Snapshot 55029
Normalized text
Scripts and page chrome removed; this is what change detection compares.
DATA PROCESSING AGREEMENT - LEEXI
Version 3.0 – Effective as of 2 October 2026
LEEXI SA
CBE Brussels
VAT BE 0782.527.110
Share capital: EUR 974,000
Avenue Herrmann-Debroux 2, 1160 Brussels (Auderghem), Belgium
Represented by Xavier Lombard, CEO
PREAMBLE
This data processing agreement (the “agreement”) is entered into between the client and Leexi on the date
on which the Client subscribes online to the Services, including in the context of a free trial.
WHEREAS:
(A) The Client uses or wishes to use the Leexi conversation intelligence platform, as described in
Annex 1 (the “Services”), provided by Leexi in the context of their business relationship, which may,
where applicable, be further specified in a purchase order, a subscription or any other contract entered
into between the Parties.
(B) In the course of providing the Services, Leexi processes, on behalf of and in accordance with the
instructions of the Client, personal data for which the Client is the controller.
(C) The Parties have come together to define, in this Agreement, the terms and conditions of such
processing, in accordance with Regulation (EU) 2016/679 of 27 April 2016 (“GDPR”) and other
applicable data protection regulations.
(D) The purpose of this Agreement is to govern, on its own, all such processing. It constitutes the
agreement of the Parties with respect to the protection of personal data and, on that matter, prevails
over any other contractual provision that may have been agreed between the Parties in relation to the
Services.
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 1
NOW, THEREFORE, IT IS AGREED AS FOLLOWS:
ARTICLE 1 – DEFINITIONS
For the purposes of this Agreement, the terms below, whether used in the singular or the plural, shall have
the following meanings:
“Agreement” means this data processing agreement together with its Annexes, which form an integral part
hereof.
“Supervisory Authority” means any independent public authority responsible for monitoring the application
of the applicable data protection regulations (in Belgium, the Data Protection Authority).
“Personal Data” means any personal data, within the meaning of Article 4(1) GDPR, processed by Leexi on
behalf of the Client in the course of providing the Services, as described in Annex 1.
“AI Model Training” means any operation consisting of using data as material for the learning, training,
retraining, fine-tuning or improvement of an artificial intelligence or machine learning model, including for
the purposes of testing or evaluating such models.
“Data Protection Legislation” means any of the regulations applicable to the Parties with respect to the
protection of personal data, namely the GDPR (Regulation (EU) 2016/679), the UK GDPR and the Data
Protection Act 2018, Quebec’s Law 25, or the Swiss Federal Act on Data Protection (FADP).
“Data Subjects” means the natural persons to whom the Personal Data relate.
“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April
2016.
“Controller” means the Party that determines the purposes and means of the processing of Personal Data,
namely the Client for the purposes of this Agreement.
“Services” means the Leexi platform services provided by Leexi to the Client, as described in Annex 1,
whether subscribed to under this Agreement or under any other contract, purchase order or subscription
entered into between the Parties.
“Processor” means the Party that processes Personal Data on behalf of the Controller, namely Leexi for the
purposes of this Agreement.
“Sub-processor” means any processor engaged by Leexi for the processing of all or part of the Personal
Data, an up-to-date list of which is set out in Annex 2.
“Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration,
unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
ARTICLE 2 – PURPOSE OF THE AGREEMENT
2.1 The purpose of this Agreement is to set out the conditions under which Leexi, acting as Processor
within the meaning of Article 28 GDPR, processes, on behalf of and on the documented instructions of the
Client, acting as Controller, the Personal Data necessary for the provision of the Services, namely a SaaS
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 2
conversation intelligence platform providing automatic transcription, semantic analysis and summary
generation for meetings and telephone calls by means of artificial intelligence technologies.
