Legal
Data Processing Agreement
Last updated: 13 July 2026
This Data Processing Agreement ("DPA") forms part of and is incorporated into the agreement between the customer ("Customer") and ALCHEMAX LLC, a California limited liability company doing business as IronMemo ("IronMemo", "we", "us"), under which IronMemo provides the IronMemo meeting-assistant service (the "Service") (the "Agreement").
This DPA governs the Processing of Customer Personal Data by IronMemo acting as a Processor on behalf of Customer. It does not govern IronMemo's own independent-controller activities (for example, account registration, billing, fraud prevention, security administration, corporate records, marketing, and website analytics), which are described in the separate Privacy Policy at /privacy, nor cookies and similar technologies, which are described in the separate Cookie Policy at /cookies.
If there is a conflict between this DPA and the Agreement with respect to the Processing of Customer Personal Data, this DPA controls.
Parties and role of this DPA
1.1 The parties are Customer and IronMemo. IronMemo's contracting entity is ALCHEMAX LLC, dba IronMemo (California Entity No. 20250348022), 732 S Spring St, Apt 1517, Los Angeles, CA 90014, United States. "IronMemo" is a trade name of ALCHEMAX LLC and is not a separate legal entity. DPA contact: info@ironmemo.com.
1.2 This DPA applies to any Customer that has entered into the Agreement, regardless of subscription tier. Execution of a separate signed copy is available on request but is not required for this DPA to apply.
Definitions
2.1 Capitalized terms not defined here have the meanings given in the Agreement or in applicable Data Protection Laws.
- "Data Protection Laws" means all laws applicable to the Processing of Customer Personal Data under the Agreement, including, as applicable, the EU General Data Protection Regulation 2016/679 ("GDPR") and equivalent United Kingdom and Swiss laws (each to the extent it applies under this DPA), and United States state privacy laws including the California Consumer Privacy Act as amended ("CCPA").
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Supervisory Authority", and "Special Categories of Personal Data" have the meanings given in the GDPR; equivalent terms in other Data Protection Laws (including "business", "service provider", "contractor", and "consumer" under the CCPA) apply where those laws apply.
- "Customer Personal Data" means Personal Data that IronMemo Processes on behalf of Customer under the Agreement, as further described in Annex I.
- "Sub-processor" means any third party engaged by IronMemo to Process Customer Personal Data on IronMemo's instructions.
- "Extension" means any IronMemo browser extension made available to Customer.
- "Local Recording" means a recording captured and stored on a User's own device by the Extension or otherwise, before any transmission to IronMemo.
- "Recording User" means the individual who initiates a recording or uploads a recording to the Service.
- "Meeting Participant" means any individual who participates in, or is referred to in, a recorded meeting.
- "Uploaded Recording" means a recording, and related data, that Customer or a User expressly uploads or transmits to the Service.
Roles of the parties
3.1 Customer as Controller. Where Customer determines the purposes and means of Processing Customer Personal Data, Customer is the Controller and IronMemo is the Processor.
3.2 Customer as Processor. Where Customer Processes Customer Personal Data on behalf of a third party (for example, where Customer provides services to its own clients), Customer may act as a Processor and IronMemo acts as a Sub-processor. Customer represents that it has the necessary authority and instructions from the relevant Controller for IronMemo to Process the Customer Personal Data under this DPA.
3.3 IronMemo's independent-controller activities. IronMemo acts as an independent controller, and not as Customer's Processor, for the activities described in the Privacy Policy (including account administration, billing, fraud and security, and legal compliance). Those activities are outside the scope of this DPA.
3.4 Payments. Payment processing is performed by Stripe. Billing, fraud-prevention, and tax activities associated with payments are independent-controller activities and are outside the scope of this DPA. Stripe is therefore not listed as a Sub-processor in Annex III unless and to the extent a specific Stripe service Processes Customer Personal Data on Customer's documented instructions.
