Data Processing Agreement
This Data Processing Agreement (“DPA”) governs our processing of personal data on your behalf when you use Memo. It forms part of the Terms of Service or of any other written agreement between us covering the Memo service (the “Agreement”), and applies automatically — you do not need to sign it separately. Where it conflicts with the rest of the Agreement, this DPA wins on matters of data protection.
If your procurement process requires a countersigned copy, or your own DPA template, write to henri@sentmemo.com and we will arrange it.
1. Definitions
“GDPR” means Regulation (EU) 2016/679. Controller, processor, data subject, personal data, processing and supervisory authority have the meanings given in the GDPR. “Customer Personal Data” means personal data contained in the Customer Data that we process on your behalf under the Agreement. “Sub-processor” means a processor we engage to process Customer Personal Data. “Data Protection Law” means the GDPR, the Finnish Data Protection Act (1050/2018), and any other applicable data protection legislation, including the UK GDPR where relevant.
2. Roles
You are the controller of Customer Personal Data and we are your processor. You are responsible for the lawfulness of the data you give us and of the instructions you issue, including having a valid legal basis for the processing and for giving any notices owed to data subjects.
We act as an independent controller for a limited set of data that is not Customer Personal Data — account administration, billing, and security and service telemetry. That processing is described in our Privacy Policy and is outside this DPA.
3. Our processing obligations
We will:
- process Customer Personal Data only on your documented instructions, including as to international transfers, unless required otherwise by EU or Member State law — in which case we will tell you before processing, unless that law forbids it. The Agreement, this DPA, and your use of the service’s features are your documented instructions;
- tell you if, in our opinion, an instruction infringes Data Protection Law;
- ensure that everyone authorised to process Customer Personal Data is bound by an appropriate duty of confidentiality;
- implement and maintain the technical and organisational measures set out in Annex II, as required by Article 32 GDPR;
- not sell Customer Personal Data, and not use it for any purpose other than providing and supporting the service under the Agreement.
We do not use Customer Personal Data to train artificial intelligence models, and we do not permit any sub-processor to do so. Content we send to model providers is processed for the request and is not retained by them for training.
4. Sub-processors
You give us general written authorisation to engage sub-processors. The current list is published at sentmemo.com/subprocessors and forms Annex III to this DPA.
We will give at least 30 days’ notice before a new sub-processor begins processing Customer Personal Data. You may object on reasonable data protection grounds within that period; if we cannot offer a reasonable alternative, you may terminate the affected part of the service and receive a pro-rata refund of prepaid, unused fees.
We impose on each sub-processor data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.
5. International transfers
Customer Personal Data is stored in the European Union. Where a sub-processor processes it outside the EEA, that transfer is made under the European Commission’s Standard Contractual Clauses (Decision 2021/914) or another valid transfer mechanism, together with the supplementary measures described in Annex II.
Where the SCCs apply between you and us, they are incorporated into this DPA: Module Two (controller to processor) applies, with the optional docking clause included; Clause 7 applies; Clause 9 option 2 (general written authorisation, 30 days) applies; Clause 11 optional redress wording does not apply; Clause 17 is governed by the law of Finland; Clause 18(b) designates the courts of Finland. Annexes I, II and III below populate the SCC annexes.
6. Assistance we owe you
Taking into account the nature of the processing and the information available to us, we will:
- Data subject requests. Assist you with appropriate technical and organisational measures in responding to requests to exercise rights under Chapter III GDPR. The service’s own export and deletion features are the primary means of this. If a request reaches us directly, we will not respond to it substantively but will forward it to you without undue delay.
- Security and breach. Assist you in complying with Articles 32 to 36 GDPR. We will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information available to us at the time and further detail as it becomes known.
- Impact assessments. Provide reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority, where these relate to our processing.
7. Audit
We will make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits conducted by you or an auditor you mandate.
In practice, we will first offer our then-current security documentation and answer a reasonable security questionnaire. If that does not satisfy a specific regulatory requirement, you may conduct an audit no more than once in any twelve-month period (and at any time after a personal data breach), on 30 days’ written notice, during business hours, without unreasonable disruption, and subject to confidentiality. Each party bears its own costs. Any auditor must not be a competitor of ours.
