Third Party Index

Snapshot 24326

Document
Data processing addendum
URL
https://meetgeek.ai/data-processing-agreement
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
179833 bytes
SHA-256 (raw)
df349415c55b298abc26aa09b3d4ab3dd76882085396aeab134d795523c70e54
SHA-256 (normalized text)
b11615ffc2d3d54c4d075a028f0fb1bd0e6a742a20a0752aa7c1da34138d8d8b

Normalized text

Scripts and page chrome removed; this is what change detection compares.

By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.
PreferencesDenyAccept
Data Processing Addendum
Last updated: 27 August 2026
For a signed copy of this Addendum, visit security.meetgeek.ai.
This Data Processing Addendum ("DPA") governs MeetGeek's processing of Customer Data in connection with MeetGeek's Services under the agreement between Customer and MeetGeek, including the Terms of Service or a signed order form (the "Agreement"), and is incorporated into the Agreement. If this DPA conflicts with the Agreement, this DPA prevails. Capitalised terms not defined here have the meaning given in the Agreement. For this DPA, "Customer" includes Customer's Affiliates.
"MeetGeek" means AIVISION PRODUCTS SRL for the EU instance of the Services and MeetGeek US Infra, Inc. for the US instance.
MeetGeek and Customer will each comply with their obligations under the data protection laws that apply to the processing of Customer Data in connection with the Services ("Data Protection Laws"). These include, as applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"); the UK GDPR and Data Protection Act 2018; the Swiss Federal Act on Data Protection; US federal and state privacy laws, including the California Consumer Privacy Act as amended ("CCPA") (together, "U.S. Privacy Laws"); Brazil's General Data Protection Law (Law No. 13,709/2018) ("LGPD"); Canada's Personal Information Protection and Electronic Documents Act; the Australian Privacy Act 1988; and any other data protection law applicable to the processing.
Customer determines the purposes and means of processing Customer Data ("Data Controller"); MeetGeek processes Customer Data on Customer's behalf and instructions ("Data Processor"). These terms include their equivalents under Data Protection Laws. "Personal Data" has the meaning given to "personal data" or "personal information" under Data Protection Laws. "Customer Data" means Personal Data contained in content that Customer or its users provide to or create in the Services, including recordings, transcripts, summaries, prompts and AI outputs, which MeetGeek processes on Customer's behalf.
1. Processing requirements
As Data Processor, MeetGeek will:
a. process Customer Data only (i) on Customer's behalf to provide, secure and support the Services, including abuse, trust and safety monitoring; (ii) on Customer's documented instructions, including in the Agreement and through Customer's configuration of the Services; and (iii) in a manner that provides no less than the level of privacy protection required by Data Protection Laws;
b. promptly inform Customer in writing, and cease processing Customer Data, if MeetGeek cannot comply with this DPA;
c. not provide Customer with remuneration in exchange for Customer Data. The parties agree that Customer has not "sold" Customer Data to MeetGeek, as that term is defined by the CCPA;
d. not "sell" (as defined by U.S. Privacy Laws) or "share" (as defined by the CCPA) Customer Data;
e. inform Customer promptly if, in MeetGeek's opinion, an instruction from Customer violates Data Protection Laws;
f. require its personnel and any other persons processing Customer Data on its behalf to be bound by a duty of confidentiality and to comply with the data protection obligations applicable to MeetGeek under the Agreement and this DPA;
g. engage the organisations listed at meetgeek.ai/subprocessors (each a "Subprocessor", and the list the "Subprocessor List") to process Customer Data. Customer consents to the use of these Subprocessors. If Customer subscribes to notifications as described on the Subprocessor List, MeetGeek will notify Customer of any intended change at least 30 days before it takes effect. Customer may object within 15 days on reasonable grounds relating to the protection of Customer Data by emailing [email protected]. MeetGeek may then: (i) not use the Subprocessor for Customer Data, or offer an alternative; (ii) take the corrective steps Customer requests and proceed; (iii) stop providing, or Customer may stop using, the feature that requires the Subprocessor; or (iv) Customer may stop providing Customer Data for processing involving the Subprocessor. If none of these options is commercially feasible and the objection is not resolved within 30 days of MeetGeek receiving it, either party may terminate the affected subscriptions for cause, and Customer will receive a refund of prepaid fees for the period after termination. This termination right is Customer's sole and exclusive remedy for an objection to a new Subprocessor. Subprocessors identified as optional in the Subprocessor List process Customer Data only where Customer has requested or enabled them, and that request constitutes Customer's consent to their engagement for Customer's account. MeetGeek will bind each Subprocessor by written contract to data protection and security obligations no less protective than this DPA, and remains liable for its Subprocessors' performance;
