MeetiaMeetia
Switch between light and dark theme
Log in
Start free
Features
Use cases
Work & businessResearch & discoveryHiring & peopleClient & customerLive thinking & creativityLearning & accessibilityIn-person & solo
DownloadHelp center
Switch between light and dark theme
Log in
Start free

Data Processing Agreement

Version 2.0 · Effective 28 July 2026 · Empha Studio Ltd. — GDPR Article 28

This Data Processing Agreement ("DPA") is entered into between Empha Studio Ltd., a company incorporated in Cyprus (registration number: CY10438500L), with its registered address at Ntempyssi 22, 3120, Limassol, Cyprus, operating the Meetia platform ("Meetia", "we", "us"), and the entity or individual accessing or using the Meetia Service ("Customer", "you").

This DPA supplements the Meetia Terms of Service ("Terms") available at meetia.io/terms and is incorporated therein by reference. In the event of any conflict between this DPA and the Terms, the terms of this DPA shall prevail with respect to the processing of Personal Data. By using the Service, Customer agrees to be bound by this DPA.

This DPA applies where and to the extent that Meetia processes Personal Data on behalf of Customer in the course of providing the Service, and Customer acts as a Data Controller (or Processor acting on behalf of another controller) in relation to that Personal Data.

1. Definitions

For the purposes of this DPA, the following terms have the meanings set out below. Capitalized terms not defined herein have the meaning given to them in the Terms or, where applicable, in the GDPR.

"Artificial Intelligence System" means a machine-based system that, for any explicit or implicit objective, infers from the inputs it receives how to generate outputs such as content, decisions, predictions, or recommendations that can influence real or virtual environments, as defined or referenced under the EU AI Act (Regulation (EU) 2024/1689).

"Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, as defined in Article 4(7) GDPR.

"Customer Personal Data" means any Personal Data contained in Meeting Content or otherwise submitted to the Service by Customer or on Customer's behalf, which Meetia processes on behalf of Customer under this DPA.

"Data Protection Laws" means all applicable data protection and privacy laws, in particular: (i) Regulation (EU) 2016/679 (GDPR); (ii) applicable EU Member State implementations of the GDPR; (iii) the Cyprus Personal Data Protection Law (Law 125(I)/2018); (iv) the EU AI Act (Regulation (EU) 2024/1689) to the extent applicable; and (v) any successor or replacement legislation.

2. Roles and Relationship of the Parties

2.1 Roles

The parties acknowledge and agree that, in connection with the processing of Customer Personal Data through the Service:

  • Customer acts as the Data Controller (or, where Customer is itself a Processor, as a Processor acting under its own controller's instructions), determining the purposes and means of processing Meeting Content and other Customer Personal Data.
  • Meetia acts as the Data Processor, processing Customer Personal Data solely on behalf of and in accordance with Customer's documented instructions, as set out in this DPA, the Terms, and Customer's configuration of the Service.

Nothing in this DPA or the Terms shall be construed to make Meetia a joint Controller or an independent Controller of Customer Personal Data. Where Meetia processes Personal Data for its own legitimate purposes (such as account management, billing, and service security), it does so as an independent Controller, and such processing is governed by Meetia's Privacy Policy at meetia.io/privacy, not this DPA.

2.2 Nature of Meetia's Service

Meetia provides real-time AI-augmented transcription and meeting intelligence. During live meetings, the Service receives audio streams from user devices, transmits them to EU-hosted speech-to-text infrastructure for transcription, and discards the audio upon completion of transcription — only the resulting text transcript is stored. AI-generated outputs are then processed in real time based on the transcript. The data residency and transfer provisions of this DPA apply to all such processing, including live inference pipelines.

2.3 Dual Role — Controller and Processor

Meetia operates this Service both as:

  • A Data Controller with respect to personal data of registered users of the Service (such as account information and billing data); and
  • A Data Processor with respect to Customer Personal Data processed on behalf of Customer through the Service (including Meeting Content).

This DPA governs Meetia's role as Data Processor only. Meetia's role as Data Controller is addressed separately in the Privacy Policy.