2.2 The Agreement specifies in particular: the nature, subject matter and purpose of the processing (Article
4 and Annex 1); the duration of the processing (Article 14); the categories of Personal Data and Data
Subjects (Annex 1); the respective obligations of the Parties (Articles 5 and 6); the data security safeguards
(Article 10 and Annex 3); the use of Sub-processors (Article 8 and Annex 2); the commitment not to use
data for the purpose of training artificial intelligence models (Article 7); international data transfers (Article
9); and the rights of Data Subjects (Article 12).
2.3 This Agreement applies to any processing of Personal Data carried out by Leexi on behalf of the Client
in the course of providing the Services, regardless of the country of origin of the data, the place of
processing, the location of the Data Subjects or any other connecting factor.
2.4 The Client acts as Controller of the Personal Data. Leexi acts as Processor and processes the Personal
Data only on behalf of and in accordance with the documented instructions of the Client, in accordance
with this Agreement.
2.5. The Client grants Leexi a non-exclusive, royalty-free, worldwide licence to use its trade name,
trademark and logo in its communication and marketing materials (including its website, sales
presentations and case studies) in order to cite the Client as a commercial reference. Leexi undertakes to
comply with the brand guidelines provided by the Client and not to harm the Client’s reputation or brand
image. The Client may revoke this authorisation at any time by written notice to Leexi.
2.6 Where the Parties have entered into, or subsequently enter into, a separate contract, purchase order or
subscription relating to the provision of the Services, this Agreement applies in addition to that document
with respect to the protection of personal data, and prevails over it in the event of any conflict on that
matter. In the absence of such a separate document, this Agreement constitutes, on its own, the agreement
of the Parties relating to the provision of the Services and to the protection of the personal data relating
thereto.
2.7 This Agreement takes effect on the date of its signature and remains in force for the entire duration of
the provision of the Services by Leexi to the Client. It survives the termination of the provision of the
Services with respect to those provisions which by their nature are intended to survive, in particular those
relating to confidentiality (Article 16), liability and governing law (Article 19), until the obligations to
return or delete the data set out in Article 17 have been fully performed.
ARTICLE 3 – LEGAL COMPLIANCE AND GENERAL OBLIGATIONS OF THE
PARTIES
3.1 Each Party undertakes to comply with all provisions of the Data Protection Legislation applicable to it
and to impose equivalent obligations on its personnel and on any third party acting under its control,
including its affiliates and subcontractors.
3.2 Each Party warrants that the personal data it holds, discloses to the other Party or to which it has access
in the context of their contractual relationship have been obtained and are used under conditions ensuring
appropriate security and confidentiality, including the prevention of any unauthorised access.
3.3 Each Party undertakes to implement appropriate technical and organisational measures to protect the
personal data it holds against any unauthorised access, breach, loss, unauthorised disclosure or accidental
destruction, and to notify the other Party without delay should any such event occur.
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 3
ARTICLE 4 – DESCRIPTION AND SCOPE OF THE PROCESSING
4.1. The details of the processing carried out by Leexi on behalf of the Client (subject matter and nature of
the operations, purposes, categories of Data Subjects, categories of Personal Data, recipients and duration)
are described exhaustively in Annex 1 to this Agreement, which forms an integral part hereof.
4.2 Leexi undertakes to process the Personal Data only to the extent strictly necessary for the performance
of the Services described in Annex 1 and in accordance with the documented instructions of the Client.
4.3 Leexi undertakes to take into account the principles of data protection by design and data protection by
default in the design of its tools, products, applications and services.
ARTICLE 5 – OBLIGATIONS OF THE CONTROLLER
As Controller, the Client:
(a) determines the purposes and means of the processing of Personal Data;
(b) ensures that the instructions given to Leexi are documented, lawful and compliant with the Data
Protection Legislation;
(c) warrants that it has a valid legal basis for collecting and disclosing the Personal Data to Leexi and,
where applicable, for recording conversations and providing prior information to the Data Subjects;
(d) ensures that Data Subjects are able to exercise the rights granted to them by the Data Protection
Legislation, under the conditions set out in Article 12;
(e) responds, as first-line point of contact, to requests from Data Subjects, with the assistance of Leexi
referred to in Article 12.
