Data Processing Addendum
Last updated: December 6, 2025
Parties
Controller = Customer. Processor = Vexa.ai Inc.
Subject Matter & Duration
Processing of meeting/transcript data and account metadata for the term of your subscription.
Nature & Purpose
Provision of real-time transcription and related support, security, and billing operations.
Types of Data
Meeting metadata, transcript text, timestamps, user/account identifiers; no recordings stored by default.
Data Subjects
Customer's authorized users and meeting participants.
Processor Obligations
- Process only on documented instructions from Controller.
- Confidentiality for personnel with access; least-privilege.
- Security measures (see Annex II).
- Assist with data subject requests and DPIAs.
- Notify without undue delay of personal data breach (aim ≤72h where feasible) with details and mitigation steps.
- Delete or return personal data at end of services (Controller's choice), subject to legal holds.
- Make available information to demonstrate compliance; reasonable audits once/year on notice.
Sub-processing
Authorized per /legal/subprocessors. Processor must flow down equivalent obligations and remain liable.
International Transfers
EU SCCs (Module 2: Controller→Processor) and UK IDTA/Addendum are incorporated by reference and apply to non-EEA/UK transfers; supplementary measures as appropriate.
Liability & Indemnity
Each party's liability under this DPA is limited as per the Terms.
Annex I – Details of Processing
As described above.
Annex II – Security Measures (summary)
See /legal/security.
Annex III – Sub-processors
See /legal/subprocessors.
Contact
For questions about this DPA, please contact us at: info@vexa.ai
Address:
Vexa.ai Inc.
16192 Coastal Highway
Lewes, DE 19958
Sussex County, DE