Home Data Processing Agreement
Article 28 GDPR

Data Processing Agreement

Annex to the Terms of Service · Article 28 GDPR · Version 4.0, in force from 10 August 2026.

This is a translation provided for convenience; the Polish version governs. The agreement is concluded upon acceptance of the Terms of Service and requires no separate signature; at the Customer’s request the Provider will sign a counterpart with a qualified electronic signature.

Przeczytaj ten dokument po polsku  ·  All legal documents

§1

Parties and roles

This agreement (the "DPA") is concluded between LUMINOTE PROSTA SPÓŁKA AKCYJNA, with its registered office in Kraków (the "Processor"), and the customer using the Luminote platform (the "Controller").

The Controller determines the purposes and means of processing of the personal data contained in Customer Data. The Processor processes that data solely on the documented instructions of the Controller.

Documented instructions comprise: the provisions of the Terms of Service and of this DPA, the configuration of the Service made by the Controller or users authorised by it, including activation of integrations and setting of retention periods, and instructions given in writing or by email to privacy@luminote.io.

If the Processor considers that an instruction of the Controller infringes the GDPR or other data protection provisions, it shall inform the Controller immediately and may withhold performance of the instruction until it is confirmed or amended.

In respect of data processed to administer the contractual relationship, billing, securing the Service and performing its own legal obligations, the Processor acts as a separate controller and processes that data on the terms described in the Privacy Policy.

§2

Subject matter, duration, nature and purpose of processing

The subject matter, duration, nature and purpose of the processing, and the categories of personal data and of data subjects, are set out in Annex A to this DPA.

Processing lasts for the term of the services agreement and for the exit period set out in the Terms of Service, after which the data is deleted in accordance with §11.

§3

Obligations of the Processor

The Processor undertakes to:

  1. process personal data solely on the documented instructions of the Controller, including as regards transfers to a third country, unless required to do so by Union or Member State law — in which case it informs the Controller before processing, unless that law prohibits such information on important grounds of public interest,
  2. ensure that persons authorised to process the data have committed themselves to confidentiality or are under a statutory obligation of confidentiality,
  3. apply the technical and organisational measures required under Article 32 GDPR, described in Annex B,
  4. respect the conditions for engaging another processor set out in §5,
  5. taking into account the nature of the processing, assist the Controller in fulfilling its obligation to respond to data subject requests, on the terms of §6,
  6. assist the Controller in fulfilling the obligations set out in Articles 32–36 GDPR, taking into account the nature of processing and the information available,
  7. after the end of the provision of services, delete or return the personal data on the terms of §11,
  8. make available to the Controller the information necessary to demonstrate compliance with the obligations under Article 28 GDPR and allow for audits on the terms of §10.
§4

Security of processing

The Processor implements technical and organisational measures appropriate to the risk to the rights and freedoms of natural persons, taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing. The list of measures constitutes Annex B.

The Processor may change individual measures provided that the level of security is not reduced. It informs the Controller of any material change.

Access to personal data is granted solely to persons for whom it is necessary to perform their duties, on the basis of a named authorisation, with multi-factor authentication for privileged access.

§5

Sub-processing

The Controller grants the Processor general authorisation to engage further processors, listed in Annex C and in the register published at luminote.io/legal.

The Processor informs the Controller of intended changes to the register — the addition or replacement of a processor — at least 30 days in advance, by message to the administrative contact address and by notice in the Service.

The Controller may, within 30 days of notification, object on reasonable data protection grounds. If the parties reach no agreement, the Controller may terminate the services agreement in the affected scope of the Service without adverse consequences.

The Processor imposes on further processors, by contract, the same data protection obligations as those resting on it under this DPA, and remains fully liable to the Controller for their performance of those obligations.

An external system connected by the Controller is not a further processor of the Processor. This concerns in particular CRM systems, calendars and mailboxes which the Controller holds under its own contract with their provider. Transfer of data to such a system occurs on the Controller’s instruction, within its own arrangements with that provider.

§6

Data subject rights

The Service provides the Controller with functions enabling it to give effect on its own to requests for access, rectification, erasure, restriction of processing and portability in respect of data held in its workspace.

If a data subject contacts the Processor directly, the Processor does not respond on the merits and forwards the request to the Controller without undue delay, no later than within 5 business days, informing the person making the request.

