Data Processing Agreement
Version 0.0.9 — effective 8 September 2026
This Data Processing Agreement is concluded pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR). It forms part of the Terms of Service and applies automatically to every organisation that uses 1nsight; no separate signature is required. A counter-signed copy is available on request at franco.noack@1nsight.ai.
(1) The Customer — the organisation identified in the Order or account registration, acting as Controller; and
(2) Franco Noack, Theresienstr. 138, 80333 München, Germany — the provider of the 1nsight service, acting as Processor.
Each a "Party" and together the "Parties".
This Agreement forms part of, and is subject to, the 1nsight Terms of Service (the "Principal Agreement"). In the event of a conflict concerning the processing of personal data, this Agreement prevails. Terms not defined here have the meaning given in the GDPR.
1. Subject matter, nature, purpose and duration
1.1 Subject matter. The Processor processes personal data on behalf of the Controller in the course of providing 1nsight, a customer-context platform that captures conversations (through a meeting bot or a local recording), calendar metadata and in-product behavioural events, and organises them per customer on a provenance-linked timeline.
1.2 Nature and purpose. Recording, transcription, storage, organisation, structuring, enrichment, retrieval, display, erasure and deletion of the Controller Data, solely for the purpose of providing and supporting the service.
1.3 Duration. This Agreement applies for the term of the Principal Agreement and until the Processor has deleted or returned the Controller Data in accordance with Clause 9.
1.4 Details. The categories of data subjects and personal data are set out in Annex 1.
2. Roles of the Parties
2.1 The Processor acts as processor within the meaning of Art. 4(8) and Art. 28 GDPR in respect of the Controller Data, namely: recordings and transcripts of conversations the Controller captures; calendar metadata relating to those conversations; contact and company records derived from them; product and behavioural events concerning the Controller's own users and counterparties; and any other personal data contained in content the Controller chooses to capture. The Controller is the controller of the Controller Data.
2.2 The Processor acts as an independent controller in respect of Service Data, namely limited technical data concerning the operation of the Processor's own software, which the Processor processes for the purposes of operating, securing and supporting the service. Service Data comprises whether the desktop application is running, its version, operating system and processor architecture; whether a user is signed in; the status of the device permissions the application requires; whether a meeting was detected and whether it was matched to a calendar entry; and records that a support session was opened. Service Data contains no conversation content, no meeting titles or links and no user identifier, and is retained for 30 days. The Processor's processing of Service Data is described in its Privacy Policy and is carried out on the basis of Art. 6(1)(f) GDPR.
2.3 For the avoidance of doubt, capture-outcome records and erasure-audit entries are Controller Data and are processed under this Agreement.
3. Instructions
3.1 The Processor processes Controller Data only on the documented instructions of the Controller, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which the Processor is subject. In such a case the Processor informs the Controller of that legal requirement before processing, unless that law prohibits it on important grounds of public interest (Art. 28(3)(a) GDPR).
3.2 This Agreement, the Principal Agreement, and the configuration the Controller makes within the service — including recording method, processing region, retention period and connected third-party sources — constitute the Controller's documented instructions.
3.3 The Processor informs the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other Union or Member State data-protection provisions (Art. 28(3), second subparagraph, GDPR).
4. Obligations of the Controller
4.1 The Controller is responsible for the lawfulness of the processing it instructs, including for having a valid legal basis for recording conversations and for providing the information required by Arts. 13 and 14 GDPR to participants, including external participants.
4.2 The Controller determines which conversations are recorded. The Processor makes available mechanisms to support lawful recording — a visibly identified recording bot in bot mode, a per-conversation control to decline recording, and a server-side gate that refuses to issue a recording token for a conversation marked as declined — but these mechanisms support the Controller's obligation and do not discharge it. The Processor does not obtain consent from participants and does not verify that the Controller has obtained it.
4.3 The Controller warrants that it will not instruct processing that requires the Processor to act unlawfully, and that it will comply with applicable law governing the recording of conversations in the jurisdictions in which it operates.
4.4 The Controller is responsible for the accuracy, quality and lawfulness of the Controller Data and of the means by which it acquired it, and for ensuring that its instructions to the Processor comply with applicable law.