3. Processing Instructions

3.1 Documented Instructions

Meetia shall process Customer Personal Data only on the basis of Customer's documented instructions. Customer's instructions include:

  • The terms of this DPA and the Terms;
  • Customer's configuration and use of the Service (including settings, workspace configurations, and active feature choices);
  • Any additional written instructions provided by Customer to Meetia from time to time, agreed in writing by both parties.

The subject matter, nature, purpose, duration, and categories of data processed are set out in Annex I to this DPA.

3.2 Limits on Processing

Meetia shall not process Customer Personal Data for any purpose other than as necessary to provide the Service and as set out in this DPA. In particular, Meetia shall not:

  • Use Customer Personal Data — including Meeting Content, transcripts, or AI-session content — to train, retrain, fine-tune, or otherwise improve any AI or machine learning model, unless Customer has provided explicit, informed, and freely given consent to such processing for that purpose;
  • Sell, rent, licence, or otherwise commercially exploit Customer Personal Data;
  • Retain Customer Personal Data beyond the retention periods specified in this DPA or Customer's instructions;
  • Combine Customer Personal Data with personal data obtained from other customers or from Meetia's own services for purposes not authorised by Customer.

Meetia may use anonymised, aggregated, and de-identified usage data derived from interactions with the Service for internal product improvement purposes, provided such data cannot reasonably be re-linked to individual Data Subjects or to Customer.

3.3 Compliance with Applicable Law

If Meetia is required by applicable EU or Cypriot law to process Customer Personal Data for a reason other than as instructed by Customer, Meetia shall inform Customer in advance of such processing to the extent permitted by law.

3.4 Notification of Unlawful Instructions

Meetia shall promptly inform Customer if, in Meetia's reasonable opinion, an instruction from Customer would violate applicable Data Protection Laws. In such case, Meetia may suspend compliance with the relevant instruction until the parties agree on a lawful alternative. Meetia shall not be liable for any failure to comply with instructions that would themselves constitute a violation of Data Protection Laws.

4. Subprocessors

4.1 Authorisation

4.2 AI Infrastructure — EU Hosting and Zero Data Retention

Meetia's AI inference and processing infrastructure is hosted exclusively within the European Union. Meetia uses Mistral AI models (including Voxtral for speech-to-text) deployed on EU-based infrastructure in France. Customer Personal Data — including meeting audio streams processed during real-time transcription — is transmitted to and processed within the EU only. No Customer Personal Data is transferred to Mistral AI's infrastructure in a manner that takes it outside the EEA, unless required by law or as otherwise notified to Customer under Section 4.3.

Meetia has executed a Data Processing Agreement with Mistral AI covering: (i) processing of Customer Personal Data solely for service delivery purposes; (ii) prohibition on use of Customer Personal Data for model training; (iii) confirmed zero data retention for all inference requests (completions, embeddings, and speech-to-text); and (iv) maintenance of EU data residency throughout the inference pipeline.

4.3 Changes to Subprocessors

Meetia shall provide Customer with at least thirty (30) days' prior written notice of any intended addition or replacement of a Subprocessor that will process Customer Personal Data. Such notice will be provided by updating the Subprocessor List and notifying Customers who have subscribed to change notifications via the account settings or contact@meetia.io.

4.4 Objection Right

Customer may object to a new or replacement Subprocessor on reasonable grounds relating to the protection of Customer Personal Data by notifying Meetia in writing at contact@meetia.io within fifteen (15) days of receiving notice of the change. The parties shall cooperate in good faith to resolve Customer's objection. If no resolution can be reached within thirty (30) days of Meetia's receipt of the objection, and Meetia cannot provide the relevant aspect of the Service without the new Subprocessor, Customer may terminate the affected Service with a pro-rata refund of prepaid fees. This termination right is Customer's sole and exclusive remedy with respect to any Subprocessor objection.

4.5 Subprocessor Obligations

Meetia shall impose on each Subprocessor data protection obligations that are no less protective than those set out in this DPA, including in particular obligations relating to: confidentiality; processing only on instructions; implementing appropriate technical and organisational security measures; data retention and deletion; and compliance with applicable Data Protection Laws. Meetia remains liable to Customer for any failure by a Subprocessor to fulfil its obligations under its sub-processing agreement.