Scope and documented instructions
4.1 IronMemo Processes Customer Personal Data only on Customer's documented instructions, including with regard to transfers, unless required to do otherwise by law to which IronMemo is subject; in that case, IronMemo will inform Customer of that legal requirement before Processing, unless the law prohibits it.
4.2 Customer's documented instructions are set out in the Agreement, this DPA, and the configuration options that Customer selects within the Service (including retention settings, provider selections available to Customer, feature toggles, and workspace settings). Routing of a task to an approved provider within the set of providers made available to Customer is an instruction of Customer.
4.3 IronMemo will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
4.4 The subject matter, duration, nature and purpose of the Processing, and the categories of Customer Personal Data and Data Subjects, are described in Annex I.
Commencement of Processing; Local Recording
5.1 IronMemo's Processing under this DPA begins when Customer Personal Data first reaches an IronMemo-controlled endpoint, IronMemo storage, or an approved Sub-processor acting on IronMemo's instructions. Metadata transmitted before a media file may independently begin Processing under this DPA if it constitutes, or is derived from, Customer Personal Data.
5.2 Local Recording is outside this DPA to the extent that neither IronMemo nor its Sub-processors receive any Customer Personal Data. A Local Recording that remains solely on a User's device is not Processed by IronMemo, is not deleted by IronMemo, and is not subject to IronMemo's return or deletion duties under this DPA.
5.3 Where an Uploaded Recording is transmitted directly to a Sub-processor (for example, through a pre-authorized upload location), that transmission remains within IronMemo's Processing on Customer's instructions.
5.4 The Recording User is responsible for the lawfulness of any recording, including obtaining any legally required notices and consents from Meeting Participants and having authority to upload. A recording feature, an in-product acknowledgement, or a checkbox is a representation by the User and does not by itself establish that every Meeting Participant has consented.
Confidentiality and personnel
6.1 IronMemo ensures that persons authorized to Process Customer Personal Data are bound by an appropriate obligation of confidentiality.
6.2 IronMemo limits access to Customer Personal Data to personnel who require access to provide the Service, on a least-privilege basis.
Security
7.1 IronMemo implements and maintains appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as further described in Annex II.
7.2 Annex II describes IronMemo's security measures by category. IronMemo may update specific measures over time provided that the updated measures do not materially reduce the overall level of security.
Sub-processors
8.1 Customer provides a general authorization for IronMemo to engage Sub-processors to Process Customer Personal Data. IronMemo's current Sub-processors are listed in Annex III.
8.2 IronMemo imposes on each Sub-processor data-protection obligations that are, in substance, equivalent to those set out in this DPA, and remains responsible to Customer for each Sub-processor's performance of its obligations.
8.3 Change notification. Until IronMemo maintains a dedicated sub-processor page, Annex III is the authoritative current list. IronMemo will give Customer at least thirty (30) days' prior notice, by email to the account owner, before authorizing a new or replacement Sub-processor, and will update Annex III on the date the notice is sent. Customer may object on reasonable data-protection grounds during the notice period; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected part of the Service.
Personal data breach
9.1 IronMemo will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data.
9.2 The notification will describe, to the extent known and available, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. IronMemo may provide information in phases as it becomes available.
9.3 IronMemo will provide reasonable assistance to Customer in connection with Customer's own breach-notification obligations to Supervisory Authorities and Data Subjects. This DPA does not make IronMemo responsible for determining whether Customer must notify, or for notifying Supervisory Authorities or Data Subjects on Customer's behalf. The seventy-two (72) hour period referenced in some Data Protection Laws is an obligation of the Controller toward its Supervisory Authority and is not a processor notification deadline under this DPA.
Assistance to Customer
10.1 Data-subject requests. Taking into account the nature of the Processing, IronMemo will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests to exercise Data-Subject rights under Data Protection Laws. If IronMemo receives such a request directly, it will, unless legally prohibited, direct the individual to Customer and inform Customer.
