Data Processing Agreement

Last Updated: August 14, 2026

Draft, pending legal review.

This page is a working draft and has not yet been reviewed by counsel. Bracketed terms are placeholders and are not final. If you are evaluating MemorDesk for procurement and need an executed DPA, contact legal@memordesk.com.

This Data Processing Agreement ("DPA") is entered into between [MemorDesk legal entity name], with its registered address at [registered address] ("MemorDesk," "Company," "we," "our," or "us"), and the customer identified in the applicable order form, account registration, or subscription agreement ("Customer"), and forms part of the agreement between MemorDesk and Customer governing Customer's use of the MemorDesk service (the "Agreement").

This DPA applies where MemorDesk processes Personal Data on behalf of Customer in the course of providing the Services, and reflects the parties' agreement with respect to the processing of Personal Data in accordance with the requirements of Data Protection Laws.

1. Definitions

1.1 "Affiliate" means an entity that directly or indirectly controls, is controlled by, or is under common control with a party, where "control" means ownership of, or the power to vote, more than 50 percent of the voting interests of the entity.

1.2 "Authorized Sub-Processor" means a third party engaged by MemorDesk that has a need to access or process Customer's Personal Data to provide the Services, as listed in Exhibit B or otherwise authorized under Section 4.

1.3 "Company Account Data" means Personal Data relating to Customer's business relationship with MemorDesk, including the names and contact details of individuals authorized by Customer to access the account, and billing contact information.

1.4 "Company Usage Data" means service usage data collected and processed by MemorDesk in connection with the operation, support, and improvement of the Services, including aggregated and de-identified analytics.

1.5 "Data Protection Laws" means all data protection and privacy laws applicable to the processing of Personal Data under this DPA, including, as applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the Nigeria Data Protection Act 2023, and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").

1.6 "Personal Data" means any information relating to an identified or identifiable natural person that is processed by MemorDesk on behalf of Customer in connection with the Services, including audio, video, and transcript content from meetings and any information discussed therein.

1.7 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, and, for transfers subject to UK GDPR, the UK's International Data Transfer Addendum to those clauses.

1.8 "Services" means the MemorDesk meeting assistant products and services described in the Agreement.

1.9 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by MemorDesk under this DPA.

2. Roles and Scope of Processing

2.1 Roles. As between the parties, Customer is the controller (or, where Customer processes Personal Data on behalf of a third party, a processor) and MemorDesk is the processor of Personal Data, except with respect to Company Account Data and Company Usage Data, for which MemorDesk acts as an independent controller as described in Section 9. Customer is solely responsible for the accuracy, quality, and legality of the Personal Data it submits to the Services and the means by which it acquired that Personal Data, and for having a valid legal basis to instruct MemorDesk to process it, including obtaining any consents from meeting participants required under applicable law.

2.2 Processing Instructions. MemorDesk shall process Personal Data only for the purposes described in the Agreement and this DPA, in accordance with Customer's documented instructions, and as otherwise required by applicable law, in which case MemorDesk will inform Customer of that legal requirement before processing unless the law prohibits this.

2.3 Details of Processing. The subject matter, duration, nature and purpose of processing, and the categories of Personal Data and data subjects, are described in Exhibit A.

2.4 Deletion. Following termination of the Services, MemorDesk will delete or, at Customer's request, return Customer's Personal Data, in each case within the timeframes described in Section 4 of the Privacy Policy, unless applicable law requires continued retention, in which case MemorDesk will isolate and protect that Personal Data from further processing.

3. Confidentiality

MemorDesk restricts access to Personal Data to personnel and Authorized Sub-Processors who need it to provide the Services, and ensures that any person authorized to process Personal Data is subject to a written obligation of confidentiality.

4. Sub-Processors

4.1 Authorization. Customer provides general written authorization for MemorDesk to engage the Authorized Sub-Processors listed in Exhibit B, and to engage its Affiliates, to process Personal Data in connection with the Services.

4.2 Notification of New Sub-Processors. MemorDesk will keep the sub-processor list in Exhibit B, and the equivalent table in the Privacy Policy, up to date, and will notify Customer at [legal@memordesk.com, or via an in-app or email notification mechanism, to be confirmed] at least ten (10) days before authorizing any new sub-processor to process Personal Data, to give Customer the opportunity to object on reasonable data protection grounds.

4.3 Sub-Processor Obligations. MemorDesk enters into a written agreement with each Authorized Sub-Processor imposing data protection obligations comparable to those in this DPA, and remains liable to Customer for each Authorized Sub-Processor's performance of those obligations.

4.4 Current List. The current sub-processor list is set out in Exhibit B.

5. Security of Personal Data

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, MemorDesk maintains appropriate technical and organizational measures designed to protect the confidentiality, integrity, and availability of Personal Data, as described in Exhibit C and in our Security page.

6. International Transfers

6.1 Transfer Mechanism. Where Customer's use of the Services involves a transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to MemorDesk or an Authorized Sub-Processor located in a country not recognized as providing an adequate level of data protection, the Standard Contractual Clauses (Module Two: Controller to Processor, or Module Three: Processor to Processor, as applicable) are incorporated into this DPA by reference and apply to that transfer, completed with the information set out in Exhibit A (Annex I) and Exhibit C (Annex II).

6.2 UK Transfers. For transfers subject to UK GDPR, the UK Addendum to the EU SCCs issued by the UK Information Commissioner's Office is incorporated by reference and applies in place of, and takes precedence over, the EU SCCs to the extent of any conflict.

