Data Processing Agreement
Version 2026-08-18 · Last updated 18 August 2026
For business customers in the EU who need us as a processor under GDPR Art. 28.
Scope
This agreement applies to business customers who process the personal data of other people (their employees, clients or call participants) through SubLive. For those customers we act as processor and they act as controller.
It does not apply to consumers using SubLive for their own purposes. In that case we are the controller and the Privacy Policy governs, not this document.
Subject matter and duration
Subject matter: real-time speech transcription and translation. Duration: the term of the customer agreement.
Nature and purpose: processing audio in memory to produce transcripts and translations, and storing transcripts where the Controller has enabled that.
Categories of data subjects: the Controller's users and anyone whose speech is processed through the service.
Categories of personal data: audio (transient), transcripts and translations (where enabled), account and usage metadata.
Processor obligations
- Process personal data only on documented instructions from the Controller.
- Ensure personnel with access are bound by confidentiality.
- Implement the technical and organisational measures described on the Security page.
- Engage subprocessors only as listed on the Subprocessors page, with 30 days notice of changes and a right to object.
- Assist the Controller with data subject requests, DPIAs and breach notification.
- Delete or return personal data at the end of the agreement, except where retention is legally required.
- Make available the information necessary to demonstrate compliance and allow audits.
International transfers
Where a subprocessor processes data outside the EEA, transfers are governed by Standard Contractual Clauses (Commission Implementing Decision 2021/914), which are incorporated by reference.
Breach notification
We will notify the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting their data.