ARTICLE 6 – OBLIGATIONS OF THE PROCESSOR
As Processor, Leexi:
(a) processes the Personal Data only on the documented instructions of the Client, including with
regard to transfers of data to a third country, unless Leexi is required to do so by European Union law
or Belgian law to which it is subject; in such a case, Leexi shall inform the Client of that legal
requirement before processing, unless that law prohibits such information on important grounds of
public interest;
(b) immediately informs the Client, without this constituting legal advice, if it considers that an
instruction from the Client infringes the Data Protection Legislation;
(c) ensures that persons authorised to process the Personal Data have committed themselves to
confidentiality or are under an appropriate statutory obligation of confidentiality;
(d) implements the security measures described in Article 10 and Annex 3;
(e) complies with the conditions for engaging Sub-processors set out in Article 8;
(f) provides the Client with the assistance set out in Articles 11, 12, 13 and 15;
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 4
(g) makes available to the Client the information necessary to demonstrate compliance with the
obligations laid down in this Agreement and in Article 28 GDPR, and allows for audits to be
conducted under the conditions of Article 13.
ARTICLE 7 – PROHIBITION ON USING PERSONAL DATA TO TRAIN
ARTIFICIAL INTELLIGENCE MODELS
7.1 No Personal Data of the Client, whether raw data (audio or video recordings), transcribed data or
derived data (summaries, chapters, follow-up tasks, translations, analyses), is used, in any form or for any
purpose whatsoever, for AI Model Training, whether the model is developed by Leexi or by a third party.
Personal Data are processed by Leexi solely for the performance of the Services for the benefit of the
Client, to the exclusion of any other purpose, in particular commercial, marketing, advertising or profiling
purposes.
7.2 Leexi contractually imposes this same prohibition on each of its Sub-processors involved in processing
voice, text or conversation content, by means of a data processing agreement compliant with Article 28
GDPR entered into with each of them. In particular:
(a) the speech recognition providers (Gladia, ElevenLabs) apply a zero-retention policy: the
transmitted audio is converted into text and then deleted, without being retained or reused for training
purposes;
(b) processing by large language models (LLMs) is carried out exclusively via Microsoft Azure
OpenAI Service, whose contractual terms guarantee the processing of data within the geographical
boundaries of the European Union (EU Data Boundary), operational retention limited to a maximum
of thirty (30) days, and the provider’s contractual commitment not to reuse such data to train its
models; Leexi does not use the OpenAI public API (api.openai.com);
(c) the provider Mistral AI, also used for processing by language models, is bound by a data
processing agreement excluding any use of the data for the purpose of training its models.
7.3 Leexi offers, on an optional basis and not activated by default, an integration based on the MCP (Model
Context Protocol) allowing the Client to connect, on its own initiative and under its exclusive control,
third-party artificial intelligence tools (such as Claude, ChatGPT or Dust) to access the transcripts and
summaries of its meetings. The activation of this feature, as well as the use made of the data by the
third-party tool thus connected, is the sole responsibility of the Client and does not affect the commitments
made by Leexi under this Article.
7.4 Upon request by the Client, Leexi shall provide it with any relevant document demonstrating
compliance with this Article, in particular the data processing agreements entered into with the relevant
Sub-processors. This right is exercised under the conditions set out in Article 13.
ARTICLE 8 – SUB-PROCESSORS
8.1 The Client grants Leexi a general written authorisation to engage the Sub-processors listed in Annex 2.
8.2 Leexi keeps the list of its Sub-processors up to date on the dedicated page of its trust center
(https://trust.leexi.ai/). Any addition or replacement of a Sub-processor gives rise to an automatic
notification to the Client, before such Sub-processor begins processing Personal Data, containing the
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 5
information necessary for the Client to exercise its right to object. The Client has a period of fifteen (15)
days from such notification to notify Leexi of its reasoned objection. The Parties then agree to meet and
discuss in good faith in order to find a reasonable and mutually acceptable solution, before any final refusal
by the Client.