Where fulfilment of a request exceeds the capability of the functions available in the Service, the Processor provides the Controller with reasonable technical assistance. Assistance going beyond a reasonable scope, in particular requiring development work, may be charged at an agreed rate, after prior notice to the Controller.

§7

Personal data breaches

The Processor notifies the Controller of a personal data breach concerning the entrusted data without undue delay and no later than within 48 hours of becoming aware of it, to the administrative contact address and — where the Controller has indicated one — to the address of its data protection officer.

The notification contains, to the extent available at the time of its submission: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the remedial measures applied or proposed, and the contact point details. Information not available at the time of notification is provided in phases, as it is established.

The Processor does not notify the supervisory authority or data subjects on behalf of the Controller unless the parties agree otherwise in writing. The notification obligation under Articles 33 and 34 GDPR rests with the Controller.

The Processor maintains a register of breaches and makes available to the Controller an extract concerning the entrusted data.

§8

Impact assessment and prior consultation

The Processor provides the Controller with reasonable assistance in carrying out a data protection impact assessment and in prior consultation with the supervisory authority, in respect of processing carried out in the Service.

Assistance comprises in particular making available a description of the processing operations, a list of technical and organisational measures and information on further processors and processing locations.

§9

Processing location and transfers to third countries

Personal data entrusted to the Processor is stored and processed within the territory of the European Union. The infrastructure on which the Service operates is located in France.

It is the Processor’s policy to engage as further processors only entities established and subject to jurisdiction in the European Union or the European Economic Area. Any departure from that policy is recorded in Annex C together with the basis of transfer and the safeguards applied.

Integrations activated by individual users themselves — in particular sign-in with an external account and calendar synchronisation — may result in the transfer of data to a provider outside the European Economic Area. Such a transfer occurs solely as a result of the user’s own act, on the basis of standard contractual clauses adopted by the European Commission, and is subject to the Controller’s contract with that provider.

On receipt of a request from an authority of a third country concerning disclosure of the entrusted data, the Processor notifies the Controller without undue delay, unless prohibited by law, and takes the available measures to challenge such a request.

§10

Demonstrating compliance and audit

The Processor makes available to the Controller on request the information necessary to demonstrate compliance with the obligations under Article 28 GDPR, including the current description of technical and organisational measures and the list of further processors.

The Controller has the right to carry out an audit, including an inspection, itself or through an authorised auditor who is not a competitor of the Processor. An audit is carried out not more than once per calendar year, upon at least 30 days’ prior notice, during working hours, in a manner that does not interrupt the Processor’s operations and with respect for trade secrets and the data of other customers.

The limitations on frequency and notice do not apply where the audit follows a personal data breach or a demand of the supervisory authority.

The costs of the audit are borne by the Controller, except where the audit reveals a material breach of the Processor’s obligations — in which case they are borne by the Processor.

§11

Return and deletion of data

After the end of the provision of services the Controller may, for 30 days, export the entrusted data using the export functions of the Service, in a structured, commonly used, machine-readable format.

After the export window closes the Processor deletes the entrusted data within 30 days, unless an obligation of further storage arises under Union or Member State law. Backups containing the entrusted data expire in the ordinary cycle, no later than within 30 days of deletion of the production data, and until then remain subject to the same security measures.

At the Controller’s request the Processor confirms deletion in writing.

Irrespective of the above, transcripts and recordings are deleted during the provision of services, in accordance with the retention period set by the Controller, on the terms described in the Terms of Service.

§12

Liability and final provisions

The parties’ liability under this DPA is subject to the limitations set out in the Terms of Service, save that those limitations do not apply to liability towards data subjects or the supervisory authority to the extent that the law does not permit its limitation.

This DPA forms an integral part of the services agreement and is in force for its duration. In the event of a discrepancy between the Terms of Service and this DPA in matters of personal data protection, this DPA prevails.

This DPA is amended in the manner applicable to amendment of the Terms of Service, save that amendments required by mandatory law or by a decision of the supervisory authority take effect on the date indicated in that provision or decision.

Annex A. Description of processing

Subject matter: provision of a platform supporting business-to-business sales, comprising customer relationship management, recording and analysis of meetings, email communication, analytics and integrations.

