This Data Processing Addendum (“DPA”) forms part of the agreement between Unifies AI, Inc. (“Unifies”, “Processor”) and the customer identified in that agreement (“Customer”, “Controller”) governing Customer's use of the Service (the “Agreement”). This published DPA applies automatically to all customers; an execution copy for countersignature is available to enterprise customers from legal@unifies.ai. In case of conflict, this DPA prevails over the Agreement for the subject matter it governs (an Order Form modifies this DPA only where it expressly amends it), and the Standard Contractual Clauses prevail over this DPA.
1. Definitions
Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach”, and “supervisory authority” have the meanings given in the GDPR. “GDPR” means Regulation (EU) 2016/679; “UK GDPR” means the GDPR as incorporated into UK law; “CCPA” means the California Consumer Privacy Act as amended by the CPRA, and “business”, “service provider”, “sell”, and “share” have the meanings given there. “Customer Personal Data” means personal data contained in Customer Content or Output that Unifies processes on Customer's behalf under the Agreement, as described in Annex I. “SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
2. Roles, scope, and instructions
2.1. Customer is the controller (or, where Customer acts for another controller, a processor with authority to bind that controller) of Customer Personal Data; Unifies is the processor.
2.2. Unifies will process Customer Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law to which Unifies is subject — in which case Unifies will inform Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest. Customer's instructions are: (a) processing necessary to provide the Service as described in the Agreement and Annex I; (b) the configurations Customer makes through the Service's controls — including capture, retention (which the Service currently applies to meeting transcripts and search embeddings), integration, delivery, visibility of execution records, and sharing settings; and (c) any further written instructions the parties agree. Unifies will inform Customer if, in its opinion, an instruction infringes applicable data-protection law.
2.3. Customer is responsible for the lawfulness of the processing it instructs — including establishing a legal basis for recording and analyzing meetings and providing participants the required notices (Agreement, Section 4.2).
3. Unifies' obligations
3.1. Confidentiality. Unifies ensures that persons it authorizes to process Customer Personal Data are bound by contractual or statutory confidentiality obligations.
3.2. Security. Unifies implements and maintains the technical and organizational measures described in Annex II, and may update them provided the protection level does not materially decrease.
3.3. Data-subject requests. Taking into account the nature of the processing, Unifies assists Customer by appropriate technical and organizational measures in fulfilling Customer's obligations to respond to data-subject requests (GDPR Arts. 15–22), primarily through the Service's built-in export, correction, attribution-contest, and deletion tooling (Annex II, item 9). If a data subject contacts Unifies directly about Customer Personal Data, Unifies will (to the extent lawful) acknowledge receipt, redirect the request to Customer, and not otherwise respond on the merits.
3.4. Assistance. Unifies provides reasonable assistance with Customer's obligations under GDPR Arts. 32–36 (security, breach notification, data-protection impact assessments, prior consultation), taking into account the nature of the processing and the information available to Unifies. The materials at unifies.ai/security and unifies.ai/subprocessors form part of that assistance.
3.5. Personal data breach. Unifies will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data — by email to workspace owners' registered addresses and to any security contact Customer registers by emailing legal@unifies.ai. The notification will describe, to the extent then known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, likely consequences, measures taken or proposed, and a contact point, and Unifies will supplement it as information becomes available. Notification is not an acknowledgment of fault.
3.6. Records; compliance information. Unifies maintains records of its processing activities as required by GDPR Art. 30(2) and will make available to Customer information reasonably necessary to demonstrate compliance with GDPR Art. 28.
3.7. Government and law-enforcement requests. If Unifies receives a legally binding demand from a public authority for Customer Personal Data, Unifies will — unless legally prohibited — redirect the requester to Customer, promptly notify Customer, use reasonable efforts to challenge overbroad or inappropriate demands, and disclose only the minimum data required.
4. Subprocessors
4.1. General authorization. Customer authorizes Unifies to engage the subprocessors listed at unifies.ai/subprocessors (Annex III incorporates that list).
4.2. Flow-down. Unifies will ensure that each subprocessor is bound by a written agreement imposing data-protection obligations that provide at least the level of protection required by this DPA, and remains liable to Customer for the subprocessor's performance.