8.3 Leexi ensures that every Sub-processor is bound by a written agreement imposing data protection
obligations at least as protective as those set out in this Agreement, in particular with regard to data security
(Article 10) and the non-use of data for the purpose of training AI models (Article 7). Leexi ensures that its
Sub-processors comply with these obligations.
8.4 Leexi remains fully liable to the Client for the performance by its Sub-processors of their data
protection obligations.
ARTICLE 9 – INTERNATIONAL DATA TRANSFERS
9.1 Where the use of a Sub-processor involves an international transfer of Personal Data, Leexi takes all
necessary measures to ensure that such transfer complies with the Data Protection Legislation.
9.2 Personal Data are transferred by Leexi to a country outside the European Economic Area, or made
accessible from such a country, only if:
(a) that country is the subject of an adequacy decision by the European Commission finding an
adequate level of protection; or
(b) the transfer is based on the Standard Contractual Clauses adopted by the European Commission in
their version in force, or on any other appropriate safeguard recognised by the Data Protection
Legislation.
ARTICLE 10 – DATA SECURITY
10.1 Leexi implements the appropriate technical and organisational measures described in Annex 3 to
ensure a level of security appropriate to the risk, including in particular encryption, access controls, regular
data backups, staff training and employee background checks.
10.2 Leexi’s security measures form part of its ISO 27001:2022 certification, the scope of which covers
Leexi’s information system and SaaS services.
10.3 Leexi applies the security by design and privacy by design principles detailed in Annex 3.
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 6
ARTICLE 11 – PERSONAL DATA BREACH
11.1 Leexi notifies the Client of any Data Breach within a maximum of twenty-four (24) hours after
becoming aware of it, by email sent to the contact designated by the Client. This notification shall include,
to the extent possible, the following information:
– a description of the nature of the Data Breach, including, where possible, the categories and
approximate number of Data Subjects concerned and the categories and approximate number of
Personal Data records concerned;
– the name and contact details of a contact point from whom further information can be obtained;
– a description of the likely consequences of the Data Breach;
– a description of the measures taken or proposed to be taken by Leexi to address the Data Breach,
including, where appropriate, measures to mitigate its possible adverse effects.
11.2 Leexi assists the Client in notifying a Data Breach to the competent Supervisory Authority by
responding to its additional requests.
ARTICLE 12 – RIGHTS OF DATA SUBJECTS
12.1 Leexi assists the Client, insofar as possible and taking into account the nature of the processing, in
fulfilling its obligation to respond to requests for the exercise of Data Subjects’ rights: the rights of access,
rectification, erasure, restriction, objection and portability, as defined by the Data Protection Legislation.
12.2 Where a Data Subject submits a request relating to the exercise of their rights directly to Leexi, Leexi
informs the Client without undue delay and does not respond directly to that request, unless otherwise
instructed by the Client.
ARTICLE 13 – ASSISTANCE AND AUDIT
13.1 Upon request by the Client, Leexi assists it, insofar as possible, in the event of an inspection by a
Supervisory Authority, or in carrying out data protection impact assessments (DPIAs) relating to the
processing covered by this Agreement.
13.2 In the event of a regulatory inspection or investigation relating to the processing of Personal Data,
Leexi promptly informs the Client and provides it with all necessary assistance.
13.3 Leexi makes available to the Client all information necessary to demonstrate its compliance with the
obligations arising from this Agreement and the Data Protection Legislation. At the Client’s request, Leexi
allows for and contributes to audits of the processing activities covered by this Agreement; in deciding
whether to conduct an audit, the Client may take into account the relevant certifications held by Leexi.
13.4 The Client may appoint an independent auditor, subject to reasonable prior notice of at least twenty
(20) days before the date of the audit, extended to thirty (30) days if the request is made at the end of the
year or at any time when Leexi cannot reasonably accommodate it. This audit right may not be exercised
more than once in any twelve (12) month period. The Client bears all costs and expenses of the audit,
unless the audit reveals a security incident, in which case Leexi bears all of its costs. Prior to the audit, the
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 7
auditor appointed by the Client shall sign a confidentiality agreement in a form reasonably satisfactory to
Leexi.
