Data Processing Addendum
Effective date: June 20, 2026
Last modified: June 20, 2026
This Data Processing Addendum ("DPA") supplements the Terms of Service or other agreement (the "Agreement") between Customer and Speech Revolutions LLC ("Speech Revolutions"). Capitalized terms not defined here have meanings in the Agreement.
1. Definitions
1.1 "Authorized Subprocessor" means a third party engaged by Speech Revolutions to process Personal Data to provide the Services and approved by Customer under Section 6.
1.2 "Account Data" means personal data relating to Speech Revolutions' relationship with Customer, including contact information for individuals authorized to access Customer's account and billing details.
1.3 "Data Privacy Framework" means the EU-U.S., UK Extension, and/or Swiss-U.S. Data Privacy Frameworks, as applicable.
1.4 "Data Subject" means a natural person whose Personal Data is protected under Privacy Laws, including "Consumer" where applicable.
1.5 "Data Subject Request" means a request from a Data Subject to exercise rights under Privacy Laws.
1.6 "EU SCCs" means standard contractual clauses approved by the European Commission in Decision 2021/914, as modified by Section 9 of this DPA.
1.7 "ex-EEA Transfer" means transfer of Personal Data subject to the GDPR from the EEA to a country without an adequacy decision.
1.8 "ex-UK Transfer" means transfer of Personal Data subject to the UK GDPR from the UK where no adequacy decision applies.
1.9 "Personal Data" means Customer Data relating to an identified or identifiable Data Subject under Privacy Laws. Personal Data excludes protected health information governed by a separate business associate agreement, if any.
1.10 "Privacy Laws" means applicable laws governing Personal Data processing, including the GDPR, UK GDPR, Swiss FADP, UK Data Protection Act 2018, and U.S. state comprehensive privacy laws such as the CCPA/CPRA, as amended. Terms such as "Controller," "Processor," "process," "sell," "share," and "Personal Data Breach" have meanings under Privacy Laws.
1.11 "Standard Contractual Clauses" means the EU SCCs and UK SCCs.
1.12 "UK Addendum" means the UK International Data Transfer Addendum completed per Exhibit D.
1.13 "UK SCCs" means the EU SCCs as amended by the UK Addendum.
2. Role of the Parties; Description of Processing
2.1 Except as stated herein, Customer is Controller and Speech Revolutions is Processor for Personal Data, or where Customer is a Processor, Speech Revolutions is a subprocessor.
2.2 Speech Revolutions processes Personal Data only (i) for purposes in the Agreement, (ii) per Customer's documented instructions including this DPA, and (iii) as required by Privacy Laws or supervisory authorities, notifying Customer before processing where legally permitted. Processing details are in Exhibit A.
3. Customer's Obligations
Customer shall process Personal Data and provide instructions in compliance with Privacy Laws and ensure instructions will not cause Speech Revolutions to breach Privacy Laws. Customer is responsible for accuracy, quality, legality, and acquisition of Personal Data. Speech Revolutions will notify Customer if an instruction appears to infringe Privacy Laws. Customer shall not provide Personal Data in violation of the Agreement.
4. Use of Personal Data
Speech Revolutions shall not: (i) sell or share Personal Data; (ii) retain, use, or disclose Personal Data outside the direct business relationship with Customer except as necessary to perform the Services or as permitted by Privacy Laws; or (iii) combine Personal Data from Customer with data from other sources except as necessary to provide the Services or as instructed by Customer.
5. Audit
5.1 Speech Revolutions maintains records demonstrating compliance with this DPA. Upon reasonable written request, Speech Revolutions will provide information reasonably available to demonstrate compliance with this DPA and applicable Privacy Laws. If Privacy Laws require additional verification beyond such information, the Parties will cooperate in good faith on reasonable measures, subject to reasonable notice and scope limited to Customer-relevant processing. Customer bears costs of any on-site review it requests where permitted by Privacy Laws.