4.3. Changes. Unifies will update the subprocessor page, and give Customer notice by email to workspace owners, at least 30 days before a new subprocessor first processes Customer Personal Data. Where a replacement is reasonably necessary for security or service continuity, Unifies may engage it without advance notice, notifying Customer as soon as reasonably practicable and in any event within 10 days, with the objection right below preserved; for transfers governed by the SCCs, the notice period in Clause 9(a) governs to the extent it requires more. Customer may object within the notice period on reasonable, documented data-protection grounds; the parties will discuss in good faith, and if the objection is not resolved, Customer may terminate the affected portion of the Service (or, if not severable, the Agreement) with a pro-rata refund of prepaid fees for the terminated portion. Customers may also request notification at an additional address by emailing legal@unifies.ai with the subject “subprocessor updates”.
5. International transfers
5.1. Customer Personal Data is processed in the United States (Annex I.C).
5.2. EEA transfers. To the extent processing involves a transfer of personal data from the EEA to a country without an adequacy decision, the parties enter into the SCCs, Module Two (controller → processor) (or Module Three where Customer is a processor, with the Annexes adjusted accordingly in the countersigned copy), which are incorporated by reference with: Clause 7 (docking) included; Clause 9(a): Option 2 (general authorisation), 30 days' notice; Clause 11(a) optional redress mechanism: not included; Clause 13: the competent supervisory authority determined in accordance with Clause 13(a); Clause 17: Option 1, the law of Ireland; Clause 18(b): the courts of Ireland. Annexes I and II of the SCCs are completed by Annexes I and II of this DPA; Annex III of the SCCs is Annex III of this DPA. Acceptance of the Agreement constitutes execution of the SCCs by both parties as of the Agreement's effective date.
5.3. UK transfers. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU SCCs (version B1.0) is incorporated; its Tables 1–3 are completed by the parties' details and Annexes I–III of this DPA, Table 4 is completed with “neither party”, and acceptance of the Agreement constitutes its execution.
5.4. Swiss transfers. For transfers subject to the Swiss FADP, the SCCs apply with the adaptations required by the FDPIC (references to the GDPR read as the FADP; the competent authority is the FDPIC; data subjects in Switzerland may enforce their rights in Switzerland).
5.5. If a required transfer mechanism is invalidated or a supplementary measure is required, the parties will cooperate in good faith to implement a lawful alternative.
6. CCPA / US state privacy laws
To the extent Customer Personal Data includes personal information governed by the CCPA or another US state privacy law under which Customer is a business/controller: Unifies acts as Customer's service provider/processor; Unifies will not sell or share Customer Personal Data; will not retain, use, or disclose it for any purpose other than performing the Service under the Agreement or as permitted by law; will not combine it with personal information from other sources except to perform the Service; will comply with applicable obligations and provide the same level of privacy protection as required of Customer; will notify Customer if it determines it can no longer meet these obligations; and grants Customer the right, upon reasonable notice, to take reasonable steps to stop and remediate unauthorized use. Unifies will assist with verifiable consumer requests as described in Section 3.3.
7. Audits
7.1. Unifies will make available the information reasonably necessary to demonstrate compliance with this DPA: this DPA, the security description at unifies.ai/security, the subprocessor list, written responses to reasonable security questionnaires (once per 12-month period, and additionally after a confirmed personal data breach affecting Customer Personal Data), and, for the infrastructure layer, the compliance reports its cloud provider makes available (for example, Google Cloud's SOC 2 and ISO reports — these are the cloud provider's certifications, not Unifies'). Unifies does not currently hold third-party certifications or audit reports of its own (no SOC 2, no ISO 27001, no penetration-test report); when such reports exist they will be offered under NDA and this section will be updated.