13.5 This audit right does not under any circumstances allow the Client to access data relating to Leexi’s
other clients.
13.6 The Parties shall use all reasonable efforts to minimise disruption to Leexi’s business.
ARTICLE 14 – DATA RETENTION AND DELETION
14.1 Unless the Client chooses different settings, Leexi retains the Personal Data within the following
limits:
– the raw media file (unprocessed audio or video recording) is not retained: it is deleted as soon as the
processed version has been generated;
– processed audio and video recordings are retained by default for two (2) years from the date of each
conversation, with a configurable minimum of one (1) day; the Client may activate the “Never keep
recordings” option for immediate deletion after analysis by artificial intelligence;
– transcripts and derived data (summaries, follow-up tasks, translations, analyses) are retained for a
minimum of one (1) day, and up to a period of 2 years depending on the settings chosen by the Client;
– user account data are retained for the duration of use of the Services, and then deleted or anonymised
at the end of the contractual relationship;
– security and audit logs are retained for a minimum period of twelve (12) months.
14.2 Upon expiry of the applicable retention periods, on the Client’s instructions, or upon termination of
the provision of the Services in accordance with Article 17, Leexi deletes all of the relevant Personal Data
within a maximum of thirty (30) days, unless a longer retention period is required by the Data Protection
Legislation or any other applicable legal provision. A certificate of destruction is issued to the Client upon
request.
ARTICLE 15 – ACCESS TO DATA BY THIRD-COUNTRY AUTHORITIES
15.1 Where Leexi receives a legally binding request from a public authority under the law of a third
country, or becomes aware of any direct access to Personal Data by such an authority, Leexi informs the
Client without undue delay, providing it with all the information available to it concerning such request or
access.
15.2 If Leexi is legally prohibited from informing the Client, it undertakes to use its best efforts to obtain a
waiver of that prohibition in order to communicate as much information as possible to the Client, and to
document its efforts to that end, such documentation being available to the Client upon request.
15.3 Leexi sets out, in a written policy made available to the Client, its internal process for handling such
requests and such direct access.
ARTICLE 16 – CONFIDENTIALITY
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 8
16.1 The Parties undertake to preserve the confidentiality of all information exchanged in the context of
their contractual relationship, including with respect to their own respective subcontractors, unless
otherwise agreed or required by law to disclose it.
16.2 Leexi undertakes not to disclose the Client’s confidential information to third parties without the
Client’s prior written authorisation.
ARTICLE 17 – RETURN OR DELETION OF DATA AT THE END OF THE
CONTRACT
17.1 Upon termination of the provision of the Services, for whatever reason, Leexi shall, at the Client’s
choice, return all Personal Data to the Client or securely delete them, under the conditions and within the
maximum period set out in Article 14.2, unless their retention is required by the Data Protection Legislation
or any other applicable legal provision.
17.2 If the deletion of the Personal Data proves materially difficult, from a commercial or technological
standpoint, Leexi may retain backup copies made in the course of its normal business activities, provided
that:
(a) Leexi represents and warrants that it has implemented and follows a process for deleting backups that
are no longer required; and
(b) Leexi uses commercially reasonable efforts to anonymise such data.
ARTICLE 18 – TERMINATION
Where a separate contract, purchase order or subscription otherwise governs the provision of the Services,
this Agreement terminates automatically upon the termination or expiry of that document, and vice versa,
these two instruments being inseparable with respect to the protection of personal data.
In the absence of such a separate document, either Party may terminate this Agreement by giving three (3)
months’ written notice to the other Party; in any event, it terminates automatically on the date on which the
Client ceases to use the Services. Termination of this Agreement does not affect obligations which, by their
nature, are intended to survive, in accordance with Article 2.7.
ARTICLE 19 – GOVERNING LAW AND DISPUTE RESOLUTION
This Agreement is governed by Belgian law and drafted in the French language. Any dispute relating to its
interpretation or performance shall fall within the exclusive jurisdiction of the courts of Brussels (Belgium).
