Legal

Data Processing Agreement

This DPA governs how TDA Group processes personal data on behalf of customers under the GDPR, Vietnam's Personal Data Protection Decree (Nghị định 13/2023/NĐ-CP), and other applicable data protection laws (including Japan's APPI and Korea's PIPA).

Effective: 15 June 2026 Last updated: 29 September 2026

1. Definitions

"Controller" means the customer entity that determines the purposes and means of processing personal data.

"Processor" means TDA Group, which processes personal data on behalf of the Controller.

"Personal Data" has the meaning given in the GDPR and applicable data protection laws.

"Service" means the ScribX meeting intelligence platform at scribx.app.

2. Subject matter and duration

This DPA applies to the processing of Personal Data by TDA Group in connection with the provision of the Service under the Terms of Service. It remains in force for the duration of the service agreement and terminates automatically upon account deletion.

3. Processing details

ItemDetails
NatureCollection, storage, analysis (transcription, translation, summarization), retrieval and deletion of meeting audio and derived text data.
PurposeProviding real-time transcription, AI translation, meeting notes, CMS storage and search as described in the Service.
Data typesMeeting audio and video recordings (unless the Controller turns recording off); transcript text; AI-generated summaries and action items; meeting metadata (date, duration, participants); account identifiers.
Data subjectsMeeting participants (employees, contractors and guests of the Controller).
RetentionAudio and video recordings: for the retention period of the Controller's plan (Free 30 days, Pro and Team 90 days, Enterprise as agreed in contract) or a shorter period set by the Controller, then deleted automatically. Transcripts and notes: until deleted by the Controller. Audit logs: minimum 7 years.
✦ No training on your data at sub-processors

Meeting audio, transcripts and summaries sent to sub-processors are never used to train AI models. The speech-to-text provider does not store real-time audio or transcripts; files sent for batch transcription are deleted by TDA Group once processed. The AI provider processes each request under a contractual training restriction. Recordings are stored only in the storage operated for ScribX, under the retention described in Section 3.

4. Processor obligations

TDA Group shall:

  • Process Personal Data only on documented instructions from the Controller (i.e., as described in this DPA and the Terms of Service).
  • Ensure that persons authorized to process the data are bound by appropriate confidentiality obligations.
  • Implement the technical and organizational security measures described in Section 8.
  • Not engage sub-processors without prior general authorization from the Controller (subject to Section 5).
  • Assist the Controller in responding to data subject rights requests, to the extent reasonably possible.
  • Delete or return all Personal Data upon termination of the service agreement.
  • Provide the Controller with information necessary to demonstrate compliance with this DPA.

5. Sub-processors

The Controller provides general authorization for TDA Group to engage the following sub-processors. We will notify the Controller of any changes with at least 14 days' notice.

Sub-processorPurposeLocation
SonioxSpeech-to-text and real-time translationJapan
Google LLC (Google Cloud Vertex AI)Summarization and translationJapan (Tokyo)
Cloudflare, Inc. (R2)Storage of audio and video recordingsAvailable on request
Amazon Web Services, Inc. (Amazon SES)Transactional emailJapan (Tokyo)
Stripe, Inc.Billing and paymentsUnited States / global
payOSPayments in VietnamVietnam

The ScribX platform, database, speaker identification and self-hosted speech recognition run on servers owned and operated by TDA Group in Vietnam and are not sub-processors. Questions about this list can be sent to support@scribx.app.

6. Data subject rights

If TDA Group receives a data subject request relating to the Controller's data, it will promptly notify the Controller and take no action without the Controller's instruction, except as required by law. The Controller is responsible for responding to data subjects within applicable statutory timescales.

7. International data transfers

Where Personal Data is transferred outside the EEA, UK or other jurisdiction with adequacy decisions, TDA Group will ensure appropriate safeguards are in place, including the Standard Contractual Clauses incorporated in Google Cloud's Data Processing Addendum and the data processing agreement between TDA Group and Soniox.

8. Technical and organizational security measures

  • Encryption in transit: TLS 1.2 or higher for all data in transit.
  • Encryption at rest: AES-256 for all stored data.
  • Access control: Role-based access; multi-factor authentication for all administrative access.
  • Audit logging: Comprehensive logs of data access and modifications, retained 7 years.
  • Vulnerability management: Regular security testing and prompt patching of critical vulnerabilities.
  • Incident response: A documented plan with defined response timescales.
  • Employee training: Annual data protection and security awareness training for all staff with data access.

9. Data breach notification

In the event of a Personal Data breach, TDA Group shall notify the Controller without undue delay and in any event within 72 hours of becoming aware. The notification will include the nature of the breach, data affected, likely consequences and measures taken or proposed.

10. Audit rights

The Controller may, on reasonable notice (minimum 30 days) and at its own cost, audit TDA Group's compliance with this DPA, up to once per year. TDA Group may satisfy this obligation by providing its current ISO/IEC 27001 certificate, whose scope covers the Service.

11. Biometric data (BIPA / CUBI compliance)

Where speaker identification features process voice characteristics that qualify as biometric identifiers under applicable law (including Illinois BIPA, Texas CUBI or similar), TDA Group:

  • Treats voiceprint data as sensitive personal data subject to heightened protection.
  • Does not sell, lease, trade or profit from biometric identifiers or information.
  • Destroys biometric data within the earlier of: (a) when the purpose for collection is fulfilled; or (b) 3 years from last interaction, unless a shorter period is required by law.
  • Contractually prohibits all sub-processors from retaining biometric data after processing.

The Controller is responsible for obtaining all required consents and providing all required notices to data subjects before enabling speaker identification features.

12. Termination

Upon termination of the service agreement, TDA Group shall, at the Controller's choice, delete or return all Personal Data within 30 days, and certify in writing that it has done so, unless retention is required by law.

13. Contact

Data Protection inquiries:
TDA Group (Công ty Cổ phần công nghệ TDA)
Hà Nội (HQ): Tầng 2, Tòa nhà Richy, 5 Nguyễn Xuân Nham, Yên Hòa, Hà Nội, Việt Nam
Đà Nẵng: Tầng 6, Tòa nhà Trực Thăng Miền Trung, Nguyễn Văn Linh, Hòa Cường, Đà Nẵng, Việt Nam
Tokyo: 5F, Tokyo Yusei Building, Iwamotocho 1-5-8, Chiyoda-ku, Tokyo, Japan
Email: support@scribx.app