10.2 Impact assessments and prior consultation. Taking into account the nature of Processing and the information available to IronMemo, IronMemo will provide reasonable assistance to Customer with data-protection impact assessments and prior consultations with Supervisory Authorities where required by Data Protection Laws. A data-protection impact assessment is not automatically required for every recording; the need for one is assessed by reference to the risk of the Processing.
Audits and records
11.1 IronMemo makes available to Customer information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice, allows for and contributes to audits, including inspections, conducted by Customer or an auditor mandated by Customer.
11.2 IronMemo may satisfy audit requests by providing relevant third-party audit reports and documentation where available. On-site inspections are limited to once per twelve (12) months (except following a material breach affecting Customer Personal Data), are conducted during business hours with minimal disruption, are subject to confidentiality, and are at Customer's cost.
11.3 IronMemo maintains records of its Processing categories carried out on behalf of Customer as required by Data Protection Laws.
International transfers
12.1 United States launch. The Service is currently offered for commercial onboarding in the United States. IronMemo does not currently offer commercial onboarding to organizations established in the European Economic Area ("EEA"), the United Kingdom, or Switzerland. The conditional transfer terms in Annex IV apply only if and when IronMemo enables onboarding for those regions.
12.2 IronMemo-operated infrastructure used to store Customer Personal Data is located in Vienna, Austria. Customer Personal Data may also be Processed by Sub-processors in the United States, as described in Annex III. Storage in Austria does not by itself mean that Customer Personal Data is Processed exclusively within the EEA.
12.3 Where transfers of Customer Personal Data are subject to the transfer requirements of Data Protection Laws, IronMemo will use a valid transfer mechanism as described in Annex IV.
Return and deletion
13.1 On expiry or termination of the Agreement, and at Customer's choice, IronMemo will delete or return Customer Personal Data that remains within IronMemo's active systems, and will delete existing copies within a reasonable period, unless retention is required by law.
13.2 IronMemo will delete defined Customer Personal Data in its active systems within thirty (30) days following deletion of the relevant account, subject to the exceptions in this Section.
13.3 Backups. Residual copies of Customer Personal Data in backups are logically isolated and are not returned to active use; they expire in the ordinary course of IronMemo's backup cycle. If a backup is restored, IronMemo re-applies the applicable deletion so that data previously marked for deletion does not return to active use.
13.4 Sub-processor copies. Deletion of copies held by Sub-processors follows each Sub-processor's own deletion mechanisms and retention periods, which may differ from the period in Section 13.2 and are summarized in Annex III.
13.5 Logs and legal holds. Operational and security logs are retained for risk-based periods and may reference limited data. IronMemo may retain Customer Personal Data where and for as long as required by law or to establish, exercise, or defend legal claims.
13.6 IronMemo's deletion duties do not extend to Local Recordings or to copies that Customer or Users send to third-party destinations (for example, integrations) that are outside IronMemo's control.
AI processing
14.1 The Service uses third-party artificial-intelligence providers to generate transcripts, summaries, action items, follow-up drafts, and AI-chat and knowledge responses where enabled. These providers are listed in Annex III.
14.2 IronMemo does not use AI to infer emotions from voice, tone, prosody, facial expressions, or biometric signals, and does not create persistent voiceprints or perform cross-meeting biometric identification of Meeting Participants as part of the standard Service. Ordinary transcription and speaker labelling (for example, "Speaker 1", "Speaker 2") do not, without more, constitute unique biometric identification.
14.3 AI outputs are generated by AI systems, may be inaccurate or incomplete, are not a verbatim record, and require human review. Customer and its Users remain responsible for reviewing outputs and for any publication or consequential use.
United States state privacy laws
15.1 Where CCPA or another United States state privacy law applies, IronMemo acts as Customer's service provider (or processor) and Processes Customer Personal Data only for the limited and specified business purposes set out in the Agreement and Annex I. The additional terms in Annex V apply.