5. Special Categories of Personal Data and Voice/Biometric Data

5.1 Voice Data

Customer acknowledges that the Service processes voice audio as part of the transcription function. Meeting audio is transmitted transiently to EU-hosted speech-to-text infrastructure and is not retained after transcription. The Service stores the resulting text transcript and speaker labels (e.g., "Speaker 1", or named identifiers where provided by users). Depending on the context and applicable law, voice data processed in transit, as well as speaker identification labels derived from it, may constitute biometric data or other Special Categories of Personal Data under Article 9 GDPR.

Customer, as Data Controller, is responsible for:

  • Identifying whether the voice data processed through the Service in its specific context constitutes Special Category Data;
  • Establishing and documenting the appropriate legal basis and any applicable exemption under Article 9(2) GDPR for such processing;
  • Providing all required information notices to Data Subjects (including meeting participants) under Articles 13 and 14 GDPR before processing begins.

5.2 Non-User Participants

Where Customer uses the Service to transcribe meetings in which third-party participants (non-Meetia users) are present, Customer is solely responsible for ensuring that all such participants have been informed of the transcription in compliance with applicable Data Protection Laws. Customer must ensure a lawful basis exists under Article 6 GDPR (and, where applicable, Article 9 GDPR) for processing the personal data of all participants.

5.3 Prohibition on Processing Without Lawful Basis

Customer shall not use the Service to process Special Categories of Personal Data unless Customer has first: (i) satisfied itself that a valid legal basis under Article 9(2) GDPR applies; (ii) implemented appropriate safeguards; and (iii) notified Meetia if such processing requires specific contractual protections. Meetia processes Special Categories of Personal Data only to the extent that such data appears incidentally in Meeting Content — Meetia does not intentionally solicit or structure the collection of such data.

6. Security

6.1 Technical and Organisational Measures

Meetia shall implement and maintain appropriate Technical and Organisational Measures (TOMs) to ensure a level of security appropriate to the risk posed by processing Customer Personal Data, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks of varying likelihood and severity to the rights and freedoms of natural persons, as required by Article 32 GDPR. The TOMs are described in Annex II to this DPA.

6.2 Live Processing Security

Given that Meetia processes Meeting Content in real time during live meetings, Meetia specifically maintains: (i) encryption of audio and text in transit from user devices to Meetia's EU infrastructure; (ii) isolated processing environments for each workspace or thread; and (iii) controls to prevent Meeting Content of one Customer from being accessible to another Customer's inference session.

6.3 Confidentiality Obligations

Meetia shall ensure that all personnel authorised to process Customer Personal Data are subject to appropriate contractual or statutory confidentiality obligations, and receive training appropriate to their role in the handling of personal data.

6.4 Updates to Security Measures

Meetia may update its TOMs from time to time, provided that any such update does not materially reduce the overall level of security protection afforded to Customer Personal Data. Meetia will notify Customer of any material changes to TOMs that affect Customer's security obligations.

7. Personal Data Breach

7.1 Notification

Meetia shall notify Customer without undue delay, and in any event within 48 hours, after Meetia becomes aware of a Personal Data Breach affecting Customer Personal Data. Notification shall be sent to the email address associated with Customer's account unless Customer has designated an alternative contact for security incidents.

The notification shall include, to the extent then known:

  • A description of the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and records affected;
  • The likely consequences of the Personal Data Breach;
  • The measures taken or proposed to be taken by Meetia to address the breach, including measures to mitigate its possible adverse effects;
  • The name and contact details of a point of contact for further information.

Meetia may provide this information in phases where it is not possible to provide all information simultaneously, provided that further information is provided without undue further delay.

7.2 Assistance with Notification

Meetia shall provide reasonable assistance to Customer in complying with Customer's obligations under Articles 33 and 34 GDPR, including Customer's obligation to notify its supervisory authority and affected Data Subjects. A Meetia notification of a Personal Data Breach does not constitute an admission of fault or liability.

7.3 Mitigation

Meetia shall take commercially reasonable steps to contain and mitigate any Personal Data Breach and will cooperate with Customer's investigation at Customer's request.

8. Data Subject Rights

8.1 Primary Responsibility

Customer is responsible, as Data Controller, for responding to Data Subject Requests in relation to Customer Personal Data. Meetia shall not respond to Data Subject Requests directly, except to direct the Data Subject to contact Customer, or where required to do so by law.

