Memo
Legal

Data Processing Agreement

1. Definitions

“GDPR” means Regulation (EU) 2016/679. Controller, processor, data subject, personal data, processing and supervisory authority have the meanings given in the GDPR. “Customer Personal Data” means personal data contained in the Customer Data that we process on your behalf under the Agreement. “Sub-processor” means a processor we engage to process Customer Personal Data. “Data Protection Law” means the GDPR, the Finnish Data Protection Act (1050/2018), and any other applicable data protection legislation, including the UK GDPR where relevant.

2. Roles

You are the controller of Customer Personal Data and we are your processor. You are responsible for the lawfulness of the data you give us and of the instructions you issue, including having a valid legal basis for the processing and for giving any notices owed to data subjects.

We act as an independent controller for a limited set of data that is not Customer Personal Data — account administration, billing, and security and service telemetry. That processing is described in our Privacy Policy and is outside this DPA.

3. Our processing obligations

We will:

4. Sub-processors

You give us general written authorisation to engage sub-processors. The current list is published at sentmemo.com/subprocessors and forms Annex III to this DPA.

We will give at least 30 days’ notice before a new sub-processor begins processing Customer Personal Data. You may object on reasonable data protection grounds within that period; if we cannot offer a reasonable alternative, you may terminate the affected part of the service and receive a pro-rata refund of prepaid, unused fees.

We impose on each sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.

5. International transfers

Customer Personal Data is stored in the European Union. Where a sub-processor processes it outside the EEA, that transfer is made under the European Commission’s Standard Contractual Clauses (Decision 2021/914) or another valid transfer mechanism, together with the supplementary measures described in Annex II.

Where the SCCs apply between you and us, they are incorporated into this DPA: Module Two (controller to processor) applies, with the optional docking clause included; Clause 7 applies; Clause 9 option 2 (general written authorisation, 30 days) applies; Clause 11 optional redress wording does not apply; Clause 17 is governed by the law of Finland; Clause 18(b) designates the courts of Finland. Annexes I, II and III below populate the SCC annexes.

6. Assistance we owe you

Taking into account the nature of the processing and the information available to us, we will:

7. Audit

We will make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits conducted by you or an auditor you mandate.

In practice, we will first offer our then-current security documentation and answer a reasonable security questionnaire. If that does not satisfy a specific regulatory requirement, you may conduct an audit no more than once in any twelve-month period (and at any time after a personal data breach), on 30 days’ written notice, during business hours, without unreasonable disruption, and subject to confidentiality. Each party bears its own costs. Any auditor must not be a competitor of ours.

8. Deletion and return

On termination or expiry of the Agreement, we will delete Customer Personal Data within 60 days, unless EU or Member State law requires us to keep it. Before deletion, you may export your data through the service; on request within that window, we will provide a copy in a commonly used machine-readable format. Backups are deleted on their normal rotation cycle and remain protected by this DPA until they are.

9. Liability

Each party’s liability arising out of this DPA is subject to the limitations and exclusions of liability in the Agreement. Nothing in this DPA limits any liability of either party to a data subject under Article 82 GDPR.

10. General

This DPA is governed by the law of Finland, and disputes are subject to the exclusive jurisdiction of the District Court of Helsinki, except where Data Protection Law or the SCCs require otherwise. If a provision is held invalid, the rest remains in force. We may update this DPA where required by a change in Data Protection Law or in the service, and will give notice of any material change; no update will reduce the protections it provides.

Annex I — Description of the processing

Parties

Data exporter / controller: the customer organisation identified in the Agreement.
Data importer / processor: Memo Technologies Oy, Business ID 3602819-5, Finland — henri@sentmemo.com.

Subject matter, nature and purpose

Provision of the Memo service: an AI assistant that reads meeting notes, messages, calendar events, emails and CRM records, and produces summaries, proposed CRM records, drafted messages and reminders for a person to review and approve. Processing operations include collection, storage, structuring, retrieval, transmission to model providers for inference, and erasure.

Duration

For the term of the Agreement, plus the deletion period in section 8.

Categories of data subjects

Categories of personal data

Special categories of data

None are requested or required. Memo is not designed to process special categories of personal data under Article 9 GDPR, and you should not use it to do so. Free-text content may incidentally contain such data; it receives the same protections as all other Customer Personal Data.

Frequency

Continuous, for the duration of the Agreement.

Annex II — Technical and organisational measures

We maintain measures appropriate to the risk, as required by Article 32 GDPR. These currently include:

We review these measures as the service develops and may replace a measure with one that offers an equivalent or higher level of protection.

Annex III — Sub-processors

The authorised sub-processors, their purpose and their processing location are listed at sentmemo.com/subprocessors, which is incorporated into this DPA and kept current.