Vexavexa

Data Processing Addendum

Last updated: September 5, 2026

Parties

Controller = Customer. Processor = Vexa.ai Inc.

Subject Matter & Duration

Processing of meeting/transcript data and account metadata for the term of your subscription.

Nature & Purpose

Provision of real-time transcription and related support, security, and billing operations.

Types of Data

Meeting metadata, transcript text, timestamps, user/account identifiers, and meeting audio recordings.

Recording is enabled by default. Controller can disable it per meeting by sending recording_enabled: false on the bot request, in which case no recording is stored for that meeting. Where recording is enabled, the audio is stored in Processor's object storage (see Annex I).

Meeting audio is transmitted to Cloudflare Workers AI for speech-to-text on every meeting — see /legal/subprocessors.

Data Subjects

Customer's authorized users and meeting participants.

Processor Obligations

  1. Process only on documented instructions from Controller.
  2. Confidentiality for personnel with access; least-privilege.
  3. Security measures (see Annex II).
  4. Assist with data subject requests and DPIAs. Erasure is currently actioned manually on request to info@vexa.ai: the self-service delete endpoint removes a meeting only before the bot starts and does not erase completed transcripts or recordings. Self-service erasure of completed meeting data is in development.
  5. Notify without undue delay of personal data breach (aim ≤72h where feasible) with details and mitigation steps.
  6. Delete or return personal data at end of services (Controller's choice), subject to legal holds.
  7. Make available information to demonstrate compliance; reasonable audits once/year on notice.

Sub-processing

Authorized per /legal/subprocessors. Processor must flow down equivalent obligations and remain liable.

International Transfers

EU SCCs (Module 2: Controller→Processor) and UK IDTA/Addendum are incorporated by reference and apply to non-EEA/UK transfers; supplementary measures as appropriate.

Liability & Indemnity

Each party's liability under this DPA is limited as per the Terms.

Annex I – Details of Processing

Subject matter, duration, nature, purpose, types of data and categories of data subject are as described above.

Processing locations. Transcripts, meeting metadata, account data and stored recordings are hosted in Seattle, Washington, USA (Akamai Connected Cloud / Linode, region us-sea): Kubernetes cluster, managed PostgreSQL database and object-storage buckets. Meeting audio is additionally processed by Cloudflare Workers AI for speech-to-text. Sub-processors and their roles are listed at /legal/subprocessors.

Annex II – Security Measures (summary)

See /legal/security.

Annex III – Sub-processors

See /legal/subprocessors.

Contact

For questions about this DPA, please contact us at: info@vexa.ai