8.2 Meetia's Assistance

Meetia shall promptly forward to Customer any Data Subject Request received that relates to Customer Personal Data. Where Customer lacks the technical capability to fulfil the request using the Service's self-service tools, Meetia shall provide reasonable assistance, at Customer's written request and expense, to:

  • Locate and provide access to Customer Personal Data;
  • Correct or update Customer Personal Data;
  • Delete or restrict processing of Customer Personal Data.

Note: Meetia does not currently provide an automated self-service data export function. Customers requiring export of Customer Personal Data for data portability purposes (Article 20 GDPR) should contact contact@meetia.io to request manual export assistance.

8.3 Rectification and Erasure

Upon Customer's written instruction, Meetia shall correct inaccurate Customer Personal Data and delete Customer Personal Data that is no longer necessary, subject to any retention obligations under applicable law. Account deletion is supported via Meetia's platform, which triggers anonymisation and soft deletion of personal data and memberships in accordance with Article 17 GDPR.

9. Data Protection Impact Assessments and Prior Consultation

Meetia shall, taking into account the nature of the processing and the information available to it, provide reasonable assistance to Customer in:

  • Conducting data protection impact assessments (DPIAs) in connection with the Service as required under Article 35 GDPR;
  • Carrying out prior consultations with supervisory authorities as required under Article 36 GDPR;
  • Complying with obligations under the EU AI Act in relation to AI systems used by the Service, including with respect to transparency, risk classification, and human oversight measures.

Meetia shall maintain records of its own processing activities under this DPA as required by Article 30(2) GDPR and make relevant information available to Customer upon request to support Customer's own DPIA and records of processing activities.

10. Audits and Inspections

10.1 Documentation and Reports

Upon Customer's written request no more than once per calendar year, Meetia shall provide Customer with such information as is reasonably necessary to demonstrate Meetia's compliance with its obligations under this DPA, including relevant security certifications, third-party audit summaries (such as SOC 2 reports, where available), and responses to a standard security questionnaire.

10.2 On-Site Audits

Where Meetia's documentation is insufficient to satisfy Customer's obligation under applicable Data Protection Laws, Customer may request an on-site audit. Any such audit shall be:

  • Subject to at least thirty (30) days' prior written notice;
  • Conducted no more than once per year (unless required by a supervisory authority);
  • Limited in scope to Meetia's processing of Customer Personal Data;
  • Conducted during normal business hours and in a manner minimally disruptive to Meetia's operations;
  • Carried out by Customer or a mutually agreed, qualified third-party auditor who is bound by an appropriate confidentiality agreement;
  • Conducted at Customer's sole cost, including Meetia's reasonable costs of cooperation.

Audit findings shall be the confidential information of Meetia and may not be disclosed to third parties without Meetia's prior written consent, except as required by law.

10.3 Compliance Certification

Where permitted by applicable Data Protection Laws, Meetia may satisfy an audit request by providing Customer with a summary of relevant third-party audit or certification reports in lieu of an on-site inspection.

11. Data Retention and Deletion

11.1 Retention During Service

Meetia shall retain Customer Personal Data for the duration of Customer's active account and as necessary to provide the Service, in accordance with the retention settings available to Customer within the Service.

11.2 Deletion on Termination

Upon termination or expiration of the Terms, Meetia shall, at Customer's election expressed within thirty (30) days of termination:

  • Contact contact@meetia.io to request manual export of Customer Personal Data; or
  • Request secure deletion or destruction of Customer Personal Data from Meetia's systems.

Where Customer makes no election within thirty (30) days, Meetia shall delete Customer Personal Data within a further thirty (30) days, except where retention is required by applicable EU or Cypriot law. Meetia shall direct each Subprocessor to delete Customer Personal Data within the same timeframe.

11.3 Anonymised Data

For the avoidance of doubt, Meetia may retain anonymised, aggregated, and de-identified data that has been derived from Customer Personal Data and cannot reasonably be re-linked to individual Data Subjects, for legitimate product improvement purposes.

11.4 Retention Obligations

Where Meetia is required by applicable law to retain certain Customer Personal Data beyond the periods described above, Meetia shall isolate such data from active processing and protect it against further use until it can lawfully be deleted.