h. on reasonable request, no more than once a year, provide Customer with MeetGeek's privacy and security policies and other information necessary to demonstrate compliance with this DPA and Data Protection Laws;
i. where required by law, on reasonable notice and under appropriate confidentiality terms, cooperate with audits or assessments by or for Customer, at Customer's expense and in a way that minimises disruption to MeetGeek's business. Customer will agree the timing and scope with MeetGeek; exclude other customers' data; obtain MeetGeek's approval before using any tools on MeetGeek's systems; not include in scope any data that could harm the security of the Services; give MeetGeek a reasonable opportunity to review the audit report and resolve questions of fact; and keep the results confidential unless disclosure is required by law. Where permitted by law, MeetGeek may instead provide a summary of a relevant third-party audit or certification report, such as its SOC 2 Type II report. Audit results are MeetGeek's Confidential Information;
j. to the extent Customer permits or instructs MeetGeek to process Customer Data subject to U.S. Privacy Laws in de-identified, anonymised or aggregated form, (i) take reasonable measures to prevent that data from being linked to a particular person or household; (ii) not attempt to re-identify it, except to test whether its de-identification processes comply with Data Protection Laws or work as intended; and (iii) before sharing it with any other party, including Subprocessors, contractually require the recipient to comply with this clause. Nothing in this clause permits any use prohibited by Section 1(m);
k. where Customer Data is subject to the CCPA, not (i) retain, use, disclose or otherwise process it except as necessary for the business purposes specified in the Agreement or this DPA; (ii) retain, use, disclose or otherwise process it outside the direct business relationship between MeetGeek and Customer; or (iii) combine it with Personal Data that MeetGeek receives from or on behalf of any third party or collects from its own interactions with individuals, except as directed by Customer or otherwise permitted by the CCPA;
l. where required by law, grant Customer the rights to (i) take reasonable and appropriate steps to ensure that MeetGeek uses Customer Data consistently with Data Protection Laws, by exercising the audit rights above; and (ii) stop and remediate unauthorised use of Customer Data, for example by requesting written confirmation that Customer Data has been deleted; and
m. no model training: not use Customer Data, including recordings, transcripts, summaries, prompts and other outputs generated from Customer Data, to train, fine-tune, evaluate or otherwise develop or improve any artificial intelligence or machine learning model, whether owned by MeetGeek or a third party, unless Customer has expressly opted in in writing; and contractually require each Subprocessor that provides AI or machine learning services (i) not to use Customer Data to train or improve its models and (ii) to retain Customer Data no longer than necessary to perform the processing, and, where the Subprocessor offers it, to apply zero data retention.
2. Notice to Customer
MeetGeek will inform Customer if it becomes aware of:
a. any legally binding request for disclosure of Customer Data by a law enforcement or other public authority, unless MeetGeek is legally prohibited from doing so. MeetGeek will challenge requests it reasonably considers unlawful or overbroad and disclose only the minimum required;
b. any notice, inquiry or investigation by a supervisory authority established under Article 51 of the GDPR (a "Supervisory Authority") concerning Customer Data; or
c. any complaint or request, in particular requests for access, rectification, erasure or restriction, received directly from Customer's data subjects. MeetGeek will not respond to such a request without Customer's prior written authorisation, except to direct the data subject to Customer.
