OpenTranscription
OpenTranscription
RankerModelsPlayground

Data Processing Agreement

Effective Date: 2026-08-12 — Version 1.0

This Data Processing Agreement is OpenTranscription's standard form. It is incorporated by reference into the Service Terms and applies to processing of Personal Data on behalf of commercial Customers and Customers subject to GDPR or equivalent laws. To request a counter-signature-ready copy, email privacy@opentranscription.io.

1. Preamble

This Data Processing Agreement ("DPA") is entered into between ReadychatAI LLC ("OpenTranscription", "we", "us") and the Customer ("you") and forms part of the Service Terms. Effective Date: 2026-08-12. Version: 1.0. In the event of any conflict between this DPA and the Service Terms with respect to the processing of Personal Data, this DPA prevails.

2. Definitions

Terms used in this DPA have the meaning given to them in the GDPR or, where not defined there, in the Service Terms. "Controller", "Processor", "Sub-processor", "Personal Data", "Processing", and "Data Subject" have the meanings given in Article 4 of the GDPR. "Applicable Data Protection Laws" means the GDPR, the UK GDPR, the Data Protection Act 2018 (UK), the California Consumer Privacy Act (CCPA), and any other privacy or data-protection laws applicable to the processing under this DPA. "Customer Personal Data" means Personal Data that OpenTranscription processes on behalf of the Customer in connection with the Service.

3. Subject Matter and Duration

The subject matter of this DPA is the processing of Customer Personal Data by OpenTranscription on behalf of the Customer in the course of providing the Service. The duration of this DPA matches the duration of the Service Terms; processing of Customer Personal Data continues for so long as the Customer uses the Service or as required by Applicable Data Protection Laws for return or deletion.

4. Nature and Purpose of Processing

OpenTranscription processes Customer Personal Data for the following purposes: (a) routing audio recordings to one or more third-party transcription Model Providers selected by the Customer; (b) returning transcripts and derived metadata to the Customer; (c) storing audio recordings and transcripts in the Customer's organization workspace for Customer access; (d) operating, securing, and billing the Service. The nature of processing includes storage, retrieval, transmission, deletion, and disclosure to authorized Sub-processors.

5. Categories of Personal Data and Data Subjects

Details are set out in Annex I. The categories of Customer Personal Data and Data Subjects are determined by the Customer through the Customer's use of the Service.

6. Processor Obligations

OpenTranscription will: (a) process Customer Personal Data only on the documented instructions of the Customer (which include the Service Terms and this DPA), and notify the Customer if it considers an instruction infringes Applicable Data Protection Laws; (b) ensure that personnel authorized to process Customer Personal Data are subject to appropriate obligations of confidentiality; (c) implement and maintain the technical and organizational measures set out in Annex II; (d) engage Sub-processors only in accordance with Section 7; (e) assist the Customer, taking into account the nature of the processing, in fulfilling the Customer's obligation to respond to Data Subject rights requests under Chapter III of the GDPR; (f) assist the Customer in ensuring compliance with Articles 32 to 36 of the GDPR (including data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to OpenTranscription; (g) notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data Breach affecting Customer Personal Data; (h) at the choice of the Customer, delete or return all Customer Personal Data after the end of the provision of the Service, and delete existing copies unless storage is required by Union or Member State law.

7. Sub-processors

The Customer grants OpenTranscription general written authorization to engage Sub-processors. Sub-processors fall into two categories, authorized differently, because they are engaged differently. Infrastructure Sub-processors — hosting, storage, database, email delivery and payment processing — process Customer Personal Data on every request, whatever the Customer chooses. OpenTranscription maintains the current list of Infrastructure Sub-processors in its Privacy Policy at /privacy#sub-processors, and the Customer agrees that publication to that list is the method by which OpenTranscription informs the Customer of changes. An addition or replacement is published at least 30 calendar days before it takes effect, except where a change is required urgently for security, legal or service-continuity reasons, in which case the list is updated as soon as practicable. The Customer may object on reasonable data-protection grounds by writing to us within 30 calendar days of publication; OpenTranscription will use reasonable efforts to make an alternative arrangement, and if none is available within 30 calendar days of the objection, the Customer may terminate the affected processing without penalty. Transcription Provider Sub-processors — the speech-to-text services that perform transcription — receive Customer Personal Data only for the jobs the Customer routes to them. The Customer selects the model for each request, and that selection is the Customer's authorization for the corresponding provider to process that request. Where the Customer uses automatic model selection, the authorization extends to the providers listed as available at the time of the request. Adding a provider or model to the catalogue does not alter the processing of any existing or in-flight job and does not require advance notice; the current list is maintained in our Privacy Policy at /privacy#sub-processors. A Customer who requires advance notice of catalogue additions may restrict routing to an explicit set of providers in the organization's routing preferences, which makes later additions inapplicable to that Customer until the Customer changes them. OpenTranscription imposes data protection obligations on each Sub-processor no less protective than those in this DPA, and remains liable to the Customer for the performance of each Sub-processor's obligations.