5.2 If Customer determines unauthorized processing, Customer may, after notice, take commercially reasonable steps to stop and remediate such processing.
6. Authorized Subprocessors
6.1 Customer authorizes Speech Revolutions to engage affiliates and Authorized Subprocessors listed in Exhibit B and /legal/subprocessors to process Personal Data.
6.2 Speech Revolutions will provide at least ten (10) days' notice before adding new subprocessors (via email subscription where available). Customer may object in writing within ten (10) days on reasonable data protection grounds. If Customer does not object, the subprocessor is authorized. Objecting to essential subprocessors may prevent provision of the Services.
6.3 If Customer reasonably objects and no commercially reasonable alternative exists, Customer may discontinue the affected Service with written notice; discontinuation does not relieve payment obligations.
6.4 Speech Revolutions enters written agreements with subprocessors imposing comparable data protection obligations and remains liable for subprocessor performance.
6.5 Where Standard Contractual Clauses apply, this authorization constitutes prior written consent to subcontracting, and subprocessor agreements may be provided upon request with commercial information redacted.
7. Confidentiality; Security of Personal Data
7.1 Speech Revolutions ensures persons authorized to process Personal Data are bound by confidentiality obligations. Speech Revolutions may disclose Personal Data to advisers and auditors as required to comply with Privacy Laws.
7.2 Speech Revolutions maintains appropriate technical and organizational measures as described in Exhibit C, considering the nature, scope, and risks of processing.
8. Personal Data Breach
8.1 Upon a Personal Data Breach, Speech Revolutions will inform Customer without undue delay and take reasonable remediation steps within its control.
8.2 Speech Revolutions will provide reasonable cooperation to help Customer comply with notification obligations to supervisory authorities and Data Subjects.
8.3 These obligations do not apply to breaches caused by Customer and do not constitute admission of fault or liability.
9. Transfers of Personal Data
9.1 Speech Revolutions may transfer Personal Data outside the EEA, UK, or Switzerland as necessary to provide the Services. Speech Revolutions processes Personal Data using infrastructure operated by Speech Revolutions and its Authorized Subprocessors in the jurisdictions identified on the Subprocessors page, which may be updated from time to time in accordance with Section 6. Where no adequacy decision exists, Speech Revolutions implements appropriate safeguards under Privacy Laws.
9.2 Ex-EEA Transfers. Ex-EEA Transfers are governed by the EU Standard Contractual Clauses completed as follows, unless Speech Revolutions or another applicable data importer is certified under the EU-U.S. Data Privacy Framework, in which case the Data Privacy Framework may be used where applicable: Module One for controller-to-controller processing; Module Two when Customer is controller and Speech Revolutions is processor; Module Three when Customer is processor and Speech Revolutions is subprocessor.
9.3 For EU SCCs: optional docking clause in Clause 7 does not apply; Clause 9 Option 2 applies with notice per Section 6.2; Clause 11 optional language does not apply; Clause 13 square brackets removed; Clause 17 governed by laws of Ireland; Clause 18(b) disputes in Ireland courts; Exhibits B and C contain Annex I and II information; Parties are deemed to have signed the EU SCCs.
9.4 Ex-UK Transfers. Ex-UK Transfers are governed by UK SCCs under laws of England and Wales with disputes in England and Wales courts, unless Speech Revolutions or another applicable data importer is certified under the UK Extension to the EU-U.S. Data Privacy Framework, in which case the Data Privacy Framework may be used where applicable.
9.5 Transfers from Switzerland. Transfers from Switzerland are governed by EU SCCs modified to include FADP/revised FADP and FDPIC authority as described in standard SCC practice, unless Speech Revolutions or another applicable data importer is certified under the Swiss-U.S. Data Privacy Framework, in which case the Data Privacy Framework may be used where applicable.