3. Assistance to Customer
Taking into account the nature of the processing, MeetGeek will provide reasonable assistance to Customer with:
a. responding to requests from Customer's data subjects to exercise their rights of access, rectification, erasure, restriction, portability or objection regarding Customer Data. If a data subject sends such a request directly to MeetGeek, MeetGeek will promptly forward it to Customer;
b. investigating any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data processed by MeetGeek (a "Personal Data Breach"); and
c. where appropriate, preparing data protection impact assessments concerning the processing of Customer Data by MeetGeek and, where necessary, prior consultations with a Supervisory Authority.
4. Required processing
If MeetGeek is required by law to process Customer Data other than in connection with the Agreement, MeetGeek will inform Customer of that requirement before processing, unless legally prohibited from doing so.
5. Security
MeetGeek will:
a. maintain reasonable and appropriate organisational and technical security measures, including for personnel, facilities, hardware and software, storage and networks, access controls, monitoring and logging, vulnerability and breach detection, incident response and encryption, to protect Customer Data against unauthorised or accidental access, loss, alteration, disclosure or destruction, as described in Exhibit B;
b. take appropriate steps to confirm that MeetGeek personnel protect the security, privacy and confidentiality of Customer Data consistently with this DPA; and
c. notify Customer of any Personal Data Breach by MeetGeek, its Subprocessors or anyone acting on its behalf without undue delay, and in any event within 72 hours of becoming aware of it, with the information Customer reasonably needs to meet its own notification obligations, updated as further information becomes available.
6. Obligations of Customer
a. Customer represents, warrants and covenants that it has and will maintain throughout the term all rights, consents and authorisations needed to provide Customer Data to MeetGeek and to authorise MeetGeek to process it as contemplated by this DPA and the Agreement, including informing meeting participants and obtaining any consent to recording required by law.
b. Customer will comply with Data Protection Laws.
c. Customer will reasonably cooperate with MeetGeek in responding to requests from Customer's data subjects.
d. Without prejudice to MeetGeek's obligations under Section 5, Customer is responsible for the configurations and design decisions within its control in the Services, including user access, sharing, integrations and retention settings, and for implementing them securely and lawfully.
e. Customer will provide Customer Data to MeetGeek only through the Services or other agreed secure mechanisms. For example, Customer will not include Customer Data, other than technical contact information, in support tickets or send it to MeetGeek by email.
f. Customer will not take any action that would (i) make the provision of Customer Data to MeetGeek a "sale" under U.S. Privacy Laws or a "share" under the CCPA; or (ii) cause MeetGeek not to be a "service provider" under the CCPA or a "processor" under U.S. Privacy Laws.
7. International transfers
a. Where MeetGeek processes Customer Data originating in the EEA outside the EEA, or where Customer on the EU instance exports Customer Data to MeetGeek on the US instance, the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 ("EU SCCs") are incorporated into this DPA by reference and completed as follows: Module Two (controller to processor) applies where Customer is a controller; Module Three (processor to processor) applies where Customer is a processor. Where a recipient is certified under the EU–US Data Privacy Framework, MeetGeek may also rely on that framework.
b. For each module of the EU SCCs: (i) the optional docking clause in Clause 7 does not apply; (ii) in Clause 9, Option 2 (general written authorisation) applies, with the notice period set out in Section 1(g); (iii) the optional language in Clause 11 does not apply; (iv) in Clause 17, Option 1 applies and the EU SCCs are governed by the law of the EU Member State where the data exporter is established, or the Member State where MeetGeek's EU entity is established where the data exporter is established outside the EU; (v) in Clause 18(b), disputes are resolved before the courts of that same Member State; (vi) Exhibit A completes Annexes I and III; and (vii) Exhibit B completes Annex II.
c. Switzerland. For Customer Data subject to the Swiss Federal Act on Data Protection of 25 September 2020, as in force since 1 September 2023 ("FADP"), the EU SCCs apply with these changes: references to the GDPR are to the FADP; the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for transfers governed by the FADP; and "Member State" is interpreted to include Switzerland, so that data subjects in Switzerland may bring claims in Switzerland under Clause 18(c).
