Data Processing Agreement

Last updated: June 2026

This DPA forms part of the Terms of Servicebetween NGJB Limited ("Actions", "Processor") and the customer organisation ("Customer", "Controller"). It applies where Actions processes personal data on the Customer's behalf, reflects Article 28 of the UK GDPR, and prevails over the rest of the Agreement for such processing. It takes effect when the Customer accepts the Terms.

1. Roles

The Customer is the Controller and Actions is the Processor of Customer Personal Data. The Customer is responsible for the lawfulness of its instructions and of its own collection and use of the data, including informing meeting participants and obtaining any consents required for recording and transcription.

2. Scope & instructions

Actions processes Customer Personal Data only on the Customer's documented instructions (including via use of the service's features) and as required by law, and will inform the Customer if it considers an instruction infringes data-protection law. The subject matter, nature, purpose, data types and data subjects are described in Annex B.

3. Confidentiality & security

Personnel are bound by confidentiality and access data only as needed. Actions implements appropriate technical and organisational measures (Annex C), including encryption in transit and at rest, tenant isolation via Row-Level Security, access controls, and reputable infrastructure providers.

4. Sub-processors

The Customer authorises the sub-processors listed in Annex A. Actions imposes data-protection obligations on each that are no less protective than this DPA and remains liable for their performance. Actions will give at least 30 days' notice of any new or replacement sub-processor; the Customer may object on reasonable data-protection grounds and, if unresolved, terminate the affected service as its sole remedy.

5. Data-subject rights & assistance

Taking into account the nature of processing, Actions will assist the Customer in responding to data-subject requests and with security, breach notification, DPIAs and prior consultation. Requests received directly from data subjects are referred to the Customer.

6. Personal data breaches

Actions will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, with information reasonably required for the Customer's own notifications.

7. International transfers

Actions keeps meeting content within the EU/EEA where its sub-processors offer this, and the AI extraction layer is provided from an EU region. Any transfer outside the UK/EEA relies on the UK IDTA / Addendum to the EU SCCs, plus a transfer risk assessment and supplementary measures.

8. Audit

Actions makes available information necessary to demonstrate Article 28 compliance and will contribute to audits, including via third-party certifications (e.g. SOC 2 / ISO 27001 of its infrastructure sub-processors). On-site audits are limited to once a year on reasonable notice and under confidentiality, unless a supervisory authority requires otherwise.

9. Deletion & return

On termination or request, Actions deletes or returns Customer Personal Data (Customer's choice) and deletes copies within 30 days, unless retention is required by law; backups are deleted on their normal rotation cycle. Liability under this DPA is subject to the limits in the Agreement. This DPA is governed by the law of England and Wales.

Annex A — Sub-processors

Sub-processorPurposeLocation
SupabaseDatabase, authentication, file storageEU — Frankfurt (eu-central-1)
Vercel Inc.Application hosting & deliveryGlobal edge network; functions US — Washington, D.C. (iad1)
Recall.ai (Hyperdoc Inc.)Meeting-bot capture, recording, transcription (uses Deepgram / AssemblyAI)EU — Frankfurt (eu-central-1)
Google Cloud — Vertex AIGenerative-AI extraction & embeddings (Gemini); no model trainingEU region
Google LLCOAuth sign-in; Calendar/Meet access you authorisePer Google terms
StripeSubscription billing & paymentsEU/US under Stripe DPA + SCCs
ResendTransactional email deliveryUS under SCCs

Annex B — Details of processing

Subject matter: provision of the Actions meeting-to-task service. Duration: the term of the Agreement plus the deletion period. Nature/purpose: recording and transcription of meetings; AI extraction of action items, summaries, talking points and projects; storage and organisation of the output. Personal data: names, emails, job/role references, voice and its transcription, and any other personal data spoken in or contained within meetings, calendars and resulting tasks. Data subjects: the Customer's staff and other meeting participants. Special category data: not intended (see the AUP).

Annex C — Technical & organisational measures

  • Encryption in transit (TLS) and at rest, including encryption of stored OAuth tokens.
  • Tenant isolation via PostgreSQL Row-Level Security.
  • Role-based access within organisations; least-privilege internal access.
  • Certified infrastructure sub-processors (SOC 2 / ISO 27001).
  • Logging and monitoring; backup and recovery; documented breach response.

Acceptance

This DPA is accepted on acceptance of the Terms of Service. For a counter-signed copy, contact legal@actions-app.com.