12. International Data Transfers

12.1 EU Infrastructure — No Third-Country Transfer

Meetia operates its core Service infrastructure within the EEA. Customer Personal Data processed through the Service — including Meeting Content and AI inference pipelines — is processed and stored within the EU. Meetia commits not to transfer Customer Personal Data outside the EEA unless required by law or as set out in this Section 12.

12.2 Standard Contractual Clauses

To the extent that any processing by Meetia or a Subprocessor involves a transfer of Customer Personal Data originating in the EEA to a country not ensuring an adequate level of data protection as determined by the European Commission, the parties agree that such transfers shall be governed by the SCCs, which are hereby incorporated into this DPA by reference, with the following elections:

  • Module Two (Controller to Processor) applies where Customer is a Controller and Meetia processes Customer Personal Data as a Processor;
  • Module Three (Processor to Sub-Processor) applies where Customer acts as a Processor and Meetia acts as a Sub-Processor;
  • The optional docking clause in Clause 7 of the SCCs does not apply;
  • In Clause 9, Option 2 (general written authorisation) applies; the minimum prior notice period for Subprocessor changes is as set out in Section 4.3 of this DPA;
  • In Clause 11, the optional language does not apply;
  • In Clause 17, the SCCs are governed by the laws of the Republic of Cyprus;
  • In Clause 18(b), disputes shall be resolved before the courts of the Republic of Cyprus;
  • Annex I and Annex II of the SCCs are deemed completed with the information in Annex I and Annex II of this DPA.

12.3 UK Transfers

To the extent that Customer Personal Data subject to UK data protection law is transferred, the parties shall comply with the UK International Data Transfer Addendum issued by the UK Information Commissioner's Office (IDTA, Version B1.0, in force 21 March 2022), which is incorporated into this DPA by reference, completing Part 1 with the information in Annex I of this DPA.

12.4 Swiss Transfers

To the extent Customer Personal Data subject to the Swiss Federal Act on Data Protection (FADP) is subject to a transfer, the parties shall conduct such transfer pursuant to the SCCs with appropriate modifications to refer to the FADP, the Swiss Federal Data Protection and Information Commissioner (FDPIC) as supervisory authority, and to preserve the rights of Data Subjects in Switzerland.

12.5 CLOUD Act and US Surveillance Law Risk Disclosure

Meetia discloses that, as an EU-registered and EU-hosted service using EU AI infrastructure (Mistral AI), Customer Personal Data is not routinely accessible to US law enforcement under CLOUD Act or FISA 702 orders. If any Subprocessor with US nexus is added to the Subprocessor List in future, Meetia will conduct a Transfer Impact Assessment and implement supplementary measures as required, and will notify Customer accordingly.

13. Confidentiality

Meetia shall ensure that all personnel who have access to Customer Personal Data are subject to a legally binding duty of confidentiality, whether contractual or statutory, that survives the termination of their engagement. Meetia shall limit access to Customer Personal Data to those personnel whose job functions require such access for the performance of the Service.

14. Customer Obligations as Data Controller

14.1 Lawful Basis

Customer represents, warrants, and covenants that it has and will maintain throughout the term all necessary rights, consents, lawful bases, and legal permissions required under applicable Data Protection Laws to: (i) provide Customer Personal Data to Meetia; (ii) authorise Meetia to process Customer Personal Data as set out in this DPA; and (iii) permit meeting participants' personal data to be transcribed and processed through the Service.

14.2 Participant Consent and Notice

Customer is solely responsible for ensuring that all meeting participants are informed that their personal data — including voice audio processed for transcription and the resulting AI-generated transcripts — will be processed through the Service. Customer shall comply with applicable notice and consent obligations under Articles 13 and 14 GDPR and under any applicable national recording or surveillance laws.

14.3 Data Minimisation

Customer shall not submit to the Service any Personal Data beyond what is strictly necessary for the purposes of using the Service, and shall in particular take reasonable steps to avoid including Special Categories of Personal Data in Meeting Content unless Customer has established a valid legal basis.

14.4 Compliance

Customer shall comply with applicable Data Protection Laws in connection with its use of the Service, including maintaining any required records of processing activities and conducting DPIAs where required.