d. United Kingdom. For Customer Data originating in the United Kingdom, the parties will comply with Part 2 (Mandatory Clauses) of the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0), as revised under Section 18 of those Mandatory Clauses (the "UK Addendum"). The information required by Part 1 of the UK Addendum is set out in Exhibit A, and either party may end the UK Addendum as set out in its Section 19.
e. Transfers from MeetGeek to Customer. Where MeetGeek, as processor on the EU instance, transfers Customer Data to a Customer established outside the EEA, Module Four (processor to controller) of the EU SCCs applies, completed as set out in Section 7(b) to the extent applicable.
f. Other jurisdictions. Where other Data Protection Laws require a specific mechanism for an international transfer of Customer Data, including the standard contractual clauses adopted by Brazil's National Data Protection Authority (ANPD) for transfers subject to the LGPD, the parties agree to rely on that mechanism. It is incorporated into this DPA by reference to the extent required, and MeetGeek will execute it separately on Customer's request.
8. Term, return and deletion
This DPA remains in effect while MeetGeek processes Customer Data on Customer's behalf. Customer can export and delete Customer Data in the Services at any time.
Within 30 days after the Agreement ends, MeetGeek will delete Customer Data from its active systems and direct its Subprocessors to do the same. Customer Data in encrypted backups is overwritten within a further 35 days. This does not apply where the law requires MeetGeek to keep Customer Data, in which case MeetGeek will isolate it and protect it from further processing except as the law requires. On request, MeetGeek will confirm deletion in writing.
MeetGeek may use aggregated usage metrics that contain no Customer Data content and identify neither individuals nor Customer, solely to operate, secure and improve the Services. This does not permit any use prohibited by Section 1(m).
9. Data location
a. Customer's instance determines its hosting region ("Hosting Region"): the European Union for the EU instance and the United States for the US instance. MeetGeek will store Customer Data at rest within the Hosting Region and will not change it without Customer's prior written instruction.
b. Customer Data may be processed outside the Hosting Region only (i) by the Subprocessors, and in the locations, identified for that Hosting Region in the Subprocessor List; (ii) by MeetGeek personnel accessing it remotely to provide support, security or maintenance; or (iii) as required by law under Section 4. Any such transfer is subject to Section 7.
c. Where Customer is subject to the GDPR and chooses the US instance, that choice is Customer's documented instruction to transfer Customer Data to the United States, and Section 7 applies.
d. On request, and subject to the order form, MeetGeek will migrate Customer Data between Hosting Regions and confirm its deletion from the original region.
Exhibit A: Description of processing (Annexes I and III)
A. List of parties
Data exporter: the Customer identified in the Agreement or its account registration. Activities: use of the Services. Role: controller (or processor, where Module Three applies).
Data importer:
EU instance: AIVISION PRODUCTS SRL, Str. Vânători nr. 5, Buzău, Buzău County, Romania. Contact: Privacy team, [email protected].
US instance: MeetGeek US Infra, Inc., 1111B S Governors Ave, STE 26235, Dover, DE 19904, USA. Contact: Privacy team, [email protected].
Activities: provision of the Services under the Agreement. Role: processor.
B. Description of the transfer
Categories of data subjects: Customer's users; meeting participants recorded by Customer's users; individuals mentioned in meeting content.
Categories of personal data: names, email addresses and job titles; voice and video recordings of meetings; transcripts, summaries, chat prompts and AI outputs; calendar metadata; and any personal data contained in meeting content.
Sensitive data: not intended to be transferred. It may appear in unstructured meeting content. Safeguards: encryption at rest and in transit, role-based access, access logging, and no model training under Section 1(m). Protected health information is processed only under a signed Business Associate Agreement.
Frequency of the transfer: continuous.
Nature and purpose of the processing: recording, transcription, summarisation, AI analysis, storage, search and delivery to integrations Customer connects, to provide the Services under the Agreement.