5. Confidentiality
The Processor ensures that persons authorised to process Controller Data are subject to an appropriate statutory or contractual duty of confidentiality, and that access is limited to those who need it to provide the service (Art. 28(3)(b) GDPR). Access to a Controller's workspace for support purposes is limited to read-only operations and is recorded.
6. Security of processing
6.1 The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Art. 32 GDPR). The measures in force are set out in Annex 2.
6.2 The Processor may update the measures in Annex 2 provided that the level of protection is not reduced.
7. Sub-processors
7.1 The Controller grants the Processor general written authorisation to engage sub-processors (Art. 28(2) GDPR). The sub-processors engaged as at the date of this Agreement are listed in Annex 3.
7.2 The Processor informs the Controller of any intended addition or replacement of a sub-processor, giving the Controller a reasonable period in which to object on reasonable data-protection grounds. If an objection cannot be resolved, the Controller may terminate the affected part of the service without penalty.
7.3 The Processor imposes on each sub-processor, by contract, data-protection obligations equivalent to those set out in this Agreement (Art. 28(4) GDPR) and remains fully liable to the Controller for the performance of each sub-processor's obligations.
7.4 Where the Controller connects a third-party source it already uses, and the service retrieves data from that source using the Controller's own credentials on the Controller's instruction, that source is not a sub-processor of the Processor, and the Controller remains responsible for its own relationship with that source.
8. Assistance to the Controller
8.1 Data-subject rights. Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to requests to exercise data-subject rights under Chapter III GDPR (Art. 28(3)(e)). Where a data subject contacts the Processor directly in relation to Controller Data, the Processor forwards the request to the Controller without undue delay and does not respond substantively itself unless instructed to.
8.2 Erasure. The service provides a mechanism by which the Controller can erase a conversation and its associated audio, transcript and derived contact records, retaining only a minimised record evidencing that the erasure took place.
8.3 Personal-data breach. The Processor notifies the Controller without undue delay after becoming aware of a personal-data breach affecting Controller Data (Art. 33(2) GDPR), providing the information then available and supplementing it as further information emerges.
8.4 Arts. 32 to 36. The Processor assists the Controller in ensuring compliance with its obligations under Arts. 32 to 36 GDPR, including data-protection impact assessments and prior consultation, taking into account the nature of processing and the information available to the Processor (Art. 28(3)(f)).
9. Deletion and return
9.1 On termination of the Principal Agreement, the Processor deletes or returns the Controller Data at the Controller's choice, and deletes existing copies, unless Union or Member State law requires continued storage (Art. 28(3)(g) GDPR). The Controller may state its choice within 30 days of termination; absent a choice, the Processor deletes the Controller Data. Deletion is completed within 30 days of the Controller's instruction or of the expiry of that period, excluding copies held in routine backups, which are deleted on the ordinary backup cycle and remain protected by this Agreement until then.
9.2 The recording provider's copy of a locally recorded upload is deleted automatically 36 hours after upload.
9.3 The Processor may retain a minimised record evidencing that an erasure took place, and Service Data in accordance with Clause 2.2.
10. Audit and demonstration of compliance
10.1 The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller (Art. 28(3)(h) GDPR).
10.2 The Processor may satisfy a request under Clause 10.1 in the first instance by providing its documented technical and organisational measures, this Agreement's annexes, and any relevant third-party report or certification it holds. Where that information does not reasonably enable the Controller to verify compliance, the Controller may conduct an on-site inspection.
10.3 An on-site inspection takes place on at least 30 days' written notice, during normal business hours, in a manner that does not disrupt the Processor's operations, and no more than once in any twelve-month period — unless a personal-data breach affecting the Controller Data has occurred, or a supervisory authority requires it, in which case a further inspection may be conducted.
10.4 The Controller bears its own costs and those of any auditor it mandates. The auditor must not be a competitor of the Processor and must be bound by an appropriate duty of confidentiality. An inspection must not extend to the personal data, systems or premises of other customers of the Processor, or to the premises of its sub-processors.
11. International transfers
11.1 The Controller selects the processing region applicable to its organisation. The transcription, audio-storage and transcript-analysis functions operate in the selected region and fail closed if a non-conforming endpoint is configured.
11.2 The Processor's database and application platform are hosted in Switzerland, which benefits from a European Commission adequacy decision; processing there is therefore not a restricted transfer.