15. Liability

Each party's liability under this DPA, whether in contract, tort, or otherwise, is subject to the limitations and exclusions set out in the Terms, including the liability cap in Section 12.3 of the Terms. The total aggregate liability of either party under this DPA shall not exceed the greater of: (a) the total fees paid by Customer to Meetia in the twelve (12) months immediately preceding the event giving rise to the claim; or (b) EUR 100.

Notwithstanding the above, nothing in this DPA limits or excludes either party's liability: (i) for death or personal injury caused by negligence; (ii) for fraud or fraudulent misrepresentation; (iii) for any liability that cannot be excluded or limited under applicable EU or Cypriot law; or (iv) as required by GDPR Articles 82 and 83 (liability and fines arising from non-compliance with GDPR obligations).

Meetia shall remain liable to Customer for breaches of this DPA by its Subprocessors to the same extent Meetia would be liable if performing the relevant services directly, subject to the liability cap above.

16. Term and Termination

This DPA enters into force on the date Customer first accesses or uses the Service and remains in force for as long as Meetia processes Customer Personal Data under the Terms. This DPA terminates automatically upon expiry or termination of the Terms.

Termination of this DPA does not affect the obligations of either party that by their nature should survive, including obligations relating to data deletion, confidentiality, audit, and liability. Meetia's data deletion obligations under Section 11.2 of this DPA shall apply following any termination.

17. Governing Law and Jurisdiction

This DPA is governed by and construed in accordance with the laws of the Republic of Cyprus, without regard to its conflict of law principles, subject to the mandatory requirements of applicable EU Data Protection Laws including the GDPR.

Subject to the dispute resolution provisions in the Terms, any dispute arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of the Republic of Cyprus, sitting in Nicosia, without prejudice to data subjects' rights to bring claims before any competent supervisory authority or court in accordance with applicable EU law.

18. Amendments

Meetia may amend this DPA from time to time to reflect changes in applicable Data Protection Laws, updated Supervisory Authority guidance, or changes in how the Service processes Personal Data. Meetia will provide at least thirty (30) days' prior written notice of material amendments. Continued use of the Service after the effective date of any amendment constitutes Customer's acceptance of the amended DPA. If Customer objects to a material amendment, Customer may terminate the Service in accordance with the Terms.

19. General Provisions

Annex I

Description of Processing Activities

A. List of Parties

DATA EXPORTER
NameCustomer (as identified in Meetia account registration)
AddressAs specified in Customer's Meetia account
ContactAs specified in Customer's Meetia account
RoleController (or Processor where Customer acts on behalf of another controller)
ActivitiesUse of Meetia's AI-powered meeting intelligence platform to transcribe and analyse meetings
DATA IMPORTER
NameEmpha Studio Ltd. (operating as Meetia)
AddressNtempyssi 22, 3120, Limassol, Cyprus
RegistrationCY10438500L
Contactcontact@meetia.io
RoleProcessor (or Sub-Processor where Customer is a Processor)
ActivitiesProvision of AI-powered meeting transcription, summarisation, real-time AI assistance, search, and workspace intelligence services

B. Description of Processing

PROCESSING DETAILS
Subject matterAI-powered transcription, real-time AI interaction, summarisation, and analysis of meetings and conversations through the Service
DurationFor the duration of the Terms and until deletion in accordance with Section 11 of this DPA
Nature of processingCollection, transmission, transcription, structuring, analysis, AI inference, summarisation, retrieval, and deletion of Meeting Content and associated metadata. Meeting audio is processed transiently for transcription and is not stored; only the resulting text transcript is retained.
PurposeProviding the Service to Customer: real-time and post-meeting transcription; AI-generated summaries, action items, and insights; cross-meeting search; workspace context management; third-party integrations; and user support
FrequencyContinuous — processing occurs in real time during live meetings and asynchronously for post-meeting processing

C. Categories of Data Subjects

CategoryDescription
Registered UsersIndividuals who create a Meetia account (employees, contractors, freelancers, professionals)
Meeting ParticipantsAny natural person whose voice or statements are transcribed through the Service (including persons not registered with Meetia)
Workspace MembersIndividuals added to a Customer's Meetia workspace by the account administrator
Third-Party ContactsAny natural person referenced in Meeting Content (e.g., clients, prospects, colleagues mentioned in meetings)