Retention: for the term of the Agreement, as set by Customer's retention settings or a custom retention period agreed for Enterprise plans, then deleted under Section 8.
Transfers to Subprocessors: as listed for each Hosting Region in the Subprocessor List, for the same subject matter, nature and duration as above.
C. Competent supervisory authority
The supervisory authority of the EU Member State where the data exporter is established. Where the data exporter is established outside the EU, the supervisory authority of the Member State where MeetGeek's EU entity is established.
D. List of Subprocessors (Annex III)
The Subprocessor List at meetgeek.ai/subprocessors, as updated under Section 1(g).
Exhibit B: Technical and organisational measures (Annex II)
MeetGeek maintains an information security programme designed to protect its systems and Customer Data. This Exhibit describes the measures that apply to the Services. More detail is available on the MeetGeek Security Portal at security.meetgeek.ai.
Corporate identity, authentication and authorisation.
Single sign-on for third-party services used to deliver the Services, and role-based access control for internal access.
Mandatory multi-factor authentication to MeetGeek's identity provider.
Unique login identifiers for each user.
Review and approval of every access request to services storing Customer Data.
Periodic access reviews to confirm access matches each person's role.
Prompt revocation of access when personnel leave.
Procedures for reporting and revoking compromised credentials, such as passwords and API keys.
Identity verification before any password reset.
Customer identity, authentication and authorisation.
A third-party identity service manages customer authentication, so MeetGeek does not store user passwords.
Customer Data is logically separated by organisation account using unique identifiers; unique user accounts are supported within each organisation.
Cloud infrastructure and network security.
Customer Data is stored within the Hosting Region selected under Section 9 of the DPA.
Separate production and non-production environments.
Production backend resources are deployed in private networks.
Routine security vulnerability testing of the Services.
Application secrets and service accounts managed in a secrets management service.
Least-privilege network policies and firewalls; traffic outside pre-approved flows is blocked.
Monitoring of service logs for security and availability.
Workstation security.
Endpoint management of corporate laptops and mobile devices.
Automatic application of security configurations.
Mandatory patch management.
Security logging on corporate devices.
Data access control.
Employee access to production follows the principle of least privilege; only personnel who support the Services are credentialed.
Customer Data is used only as permitted by the DPA and the Agreement, and never for model training (Section 1(m)).
Disclosure control.
AES-256 encryption of data at rest in production datastores.
TLS 1.2 or higher for data in transit.
Audit trail of access to production datastores.
Full-disk encryption and device management on all corporate workstations.
Restrictions on portable and removable media.
Customer Data can be deleted on request.
Availability control.
Encrypted backups replicated within the Hosting Region, with restoration procedures tested at least annually.
Monitoring and alerting for system faults.
Anti-malware and intrusion detection across the environment.
Segregation control.
Logical segregation of Customer Data.
Access to data restricted by role and purpose.
Segregation of business system functions and of testing and production environments.
Risk management.
Threat modelling to identify and prioritise security risks.
Penetration testing of the Services at least annually, with findings remediated on a timeline matching their risk. A summary is available on request.
An annual SOC 2 Type II audit by a qualified, independent auditor. A summary is available on reasonable request.
A vulnerability management programme for prompt remediation.
Personnel.
Background checks, where legally permitted, for personnel with access to Customer Data.
Security training at onboarding and annually.
Physical security.
MeetGeek does not operate its own data centres. Physical security of production systems is provided by Amazon Web Services under its SOC 2 and ISO 27001 certified controls.
Access to MeetGeek offices is restricted to authorised personnel.
Third-party risk management.
Written contracts requiring Subprocessors to maintain appropriate safeguards for Customer Data.
A security assessment of every vendor before it receives Customer Data.
Security incident response.
A documented incident response plan covering detection, containment, recovery and review.
Centralised log aggregation to support detection and investigation.
Notification of Personal Data Breaches to Customer under Section 5(c) of the DPA.
Security evaluations. MeetGeek regularly tests whether key controls are implemented and effective against industry standards, its policies, and its legal and contractual obligations for Customer Data.
‍