EN· SV· DA· NO· DE

Data Processing Agreement (DPA)

Last updated: 2026-08-12
DRAFT — not yet legally reviewed. This document is a working draft that must be reviewed by legal counsel before launch. Items marked [VERIFIERA: …] are not yet confirmed and items marked [PLATSHÅLLARE: …] are placeholders to be filled in with the registered company details.

This Data Processing Agreement ("DPA") forms part of the agreement between the customer and Byki for the BYKI Notetaker service, and governs the processing of personal data carried out by Byki on the customer's behalf under Article 28 of the EU General Data Protection Regulation (GDPR).

1. Parties and roles

The customer (the account owner) is the data controller. Byki, the provider of BYKI Notetaker, is the data processor. [PLATSHÅLLARE: full legal company name, company registration number, registered address, VAT number — Byki is currently being incorporated.] Contact: privacy@byki.app [VERIFIERA: contact address].

2. Subject matter, duration, nature and purpose

The processing consists of a meeting bot joining the customer's online meetings after being admitted (and with consent), recording the meetings, transcribing them, generating meeting notes with a language model, and delivering the notes to the channels the customer has configured. The processing lasts for the duration of the service agreement, plus the retention and deletion periods in section 9. The purpose is solely to provide the BYKI Notetaker service to the customer.

3. Categories of data subjects and personal data

4. Documented instructions

Byki processes personal data only on the customer's documented instructions — as expressed in the service agreement and the customer's configuration in the app — unless processing is required by EU or Member State law, in which case Byki informs the customer of that legal requirement before processing, unless the law prohibits it.

5. Confidentiality

Byki ensures that every person authorised to process the personal data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.

6. Security measures

Byki implements appropriate technical and organisational measures, including: hosting within the EU, encryption in transit (TLS) and at rest, access control, tenant isolation and an immutable audit log.

7. Sub-processors

The customer grants a general authorisation for the sub-processors listed on the Sub-processors page, which forms part of this DPA. Byki announces intended changes to that list in advance on the same page, giving the customer the opportunity to object. Byki imposes the same data-protection obligations on each sub-processor and remains fully liable for their performance.

8. No use of data for AI or model training

Byki never uses the customer's data to train AI or machine-learning models. Byki's AI providers are contractually prohibited from using the customer's data for machine learning or model training, and Byki's own models learn nothing from the customer's data.

9. Retention and deletion

Meeting notes, transcripts and recordings are retained for the customer's plan retention period — 30 days on Starter (and during the trial), 1 year on Pro and Business, and never longer than 1 year on any plan — and are then deleted automatically; recordings are always deleted together with the transcripts. On termination of the agreement or deletion of the account, Byki deletes all personal data processed on the customer's behalf, unless EU or Member State law requires further storage.

10. Assistance with data-subject rights

Taking into account the nature of the processing, Byki assists the customer with appropriate technical and organisational measures in fulfilling the customer's obligation to respond to data-subject requests (access, rectification, erasure, restriction, data portability, objection), and assists the customer in ensuring compliance with the obligations under Articles 32–36 GDPR, including notifying the customer without undue delay after becoming aware of a personal data breach.

11. Audit and information rights

Byki makes available to the customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the customer or an auditor mandated by the customer, subject to reasonable prior notice.

12. Processing location — EU only

All processing under this DPA takes place within the EU: France (OVHcloud — speech-to-text and language models; Mistral AI — fallback language model), Germany (Strato — hosting and database) and Sweden (Byki's own servers in Gothenburg — meeting bot and fallback transcription). No personal data is transferred outside the EU in the processing chain.

← Back to start