Legal
Data Processing Agreement
For professional and enterprise customers requiring GDPR, HIPAA-aligned, or ISO 27001 compliance documentation.
Effective: August 2026 · Last updated: August 2026
1. Parties and Context
This Data Processing Agreement ("DPA") is entered into between the Customer (identified in the applicable Order Form or account) ("Controller") and OneTranscript / TheOne Ventures ("Processor"). This DPA supplements the Terms of Service and governs the processing of Personal Data by OneTranscript on behalf of the Customer.
This DPA applies when OneTranscript processes Personal Data contained in audio recordings or transcripts on behalf of the Customer in the course of providing the Service.
2. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable data protection law including the EU General Data Protection Regulation (GDPR) and equivalent national laws.
"Processing" means any operation performed on Personal Data, including collection, recording, storage, analysis, transmission, and deletion.
"Data Subject" means the natural person whose Personal Data is being processed — in this context, typically the speaker(s) in a recorded conversation.
"Sub-Processor" means any third party engaged by OneTranscript to process Personal Data in the course of providing the Service.
3. Nature and Purpose of Processing
OneTranscript processes Personal Data on behalf of the Controller for the following purposes:
- Audio-to-text transcription of recordings submitted by the Controller.
- Speaker identification and diarization (distinguishing between speakers in a recording). Voice embeddings used for diarization are ephemeral and not retained after processing.
- AI-generated summarization, action item extraction, and conversational query responses based on transcribed content.
- Storage and retrieval of transcripts and associated metadata within the Controller's account.
Processing is performed only on the documented instructions of the Controller, including those set out in these Terms and the Customer's selected privacy tier configuration.
The Processor does not use Personal Data for training AI or machine learning models. Personal Data is processed solely for the purpose of delivering the Service.
4. Categories of Data and Data Subjects
Categories of Personal Data: voice recordings; resulting transcripts containing names, opinions, and statements of natural persons; speaker labels; metadata associated with recordings (date, duration, participant count).
Biometric data: speaker diarization creates ephemeral mathematical voice embeddings (voiceprints) to distinguish speakers. These are not stored after processing is complete.
Special categories: Recordings may incidentally capture special category data (health information, legal advice, etc.) depending on the Customer's use case. The Customer is responsible for ensuring appropriate legal basis for processing such data.
Categories of Data Subjects: Participants in meetings, client calls, depositions, consultations, or other recorded conversations submitted by the Controller.
5. Processor Obligations
OneTranscript agrees to:
- Process Personal Data only on documented instructions from the Controller, unless required by applicable law.
- Ensure that personnel with access to Personal Data are bound by appropriate confidentiality obligations.
- Implement the technical and organizational security measures described in Section 7.
- Not engage Sub-Processors without prior authorization from the Controller, as set out in Section 6.
- Assist the Controller in responding to Data Subject rights requests to the extent technically feasible.
- Notify the Controller without undue delay (and in any case within 72 hours) upon becoming aware of a Personal Data breach.
- Delete or return all Personal Data upon termination of the Service, at the Controller's election, unless retention is required by applicable law.
- Make available all information necessary to demonstrate compliance with this DPA and permit reasonable audits (with 30 days' advance notice).
- Not use Personal Data for training, fine-tuning, or improving AI or machine learning models.
6. Sub-Processors
By selecting a privacy tier, the Controller authorizes engagement of the following Sub-Processors as applicable to that tier:
- Self-Hosted: No Sub-Processors. All processing occurs on Customer infrastructure.
- US Speed: Groq, Inc. (San Francisco, CA, USA) — transcription and LLM inference.
- EU Privacy: Mistral AI SAS (Paris, France) — LLM inference only. Audio transcription is local.
- Swiss Vault: Infomaniak Network SA (Geneva, Switzerland) — LLM inference only. Audio transcription is local.
- Enterprise: AssemblyAI, Inc. (configurable EU region) — transcription; Nexos.ai (EU) — LLM inference.
- All tiers (when opted in): Functional Software, Inc. (Sentry, San Francisco, CA, USA) — anonymized error reporting only. No Personal Data, audio, or transcript content is transmitted.
OneTranscript will provide 30 days' advance written notice of any new or changed Sub-Processor. If the Controller objects on reasonable grounds, OneTranscript will use reasonable efforts to accommodate the objection or, if unable to do so, the Controller may terminate the affected Service with a pro-rated refund.
7. Technical and Organizational Security Measures
OneTranscript implements security measures appropriate to the risk, including:
- Encryption of Personal Data in transit (TLS 1.2 minimum) and at rest (AES-256-GCM).
- Access controls: role-based access, principle of least privilege, multi-factor authentication for administrative systems.
- Logical isolation of Customer data to prevent cross-customer access.
- Regular penetration testing and vulnerability assessments.
- Incident response plan with documented escalation procedures.
- Employee security training and background checks for personnel with data access.
- Business continuity and disaster recovery procedures.
8. Data Subject Rights
The Controller is primarily responsible for responding to Data Subject rights requests. OneTranscript will, to the extent technically feasible, assist the Controller in fulfilling such requests (access, rectification, erasure, portability, restriction, objection) within 5 business days of receiving written instructions from the Controller.
For erasure requests, OneTranscript will permanently delete the relevant Personal Data from active systems within 30 days and from backups within 90 days.
9. Personal Data Breach Notification
In the event of a Personal Data breach affecting Customer data, OneTranscript will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach. Notification will include: the nature of the breach; categories and approximate number of Data Subjects affected; categories and approximate number of Personal Data records affected; likely consequences; measures taken or proposed to address the breach.
10. International Data Transfers
Transfers of Personal Data outside the EEA or UK are governed as follows: EU Privacy and Swiss Vault tiers are designed to minimize cross-border transfer (audio stays local; only text is sent to EU/Swiss providers). For US Speed and Enterprise tiers where transfers occur, such transfers are made pursuant to Standard Contractual Clauses (EU Commission Decision 2021/914) or equivalent transfer mechanisms. Copies of applicable SCCs are available upon request.
11. HIPAA Compliance
For Customers who are Covered Entities or Business Associates under the Health Insurance Portability and Accountability Act (HIPAA), OneTranscript offers a Business Associate Agreement (BAA) as a separate addendum to this DPA.
The BAA is available upon request for Professional and Enterprise tier customers. It covers the use, disclosure, and safeguarding of Protected Health Information (PHI) in accordance with HIPAA requirements. Contact hello@onetranscript.app with "HIPAA BAA Request" in the subject line.
Self-Hosted tier customers processing PHI on their own infrastructure do not require a BAA with OneTranscript, as no PHI is transmitted to or accessible by OneTranscript.
12. Duration and Termination
This DPA remains in effect for as long as OneTranscript processes Personal Data on behalf of the Controller. Upon termination of the underlying Service agreement, OneTranscript will, at the Controller's written election, either return all Personal Data in a portable format or securely delete it, and certify such deletion in writing within 30 days.
13. Governing Law
This DPA is governed by the laws of the European Union and, where applicable, the laws of the EU Member State in which the Controller is established. For UK Controllers, the DPA is also governed by the UK GDPR and Data Protection Act 2018.
14. Execution
By accepting the Terms of Service, the Controller agrees to this DPA. For enterprise accounts requiring countersigned DPAs on custom terms, contact hello@onetranscript.app.
Questions? hello@onetranscript.app