Scribe← Back to home

Data Processing Agreement

Data Processing Agreement (DPA) — Version 1.3

Last updated: 30 September 2026

This English version is a translation provided for convenience only. In case of any discrepancy or dispute, the French version prevails.

Processor: Reverdin Studio, Corso Vittorio Emanuele II 154, 00186 Roma (Italy) — Partita IVA (VAT number) IT17458801002

Controller: The customer organisation (hereinafter "the Customer") using the Scribe service

1. Subject matter

This Data Processing Agreement (DPA) sets out the terms on which Reverdin Studio (hereinafter "Scribe") processes personal data on behalf of the Customer in connection with the provision of the transcription and minute-taking service for professional meetings (the Scribe service, available at scribeapp.eu).

This DPA supplements the Terms of Use and is incorporated into them by reference. In the event of any conflict, this DPA prevails in all matters relating to the processing of personal data.

2. Nature and purpose of the processing

Scribe processes the personal data of users and meeting participants solely for the following purposes:

  • Automatic transcription of the audio content of recorded meetings
  • Generation of summaries, key points and action items using artificial intelligence
  • Synchronisation of calendar events (Google Calendar, Microsoft Outlook)
  • Written recording announcement, posted by the bot in the chat of every Teams or Nextcloud Talk meeting it joins (name of the user who added Scribe, how to opt out, links to the privacy policy and the participant information page); the announcement is written only, the bot never emits any sound
  • Export of summaries to OneDrive/SharePoint at a user's initiative and, where the Customer has requested it, automatic upload of every completed summary of the designated users, as a Word file (.docx), to a folder of the Customer's SharePoint site (title, date, duration, participants, summary, action items, key questions, chapters; neither the audio nor the full transcript)
  • Authentication and user account management
  • Provision, maintenance and improvement of the Scribe service

The Customer's data will not be processed for commercial or advertising purposes, nor used to train artificial intelligence models.

3. Categories of data processed

  • Identity data: name and email address of the organisation's members
  • Calendar data: meeting titles, dates, participants and URLs
  • Audio data: meeting recordings (temporary — deleted as soon as processing is complete, or after 14 days if processing does not succeed)
  • Transcription data: full text of the transcript, identity of speakers (diarisation)
  • Authentication tokens: Google/Microsoft OAuth tokens
  • Bot technical diagnostic files: for every recorded Teams meeting, participants' names as displayed by Teams and the timeline of who spoke when; HTML code of the meeting page if no speaking indicator is detected after 5 minutes; screenshot, HTML code and text of the page when a connection or capture incident occurs (14 days)
  • Technical data: IP addresses, application logs (size-based rotation, at most 5 files of 10 MB per service)

4. Duration of the processing

Scribe processes the data for the term of the service agreement. Upon expiry of the agreement or at the Customer's request:

  • Transcripts and summaries: automatically deleted 12 months after their creation, and immediately when the Customer deletes a report, the account or the organisation
  • Audio data: deleted as soon as processing is complete, and after 14 days if processing does not succeed; bot technical diagnostic files: automatically deleted after 14 days
  • Account data: deleted immediately upon deletion of the account, with the exception of the organisation's audit log (actions and the name of the person who performed them), which is retained as evidence until the organisation is deleted
  • Technical logs: no fixed retention period; size-based rotation (at most 5 files of 10 MB per service), with the oldest entries being erased on a rolling basis
  • Summaries exported or uploaded to the Customer's SharePoint/OneDrive: hosted in the Customer's Microsoft 365 environment and subject to its own retention rules; neither Scribe's automatic purge nor the deletion of a report in Scribe erases them

5. Obligations of Scribe (Processor)

Scribe undertakes to:

  • Process personal data only on documented instructions from the Customer
  • Ensure that persons authorised to process the data are bound by a duty of confidentiality
  • Implement appropriate technical and organisational measures (encryption in transit, access control, segregation of data by organisation)
  • Notify the Customer without undue delay (and no later than within 72 hours) of any personal data breach
  • Assist the Customer in responding to requests to exercise data subjects' rights (access, rectification, erasure, portability)
  • Delete or return all data at the end of the agreement, at the Customer's choice
  • Make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in this DPA

6. Obligations of the Customer (Controller)

The Customer undertakes to:

  • Inform the participants in each recorded meeting of the presence of a transcription bot, in accordance with Article 13 GDPR and Article 226-1 of the French Criminal Code; the written announcement posted by the bot in the meeting chat contributes to this but is not sufficient on its own, in particular if the chat is unavailable
  • Obtain the explicit consent of the participants before recording is activated
  • Not use the service to process special categories of personal data (Article 9 GDPR: health data, political opinions, etc.) without a prior data protection impact assessment (DPIA)
  • Inform Scribe of any change affecting the lawfulness of the processing

7. Sub-processors

The Customer authorises Scribe to engage the following sub-processors. Scribe undertakes to impose on these sub-processors obligations equivalent to those set out in this DPA.