Duration: the term of the services agreement, extended by the exit period and the deletion period in accordance with §11.

Nature and purpose: collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission to systems designated by the Controller, alignment, combination, restriction, erasure and destruction — for the purpose of making the functions of the Service available to the Controller.

Categories of data subjects: users of the Controller (its personnel); contact persons at the Controller’s customers and prospective customers; participants in meetings recorded by the Controller; senders and recipients of correspondence conducted in the Service.

Categories of personal data: identification and contact data (given name, surname, email address, telephone number, position, employer); content of communications (messages, notes, transcripts and — where the Controller enables it — audio recordings of meetings); activity data in the Service (time and type of action, technical identifiers); data of commercial relationship records transferred from the Controller’s systems.

Special categories of data: the processing of data referred to in Articles 9 and 10 GDPR is not the subject of this DPA. The Controller undertakes not to enter such data into the Service. If it nevertheless appears in free text, the Processor treats it applying the measures in Annex B, which does not alter the Controller’s undertaking.

Automated decision-making: the Service is not intended for making decisions producing legal effects concerning natural persons or similarly significantly affecting them within the meaning of Article 22 GDPR. Generated outputs require human verification before use.

Annex B. Technical and organisational measures (Article 32 GDPR)

Access control. Role-based access with the principle of least privilege. Multi-factor authentication for privileged accounts and the ability for the Controller to enforce it for all its users. Named processing authorisations. Withdrawal of access immediately once the need ceases.

Data isolation. Logical separation of the data of individual organisations at database level, enforced by access policies on every table containing user data, and not solely at application level.

Encryption. Transmission solely over encrypted channels. Credentials to external systems and backups stored in encrypted form. Encryption keys are rotated and stored separately from the data.

Minimisation towards artificial intelligence providers. Before content is transmitted to an external language model, identifying elements are removed from it and replaced with placeholders; restoration occurs solely within the Processor’s infrastructure. Model providers do not use the transmitted data for training.

Storage limitation. Transcripts are deleted after analysis is complete, in accordance with the period set by the Controller. Retention of audio recordings after analysis requires express activation. A shortening of the retention period is preceded by a notice period.

Event logging. Event logs contain technical identifiers and the type of action; they do not contain the content of communications or personal data contained in content. Logs are subject to restricted access and retention.

Continuity. Backups made not less than once every 24 hours, retained for 30 days, with periodic restoration testing. Recovery point objective 24 hours, recovery time objective 12 business hours.

Development security. Review of code changes before deployment, automated tests executed on every change, dependency control, separation of environments, prohibition on storing secrets in the code repository and a procedure for their immediate rotation in the event of disclosure.

Personnel. Confidentiality undertakings, data protection training, procedure applicable on termination of cooperation.

Incident management. Procedure for detection, classification and handling of incidents, with the notification period to the Controller set out in §7 and a register of breaches.

Annex C. Further processors

The list is current as at the effective date of this DPA. The current version is published at luminote.io/legal and forms part of this Annex.

Providers marked as outside the European Economic Area serve functions activated by the user themselves; transfer of data occurs on the basis of standard contractual clauses.

Entity Establishment Role Scope of data
OVH France Hosting of the entire platform: database, authentication, files, application servers all entrusted data
Mistral AI France Language models and speech-to-text transcription meeting audio; content after removal of identifying elements
Skribby Belgium Meeting notetaker bot: recording and transcription meeting audio and transcript, participant names; data deleted at the provider once the transcript has been retrieved
MailerSend (MailerLite UAB) Lithuania Outbound email delivery addresses and content of messages sent by the Controller
AppSignal Netherlands Application error monitoring error messages and technical identifiers; no content of communications
Stripe Payments Europe Ireland Payment and subscription handling the Controller’s billing data; no transcripts, relationship records or correspondence content
Google United States Sign-in with an external account and calendar synchronisation — activated by the user user identity, calendar event data
Microsoft United States Sign-in with an external account and calendar synchronisation — activated by the user user identity, calendar event data
LUMINOTE PROSTA SPÓŁKA AKCYJNA ul. Olszańska 7, 31-513 Kraków, Polska
KRS: 0001223956 · NIP: 6751824986
Questions about this document: legal@luminote.io

We publish this document from a single source together with the application. The Polish version governs.