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 9
ARTICLE 20 – MISCELLANEOUS
20.1 This Agreement, together with its Annexes, constitutes the entire agreement of the Parties relating to
the processing of Personal Data, and supersedes any prior agreement, understanding or representation
relating to the same subject matter. It supplements, without replacing, any other contract, purchase order or
subscription entered into between the Parties relating to the provision of the Services, in accordance with
Article 2.6.
20.2 Any amendment to this Agreement must be made in writing and signed by duly authorised
representatives of both Parties.
20.3 In accordance with Article 30 GDPR, Leexi maintains an up-to-date written record of all categories of
processing activities carried out on behalf of the Client.
20.4 If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions
shall remain in full force and effect.
20.5 The failure of either Party to enforce any provision of this Agreement shall not constitute a waiver of
that provision or of any other provision.
ARTICLE 21 – CONTACTS AND EXERCISE OF RIGHTS
For any question relating to this Agreement or for the exercise of Data Subjects’ rights, each Party may
contact the representative designated by the other Party:
For Leexi: Data Protection Officer — dpo@leexi.ai, or by post to the following address: Data Protection
Officer, Leexi, Avenue Herrmann-Debroux 2, 1160 Brussels (Auderghem), Belgium.
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 10
ANNEXES
ANNEX 1 – DESCRIPTION OF THE PROCESSING
This Annex describes, exhaustively and without repetition in the body of the Agreement, the nature and
scope of the processing carried out by Leexi on behalf of the Client (see Article 4).
Provision of the Leexi Services to the Client: automatic transcription, semantic
Subject matter of analysis and summary generation for meetings and telephone calls by means of
the processing artificial intelligence technologies, in the context of the contractual relationship
between the Parties.
Nature of the Collection, recording, transcription, analysis, generation of derived content,
operations storage, transmission, retention and deletion.
Performance of the contractually agreed Services: support for the Client, account
Purposes management, technical support, production of deliverables resulting from the
analysis of recorded conversations.
Categories of Data Employees, agents, suppliers and customers of the Client, as well as any other
Subjects person taking part in the meetings or calls recorded on behalf of the Client.
(i) identification and contact data of users and participants: last name, first name,
email address, telephone number, job title, company name; (ii) content of
conversations recorded via videoconference or audio system (VoIP), together
Categories of
with their metadata (participants, date, duration, calendar synchronisation); (iii)
Personal Data
structured derived data: text transcripts, summaries, chapters, follow-up tasks,
translations, talk-time analyses; (iv) user account data: professional login
credentials, languages spoken, connection logs.
Authorised personnel of the Client and of Leexi, as well as the Sub-processors
Recipients listed in Annex 2, to the extent strictly necessary for the performance of the
Services.
For the entire duration of the provision of the Services, and thereafter under the
Duration of the
conditions and within the limits set out in Article 14 (retention) and Article 17
processing
(return or deletion of data at the end of the Services) of this Agreement.
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 11
ANNEX 2 – LIST OF SUB-PROCESSORS
This Annex lists, for each Sub-processor engaged by Leexi for the processing of the Personal Data defined
in Annex 1, its function, the data it receives and its processing location, in accordance with Article 8. This
list is kept up to date by Leexi and communicated to the Client in the event of any change, under the
conditions of Article 8.2.
1. Amazon Web Services EMEA SARL (AWS)
Company No. IE 908705 — 38 avenue John F. Kennedy, L-1855 Luxembourg
Provision of cloud infrastructure: hosting, compute, storage, databases,
Function
networking and managed services.
All Personal Data processed by the platform (recordings, transcripts,
Data received
derived data, account data).
European Union — France (Paris, eu-west-3, primary region) and Ireland
Processing location
(eu-west-1, backup and disaster recovery).
2. Microsoft Ireland Operations Ltd (Azure)
Company No. IE 8256796 U — One Microsoft Place, South County Business Park, Leopardstown, Dublin
18 D18 P521, Ireland
Processing by language models (Azure OpenAI Service) and speech
Function
recognition (speech-to-text).
