1. Subject matter, nature and duration
The Customer (Controller) entrusts [ • ] (Processor) with processing personal data to the extent necessary to provide the services described in the Terms of Service.
The purpose is sales-conversation practice and grading, and team progress reporting. Processing lasts for the term of the agreement and ends as set out in section 9.
2. Categories of data and data subjects
- Categories of data subjects
- The Controller's employees and contractors using the Platform (sales reps, managers, trainers) and people taking part in recorded sales conversations, including representatives of the Controller's customers and prospects.
- Categories of data
- Identification and contact data, employment and team-role data, voice and speech content captured in a recording, conversation transcripts, grading results and progress information, and coaching-assistant conversations.
- Excluded data
- This agreement does not cover special categories of data (Art. 9 GDPR) or criminal-conviction data (Art. 10 GDPR). The Controller undertakes not to enter them.
3. Processing on documented instructions
We process data only on the Controller’s documented instructions. The Terms of Service, this agreement and actions taken by Users in the Platform constitute such instructions.
If we consider an instruction to infringe the GDPR or other data protection law, we inform the Controller without delay and may suspend it until the matter is resolved.
4. Confidentiality
Access is granted only to people who need it and who are bound by confidentiality under contract or statute. That obligation survives the end of their engagement.
5. Technical and organisational measures (Art. 32 GDPR)
- Encryption in transit (TLS) and encryption at rest by the infrastructure provider.
- Separation of data between organisations enforced at the database level (Row Level Security), independent of application logic.
- Role-based access control; production access restricted and recorded in an administrative audit log.
- Audio files reachable only through signed URLs that expire after one hour.
- Database backups with point-in-time recovery.
- Error and security-event monitoring; automated tests covering data isolation rules.
- Separation of production and test environments; production data is not copied into test environments.
6. Sub-processing
The Controller gives general authorisation for the sub-processors listed below. These are the same providers named in the Privacy Policy — one shared list, so the two cannot drift apart.
| Sub-processor | Purpose | Data scope | Location |
|---|---|---|---|
| Supabase | Database, authentication, audio file storage | All account data, recordings, transcripts, grading results | European Union (Ireland) |
| Vercel | Application hosting | Data in transit, server logs | European Union (Dublin) |
| AssemblyAI | Transcription and speaker diarization of recordings | Audio recordings | United States |
| Anthropic | Conversation grading, rep-speaker detection, manager copilot, industry trends | Transcripts, company profile, aggregated team results | United States |
| Google (Gemini) | Voice conversation with the practice bot, coaching chat, persona and scenario generation | Practice-conversation voice and transcript, company profile, chat messages | European Union / United States |
| OpenAI | Company website analysis during onboarding, coach cover imagery | Public company website content, training material descriptions | United States |
| Recall.ai | Joining and recording online meetings at the user's instruction | Online meeting audio, meeting metadata | United States |
| Resend | Transactional email delivery | Email address, name, notification content | United States |
| Stripe | Payment and subscription processing | Billing data, email address (Stripe is a separate controller of payment data) | European Union / United States |
We give at least 30 days’ notice before adding or changing a sub-processor. The Controller may object on reasonable grounds within that period; if no solution is found, the Controller may terminate without charge for the unused period.
Every sub-processor is bound by data protection obligations no less strict than those in this agreement, and we remain liable for their acts as for our own.
7. Assistance to the Controller
- We assist the Controller in handling data-subject requests. A request addressed directly to us is forwarded to the Controller without undue delay; we do not answer it ourselves.
- The Platform supports self-service export and deletion, which in most cases lets the Controller fulfil a request without involving us.
- We assist with data protection impact assessments (DPIA) and prior consultation with a supervisory authority, to the extent of information in our possession.
8. Personal data breaches
We notify the Controller of a personal data breach without undue delay and no later than 48 hoursafter becoming aware of it. The notification covers the nature of the breach, its approximate scope, likely consequences, and the measures taken and proposed. Notifying the supervisory authority remains the Controller’s obligation.
9. Deletion or return of data
After the services end, the Controller has 30 days to export their data. After that we delete it, including copies, except data we are required by law to keep (billing records — 5 years). Backups expire according to their rotation cycle.
10. Demonstrating compliance and audits
We make available the information necessary to demonstrate compliance with Art. 28 GDPR. The Controller may audit no more than once a year, on 30 days’ notice, during working hours and without disrupting the service. An audit may not extend to other customers’ data. More frequent audits are permitted after a confirmed breach or at a supervisory authority’s request.
11. Transfers outside the EEA
Some sub-processors process data in the United States. Transfers rely on Standard Contractual Clauses approved by the European Commission, together with a transfer impact assessment and, where applicable, the provider’s Data Privacy Framework participation. The database, recordings and application hosting stay within the European Union.
12. Final provisions
Matters not covered here are governed by the Terms of Service and the GDPR. In case of conflict, this agreement prevails over the Terms of Service on data protection matters. The Polish version is binding; this English version is informational. Contact for processing matters: [ • ].