List of sub-processors current as of 30 September 2026.

Sub-processorCountryPurposeSafeguards
Hetzner Online GmbHGermany (EU)Hosting, database, audio storage, email delivery (Mailu self-hosted on this infrastructure)EU law applies
Gladia SASFrance (EU)Audio transcription and diarisation (primary pipeline)EU law applies
Groq, Inc.United StatesWhisper audio transcription (fallback if Gladia fails)Transfer outside the EU
Faster-Whisper (local)Germany (EU) — HetznerLast-resort audio transcription (local processing, nothing sent externally)No third-party sub-processor — 100% local processing
Google LLCUnited StatesOAuth authentication, Calendar API, and Gemini model (direct call from our LiteLLM gateway) for summaries, speaker attribution and pre-meeting briefs — text transcripts only, never the audioTransfer outside the EU
OpenRouterUnited StatesFallback only, if the Google API is unavailable: AI request routing from our self-hosted LiteLLM gateway to the Google Gemini model (primary and fallback model): receives the text transcripts for summaries, speaker attribution, pre-meeting briefs — never the audioTransfer outside the EU
Microsoft CorporationUnited StatesOAuth authentication, Microsoft Graph API (Outlook calendar, export and upload of summaries to the Customer's SharePoint/OneDrive, in the Customer's Microsoft 365 environment)Transfer outside the EU
Stripe Payments Europe, Ltd.Ireland (EU)Payment processing and subscription management; card details are entered directly with Stripe and do not pass through ScribeEU law applies

Changes to sub-processors. Scribe informs the Customer of any addition or replacement of a sub-processor, and of any change to its purpose or country of processing, at least 30 days before it takes effect, by email to the owners and administrators of the Customer's organisation in Scribe. The notice specifies the sub-processor concerned, the purpose, the country of processing and the effective date; it is recorded in the organisation's audit log.

During this period, the Customer may object to the change on reasonable data protection grounds by email to support@scribeapp.eu. The parties will then seek a solution in good faith; failing that, the Customer may terminate its subscription before the change takes effect, without penalty. If no objection is raised within this period, the change is deemed accepted.

8. Transfers outside the European Union

Hosted data is stored exclusively in Germany (Hetzner). Data transmitted to sub-processors established in the United States (Groq, OpenRouter, Google, Microsoft) is transferred outside the European Union (see the table in section 7).

9. Data security

Scribe implements the following security measures:

  • Encryption of data in transit (TLS 1.2 or 1.3)
  • Token-based authentication for all internal API access
  • Access logging and alerts in the event of abnormal activity
  • Isolation of data by organisation (strict multi-tenancy)
  • Automatic deletion of audio files as soon as processing is complete (after 14 days at most if processing does not succeed)
  • Security updates applied within 72 hours of becoming available

10. Audits and inspections

The Customer may, once a year and subject to 30 days' notice, request that Scribe provide information demonstrating that the processing complies with this DPA. Such verification may take the form of a written questionnaire or a documentary audit. Any on-site audit requires prior agreement on its terms and costs.

11. Personal data breaches

In the event of a personal data breach within the meaning of Article 4(12) GDPR, Scribe will notify the Customer by email within 72 hours of becoming aware of the incident. The notification will include: the nature of the breach, the categories and approximate number of data subjects concerned, and the measures taken and recommended.

12. Governing law and jurisdiction

This DPA is governed by French law and by Regulation (EU) 2016/679 (GDPR). In the event of a dispute, the parties will seek an amicable settlement. Failing agreement within 30 days, the courts of Paris shall have jurisdiction.

DPA contact: support@scribeapp.eu

Signatures

For the Processor (Scribe / Reverdin Studio)

Marc Reverdin — Director

Date: _____________

For the Controller (Customer)

Name: _____________

Title: _____________

Date: _____________

Version history

  • Version 1.3 — 30 September 2026: list of sub-processors dated; 30-day prior notice by email to organisation administrators before any change of sub-processor, with a right to object; safeguards for the transfer to Microsoft and TLS version corrected.
  • Version 1.2 — 30 September 2026: written recording announcement in the meeting chat; export and automatic upload of Word summaries to the Customer's SharePoint; roles of Gladia (primary transcription), Groq (backup) and Google (Gemini by direct call, Calendar) clarified; OpenRouter as a fallback only.
  • Version 1.1 — 30 September 2026: sub-processors and transfers outside the EU completed (OpenRouter, Google, Microsoft); bot diagnostic files, retention periods and security measures aligned with actual operation.
Data Processing Agreement (DPA) — Scribe — Scribe