8. Security Measures

OpenTranscription implements the technical and organizational measures set out in Annex II.

9. International Transfers

Where Customer Personal Data is transferred outside the European Economic Area, the United Kingdom, or Switzerland to a country that has not been the subject of an adequacy decision, the transfer is governed by the mechanism set out in Annex III, including the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914 Module Two), as supplemented by the UK Addendum where applicable.

10. Audit Rights

The Customer may, on no more than one occasion in any twelve-month period and at the Customer's expense, audit OpenTranscription's compliance with this DPA. OpenTranscription will cooperate by responding to a reasonable written questionnaire and providing relevant documentation. On-site audits require not less than 60 calendar days' written notice and reasonable scheduling. Once OpenTranscription obtains a current SOC 2 Type II report, that report will satisfy the Customer's audit rights for the period it covers, unless the Customer demonstrates that the report does not address the matters subject to the audit.

11. Liability

Each Party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Service Terms, including the aggregate liability cap.

12. Term and Termination

This DPA terminates automatically on termination or expiry of the Service Terms. On termination, OpenTranscription will, at the Customer's choice, delete or return all Customer Personal Data within 30 calendar days, and delete any existing copies unless storage is required by Union or Member State law.

13. General

This DPA is governed by the law of the Service Terms. With respect to the processing of Customer Personal Data, the provisions of this DPA prevail over any conflicting provisions of the Service Terms. No variation of this DPA is effective unless made in writing and signed by both Parties (or, in the case of OpenTranscription's standard-form updates, posted as a new version with reasonable notice to active Customers).

Annex I — Subject Matter and Details of Processing

Categories of Personal Data: audio recordings submitted by the Customer; derived transcripts; account identifiers (email address, name); usage data (job metadata, timestamps, model selection); billing data. Categories of Data Subjects: the Customer's authorized users; speakers and other individuals identifiable in audio recordings submitted by the Customer; the Customer's employees and agents.

Annex II — Technical and Organizational Security Measures

Encryption in transit: TLS 1.2 or higher for all customer-facing APIs and provider-bound calls. Encryption at rest: object storage and database encryption at rest as provided by the underlying managed infrastructure (Supabase); specific cipher selection is governed by Supabase's managed-storage controls and documented in their security materials. Multi-tenant isolation: Row-Level Security on all tables containing Customer data; org-scoped storage paths. Access controls: role-based access through the organization-membership model; multi-factor authentication required for OpenTranscription personnel access to production systems (operational policy). Audit logging: error, authentication, and authorization-change events captured via our error-monitoring infrastructure; application-level logs of data-access operations. Backup: database backups as provided by Supabase's managed-database service; retention per the Supabase plan in effect. Personnel: confidentiality obligations on all personnel with access to Customer Personal Data. Incident response: breach notification commitment without undue delay, and in any event within 72 hours of becoming aware (GDPR Art. 33); a documented incident response runbook is being formalized.

Annex III — Sub-processors

The current list of Sub-processors is maintained at /privacy#sub-processors. General written authorization to engage Sub-processors is granted in Section 7. Transfers of Customer Personal Data outside the European Economic Area to the United States and other non-adequacy jurisdictions are governed by the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914 Module Two), incorporated into this DPA by reference. For transfers subject to UK data-protection law, the UK Addendum to the EU SCCs (Information Commissioner's Office) applies.

OpenTranscription
OpenTranscription

One API to every speech-to-text model worth using. Compare them on your audio, route to the best one, pay per second.

Platform status

Product

RankerModelsTranscriptionsPlaygroundBlog

Developers

DocumentationReliabilityAPI VersioningStatus

Legal

Privacy PolicyTerms of ServiceSupport
© 2026 OpenTranscription