Legal
Data Processing Agreement (DPA)
Last updated: 26 September 2026
For companies and professionals: how SwiftBOL processes, on your behalf, the data of the people in your recordings (article 28 of the General Data Protection Regulation).
1. Parties and when it applies
This agreement applies automatically, with no need to sign it, when you use SwiftBOL for professional or business purposes (for example, to record meetings with colleagues or clients, interviews or classes you teach) and, regarding the personal data of other people contained in your recordings, you act as the controller. It forms part of the Terms and Conditions and, as regards data protection, prevails over them.
Controller: you, or the company or organisation on whose behalf you use SwiftBOL ("the Customer"). Processor: SwiftBOL, tax ID to be published, with address at Spain (postal address available on request at support@swiftbol.com) ("SwiftBOL").
If you need a signed copy for your records of processing or an audit, ask support@swiftbol.com: we'll send it with this same content. The Spanish version prevails if the two differ.
2. Subject matter, duration, nature and purpose
Subject matter: processing the personal data the Customer uploads, records or has recorded in SwiftBOL (including the meeting assistant) and the data SwiftBOL generates from it, for the sole purpose of providing the service: transcribing, identifying who speaks when asked, summarizing, translating, creating tests, flashcards and documents, answering questions about the recordings, storing, sharing and sending them wherever the Customer decides.
Duration: as long as the Customer keeps their account. Operations: collection, recording, storage, transcription and automated analysis, consultation, disclosure to whomever the Customer decides (team, public links, integrations) and erasure.
3. Data and data subjects
Types of data: the voice and what is said by the people in the recordings; transcripts, summaries and other generated content; names mentioned or assigned by the Customer to speakers; for the meeting assistant, the meeting link, title and time and the names participants appear under; and, if the Customer sends a session to their CRM, the contact email they enter.
Data subjects: employees, collaborators, clients, students, interviewees and anyone else taking part in the conversations the Customer records, plus the members of their SwiftBOL team.
SwiftBOL doesn't need special categories of data (health, beliefs, etc.) to provide the service. If the Customer's recordings contain them, the Customer warrants they have a legal basis to process them and can have them processed on their behalf.
4. The Customer's obligations
To inform the people they record and have a legal basis to do so (including consent where required), as section 2 of the Terms and applicable law require; the notice the meeting assistant posts in the chat doesn't replace this.
To give SwiftBOL lawful instructions: the Customer's configuration and use of the service are their documented instructions.
5. SwiftBOL's obligations
To process the data only on the Customer's documented instructions, including with regard to international transfers, unless required by law; if we believe an instruction infringes data protection law, we'll say so. Not to use the data for our own purposes or to train AI models, not to sell it and not to disclose it to third parties except the sub-processors in section 7 or when the Customer decides.
To ensure that people authorised to process the data have committed to confidentiality.
To apply the security measures in section 6 and help the Customer, taking into account the nature of the processing, to meet their obligations on security, personal data breach notification, impact assessments and prior consultation (GDPR arts. 32 to 36).
To help the Customer answer data subject requests (access, rectification, erasure, objection, restriction and portability). The Customer can handle most of them directly in the dashboard (edit, export or delete sessions); if someone contacts SwiftBOL directly, we'll pass it on without delay.
To notify the Customer without undue delay, and where possible within 48 hours of becoming aware, of any security breach affecting their data, with the information available so they can document it and, where appropriate, notify the supervisory authority and the people affected.
To make available the information needed to demonstrate compliance with this agreement and allow reasonable audits, including inspections, by the Customer or an auditor they appoint, with 30 days' notice, at most once a year unless there is a well-founded indication of non-compliance, at their expense and without compromising the security or confidentiality of other customers.
6. Security measures
Data hosted in the European Union (Frankfurt, Germany); encryption in transit (HTTPS with HSTS) and at rest; access keys to connected services (calendar, CRM) encrypted with our own key; access to each account's data restricted to its owner through database security policies; secrets and credentials only on the server; anti-abuse limits; security headers and content security policy; error logs without email or name; encrypted backups that roll over within 30 days at most; and internal access limited to what support strictly needs.
SwiftBOL reviews these measures periodically and may improve them, never lowering the level of protection.
7. Sub-processors
The Customer gives SwiftBOL general authorisation to use the following sub-processors, bound by contracts imposing data protection obligations equivalent to this agreement: Supabase (database, authentication and storage; Frankfurt, Germany); Vercel (application hosting; Frankfurt, Germany); Groq (transcription; USA); Deepgram (transcription when identifying speakers is requested, large files or fallback; USA); OpenAI (summaries, chat, translations, tests, flashcards and documents; USA); Recall.ai (meeting assistant; Frankfurt, Germany region, deleting its copy of the recording as soon as we have processed it and within 48 hours at most); Resend (sending emails, such as the notice that a summary is ready; USA); and Upstash (anti-abuse counters with pseudonymised identifiers).
Services the Customer connects themselves (Slack, Zapier, Make, HubSpot, Salesforce, Google Calendar) are not SwiftBOL sub-processors: the Customer decides to send them data and they process it under their relationship with the Customer.
SwiftBOL will notify the Customer at least 15 days in advance, by email or in the dashboard, of any new or replacement sub-processor. The Customer may object on reasonable data protection grounds; if no solution is found, they may close their account and, if they paid in advance, we'll refund the proportional part of the unused period.
8. International transfers
When a sub-processor processes data outside the European Economic Area, the transfer relies on the EU-US Data Privacy Framework where the provider is certified or, otherwise, on the European Commission's Standard Contractual Clauses, with any additional measures required. AI providers don't use the data to train their models and only keep it temporarily (usually up to 30 days) to monitor abuse.
9. End of processing: return and deletion
The Customer can export their sessions at any time (PDF, Word, TXT, subtitles) and delete them. When the account is deleted, SwiftBOL immediately erases sessions, audio, transcripts and other content, which disappear from backups within 30 days at most, unless a law requires keeping some data, in which case it will be blocked.
10. Liability, governing law and changes
Each party's liability is governed by GDPR article 82 and the Terms and Conditions. This agreement is governed by Spanish law and the GDPR; the supervisory authority is the Spanish Data Protection Agency (aepd.es).
If we change this agreement, we'll give notice as provided in section 12 of the Terms; changes will never reduce the protection of the Customer's data.
Questions about this document? Email support@swiftbol.com.