8. Deletion and return
On termination or expiry of the Agreement, we will delete Customer Personal Data within 60 days, unless EU or Member State law requires us to keep it. Before deletion, you may export your data through the service; on request within that window, we will provide a copy in a commonly used machine-readable format. Backups are deleted on their normal rotation cycle and remain protected by this DPA until they are.
9. Liability
Each party’s liability arising out of this DPA is subject to the limitations and exclusions of liability in the Agreement. Nothing in this DPA limits any liability of either party to a data subject under Article 82 GDPR.
10. General
This DPA is governed by the law of Finland, and disputes are subject to the exclusive jurisdiction of the District Court of Helsinki, except where Data Protection Law or the SCCs require otherwise. If a provision is held invalid, the rest remains in force. We may update this DPA where required by a change in Data Protection Law or in the service, and will give notice of any material change; no update will reduce the protections it provides.
Annex I — Description of the processing
Parties
Data exporter / controller: the customer organisation identified in the
Agreement.
Data importer / processor: Memo Technologies Oy, Business ID 3602819-5,
Finland — henri@sentmemo.com.
Subject matter, nature and purpose
Provision of the Memo service: an AI assistant that reads meeting notes, messages, calendar events, emails and CRM records, and produces summaries, proposed CRM records, drafted messages and reminders for a person to review and approve. Processing operations include collection, storage, structuring, retrieval, transmission to model providers for inference, and erasure.
Duration
For the term of the Agreement, plus the deletion period in section 8.
Categories of data subjects
- The customer’s personnel who use Memo.
- The customer’s prospects, customers and business contacts, and the individuals appearing in the customer’s CRM, calendar, email and meeting records.
Categories of personal data
- Identity and contact data — names, work email addresses, phone numbers, job titles, employer.
- Professional relationship data — deals, pipeline stages, values, notes, tasks, ownership and activity history.
- Communications content — meeting notes, chat messages, voice notes and their transcripts, meeting transcripts, calendar event details, and email content where Gmail is connected.
- Account and usage data — sign-in identity, role, preferences, product usage events and session recordings of the web application.
Special categories of data
None are requested or required. Memo is not designed to process special categories of personal data under Article 9 GDPR, and you should not use it to do so. Free-text content may incidentally contain such data; it receives the same protections as all other Customer Personal Data.
Frequency
Continuous, for the duration of the Agreement.
Annex II — Technical and organisational measures
We maintain measures appropriate to the risk, as required by Article 32 GDPR. These currently include:
- Data residency. The production database, application compute and product analytics run in the European Union.
- Encryption. Data is encrypted in transit with TLS and at rest by the underlying storage platform.
- Tenant isolation. Each customer’s data is separated at the database level by row-level security, so a query issued in one customer’s context cannot read another’s.
- Network isolation. The production database is not reachable from the public internet and is accessed over a private connection.
- Secret management. Credentials and keys are held in a managed secret store, never in source code, and are access-controlled and versioned.
- Access control. Access to production systems and data is limited to personnel who need it, uses individual accounts with multi-factor authentication, and is reviewed periodically.
- Authentication. End users authenticate through their organisation’s Google identity. Session cookies are HTTP-only, secure and same-site.
- Application hardening. Security response headers including a Content Security Policy and HTTP Strict Transport Security; signature verification on inbound webhooks; state validation on OAuth flows.
- Logging and monitoring. Application and access logs are centralised, retained for a limited period, and monitored for errors and anomalies.
- Change management. Changes are version-controlled, reviewed, and gated by an automated test suite before reaching production. Database migrations are applied through a controlled process.
- Dependency management. Dependencies are scanned for known vulnerabilities on a recurring schedule, and security patches are applied promptly.
- Human approval by design. Changes Memo proposes to a customer’s CRM, email or calendar are presented for approval before they take effect, limiting the impact of an incorrect model output.
- Deletion. Disconnecting an integration removes the stored access credentials for it. Account termination triggers deletion per section 8.
We review these measures as the service develops and may replace a measure with one that offers an equivalent or higher level of protection.
Annex III — Sub-processors
The authorised sub-processors, their purpose and their processing location are listed at sentmemo.com/subprocessors, which is incorporated into this DPA and kept current.
Business ID 3602819-5 · VAT FI36028195 · Finland
henri@sentmemo.com · Privacy Policy · Terms of Service · Sub-processors