Data Processing Agreement (DPA)

Last updated: July 2026

This Data Processing Agreement (DPA) sets out the obligations of modulo8 GmbH ("Processor") when processing personal data on behalf of business customers ("Controller") who use withmo to process the personal data of third parties, pursuant to Art. 28 GDPR. It supplements our Terms of Service. See the end of this page for how it becomes effective.

1. Preamble and Scope

The Controller uses withmo to organize, record, transcribe, and follow up on meetings, and in doing so acts as the data protection controller within the meaning of the GDPR with respect to the data of its employees, customers, and other meeting participants. The Processor processes this data solely as a processor within the meaning of Art. 28 GDPR and within the scope of the Controller's instructions.

2. Subject Matter and Duration of Processing

The subject matter of this Agreement is the processing of personal data by the Processor in the course of providing withmo, as further described in Annex 1. The duration of processing corresponds to the term of the underlying agreement between the parties (the usage contract under our Terms of Service).

3. Nature and Purpose of Processing, Categories of Data Subjects and Data

The nature and purpose of processing, the categories of data subjects, and the types of personal data processed are set out in Annex 1 to this Agreement.

4. Processing on Instructions

The Processor shall process personal data only on the documented instructions of the Controller, unless required to do otherwise by European Union or member state law, in which case the Processor shall inform the Controller of that legal requirement before processing, unless the law in question prohibits such notification on important grounds of public interest. Use of withmo in accordance with its documented functionality (in particular the recording, transcription, and AI-generated summarization of meetings initiated by the Controller) constitutes an instruction within the meaning of this clause.

If the Processor considers that an instruction from the Controller infringes the GDPR or other data protection provisions, it shall inform the Controller without delay.

5. Confidentiality

The Processor ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that such persons only access the data to the extent necessary.

6. Technical and Organizational Measures

The Processor implements the technical and organizational measures described in Annex 2 pursuant to Art. 32 GDPR, to ensure a level of security appropriate to the risk. The Processor may modify these measures provided the agreed level of protection is not diminished.

7. Use of Sub-processors

The Controller hereby grants general authorization for the use of the sub-processors listed in Annex 3. The Processor will inform the Controller before engaging any new sub-processor or replacing an existing one, giving the Controller the opportunity to object within 14 days for an important, data-protection-related reason. If the Controller objects on reasonable grounds, both parties will work toward a mutually acceptable solution; if no agreement is reached, the Controller may terminate the affected service for cause.

The Processor imposes data protection obligations on each sub-processor by way of an agreement that are equivalent to those set out in this Agreement.

8. Assistance to the Controller

The Processor assists the Controller, to the extent reasonable, in responding to requests from data subjects exercising their rights (Art. 12–22 GDPR) and in complying with its obligations under Art. 32–36 GDPR, including the notification of personal data breaches, data protection impact assessments, and any prior consultation with a supervisory authority, taking into account the nature of processing and the information available to the Processor.

9. Audit and Verification Rights

The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. The Controller will give reasonable advance notice of any on-site audit, generally at least two weeks, and take the Processor's ongoing operations into account. As an alternative to an on-site audit, the Processor may provide current evidence of compliance, such as self-assessments or its sub-processors' certifications.

10. Notification of Personal Data Breaches

The Processor will notify the Controller of a personal data breach affecting the Controller's data without undue delay, and no later than 48 hours after becoming aware of it, and will assist the Controller in meeting its notification obligations under Art. 33 and 34 GDPR.

11. Deletion and Return upon Termination

Voice recordings are not stored as persistent audio or video files; they are processed solely for transcription and are not retained afterward. Upon termination of the underlying agreement, the Processor will promptly delete all personal data processed on behalf of the Controller, including transcripts and derived meeting data, from the production database. A copy may persist for up to 7 days in the encrypted database backups — including the offsite copy — until overwritten by the backup rotation schedule, unless statutory retention obligations require otherwise. At the Controller's request, the Processor will provide an export of the data in a common, machine-readable format before deletion.

12. Liability

The liability provisions of Art. 82 GDPR apply, supplemented by the liability limitations agreed in our Terms of Service to the extent they are compatible with mandatory law.

13. Term and Final Provisions

This Agreement takes effect as set out in Section 17 and terminates automatically upon termination of the underlying agreement, without prejudice to the deletion obligations set out in Section 11. In the event of any conflict between this DPA and the Terms of Service, this DPA prevails on data protection matters. Amendments to this Agreement require text form.

Annex 1 — Subject Matter, Duration, Nature, and Purpose of Processing

Subject matter and duration: provision of the withmo platform for the term of the underlying agreement, including recording, transcription, AI-generated summarization, and follow-up of meetings.

Purpose of processing: organizing and documenting the Controller's meetings, including the creation of transcripts, summaries, decision logs, and action items, and optional forwarding to third-party systems configured by the Controller (Slack, Jira, Linear, webhooks).

Categories of data subjects: employees of the Controller who use withmo; and external and internal meeting participants invited or recorded by the Controller, regardless of whether they are withmo users themselves.

Types of personal data: names, email addresses, voice and, where applicable, video recordings, conversation content in transcript form, summaries, decisions, and action items derived from it, and calendar and meeting metadata.

Annex 2 — Technical and Organizational Measures

Confidentiality: all connections encrypted in transit via HTTPS/TLS; token-based authentication through a self-hosted Authentik instance with passwords stored only in hashed form; strict organization-scoped data separation (multi-tenancy), with organization membership derived server-side from the authentication token and never accepted from the client; role-based access control (Owner/Admin/Member); encrypted storage of third-party integration access tokens.

Integrity and availability: operated on our own infrastructure hosted by Hetzner Online GmbH at its Falkenstein, Germany data center; additional encrypted backup copies of object storage kept with Cloudflare R2.

Encryption at rest currently relies on the underlying infrastructure's standard mechanisms; there is no end-to-end application-layer encryption in place.

This Annex describes the measures in place as of the last update. We recommend reviewing it alongside a current technical security assessment before signature, and supplementing it with any further measures relevant to the specific Controller.

Annex 3 — Approved Sub-processors

Hetzner Online GmbH, Germany — hosting infrastructure.

Cloudflare, Inc., USA — encrypted backup of object storage (Cloudflare R2), based on EU Standard Contractual Clauses.

AssemblyAI, Inc., USA (processing takes place in the EU data center in Dublin) — transcription and speaker recognition.

Mistral AI SAS, France (EU) — AI-generated summaries, decision logs, and suggested action items; processing within the EU.

Stripe Payments Europe, Ltd. — payment processing (to the extent billing data with personal reference relating to the Controller is affected).

Brevo SAS / Brevo GmbH — transactional email delivery.

The list above reflects the status when this Agreement takes effect. The current list is additionally maintained on an ongoing basis on our public sub-processor page; changes follow the procedure described in Section 7.

17. Effectiveness of This Agreement

This text constitutes modulo8 GmbH's contract offer for a Data Processing Agreement. It becomes effective between the parties once the Controller sends us a countersigned version by email to hello@withmo.io. A signature-ready PDF version is available on request.

Data Processing Agreement (DPA) — withmo