Web Services), AI model providers for transcription and summarization. A current list of specific sub-processors is available on request. We will notify the Controller at least 30 days before engaging a new sub-processor.
Data Subject Rights
IronMemo will assist the Controller in fulfilling data subject requests under GDPR Articles 15-22, including requests for access, rectification, erasure, restriction, portability, and objection. We will respond to such assistance requests within 10 business days.
Data Breach Notification
In the event of a personal data breach, IronMemo will notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach. The notification will include the nature of the breach, categories and number of data subjects affected, likely consequences, and measures taken to address the breach.
International Transfers
Where personal data is transferred outside the EEA, IronMemo ensures appropriate safeguards through Standard Contractual Clauses (SCCs) as approved by the European Commission, supplementary measures where required, and adequacy decisions where applicable. EU data residency is available on request.
Term and Termination
This DPA remains in effect for the duration of the service agreement. Upon termination, IronMemo will, at the Controller's choice, delete or return all personal data within 30 days. Certification of deletion is available on request.
Contact
For questions about this DPA or to request a signed copy, contact dpa@ironmemo.com.