Data Processing Agreement
Effective date: July 2026 · Last updated: July 2026
This Data Processing Agreement (“DPA”) is incorporated into and forms part of the MeetBlink Terms of Service (“Agreement”). It applies where MeetBlink processes personal data on behalf of a Customer subject to data protection laws including the GDPR, UK GDPR, Swiss DPA, or equivalent legislation. If you require a signed DPA for enterprise procurement, contact legal@meetblink.app.
1. Definitions
Terms not defined here have the meanings given in the Agreement or applicable data protection law.
- “Controller” means the entity that determines the purposes and means of processing personal data. In this DPA, the Customer is the Controller.
- “Processor” means the entity that processes personal data on behalf of the Controller. In this DPA, MeetBlink is the Processor.
- “Sub-processor” means any third party engaged by MeetBlink to process personal data in connection with the Service.
- “Customer Data” means personal data submitted to the Service by or on behalf of the Customer, including meeting audio, transcripts, and account information.
- “GDPR” means the EU General Data Protection Regulation 2016/679, and “UK GDPR” means the GDPR as retained in UK law by the European Union (Withdrawal) Act 2018.
- “Standard Contractual Clauses” or “SCCs” means the European Commission’s standard contractual clauses for the transfer of personal data to third countries (Decision 2021/914).
2. Scope and Roles
This DPA applies to the processing of Customer Data by MeetBlink in connection with providing the Service. The Customer (as Controller) instructs MeetBlink (as Processor) to process Customer Data only for the purposes described in this DPA and the Agreement.
Where MeetBlink processes personal data for its own purposes as described in its Privacy Policy (e.g., service improvement analytics), MeetBlink acts as a Controller for that data.
3. Details of Processing
3.1 Subject Matter
Provision of the MeetBlink real-time conversation assistant service across desktop and mobile platforms, including transcription, AI-generated summaries, script generation, and communication coaching.
3.2 Duration
For the term of the Agreement plus any post-termination period required for secure deletion, which shall not exceed 90 days.
3.3 Nature and Purposes of Processing
- Receiving and temporarily processing audio streams for real-time speech-to-text transcription via streaming
- Recording and temporarily storing session audio for post-session speaker diarization via batch processing
- Speaker diarization (identifying and differentiating speakers from the full session recording)
- Generating AI summaries, speaking scripts, and coaching insights from transcripts
- Storing transcripts and AI outputs in the Customer’s account
- Providing real-time data sync to the Customer’s authenticated sessions
- Customer authentication and account management
3.4 Types of Personal Data
- Identity data: names, email addresses of account holders and conversation participants
- Audio recordings and derived voice data (potentially biometric), captured via system audio (desktop) and/or device microphone (desktop and mobile)
- Conversation transcripts and metadata (title, date, duration, conversation context)
- AI-generated summaries, scripts, and coaching insights
- Account credentials and authentication tokens
- Usage data (feature interactions, timestamps — not transcript content)
3.5 Categories of Data Subjects
- The Customer’s employees and contractors who use MeetBlink accounts
- Third-party conversation participants whose voice may be captured during recorded sessions (including meeting attendees, phone call participants, and persons present during in-person recordings)
4. MeetBlink’s Obligations as Processor
MeetBlink shall:
- Process Customer Data only on the documented instructions of the Customer (as set out in the Agreement and this DPA), unless required to do otherwise by applicable law, in which case MeetBlink shall inform the Customer of that legal requirement before processing (unless prohibited by law);
- Ensure that persons authorised to process Customer Data are subject to confidentiality obligations;
- Implement and maintain appropriate technical and organisational security measures as described in Section 7;
- Not engage Sub-processors without prior authorisation from the Customer (general authorisation is granted for Sub-processors listed in Section 6; the Customer will be notified of changes as set out there);
- Assist the Customer, taking into account the nature of processing, with appropriate technical and organisational measures to fulfil obligations to respond to data subject rights requests;
- Assist the Customer in ensuring compliance with obligations regarding security, breach notification, data protection impact assessments, and prior consultation;
- At the Customer’s choice, delete or return all Customer Data upon termination of the Agreement, and delete existing copies unless applicable law requires storage;
- Make available all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits conducted by the Customer or a mandated auditor, provided reasonable prior notice is given and audits do not unreasonably interfere with our operations.
5. Customer’s Obligations as Controller
The Customer is responsible for:
- Ensuring there is a valid legal basis for processing Customer Data (e.g., consent, legitimate interests, or contractual necessity);
- Obtaining all required consents from conversation participants prior to recording, including any consents required under wiretapping, privacy, or biometric data laws applicable to any participant’s jurisdiction — whether the recording takes place during a meeting, phone call, or in-person conversation;
- Providing adequate privacy notices to data subjects informing them that their conversations may be recorded and processed by an AI service (MeetBlink does not notify other participants on the Customer’s behalf);
- Ensuring that instructions to MeetBlink comply with applicable data protection law;
- Conducting any required data protection impact assessments (DPIAs) for high-risk processing activities.
6. Sub-processors
By accepting these Terms (or this DPA), the Customer grants MeetBlink general authorisation to engage the following Sub-processors. MeetBlink will notify the Customer at least 10 days before adding or replacing a Sub-processor by email or via the changelog at meetingai.com/changelog. The Customer may object to a new Sub-processor within 10 days; if the objection cannot be resolved, either party may terminate the Agreement without penalty.
| Sub-processor | Purpose | Country | Transfer Mechanism |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, real-time subscriptions | USA | SCCs + DPA |
| Deepgram, Inc. | Speech-to-text transcription and speaker diarization | USA | SCCs + DPA; zero data retention policy |
| OpenAI, L.L.C. | AI summaries, script generation, coaching insights | USA | SCCs + DPA; zero data retention API tier |
| Render Services, Inc. | Backend server hosting | USA | SCCs + DPA |
| Stripe, Inc. | Payment processing (billing data only) | USA / EU | SCCs + PCI DSS; EU data stays in EU |
MeetBlink enters into written data processing agreements with each Sub-processor that impose data protection obligations at least as protective as those in this DPA.