6.3 Onward Transfers. MemorDesk will not authorize any Authorized Sub-Processor to further transfer Personal Data outside the jurisdiction from which it was collected without ensuring an equivalent transfer mechanism is in place.

7. Data Subject Rights

7.1 Requests. If MemorDesk receives a request from a data subject to exercise a right under Data Protection Laws (access, rectification, erasure, restriction, portability, or objection) in relation to Personal Data processed under this DPA, MemorDesk will, to the extent legally permitted, direct the data subject to Customer, and will not respond directly except on Customer's documented instructions.

7.2 Assistance. Taking into account the nature of the processing, MemorDesk will provide reasonable assistance to Customer, at Customer's cost, to enable Customer to respond to such requests, including through the account-level export and deletion tools described in Customer's Privacy Policy.

8. Audits, Assessments, and Breach Notification

8.1 Records and Compliance Information. Upon Customer's written request, at reasonable intervals and subject to reasonable confidentiality controls, MemorDesk will make available information reasonably necessary to demonstrate compliance with this DPA, which may take the form of a summary of relevant security certifications or reports then held by MemorDesk.

8.2 Audit. Where the information provided under Section 8.1 is not sufficient to demonstrate compliance, and Customer is required by a supervisory authority or applicable law to conduct an audit, MemorDesk will permit Customer, or an independent auditor mutually agreed by the parties, to conduct an audit of MemorDesk's compliance with this DPA, no more than once per year, on reasonable notice, during business hours, and without unreasonably interfering with MemorDesk's business operations. Customer bears the costs of any such audit, including reasonable compensation for MemorDesk's time.

8.3 Data Protection Impact Assessments. MemorDesk will provide reasonable cooperation to Customer, at Customer's cost, in connection with any data protection impact assessment or prior consultation with a supervisory authority that Customer reasonably considers necessary, to the extent Customer does not otherwise have access to the relevant information.

8.4 Breach Notification. MemorDesk will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer's Personal Data, and will take reasonable steps to identify the cause, mitigate the effects, and remediate the cause, to the extent remediation is within MemorDesk's reasonable control.

8.5 Breach Cooperation. MemorDesk will provide reasonable assistance to Customer to the extent needed for Customer to comply with its own obligations under Data Protection Laws to notify a supervisory authority or affected data subjects of a Personal Data Breach. Notification of, or response to, a Personal Data Breach is not an acknowledgement by MemorDesk of fault or liability.

9. MemorDesk as an Independent Controller

With respect to Company Account Data and Company Usage Data, MemorDesk acts as an independent controller, not a processor, and processes that data to manage the business relationship with Customer, for billing and account administration, to detect, prevent, and investigate fraud and security incidents, to comply with legal and regulatory obligations, and to maintain and improve the Services, in each case as described in our Privacy Policy. Meeting content, including audio, video, and transcripts, is not Company Usage Data and is processed by MemorDesk solely as a processor on Customer's instructions.

10. Term, Precedence, and Governing Law

10.1 Term. This DPA takes effect on the date Customer accepts the Agreement and remains in effect for as long as MemorDesk processes Personal Data on Customer's behalf.

10.2 Precedence. In the event of a conflict between this DPA and the Agreement, this DPA governs with respect to the processing of Personal Data. Where the Standard Contractual Clauses are incorporated under Section 6, the Standard Contractual Clauses govern to the extent of any conflict with the rest of this DPA.

10.3 Governing Law. [Governing law and jurisdiction to be confirmed, this DPA is governed by the law stated in the Agreement, unless the Standard Contractual Clauses specify otherwise for the portion of processing they cover.]

Exhibit A: Details of Processing

Subject matterMemorDesk's provision of the Services to Customer under the Agreement.
DurationFor the term of the Agreement, and thereafter as described in Section 2.4 of this DPA and the Data Retention section of the Privacy Policy.
Nature and purposeRecording, transcription, summarization, and analysis of meetings, and related search, notification, and integration features, as necessary to provide the Services.
Categories of data subjectsCustomer's authorized users, and meeting participants (who may or may not be Customer's own employees or contractors), including internal colleagues, prospects, clients, and other external attendees.
Categories of Personal DataAudio and video recordings of meetings, transcripts, meeting metadata (participant names and email addresses, meeting titles, timestamps), and any personal information discussed during a meeting.
Special category dataMemorDesk does not intentionally collect special category data. Meeting audio, video, and transcripts may incidentally include special category data if discussed by participants during a meeting; Customer is responsible for the appropriateness of discussing such data in recorded meetings.

Exhibit B: Sub-Processors

The current list of Authorized Sub-Processors is the same list published in Section 3 of the Privacy Policy, reproduced here for reference. That page is the authoritative, kept-current version.

Exhibit C: Technical and Organizational Security Measures

Encryption in transitTLS 1.3 for all data in transit.
Encryption at restAES-256 encryption for stored data.
InfrastructureHosted on SOC 2 certified cloud infrastructure providers.
Access controlRole based access control, admin access gated by IP allowlisting and authenticated role checks, signed and time limited URLs for stored media.
API securityHashed API keys with granular, scoped permissions.
Sub-processor managementWritten agreements with Authorized Sub-Processors imposing data protection obligations no less protective than this DPA. Zero retention agreements with AI model providers, meeting content is processed to generate a result and is not retained by them or used to train their models.
Data subject toolsSelf service export and deletion tools available directly in the product, described in the Privacy Policy.
RetentionTiered retention by plan and data type, described in the Data Retention section of the Privacy Policy.

Contact

Questions about this DPA, or requests for an executed copy, can be sent to:

Email: legal@memordesk.com

    Data Processing Agreement | MemorDesk | MemorDesk