Restrictions on use
16.1 No sale; no sharing. IronMemo will not sell Customer Personal Data and will not "share" it for cross-context behavioral advertising, as those terms are defined under applicable Data Protection Laws.
16.2 No targeted advertising. IronMemo does not use Customer Personal Data for cross-context behavioral or targeted advertising.
16.3 No independent secondary use. IronMemo will not retain, use, or disclose Customer Personal Data for any purpose other than the specified business purposes, or outside the direct business relationship, except as permitted by Data Protection Laws.
16.4 No training of IronMemo models on Customer Content. IronMemo does not use Customer Personal Data to train IronMemo's own artificial-intelligence models. The manner in which each AI Sub-processor may or may not use data (including default retention windows and any de-identified or aggregated-data rights) is described, by provider, in Annex III.
16.5 Telemetry. IronMemo may collect technical telemetry (such as request identifiers, routing information, and error information) to operate and secure the Service, minimized so as not to use Customer Personal Data for a purpose outside this DPA.
Supported countries
17.1 The Service is enabled for commercial onboarding only in countries listed in IronMemo's internal Supported Country Register. Availability of the website in a country does not mean commercial onboarding is enabled there. Conditional schedules for additional regions appear in Annex IV (EEA/UK/Switzerland) and Annex VI (specified CIS countries) and are not operative until enabled.
Government and third-party requests
18.1 If IronMemo receives a legally binding request from a public authority for Customer Personal Data, IronMemo will, unless legally prohibited, inform Customer, and will not disclose Customer Personal Data except as legally required. IronMemo will challenge requests that appear unlawful or excessive where it has reasonable grounds to do so.
Liability, term, and governing law
19.1 Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
19.2 This DPA takes effect on the effective date of the Agreement and continues for as long as IronMemo Processes Customer Personal Data.
19.3 This DPA is governed by the laws of the State of California, without regard to conflict-of-laws rules, and the parties submit to the exclusive jurisdiction of the state and federal courts located in Los Angeles County, California, subject to any mandatory forum that cannot lawfully be waived. This DPA uses court litigation in Los Angeles County, California, and does not add a separate dispute-resolution mechanism or a class-action waiver.
19.4 If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force.
Description of Processing
Subject matter. Processing of recordings and related data expressly uploaded or transmitted by Customer to the Service, and of data derived from them, to provide the Service.
Duration. For the term of the Agreement and until return or deletion in accordance with Section 13.
Nature and purpose. Recording ingestion; transcription; AI summarization; extraction of action items; generation of follow-up drafts; AI-chat and knowledge responses where enabled; storage; search; and deletion in accordance with configured settings and this DPA.
Categories of Customer Personal Data.
- Audio and video recordings expressly uploaded or transmitted by Customer.
- Transcripts and time-coded speaker labels.
- AI-generated summaries, action items, and follow-up drafts.
- AI-chat prompts and responses where enabled.
- Semantic-search indices and related derived data where such features are enabled (generated using the AI providers listed in Annex III or IronMemo-operated infrastructure; no additional Sub-processor is used for this purpose).
- Meeting metadata (such as titles, times, and the names or email addresses of Meeting Participants).
- Technical telemetry associated with Processing, minimized as described in Section 16.5.
Special categories / sensitive data. Recordings and transcripts may incidentally contain Special Categories of Personal Data or sensitive information because a meeting may cover any subject. IronMemo does not intentionally solicit such data. Customer, as Controller, is responsible for having a lawful basis for any such data and for instructing IronMemo accordingly.
Categories of Data Subjects.
- Customer's authorized users and personnel.
- Meeting Participants, who may be internal or external to Customer's organization.
- Individuals referred to within a recording who are not themselves participants.
Technical and Organizational Measures
IronMemo maintains a security program that includes, by category and appropriate to the risk:
- Access control. Role-based access to Customer Personal Data limited to authorized personnel on a least-privilege basis; authentication controls for administrative access.