Audio streams and transcripts transmitted for semantic analysis and
Data received
summary generation.
Processing location European Union — France (Paris) and Sweden.
3. Google Ireland Limited
Company No. IE6388047V — Gordon House, Barrow Street, Dublin 4, Ireland
Function Identity provider (Google Workspace / single sign-on).
Data received Professional login credentials: name, professional email address.
Processing location European Union.
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 12
4. Gladia SAS
Company No. 909 935 736 — 6B rue du Bas Village, 35510 Cesson-Sévigné, France
Function Speech recognition (speech-to-text), primary provider.
Audio streams of conversations, converted into text and then immediately
Data received
deleted (zero-retention policy, no model training).
Processing location France (European Union).
5. Eleven Labs Inc. (ElevenLabs)
Company No. 88-2721123 — Floor 4, 33 Broadwick Street, London, England, W1F 0DQ
Backup speech recognition (speech-to-text) and speech synthesis
Function
(text-to-speech).
Audio streams of conversations, ephemeral processing, zero-retention
Data received
policy, no model training.
Processing location Europe.
6. Mistral AI
Company No. (Paris registration) FR95952418325 — 15 rue des Halles, 75001 Paris, France
Function Processing by language models (summary and analysis generation).
Transcripts and derived content transmitted for analysis, without use for
Data received
model training purposes.
Processing location France (European Union).
7. Scaleway SAS
Company No. FR 35 433 115 904 — 8 rue de la Ville-l'Évêque, 75008 Paris, France
Secondary data hosting and storage (enhanced sovereignty option, at the
Function
Client’s request).
Data received Copy of the data stored according to the configuration chosen by the Client.
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 13
France (Paris; exclusive Paris + Amsterdam configuration available on
Processing location
request for certain clients).
8. New Relic
Company number: FR33841811888, 33 rue La Fayette, 75009 Paris, France
Function Application performance monitoring.
Encrypted technical logs and security metadata only; no conversation
Data received
content.
Processing location Germany (processing).
9. Cloudflare, Inc.
Company No. 08778322 — County Hall, The Riverside Building, Belvedere Road, London SE1
Perimeter security, content delivery network (CDN) and application
Function
protection (WAF, anti-DDoS).
Data received Technical connection metadata (IP addresses, requests).
Processing location Europe / United Kingdom.
10. Sinch (Mailgun Technologies Inc.)
Company No. (Texas) 80265351 Lindhagensgatan 112, 112 51 Stockholm, Sweden
Function Sending of transactional emails (confirmations, notifications, exports).
Data received Email address and content strictly necessary for the notification sent.
Processing location European Union — Frankfurt, Germany (processing).
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 14
ANNEX 3 – TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
1. Security by design principles
1. Minimise the attack surface
2. Establish secure defaults
3. Apply the principle of least privilege
4. Apply the principle of defence in depth
5. Fail securely
6. Do not trust services by default
7. Ensure separation of duties
8. Avoid security by obscurity
9. Keep security simple
10. Fix security issues correctly
2. Privacy by design principles
1. Proactive not reactive; preventive not remedial
2. Privacy as the default setting
3. Privacy embedded into design
4. Full functionality (positive-sum, not zero-sum)
5. End-to-end security, full lifecycle protection
6. Visibility and transparency
7. Respect for user privacy, user-centric design
3.3 Security measures implemented
– Encryption of data at rest and in transit
– Access controls based on the principle of least privilege and multi-factor authentication
– Regular encrypted backups and restoration testing
– Regular staff training and awareness on security and data protection
– Employee background checks upon recruitment
– Logging and continuous monitoring of access and security incidents
These measures form part of Leexi’s ISO 27001:2022 certification, the scope of which covers Leexi’s
information system and SaaS services (see Article 10).
Data Processing Agreement - Version 2026 https://www.leexi.ai/ - hello@leexi.ai 15