11.3 Where a sub-processor processes Controller Data outside the EEA and outside the scope of an adequacy decision, the transfer is made subject to appropriate safeguards under Chapter V GDPR, namely the European Commission's Standard Contractual Clauses or, where the recipient is certified, the EU-US Data Privacy Framework, together with supplementary technical measures including encryption in transit and at rest.
12. Liability
Liability under this Agreement is governed by the Principal Agreement. Nothing in this Agreement limits or excludes either Party's liability under Art. 82 GDPR, or any liability that cannot lawfully be limited or excluded.
13. Governing law and jurisdiction
This Agreement is governed by the laws of the Federal Republic of Germany, excluding its conflict of laws rules and the UN Convention on Contracts for the International Sale of Goods. The courts of Munich, Germany have jurisdiction, to the extent permitted by law.
14. Term and precedence
This Agreement takes effect when the Controller accepts the Principal Agreement, or on the effective date shown above if later, and remains in force for the term of the Principal Agreement. Should any provision be or become invalid, the remaining provisions remain unaffected, and the invalid provision is to be replaced by one that most closely reflects its commercial and data-protection purpose.
Annex 1 — Details of the processing
Categories of data subjects
The Controller's personnel and account users. Participants in conversations the Controller records, including external participants who are not users of the service. People who have exchanged direct messages with a member on a connected LinkedIn account, where that member replied or initiated the exchange. The Controller's own end users, where the Controller deploys the product-event SDK.
Categories of personal data
Identity and account data: name, business email address, organisation, role. Calendar metadata: event titles, times, meeting join links, attendee names and email addresses, attendance status. Where a member connects a LinkedIn account: the text and dates of direct messages in that account, and the names, LinkedIn profile URLs and — where the member's own connections export contains them — email addresses of the people in each conversation. Limited to conversations the member replied to or started; a message from someone never answered is not imported. Audio, and in bot mode video, of recorded conversations. Transcripts of recorded conversations, including speaker attribution. Contact and company records derived from the above. Product and behavioural event data concerning the Controller's users, where the SDK is deployed. Any other personal data contained in content the Controller chooses to capture. Conversation content is free-form; it may include personal data relating to third parties and may incidentally include special categories of personal data within the meaning of Art. 9 GDPR. The Processor does not seek such data and does not generate inferences about it.
Frequency of processing — continuous, for the duration of the Principal Agreement.
Retention — as set out in Clause 9 and the Controller's configured retention period.
Annex 2 — Technical and organisational measures (Art. 32 GDPR)
Encryption. Transport encryption (TLS) for all connections between the client applications and the platform, and between the platform and its sub-processors. Encryption at rest for recording audio using AES-256 with managed keys. Third-party access tokens are encrypted at rest using AES-256-GCM.
Pseudonymisation and minimisation. Calendar data is minimised on the server to the event title, start and end time, join URL and attendees. An event is retained as Controller Data when it is a meeting with a participant outside the Controller's organisation, whether or not it was recorded; events with no external participant, and events still in the future, are read to render the Controller's calendar and are not retained. Product analytics mask input values by default and do not persist IP addresses. Service Data is collected without a user identifier.
Confidentiality and access control. Separation of each organisation's data, enforced in the database through row-level security. Role-based access control distinguishing owner, administrator and member. Least-privilege internal access; provider support access to a customer workspace is restricted to read-only operations, enforced server-side, and is recorded.
Integrity. A server-authoritative gate refuses to issue a recording token for a conversation the Controller has marked as declined; this decision is made on the server and cannot be overridden from a user's device. Erasures, deletions and retention changes are recorded in an append-only log. Region enforcement fails closed rather than falling back to an alternative region.
Availability and resilience. Managed, redundant infrastructure with provider-operated backups.
Verification. An automated verification suite covering the platform's logic, database migrations and client application is executed on every change before it is released, and the signed desktop release is gated on it. Changes are reviewed before merge.
Deletion. Configurable per-organisation retention periods with enforced purging; an erasure function covering a conversation's audio, transcript and derived contact records, with an append-only audit record of erasures performed.