D. Types of Personal Data

CategoryExamples / Notes
Account DataName, email address, profile information, account settings, subscription details
Voice / Audio Data (transient)Live audio streams processed in transit during transcription. Audio is not stored by Meetia — it is transmitted to EU-hosted speech-to-text infrastructure and discarded after transcription. Speaker labels are stored.
Meeting Content (stored)Text transcripts, speaker labels, session metadata, meeting titles, timestamps, participant names, AI-generated summaries and action items
User-Uploaded FilesDocuments, images, audio, and video uploaded manually by users to Knowledge or as message attachments — stored in Meetia's EU object storage
AI-Generated DataSummaries, action items, insights, search results, AI query responses
Calendar & MetadataCalendar event data, meeting metadata, timestamps, duration, platform identifiers
Usage DataFeature usage events, session information, workspace activity, integration logs (analytics collected only after user consent)
Communications ContentChat messages, edits, and attachments submitted to the Service
Integration CredentialsOAuth tokens for connected third-party integrations and calendar access; BYO API keys — encrypted at the application level with AES
Special Categories (incidental)Where present in Meeting Content: health information, beliefs, or other Article 9 data provided by participants — processed only incidentally and subject to Section 5 of this DPA

E. Competent Supervisory Authority

The competent supervisory authority for the purposes of the GDPR and the SCCs is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (as the EU Member State in which Meetia is established), unless otherwise required by Clause 13 of the SCCs.

Annex II

Technical and Organisational Security Measures

The following Technical and Organisational Measures (TOMs) describe the security standards Meetia maintains to protect Customer Personal Data processed through the Service. These measures apply to Meetia's production infrastructure and to all Subprocessors processing Customer Personal Data.

1. Data Encryption

  • All Customer Personal Data in transit between user devices and Meetia servers is encrypted using TLS 1.2 or higher.
  • Encryption at rest is applied selectively. API keys and OAuth credentials for third-party integrations are encrypted at the application level using AES-256. Object storage holding meeting transcripts and uploaded files is provided by Amazon S3 in the European Union, which encrypts every object at rest with AES-256; encryption and key management are performed by the storage provider. Database backups are encrypted with AES-256 before leaving our servers. Database tables (PostgreSQL) and the underlying server disks do not use encryption at rest; Meetia is evaluating full-disk encryption and managed database hosting as a future security enhancement.
  • Live audio streams are encrypted in transit from the point of capture to Meetia's EU processing infrastructure; audio is not written to persistent storage.
  • Full-disk encryption is applied to all corporate workstations with access to production systems.

2. Access Controls

  • Role-based access control (RBAC) is applied to all internal systems storing or processing Customer Personal Data;
  • Principle of least privilege: access to Customer Personal Data is restricted to personnel whose job function requires it;
  • Mandatory multi-factor authentication (MFA) for all systems with access to Customer Personal Data;
  • Customer Data is logically segregated by account using unique identifiers — one Customer's data is not accessible to another;
  • Periodic access reviews to ensure access rights remain appropriate;
  • Prompt revocation of access on employee departure or role change.

3. Infrastructure and Network Security

  • Production infrastructure hosted exclusively within EU data centres;
  • Network segmentation: production and non-production environments are separated;
  • Primary backend resources are deployed behind a VPN with restricted access;
  • Firewall and network security policies enforce least-privilege traffic flows;
  • Application secrets are managed via a secrets management service;
  • Continuous log monitoring for security events and anomalous activity.

4. Vulnerability and Incident Management

  • Security logs aggregated centrally for monitoring and forensic investigation;
  • Personal data breach detection, escalation and notification handled in accordance with Articles 33 and 34 GDPR;
  • Meetia intends to introduce independent penetration testing and a formal, documented vulnerability management programme as the Service matures, and will update this Annex when it does.

5. Personnel Security

  • Background checks on employees with access to production systems (where legally permissible);
  • Annual security and data protection training for all personnel;
  • All personnel with access to Customer Personal Data are subject to confidentiality obligations.