9.6 Supplementary Measures. Speech Revolutions has not received formal government intelligence requests for exported Personal Data as of this DPA's date. If compelled to disclose Personal Data, Speech Revolutions will notify Customer where permitted and cooperate on protective orders. Parties will confer on whether transfers should continue or be suspended.
10. Data Protection Assessments
Speech Revolutions will reasonably cooperate with Customer on privacy or data protection impact assessments required by Privacy Laws by providing information Customer cannot obtain independently. Each party remains responsible for its allocated obligations.
11. Data Subject Requests
11.1 Speech Revolutions will notify Customer of Data Subject Requests where permitted and direct Data Subjects to Customer. Customer is responsible for responses and maintaining consent records.
11.2 Upon request, Speech Revolutions will apply reasonable measures to assist Customer where Customer cannot respond without assistance. Customer bears costs where legally permitted.
12. Return or Destruction of Personal Data
Upon Agreement termination, Speech Revolutions will return or delete Personal Data per Customer instructions unless retention is required by law. Where return or deletion is impracticable, Speech Revolutions will block further processing except as required by law and continue protection. Deletion certification is provided upon Customer request where SCCs apply.
13. Speech Revolutions as Controller
For Account Data and Usage Data, Speech Revolutions is an independent controller to manage the Customer relationship, operate core business functions, prevent fraud and abuse, verify identity, comply with legal obligations, and maintain the Services as permitted by Privacy Laws. Such processing follows our Privacy Policy.
14. Miscellaneous
Precedence: (1) Standard Contractual Clauses; (2) this DPA; (3) the Agreement; (4) Privacy Policy. DPA claims are subject to Agreement liability limits and exclusions.
Exhibit A — Details of Processing
Nature and purpose: Speech Revolutions processes Personal Data to provide the Services per the Agreement and Customer instructions, including receiving, storing, analyzing, updating, protecting, sharing, returning, and deleting data as necessary for batch speech-to-text and related features.
Duration: Personal Data is processed to provide the Services and per Customer instructions. Uploaded audio and transcripts are deleted within 30 minutes of job completion unless law requires otherwise. Account Data is retained per the Privacy Policy.
Categories of Data Subjects: Customer employees, contractors, end users, and individuals whose voice appears in submitted audio.
Categories of Personal Data: Account Data, Usage Data, and Personal Data in Customer submissions including names, contact details, occupation, and voice or transcript content.
Sensitive data: None except as submitted by Customer in compliance with the Agreement and Privacy Laws.
Exhibit B — Transfer Details and Subprocessors
| Item | Details |
|---|---|
| Data exporter | Customer — details as in console account and Agreement |
| Data importer | Speech Revolutions LLC — contact: legal@speechrevolutions.com |
| Transfer frequency | As necessary to perform obligations under the Agreement |
| Authorized Subprocessors | /legal/subprocessors |
| Processing locations | As listed on the Subprocessors page |
| Supervisory authority | Data exporter's authority under EU SCCs; UK ICO for UK Addendum |
Exhibit C — Technical and Organizational Measures
| Category | Description |
|---|---|
| Access controls | Access to production systems is restricted to authorized personnel; role-based access controls are used where applicable |
| Encryption | Personal Data is encrypted in transit and at rest |
| Monitoring | Logging and monitoring are maintained for systems handling Personal Data |
| Maintenance | Security updates are applied on a reasonable basis |
| Incident response | Incident response procedures are maintained |
| Retention | Customer data is retained only as necessary to provide the Services and as described in Exhibit A |
| Physical security | Infrastructure providers maintain physical and environmental controls at hosting facilities |
| Business continuity | Reasonable backup and recovery practices are maintained for core Services |
Exhibit D — UK Addendum
The UK International Data Transfer Addendum to the EU SCCs is incorporated by reference. Table 1 parties are Customer (exporter) and Speech Revolutions (importer). Table 2 references EU SCCs completed per Section 9. Table 3 references Exhibits B and C. Table 4: both parties may end this UK Addendum when the approved addendum changes.