7.2. Where the information above is insufficient to demonstrate compliance, or where required by a supervisory authority, Customer (or an independent auditor bound to confidentiality, not a competitor of Unifies) may audit Unifies' compliance with this DPA, subject to: Customer first identifying in writing the specific compliance question the provided materials do not answer, and Unifies having a reasonable opportunity to answer in writing; 30 days' notice; at most once per 12-month period (except following a confirmed personal data breach affecting Customer Personal Data, or where a supervisory authority requires more); remote execution unless otherwise agreed; business hours; and a manner that does not compromise other customers' data or the Service's security. For Customers on the Free plan, Customer bears all costs of an audit under this Section; otherwise each party bears its own costs, and Customer reimburses Unifies' reasonable time at Unifies' then-standard professional-services rates for audit effort exceeding one business day, except for audits required by a supervisory authority or following such a breach. Audit findings are Confidential Information. This Section does not limit any audit right mandatorily granted by the SCCs.
8. Return and deletion
8.1. During the term, Customer can export Customer Personal Data through the Service (account export; receipt and report exports; transcripts in the room record). Unifies will provide reasonable assistance with retrieval of remaining Customer Personal Data on written request.
8.2. Upon closure of a workspace, the workspace enters a 30-day retention window during which Customer may reopen it (including to complete exports). After that window, Unifies permanently deletes the workspace's Customer Personal Data from live systems through its purge process, and instructs its subprocessors to delete residual copies they hold for Unifies. Upon termination of the Agreement, Unifies will close any remaining Customer workspaces, and the same process applies.
8.3. Deletion from backups occurs as backup copies expire on the rolling backup schedule (currently up to 7 daily database snapshots plus a point-in-time-recovery log window); until expiry, backup copies remain protected by Annex II and are used only for restoration. If a restoration re-introduces deleted data, Unifies will re-apply the deletion.
8.4. Unifies may retain data it must keep under applicable law, and de-identified, aggregated data that no longer identifies a data subject — in each case subject to the Agreement's restrictions on cross-customer benchmarking (Terms, Section 6.4).
8.5. Records documented as workspace evidence survive an individual user's deletion in pseudonymized form (“Deleted user”), as described in the Privacy Policy; a workspace-level purge under Section 8.2 removes them entirely.
9. Liability; term
Liability under this DPA (including the SCCs, to the extent permitted) is subject to the limitations and exclusions of the Agreement; nothing in this Section limits a data subject's rights against either party under the SCCs. This DPA runs for the term of the Agreement plus the deletion periods of Section 8.
Annex I — Description of processing
A. Parties. Data exporter: Customer (contact: workspace owner's registered email); role: controller (or processor, where Module Three applies); activities: use of the Service for its internal business purposes. Data importer: Unifies AI, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA; legal@unifies.ai; activities: provision of the Service; role: processor.
B. Processing description.
- Subject matter and nature: meeting capture (live transcription via a bot participant; no audio or video is retained), capture of content Customer forwards or connects from other sources (such as forwarded email), AI analysis (summaries, decisions, commitments, task drafts, embeddings for search), task creation and status reconciliation in Customer-authorized tools, execution records and per-person follow-through standings, digests and notifications, sharing artifacts Customer chooses to create, and related storage, security, and administration.
- Duration: the term of the Agreement plus the retention and deletion windows in Section 8.
- Purpose: providing the Service to Customer.
- Categories of data subjects: Customer's users and workspace members (including members imported from connected tools who have not signed up); meeting participants, including external guests; individuals referenced in meetings and messages; recipients of invitations, recaps, and notifications.
- Categories of personal data: identification and contact data (names, emails, avatars, roles); meeting content (transcripts, speaker labels, timestamps); derived work records (commitments, attributions, task metadata, follow-through standings); calendar/scheduling data including attendee emails; authentication artifacts for connected services (OAuth tokens, encrypted); usage and device data (session IPs, device info) for security.
- Special categories: none intended; the Agreement (Section 4.4) prohibits Customer from deliberately submitting special-category data absent a separate written agreement. Incidental capture of such data in meeting speech is processed only as part of the transcripts and is subject to the same protections and deletion.
- Frequency: continuous, as instructed through the Service.
C. Processing location and competent authority. Customer Personal Data is processed in the United States (Google Cloud, us-central1). For SCC Clause 13, the competent supervisory authority is determined in accordance with Clause 13(a) (for an exporter established in an EEA member state, that member state's authority; for an exporter not established in the EEA, the authority of the member state of its Art. 27 representative or, absent one, of the member state where the relevant data subjects are).
