This agreement applies between the customer as controller and ByteHawk GmbH, Fährstraße 217, 40221 Düsseldorf, Germany, as processor ("Kalima"). Under section 7 of the Terms of Service it forms part of the contract for the use of Kalima and applies as soon as a business uses Kalima to process personal data it is responsible for. No separate signature is needed. This English version is a translation; the German version is binding.
1. Scope and duration
Kalima processes personal data on the customer's behalf to provide the Service: recording, transcription, translation, AI features, storage, sharing, and export. This agreement runs for as long as the main contract and ends with it. Obligations meant to outlast it, such as deletion, remain in force.
2. Nature of processing
- Purpose: providing the Service under the main contract.
- Types of data: audio recordings and uploaded files, transcripts, translations, speaker names, titles and notes, AI summaries and AI chats, sharing settings, and account and usage data of the customer's members. Depending on what is discussed, special categories of personal data (Art. 9 GDPR) may be included.
- Data subjects: the customer's users and team members, participants whose voice is recorded, and people named in recordings or files.
Account, billing, and usage data that Kalima processes for its own purposes, such as billing, security, and improving the Service, is not covered by this agreement. Kalima is the controller for that data, and the Privacy Policy applies.
3. Instructions
Kalima processes the data only on the customer's documented instructions, unless EU or German law requires otherwise; in that case Kalima informs the customer beforehand unless the law forbids it. Instructions are this agreement, the customer's settings and actions in the Service, and written instructions sent to privacy@meetkalima.com. If Kalima considers an instruction unlawful, it tells the customer without delay.
4. Confidentiality
Everyone at Kalima with access to the data is bound to confidentiality. If the customer is subject to professional secrecy under section 203 of the German Criminal Code, Kalima additionally binds these persons expressly to secrecy and informs them of the criminal consequences of a breach.
5. Security
Kalima takes the technical and organizational measures under Art. 32 GDPR described in Annex 2. Kalima may develop them further as long as the level of protection does not fall.
6. Subprocessors
The customer gives general authorization for the subprocessors listed in Annex 1. Kalima binds each of them by contract to a level of protection equivalent to this agreement and is liable for them as for its own conduct. Before adding or replacing a subprocessor, Kalima emails the owners of customer accounts at least 14 days in advance. During that time the customer may object on reasonable data protection grounds. If the parties find no solution, the customer may terminate the main contract as of the change. Customers can view the complete Annex 1 with every provider named at any time after signing in, in the list of subprocessors.
Transfers to countries outside the EU take place only under the conditions of Art. 44 to 49 GDPR. The safeguard used is stated in Annex 1.
7. Assistance and breaches
Kalima assists the customer with requests from data subjects, security of processing, data protection impact assessments, and consultation of the supervisory authority, to the extent the information lies with Kalima. The customer can handle many requests directly in the Service, for example by exporting or deleting recordings. If a data subject contacts Kalima directly, Kalima forwards the request to the customer.
If Kalima becomes aware of a personal data breach, it notifies the customer by email without undue delay and provides the information the customer needs for notifications under Art. 33 and 34 GDPR.
8. Deletion and return
The customer can export and delete its data at any time during the term. Kalima permanently removes deleted recordings and their related data within 30 days. When the contract ends, Kalima returns the customer data through the export function or deletes it, at the customer's choice, unless a statutory retention duty applies. Copies in database backups are overwritten after seven days at most.
9. Proof and audits
On request, Kalima provides the information needed to demonstrate compliance with this agreement. Beyond that, the customer may carry out audits, or have them carried out by an auditor bound to confidentiality, with reasonable notice, during normal business hours, and without disrupting operations.
10. Final provisions
Liability follows the main contract unless Art. 82 GDPR requires otherwise. Where this agreement and the main contract conflict on the protection of personal data, this agreement prevails. German law applies.
Annex 1: Subprocessors
| Provider | Purpose | Processing location | Safeguard |
|---|---|---|---|
| netcup GmbH, Karlsruhe | Servers for the application and the database | Germany | Not required (EU) |
| Hetzner Online GmbH, Gunzenhausen | Data storage | Germany | Not required (EU) |
| Speech recognition provider, USA | Speech recognition and translation of audio | EU | EU Standard Contractual Clauses |
| OpenRouter, Inc., New York, USA | Routing of AI requests (summaries, chat, titles) to language models | EU | EU Standard Contractual Clauses |
| Cloudflare, Inc., San Francisco, USA | Network delivery, encryption in transit, protection against attacks and bots | Worldwide network | EU Standard Contractual Clauses |
| Mailjet SAS (Sinch), Paris | Sending emails, for example invitations and share notifications | EU | Not required (EU) |
| Functional Software, Inc. (Sentry), San Francisco, USA | Error and performance monitoring | Germany | EU Standard Contractual Clauses |
| PostHog, Inc., San Francisco, USA | Product analytics | EU (Frankfurt) | EU Standard Contractual Clauses |
Annex 2: Technical and organizational measures
- Physical access: servers run in data centers of the providers listed in Annex 1, which control physical access.
- System access: passwords are stored only as hashes. Sign-in is protected against automated attacks. Administrative access is limited to a small group of authorized people.
- Data access: roles in organizations and teams decide who can see which recordings. System access follows the principle of least privilege.
- Transfer and storage: connections are encrypted with TLS. For stored recordings and transcripts, Kalima additionally uses encryption at the application level.
- Separation: data of different customers is logically separated. Development and production run on separate systems.
- Input control: administrative actions are logged.
- Availability: data is backed up regularly. Operations are monitored continuously.
- Review: Kalima reviews security and data protection regularly and fixes the weaknesses it finds.
- AI: customer content is not used to train AI models.
Customers can request further details on these measures at privacy@meetkalima.com.
Please send questions about this agreement to privacy@meetkalima.com.