Legal

Data Processing Agreement

This DPA governs how TDA Group processes personal data on behalf of customers under the GDPR, Vietnam's Personal Data Protection Decree (Nghị định 13/2023/NĐ-CP), and other applicable data protection laws (including Japan's APPI and Korea's PIPA).

Effective: 15 June 2026 Last updated: 2 July 2026

Note: This is a working draft for beta. Sections marked [to confirm] require final details from TDA and legal review before production use.

1. Definitions

"Controller" means the customer entity that determines the purposes and means of processing personal data.

"Processor" means TDA Group, which processes personal data on behalf of the Controller.

"Personal Data" has the meaning given in the GDPR and applicable data protection laws.

"Service" means the ScribX meeting intelligence platform at scribx.app.

2. Subject matter and duration

This DPA applies to the processing of Personal Data by TDA Group in connection with the provision of the Service under the Terms of Service. It remains in force for the duration of the service agreement and terminates automatically upon account deletion.

3. Processing details

ItemDetails
NatureCollection, storage, analysis (transcription, translation, summarization), retrieval and deletion of meeting audio and derived text data.
PurposeProviding real-time transcription, AI translation, meeting notes, CMS storage and search as described in the Service.
Data typesVoice recordings (transient); transcript text; AI-generated summaries and action items; meeting metadata (date, duration, participants); account identifiers.
Data subjectsMeeting participants (employees, contractors and guests of the Controller).
RetentionAudio: deleted after processing. Transcripts and notes: for the life of the account. Audit logs: minimum 7 years.
✦ Zero data retention at sub-processors

Meeting audio, video, transcripts and summaries are not stored by any third-party vendor after processing, are not accessed by any vendor once the service is completed, and are never used to train AI models. This is enforced by contract with every sub-processor.

4. Processor obligations

TDA Group shall:

  • Process Personal Data only on documented instructions from the Controller (i.e., as described in this DPA and the Terms of Service).
  • Ensure that persons authorized to process the data are bound by appropriate confidentiality obligations.
  • Implement the technical and organizational security measures described in Section 8.
  • Not engage sub-processors without prior general authorization from the Controller (subject to Section 5).
  • Assist the Controller in responding to data subject rights requests, to the extent reasonably possible.
  • Delete or return all Personal Data upon termination of the service agreement.
  • Provide the Controller with information necessary to demonstrate compliance with this DPA.

5. Sub-processors

The Controller provides general authorization for TDA Group to engage the following categories of sub-processors. We will notify the Controller of any changes with at least 14 days' notice.

Sub-processorPurposeLocation
Stripe, Inc.Billing and paymentsUnited States / global
Cloud infrastructure providerHosting, storage, computeAvailable on request
Speech-to-text providerAudio transcriptionAvailable on request
AI / LLM providerTranslation and summarizationAvailable on request
Analytics providerProduct analytics (anonymized)Available on request
Email delivery providerTransactional emailAvailable on request

The specific vendor within each category is available on request at support@scribx.app and the full, up-to-date list will be published before general availability.

6. Data subject rights

If TDA Group receives a data subject request relating to the Controller's data, it will promptly notify the Controller and take no action without the Controller's instruction, except as required by law. The Controller is responsible for responding to data subjects within applicable statutory timescales.

7. International data transfers

Where Personal Data is transferred outside the EEA, UK or other jurisdiction with adequacy decisions, TDA Group will ensure appropriate safeguards are in place, including [to complete — Standard Contractual Clauses / adequacy decision / BCRs as applicable].

8. Technical and organizational security measures

  • Encryption in transit: TLS 1.2 or higher for all data in transit.
  • Encryption at rest: AES-256 for all stored data.
  • Access control: Role-based access; multi-factor authentication for all administrative access.
  • Audit logging: Comprehensive logs of data access and modifications, retained 7 years.
  • Vulnerability management: Regular security testing and prompt patching of critical vulnerabilities.
  • Incident response: A documented plan with defined response timescales.
  • Employee training: Annual data protection and security awareness training for all staff with data access.

9. Data breach notification

In the event of a Personal Data breach, TDA Group shall notify the Controller without undue delay and in any event within 72 hours of becoming aware. The notification will include the nature of the breach, data affected, likely consequences and measures taken or proposed.

10. Audit rights

The Controller may, on reasonable notice (minimum 30 days) and at its own cost, audit TDA Group's compliance with this DPA, up to once per year. TDA Group may satisfy this obligation by providing a current third-party audit report (e.g., SOC 2 Type II) [to complete — once available].

11. Biometric data (BIPA / CUBI compliance)

Where speaker identification features process voice characteristics that qualify as biometric identifiers under applicable law (including Illinois BIPA, Texas CUBI or similar), TDA Group:

  • Treats voiceprint data as sensitive personal data subject to heightened protection.
  • Does not sell, lease, trade or profit from biometric identifiers or information.
  • Destroys biometric data within the earlier of: (a) when the purpose for collection is fulfilled; or (b) 3 years from last interaction, unless a shorter period is required by law.
  • Contractually prohibits all sub-processors from retaining biometric data after processing.

The Controller is responsible for obtaining all required consents and providing all required notices to data subjects before enabling speaker identification features.

12. Termination

Upon termination of the service agreement, TDA Group shall, at the Controller's choice, delete or return all Personal Data within 30 days, and certify in writing that it has done so, unless retention is required by law.

13. Contact

Data Protection inquiries:
TDA Group (Công ty Cổ phần công nghệ TDA)
Hà Nội (HQ): Tầng 2, Tòa nhà Richy, 5 Nguyễn Xuân Nham, Yên Hòa, Hà Nội, Việt Nam
Đà Nẵng: Tầng 6, Tòa nhà Trực Thăng Miền Trung, Nguyễn Văn Linh, Hòa Cường, Đà Nẵng, Việt Nam
Tokyo: 5F, Tokyo Yusei Building, Iwamotocho 1-5-8, Chiyoda-ku, Tokyo, Japan
Email: support@scribx.app