Annex 3 — Sub-processors
Sub-processor: Recall.ai; Purpose: Meeting recording (bot and local upload); Personal data: Audio; video in bot mode. In bot mode only, the meeting's join link and scheduled start time, so the notetaker joins the correct call; no attendee names, email addresses or RSVP status; Location and transfer basis: Region selected by the Controller: EU (Frankfurt) or US (Oregon). US processing under the Standard Contractual Clauses, and the EU-US Data Privacy Framework where certified. Sub-processor: Deepgram; Purpose: Speech-to-text transcription; Personal data: Audio, converted to transcript text; Location and transfer basis: EU endpoint enforced; provider instructed not to train on the data. Sub-processor: Amazon Web Services (S3); Purpose: Storage of recording audio; Personal data: Audio files at rest; Location and transfer basis: EU region enforced; encrypted with managed keys. Sub-processor: Amazon Web Services (Bedrock) / Anthropic; Purpose: AI-assisted summarisation and analysis; Personal data: Transcript text, and meeting metadata — title, date and the participants a meeting was with; Location and transfer basis: EU region and model enforced in code, failing closed; no training on the data. Sub-processor: Supabase (via Lovable Cloud); Purpose: Database, authentication, storage, application functions; Personal data: All account and Controller Data; Location and transfer basis: Switzerland (AWS Europe/Zurich); European Commission adequacy decision. Sub-processor: Resend; Purpose: Transactional and authentication email; Personal data: Email address; Location and transfer basis: EU sending infrastructure (Ireland); account data in the US under the Standard Contractual Clauses and the EU-US Data Privacy Framework. Sub-processor: Google; Purpose: Calendar access (read-only) and sign-in; Personal data: Calendar metadata; identity assertion; Location and transfer basis: Google Ireland Limited / Google LLC; EU-US Data Privacy Framework. Sub-processor: Cloudflare; Purpose: Application-update endpoint, object storage, company-mark delivery, and real-time update notification relay; Personal data: Client IP address, request timestamp and path, in transient logs; for company marks the path contains a company domain and no user, account or organisation identifier; for the notification relay, an opaque connection identifier derived by HMAC from the user identifier (not reversible without a secret held only by the controller's processor infrastructure) and a timestamp — no content, event data, attendees, email addresses or organisation identifiers. The relay is pinned to Cloudflare's EU jurisdiction and persists nothing; Location and transfer basis: Cloudflare Germany GmbH / Cloudflare, Inc.; EU-US Data Privacy Framework and Standard Contractual Clauses.
Third-party sources connected by the Controller using its own credentials are not sub-processors of the Processor (Clause 7.4).
Changes to this list
We record every addition, replacement or removal of a sub-processor here, with the date it takes effect. Organisations that use 1nsight may object to a change on reasonable data-protection grounds under Clause 7.2 by writing to franco.noack@1nsight.ai. Checking this page is the reliable way to see the current list.
Date: 7 August 2026; Change: Initial published list. Date: 30 August 2026; Change: Cloudflare's entry corrected to disclose company-mark delivery, which had been live since the mark service replaced a third-party favicon endpoint and was not reflected here. No new sub-processor; the purpose and data categories for an existing one are stated accurately. Date: 31 August 2026; Change: Annex 2 corrected: the statement that calendar events not becoming recorded conversations are "not stored" had been untrue since 20 August 2026, when calendar meetings with an external participant began being retained as part of the record whether or not they were recorded. No change in processing; the description now matches it. Date: 31 August 2026; Change: Cloudflare's entry extended to disclose the real-time update notification relay, which delivers a "something changed" signal to the desktop app so a calendar change appears within seconds rather than on a timer. No new sub-processor and no new transfer: an additional purpose for an existing one, carrying an opaque, non-reversible connection identifier and a timestamp, pinned to Cloudflare's EU jurisdiction, storing nothing and carrying no content. Disclosed on the same day the relay began serving a second organisation. Date: 8 September 2026; Change: Annex 1 extended for the LinkedIn import, which went live for one workspace on 7 September 2026: the direct messages of a connected account, and the people in them. No new sub-processor — LinkedIn is not one. We send it nothing; an import is our outbound retrieval on the member's behalf under the EU Digital Markets Act's portability right, and LinkedIn remains controller of the account we read from. The narrowing rules are stated because they bound what can enter: only conversations the member replied to or started, and paid advertising messages discarded before anything is read.