Annex II — Technical and organizational measures
Unifies implements and maintains the following measures for Customer Personal Data, and will not materially decrease the overall level of protection they provide (Section 3.2). Rows marked (environment) describe the deployed cloud environment.
- Encryption in transit. TLS for all client–service traffic with forced HTTPS redirect and HSTS.
- Encryption at rest. Databases and object storage are encrypted at rest with cloud-provider managed keys. In addition, the application encrypts stored OAuth tokens and outbound-webhook secrets at the application layer (Fernet, AES-CBC + HMAC-SHA-256, with key-rotation support).
- Credential storage. API keys, SCIM tokens, sign-in codes and links, one-tap response tokens, verification codes, export tokens, and refresh tokens are stored hashed (sign-in codes keyed-HMAC); one-time secrets are single-use with expiry. Public share-link tokens are high-entropy random values that their owners can revoke at any time.
- Access control and tenant isolation. Server-side authentication on every API request; workspace-scoped authorization with owner/admin role gates; uniform not-found responses to prevent tenant probing; a structural test suite that classifies every route's authorization, plus behavioral cross-tenant tests.
- Session security. Short-lived access tokens (currently 15 minutes) with rotating refresh tokens (currently 30 days), HttpOnly/Secure/SameSite cookies, server-side revocation (per-token, per-session, per-user), and daily purge of expired credentials.
- Application-boundary controls. Signature verification on inbound provider webhooks; HMAC-signed outbound webhooks restricted to public HTTPS endpoints with SSRF protections; allow-listed, length-capped fields on data written to Customer-connected tools; injection fencing and bounding of untrusted meeting content before AI calls; CSV-export formula neutralization; security headers (CSP, HSTS, frame denial, nosniff) on responses; closed CORS allow-list; per-credential idempotency scoping; rate limits on authentication, export, and API-key surfaces.
- (environment) Network architecture. Private compute nodes; database reachable only over a private network (no public IP); default-deny ingress network policies; secrets held in a managed secret store and delivered via workload identity (no long-lived exported keys).
- Logging and audit-log integrity. Structured request logging with request IDs. A per-workspace, hash-chained, tamper-evident audit log of administrative and security-relevant actions, verified end-to-end daily. Sensitive fields (tokens, emails, message content) are automatically scrubbed at telemetry egress points (error reporting and product analytics).
- Data-subject tooling. Self-service account export (single-use, expiring download; credentials stripped); self-service account deletion executing a multi-phase, durable erasure across all modules (transcripts deleted, identifiers pseudonymized in retained workspace evidence, sessions revoked); profile self-correction and receipt-level attribution-contest tooling; per-workspace retention windows with automated daily purge of transcripts and embeddings; workspace-level purge on closure.
- (environment) Availability and recovery. Highly available managed database (regional), daily automated backups with point-in-time recovery, deletion protection on the database instance; container orchestration with health checks and automated restarts.
- Development controls. Changes are integrated through version control, with an automated server-side test suite (including the security tests above) gating merges in continuous integration; dependency lockfiles; infrastructure as code.
- Organizational measures. Access to production data is limited to authorized personnel bound by confidentiality obligations; administrative interfaces are restricted to an explicit allowlist of named staff accounts.
Not currently implemented (the same list is published at unifies.ai/security and maintained in one canonical register): third-party certifications or audit reports of Unifies' own; penetration testing; formal 24×7 monitoring and alerting; enforced multi-factor authentication; cross-region backup replication; verified restore drills; an EU data region; an uptime SLA.
Annex III — Subprocessors
The authorized subprocessors of Customer Personal Data, with processing purposes, data categories, and regions, are listed at unifies.ai/subprocessors (incorporated here as of the effective date): Google Cloud Platform (hosting, US); Recall.ai (meeting capture and transcription, US); OpenAI (AI analysis, US); Resend (email delivery, US). A subprocessor may engage its own subprocessors under data-protection terms consistent with this DPA. For transparency: Stripe processes Unifies' own billing data (for which Unifies is the controller, as described in the Privacy Policy) and does not process Customer Personal Data; the same is true of the conditional observability vendors identified on the subprocessor page if and when enabled.
This published DPA governs customers without a separately negotiated DPA.