- Encryption. Encryption of Customer Personal Data in transit over public networks, and encryption of stored Customer Personal Data, using industry-standard methods.
- Logical isolation. Separation of customer data within IronMemo's systems.
- Logging and monitoring. Logging of relevant administrative and security-relevant events, and monitoring designed to detect and respond to security events.
- Confidentiality. Confidentiality obligations for personnel and vendor-management controls for Sub-processors.
- Resilience and backups. Backup and restoration procedures designed to support availability and recovery, with deletion re-applied on restore as described in Section 13.3.
- Incident response. Procedures to detect, investigate, and respond to security incidents and to notify Customer as described in Section 9.
IronMemo continues to develop its security program, including toward independent security attestation. Where a specific control, certification, or attestation has not yet been completed, IronMemo does not represent that it is in place.
Sub-processors
The following third parties may Process Customer Personal Data on IronMemo's instructions. IronMemo operates its application layer on this infrastructure as a first-party layer; the underlying server infrastructure is provided by the hosting provider identified below.
Infrastructure and hosting:
| Sub-processor | Entity | Purpose | Notes on data handling |
|---|---|---|---|
| netcup | netcup GmbH (Germany; part of the Anexia group) | Server and storage infrastructure hosting | Provides the underlying servers on which IronMemo operates. Customer Personal Data is stored in a data center located in Austria (European Economic Area). IronMemo administers the operating system and application layer. |
Speech-to-text (transcription):
| Sub-processor | Entity | Purpose | Notes on data handling |
|---|---|---|---|
| ElevenLabs | Eleven Labs Inc. (United States) | Speech-to-text | By default, provider retention applies. Any reduced-retention or no-log operation requires eligible enterprise configuration and account-level verification. ElevenLabs uses its own sub-processors (published by ElevenLabs). |
| AssemblyAI | AssemblyAI Inc. (United States) | Speech-to-text | Retention is configurable; by default the provider's deletion and retention terms apply, and the provider's standard terms permit certain de-identified use unless configured otherwise. AssemblyAI uses third-party cloud infrastructure and its own sub-processors (published by AssemblyAI). |
Large-language-model (summaries, action items, AI chat):
| Sub-processor | Entity | Purpose | Notes on data handling |
|---|---|---|---|
| OpenAI | OpenAI OpCo, LLC (United States); OpenAI Ireland Ltd for certain non-U.S. Processing where enabled | Summaries, action items, AI chat | By default, inputs and outputs are not used to train models; abuse-monitoring logs may be retained for a limited period (by default up to 30 days) unless an approved reduced-retention or modified-monitoring configuration is enabled. |
| Google LLC (United States) | Summaries, action items, AI chat | On paid API/Vertex AI, inputs and outputs are not used to improve Google's products; abuse-monitoring retention applies by default (currently up to 55 days) unless an approved reduced-retention configuration is enabled for the project. Certain stateful features may involve additional storage. | |
| xAI | X.AI LLC (United States) | Summaries, action items, AI chat | By default, inputs and outputs are not used to train foundation models; content is temporarily retained (by default up to 30 days) unless an approved reduced-retention configuration is enabled. Outside such a configuration, the provider may create and use de-identified or aggregated data. This provider is not used for Processing of data originating from the EEA, the United Kingdom, or Switzerland. |
Payments. Stripe processes payments as an independent controller and is not a Sub-processor of Customer Personal Data under this DPA.
The current list above is the authoritative Sub-processor schedule and is maintained in accordance with Section 8.3.
International Transfers (Conditional — not operative at United States launch)
This Annex applies only if and when IronMemo enables commercial onboarding for the EEA, the United Kingdom, or Switzerland. It is not operative while those regions remain disabled, and IronMemo does not represent that it is operationally available in those regions.
