Introduction
This Data Processing Agreement ("DPA") is entered into between the customer ("Controller") and [Company Name] ("Superlumy" or "Processor") and applies to the processing of personal data carried out by Superlumy on the Controller's behalf in connection with the Service. It is designed to support compliance with the EU/UK General Data Protection Regulation (GDPR) and comparable laws.
Definitions
Terms such as "personal data", "processing", "controller", "processor", and "data subject" have the meanings given in applicable data-protection law. "Customer Personal Data" means personal data Superlumy processes on the Controller's behalf under the Service.
Roles of the parties
The Controller determines the purposes and means of processing Customer Personal Data; Superlumy acts as Processor and processes it only on documented instructions from the Controller, including as set out in the Terms, this DPA, and the Controller's use of the Service.
Scope & nature of processing
- Subject matter: provision of the Superlumy voice dictation and related services.
- Duration: for the term of the agreement and any permitted retention period.
- Nature & purpose: hosting, processing speech into text, account management, support, and security.
- Types of data:account identifiers, contact details, usage and billing metadata, and content the Controller's users choose to process. Audio is not retained.
- Data subjects:the Controller's users and authorized end users.
Our obligations
- Process Customer Personal Data only on documented instructions.
- Ensure personnel authorized to process data are bound by confidentiality.
- Implement appropriate technical and organizational measures.
- Assist the Controller, taking into account the nature of processing, with data-subject requests and with its own compliance obligations.
- Make available information reasonably necessary to demonstrate compliance and allow for audits subject to reasonable conditions.
Subprocessors
The Controller authorizes Superlumy to engage subprocessors to support the Service. We maintain a current list of subprocessors, impose data-protection terms on them consistent with this DPA, and remain responsible for their performance. We will give notice of new subprocessors so the Controller may object on reasonable grounds.
Security measures
Superlumy maintains the technical and organizational measures described on our Security page, including encryption in transit and at rest, access controls, and monitoring, appropriate to the risk.
Personal data breach notification
Superlumy will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to assist the Controller in meeting its notification obligations.
Data subject rights
Taking into account the nature of the processing, Superlumy will assist the Controller by appropriate measures to respond to requests from data subjects exercising their rights under applicable law.
International transfers
Where Customer Personal Data is transferred outside the EEA, UK, or other regulated regions, Superlumy relies on appropriate safeguards such as the Standard Contractual Clauses, which are incorporated by reference where applicable.
Return & deletion of data
On termination of the Service, Superlumy will, at the Controller's choice, delete or return Customer Personal Data, and delete existing copies unless retention is required by law.
Requesting a signed DPA
To execute this DPA for your organization, contact legal@superlumy.com. Please include your legal entity name and the email associated with your account.