Legal

Meetopio — Data Processing Agreement (DPA)

Version: 1.0 · Effective on acceptance of the Meetopio Terms of Service

This DPA forms part of the Terms of Service between the customer ("Controller" / "Data Fiduciary," "you") and Roving Rock Pte. Ltd. ("Processor," "Meetopio") and governs Meetopio's processing of personal data on your behalf.

1. Roles

For the lead and event personal data you capture using the Service, you are the Controller / Data Fiduciary and Meetopio is the Processor. You determine the purposes and means; we process only on your documented instructions (which include your configured use of the Service and these terms).

2. Scope of processing

  • Subject matter & duration: processing of personal data for the term of your use of the Service.
  • Nature & purpose: capturing, transcribing, storing, analysing (lead briefs, qualification scores) and generating draft follow-ups from event conversations, to provide the Service.
  • Types of personal data: contact details (name, email, phone, job title, company), voice recordings (deleted after transcription), transcripts, notes, card/badge images, and derived analysis.
  • Categories of data subjects: the leads and event contacts you capture, and your team users.

3. Our obligations as Processor

We will: (a) process personal data only on your documented instructions, including for transfers, unless required by law (and then we'll tell you unless legally prohibited); (b) ensure people authorised to process it are under confidentiality; (c) implement appropriate technical and organisational security measures (§5); (d) respect the conditions for engaging sub-processors (§4); (e) assist you, taking into account the nature of processing, to respond to data-subject requests; (f) assist you with security, breach notification, and data-protection impact assessments; (g) delete or return personal data at the end of the service as you choose (§6); and (h) make available information reasonably necessary to demonstrate compliance and allow for audits (§7).

4. Sub-processors

You authorise Meetopio to engage sub-processors to provide the Service. Each is bound by data- protection obligations no less protective than this DPA. Our current sub-processors are:

| Sub-processor | Purpose | |---|---| | Supabase | Cloud hosting, database and file storage | | Google (Gemini / Vertex, Google Search grounding) | AI transcription support and language analysis | | Deepgram | Speech-to-text transcription | | RevenueCat | Subscription and purchase management | | Resend | Transactional email (account and security messages) | | Vercel | Web application hosting | | HubSpot | CRM integration and lead export (where you enable it) |

We will give you advance notice of any new or replacement sub-processor and a chance to object on reasonable data-protection grounds. (Anticipated additions as those rails go live: Apple (App Store billing), Stripe and Razorpay (payment processing).)

5. Security measures

We maintain measures appropriate to the risk, including: encryption of personal data in transit; tenant isolation enforced at the database layer so each customer's data is accessible only to that customer's authorised users; access controls and least-privilege for our systems; deletion of voice recordings once transcribed; and logging of deletions. We review and improve these over time.

6. Return and deletion

On termination or your request, we will delete or return the personal data we process on your behalf, and delete existing copies, except where retention is required by law. Deletion removes your personal data and stored recordings, and cascades to derived data (transcripts, analysis, embeddings, cached enrichment); where any derived artifact is not yet removed automatically, we will delete it on request.

7. Audits

We will provide information reasonably necessary to demonstrate compliance with this DPA and, on reasonable notice and confidentiality terms, respond to a reasonable audit request, using third-party reports or questionnaires where available.

8. Data-subject requests

If a data subject contacts us directly about data we process for you, we will refer them to you and assist you in responding, as required by law.

9. Personal-data breach

We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you reasonably need to meet your own notification obligations.

10. International transfers

Where providing the Service involves transferring personal data across borders, we will use safeguards required by applicable law (such as Standard Contractual Clauses), to be appended for EU/UK data where required.

11. Your obligations as Controller

You warrant that you have a lawful basis to capture each lead's data, that you have informed the people you capture and obtained any legally required consent (including for recording), and that your instructions to us comply with applicable law.

12. General

This DPA is governed by the laws of Singapore. If any conflict arises between this DPA and the Terms of Service on data-protection matters, this DPA prevails. Contact: privacy@meetopio.com.