Article 28 controller-to-processor terms. Where the GDPR applies, the controller-to-processor obligations of this DPA are intended to satisfy Article 28 of the GDPR and, where the parties so agree, may incorporate the standard contractual clauses adopted for controller-to-processor relationships under Commission Implementing Decision (EU) 2021/915. These terms address the content of the Processing relationship and are distinct from, and do not by themselves authorize, any transfer to a third country.
Third-country transfer terms. Where Customer Personal Data is transferred from the EEA to a third country that is not the subject of an adequacy decision, the parties will rely on the standard contractual clauses adopted under Commission Implementing Decision (EU) 2021/914 (Module Two for controller-to-processor transfers, or Module Three for processor-to-processor transfers), together with any required supplementary measures and a transfer impact assessment. For transfers from the United Kingdom, the UK International Data Transfer Addendum (or the IDTA) applies; for transfers from Switzerland, the clauses apply with the amendments required by Swiss law. An adequacy decision (such as the EU-U.S. Data Privacy Framework) may be relied upon only where the relevant importer has a valid participation/listing under it; because the validity of that framework is subject to ongoing proceedings, the parties will maintain standard contractual clauses as the primary mechanism.
Data exporter / importer. For each transfer, the exporter is Customer (or the relevant Controller) and the importer is ALCHEMAX LLC, dba IronMemo, with onward transfers to the Sub-processors listed in Annex III as further importers.
United States State Privacy Terms
Where CCPA or another comprehensive United States state privacy law applies, and IronMemo acts as Customer's service provider (or processor):
1. Limited, specified purposes. IronMemo Processes Customer Personal Data only for the specific business purposes set out in the Agreement and Annex I, and not for any other commercial purpose. 2. No sale or sharing. IronMemo will not sell Customer Personal Data or share it for cross-context behavioral advertising. 3. No combining. IronMemo will not combine Customer Personal Data with personal information received from or on behalf of another person, or collected from its own interactions with the consumer, except as permitted by applicable law. 4. No use outside the direct business relationship. IronMemo will not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer. 5. Same level of protection. IronMemo will provide the level of privacy protection required of a service provider (or processor) under applicable law. 6. Notice and remediation. IronMemo will notify Customer if it determines it can no longer meet its obligations, and Customer may take reasonable steps to stop and remediate unauthorized use. 7. Certification and monitoring. IronMemo certifies that it understands and will comply with these restrictions, and permits Customer to take reasonable and appropriate steps to monitor compliance, including assessments or audits as described in Section 11, at least once every twelve (12) months. 8. Downstream obligations. IronMemo imposes equivalent restrictions on Sub-processors that Process Customer Personal Data and notifies Customer of, and contracts with, such Sub-processors as required by applicable law. 9. Assistance with consumer requests. IronMemo assists Customer in responding to verifiable consumer requests as described in Section 10. 10. De-identified data. Where a Sub-processor is permitted to create de-identified or aggregated data as described in Annex III, IronMemo does not authorize any use that would re-identify a consumer, and requires that such data be maintained and used in a de-identified form.
Specified CIS Country Schedule (Reserved — not operative)
This Annex is reserved. Commercial onboarding for the specified Commonwealth of Independent States countries under review — Armenia, Belarus, Kyrgyzstan, and Moldova — is not enabled at United States launch. Each such country is enabled, if at all, only after it passes a separate country-compliance gate, which addresses (as applicable) the local legal basis for cross-border transfer (noting that EU standard contractual clauses are not recognized as a transfer mechanism in several of these countries), any registration or notification obligation, any local-representative requirement, consent and notice requirements, sanctions and payment-availability screening, and local data-subject rights. IronMemo does not offer local in-country data residency for these countries. Russia, Kazakhstan, Uzbekistan, Azerbaijan, Tajikistan, and Turkmenistan are not supported. Georgia is not treated as part of this schedule and is subject to separate review. Where a country's data-protection law becomes aligned with the GDPR, IronMemo may instead treat that country under the EEA gate.
Contact
For questions about this DPA, contact info@ironmemo.com.