6. Physical Security

  • Meetia's production infrastructure is hosted in EU data centres with controlled physical access, 24-hour on-site security, video surveillance, and access logging;
  • Corporate workstations are subject to device management controls and endpoint security policies.

7. Availability and Business Continuity

  • Systems designed for recovery in the event of interruption;
  • Fault reporting and system health monitoring;
  • Automated daily backups of production databases, encrypted with AES-256 and stored off-site, separately from the production environment;
  • Backup restoration is tested to confirm that backups are recoverable.

8. Data Segregation

  • Customer Personal Data is logically segregated from data of other customers;
  • Live AI inference sessions are isolated per workspace and thread to prevent cross-customer data exposure;
  • Testing and production environments are strictly segregated.

9. Third-Party / Subprocessor Security

  • All Subprocessors are subject to written contractual obligations providing no less protection than this DPA;
  • Subprocessors undergo security assessment prior to engagement;
  • EU AI subprocessors (including Mistral AI) are contractually prohibited from using Customer Personal Data for model training.

10. AI System Security

  • AI inference calls are transmitted over encrypted channels to EU-hosted model endpoints;
  • Customer Personal Data included in inference requests is not retained by the AI model beyond the inference session; zero data retention is confirmed with Mistral AI for all inference endpoints (completions, embeddings, and speech-to-text);
  • AI outputs are stored within Meetia's EU infrastructure and subject to the same access controls as all other Customer Personal Data.

Annex III

List of Approved Subprocessors

The following Subprocessors are authorised as of the effective date of this DPA. The current and up-to-date list is maintained at meetia.io/subprocessors. Changes to this list are subject to the notification and objection procedures in Section 4 of this DPA.

SubprocessorPurposeData ProcessedLocationTransfer Mechanism
Contabo GmbHVPS hosting; runs PostgreSQL, Redis, NATS, MinIO/S3 — core data storage and servicesAll Customer Personal Data (transcripts, files, metadata)EU (Germany)No transfer — EU-hosted
Mistral AILLM inference, embeddings, and Voxtral speech-to-text. Zero data retention confirmed for all endpoints.Audio streams (transient), transcript text, AI query contentEU (France)No transfer — EU-hosted; DPA in place
Auth0 / OktaUser identity and authentication management; automated transactional emails (verification, password reset)Account credentials, email addressesEU tenantNo transfer — EU tenant; DPA in place
PostHogProduct analytics and session events — collected only after explicit user consentUsage events, session data (consent-gated)EUNo transfer — EU-hosted (eu.i.posthog.com)
Amazon Web Services (SES)Simple Email Service — transactional email delivery (e.g., notifications)Email addresses, email contentEUSCCs; DPA in place
StripePayment processing and subscription billing. Processes billing data only — does not process Meeting Content.Billing data, payment details (no meeting content)USA / GlobalSCCs; DPA in place

For the full, up-to-date subprocessor list including contact details and DPA summaries, visit meetia.io/subprocessors. To subscribe to change notifications, email contact@meetia.io.

Execution

This DPA may be accepted electronically by Customer through the Service registration process or by clicking an acceptance button on the Meetia platform. Where a signed version is required for enterprise or legal purposes, the parties may execute this DPA in counterparts by written signature below.

For and on behalf of EMPHA STUDIO LTD. (MEETIA)For and on behalf of CUSTOMER
Signature:Signature:
Name:Name:
Title:Title:
Date:Date:

For a signed version of this DPA, please contact contact@meetia.io.

MeetiaMeetia

One workspace for every meeting:
before, during, and after

Start free

Use cases

Work & businessResearch & discoveryHiring & peopleClient & customerLive thinking & creativityLearning & accessibilityIn-person & solo

Resources

FeaturesDownload for MacHelp centerContact

Legal

Privacy PolicyTerms of ServiceDPA

© 2026 Meetia.io. All rights reserved

Audio never stored — transcripts only

By clicking “Accept all”, you agree to cookies being stored on your device to help us understand how Meetia is used. Analytics only — we run no advertising and never sell your data. Privacy Policy

Reject all
Customise
Accept all

Necessary

Your cookie choice, your theme, and site security.

Always on

Analytics

Google Analytics and PostHog, including session replay.

Save choices
Cookie preferences