7. Security Measures
MeetBlink implements and maintains the following technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access:
Technical Measures
- TLS 1.2+ encryption in transit for all API and data transmission
- AES-256 encryption at rest for all database storage
- Row-Level Security (RLS) on all database tables — users can only access their own data
- Short-lived, scoped API tokens for third-party services (e.g., ephemeral Deepgram tokens generated per session — the raw API key is never transmitted to client applications)
- No transcript text or audio content in application logs — logs contain only session IDs and metadata
- Automated vulnerability scanning and dependency updates
- Access controls with principle of least privilege for MeetBlink staff
Organisational Measures
- Confidentiality obligations for all staff with access to Customer Data
- Access to production data restricted to essential personnel
- Incident response plan with defined escalation paths
- Regular review of security policies and procedures
Pseudonymisation and Minimisation
- Raw audio is deleted after post-session diarization is complete — it is never stored long-term
- Speaker labels use numeric identifiers (“Speaker 1”) rather than biometric profiles in stored transcripts
8. Personal Data Breach Notification
In the event of a personal data breach affecting Customer Data, MeetBlink will:
- Notify the Customer without undue delay, and in any event within 72 hours of becoming aware of the breach;
- Provide the Customer with sufficient information to allow them to fulfil any breach notification obligations to supervisory authorities and data subjects, including: (a) a description of the nature of the breach; (b) the categories and approximate number of data subjects and records affected; (c) likely consequences; and (d) measures taken or proposed to address the breach;
- Cooperate fully with the Customer in investigating and remediating the breach.
Breach notifications will be sent to the account email address on file. Enterprise customers may designate a specific security contact via security@meetblink.app.
9. Data Subject Rights
Where MeetBlink receives a request directly from a data subject exercising rights under applicable data protection law (access, rectification, erasure, portability, objection, restriction), MeetBlink will:
- Promptly notify the Customer of such request (to the extent permitted by law);
- Not respond to the request itself (except to inform the data subject to contact the Controller), unless instructed to do so by the Customer or required by applicable law;
- Provide reasonable assistance to the Customer in responding to such requests, including by making available Customer Data in a machine-readable format for portability requests.
The Customer may action data subject requests directly via the MeetBlink dashboard (session deletion) or by contacting privacy@meetblink.app.
10. International Data Transfers
MeetBlink is based in the United States. Processing of Customer Data by MeetBlink and its Sub-processors may involve transfers to the United States or other third countries outside the EEA, UK, or Switzerland.
For transfers from the EEA, UK, or Switzerland, MeetBlink relies on the European Commission’s Standard Contractual Clauses (Module 2: Controller-to-Processor, Commission Implementing Decision 2021/914) as the appropriate safeguard. By accepting this DPA, the parties are deemed to have entered into the applicable SCCs (with MeetBlink as “data importer” and the Customer as “data exporter”).
For UK transfers, the UK Addendum to the SCCs (as issued by the ICO) applies. For Swiss transfers, the Swiss Federal Act on Data Protection (revFADP) applies.
Enterprise customers requiring a fully executed SCC annex for their records should contact legal@meetblink.app.
11. Deletion and Return of Customer Data
Upon termination or expiry of the Agreement, at the Customer’s written request, MeetBlink will:
- Return: Provide an export of Customer Data (transcripts, summaries, session metadata) in JSON or CSV format within 30 days of request; or
- Delete: Securely delete all Customer Data within 90 days of termination, subject to applicable retention obligations (e.g., billing records retained for 7 years).
MeetBlink will provide written confirmation of deletion upon request.
Raw audio is not retained beyond the transcription and diarization pipeline — it is deleted after post-session speaker diarization is complete and is not available for export.
12. Audit and Compliance
MeetBlink shall make available, upon written request with at least 30 days’ notice, information reasonably necessary to demonstrate compliance with this DPA. This may include:
- Responses to security questionnaires
- Summary compliance reports or certifications (e.g., SOC 2 reports once obtained)
- Confirmation of Sub-processor DPAs
On-site or remote audits may be conducted no more than once per year, at the Customer’s expense, subject to reasonable confidentiality protections and without unreasonably disrupting MeetBlink’s operations. MeetBlink may satisfy audit requests via a qualified third-party auditor.
13. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions set out in the Agreement. Nothing in this DPA limits a party’s liability for: (a) fraud or wilful misconduct; or (b) obligations that cannot be limited by applicable law (e.g., GDPR Article 82 data subject compensation claims).
Where a data subject brings a claim against MeetBlink for damages attributable to the Customer’s instructions or breach of Controller obligations, the Customer shall indemnify MeetBlink for the portion of compensation attributable to the Customer.
14. Order of Precedence
In the event of a conflict between this DPA and the Agreement with respect to the processing of personal data, this DPA takes precedence. In the event of a conflict between this DPA and applicable SCCs with respect to international transfers, the SCCs take precedence.
15. Changes to This DPA
MeetBlink may update this DPA to reflect changes in law, regulatory guidance, or Sub-processor arrangements. Material changes will be communicated by email with at least 14 days’ notice. Enterprise customers may contact legal@meetblink.app to request a signed, versioned DPA for records.
16. Contact
For DPA-related enquiries, data protection questions, or to request a signed DPA:
Email: legal@meetblink.app
Security issues: security@meetblink.app
Also see our Privacy Policy and Terms of Service.