This page is the public draft of REKORD's Data Processing Agreement. A signed version is issued with every paying customer contract. If you are evaluating REKORD, we will send a Word or PDF copy with your order form.
1. Subject matter
This DPA applies when REKORD processes personal data in customer content on REKORD Cloud: audio recordings, transcripts, summaries, speaker labels, action items, and related metadata. The customer is the controller. REKORD is the processor. It does not apply to customer-cloud or on-premise deployments where REKORD does not host the content.
2. Duration
This DPA lasts for the term of the service agreement and until REKORD has deleted or returned the personal data, including backups that expire on their normal cycle.
3. Nature and purpose
REKORD processes the data to transcribe audio, produce summaries and action items, run customer-configured automations, store the results, and provide support the customer asks for. REKORD does not process customer content to train or fine-tune any model.
4. Types of data and data subjects
Typical data: voice recordings, names and work emails of speakers, meeting titles, calendar context the customer connects, and whatever people say in the room. Data subjects are the customer's staff, contractors and meeting guests. Special-category data may appear if someone says it. The controller decides whether that processing is lawful.
5. Instructions
REKORD processes personal data only on documented instructions from the customer, including transfers, unless EU or Member State law requires otherwise. The service configuration (region, retention, automations, export, deletion) is an instruction. Additional written instructions go to [email protected].
6. Confidentiality
People who can access customer content are bound to confidentiality and may access it only to provide the service or as required by law.
7. Security
REKORD applies the measures described in the security overview, including AES-256 on-device storage, TLS in transit, encryption at rest, optional customer-managed keys, EU-only residency on REKORD Cloud, access logging, and annual penetration testing. REKORD maintains ISO 27001, ISO 27701 and SOC 2 Type II.
8. Subprocessors
The current list is published at https://rekord.tech/subprocessors. REKORD will notify the customer at least 30 days before adding or replacing a product subprocessor. The customer may object on reasonable data-protection grounds. If the parties cannot resolve the objection, the customer may terminate the affected service without penalty for that change.
9. International transfers
REKORD Cloud processing of customer content stays inside the European Union (Paris and Frankfurt). There is no fallback region outside the Union. If a future transfer is required, REKORD will use an adequacy decision or the European Commission's Standard Contractual Clauses and will complete a transfer impact assessment before the transfer starts.
10. Assistance
REKORD will help the customer respond to data-subject requests, run DPIAs, and handle incidents, taking into account the nature of the processing. Product tools already provide export, deletion and audit logs.
11. Incidents
REKORD will notify the customer without undue delay after becoming aware of a personal data breach affecting customer content, with the facts then known, the likely consequences, and the measures taken or proposed.
12. Return and deletion
On termination, or earlier on request, REKORD will return customer content through the export API and then delete it from REKORD Cloud, unless EU or Belgian law requires storage. Backup copies expire on their cycle and are not restored into production after a deletion request, except as required by law.
13. Audits
REKORD will make available ISO, SOC 2 and penetration-test summaries. On reasonable written notice, and no more than once per year unless an incident requires it, the customer may audit REKORD's relevant controls, or appoint an independent auditor bound to confidentiality. Audits happen in a way that does not compromise other customers.
14. Governing law
This DPA follows the governing law and courts of the main service agreement. If that agreement is silent, Belgian law and the courts of Brussels apply.
Request a signable copy: [email protected].