Data Processing Agreement
Last updated: June 2026
This DPA forms part of the Terms of Servicebetween NGJB Limited ("Actions", "Processor") and the customer organisation ("Customer", "Controller"). It applies where Actions processes personal data on the Customer's behalf, reflects Article 28 of the UK GDPR, and prevails over the rest of the Agreement for such processing. It takes effect when the Customer accepts the Terms.
1. Roles
The Customer is the Controller and Actions is the Processor of Customer Personal Data. The Customer is responsible for the lawfulness of its instructions and of its own collection and use of the data, including informing meeting participants and obtaining any consents required for recording and transcription.
2. Scope & instructions
Actions processes Customer Personal Data only on the Customer's documented instructions (including via use of the service's features) and as required by law, and will inform the Customer if it considers an instruction infringes data-protection law. The subject matter, nature, purpose, data types and data subjects are described in Annex B.
3. Confidentiality & security
Personnel are bound by confidentiality and access data only as needed. Actions implements appropriate technical and organisational measures (Annex C), including encryption in transit and at rest, tenant isolation via Row-Level Security, access controls, and reputable infrastructure providers.
4. Sub-processors
The Customer authorises the sub-processors listed in Annex A. Actions imposes data-protection obligations on each that are no less protective than this DPA and remains liable for their performance. Actions will give at least 30 days' notice of any new or replacement sub-processor; the Customer may object on reasonable data-protection grounds and, if unresolved, terminate the affected service as its sole remedy.
5. Data-subject rights & assistance
Taking into account the nature of processing, Actions will assist the Customer in responding to data-subject requests and with security, breach notification, DPIAs and prior consultation. Requests received directly from data subjects are referred to the Customer.
6. Personal data breaches
Actions will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, with information reasonably required for the Customer's own notifications.
7. International transfers
Actions keeps meeting content within the EU/EEA where its sub-processors offer this, and the AI extraction layer is provided from an EU region. Any transfer outside the UK/EEA relies on the UK IDTA / Addendum to the EU SCCs, plus a transfer risk assessment and supplementary measures.
8. Audit
Actions makes available information necessary to demonstrate Article 28 compliance and will contribute to audits, including via third-party certifications (e.g. SOC 2 / ISO 27001 of its infrastructure sub-processors). On-site audits are limited to once a year on reasonable notice and under confidentiality, unless a supervisory authority requires otherwise.
9. Deletion & return
On termination or request, Actions deletes or returns Customer Personal Data (Customer's choice) and deletes copies within 30 days, unless retention is required by law; backups are deleted on their normal rotation cycle. Liability under this DPA is subject to the limits in the Agreement. This DPA is governed by the law of England and Wales.
Annex A — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU — Frankfurt (eu-central-1) |
| Vercel Inc. | Application hosting & delivery | Global edge network; functions US — Washington, D.C. (iad1) |
| Recall.ai (Hyperdoc Inc.) | Meeting-bot capture, recording, transcription (uses Deepgram / AssemblyAI) | EU — Frankfurt (eu-central-1) |
| Google Cloud — Vertex AI | Generative-AI extraction & embeddings (Gemini); no model training | EU region |
| Google LLC | OAuth sign-in; Calendar/Meet access you authorise | Per Google terms |
| Stripe | Subscription billing & payments | EU/US under Stripe DPA + SCCs |
| Resend | Transactional email delivery | US under SCCs |
Annex B — Details of processing
Subject matter: provision of the Actions meeting-to-task service. Duration: the term of the Agreement plus the deletion period. Nature/purpose: recording and transcription of meetings; AI extraction of action items, summaries, talking points and projects; storage and organisation of the output. Personal data: names, emails, job/role references, voice and its transcription, and any other personal data spoken in or contained within meetings, calendars and resulting tasks. Data subjects: the Customer's staff and other meeting participants. Special category data: not intended (see the AUP).
Annex C — Technical & organisational measures
- Encryption in transit (TLS) and at rest, including encryption of stored OAuth tokens.
- Tenant isolation via PostgreSQL Row-Level Security.
- Role-based access within organisations; least-privilege internal access.
- Certified infrastructure sub-processors (SOC 2 / ISO 27001).
- Logging and monitoring; backup and recovery; documented breach response.
Acceptance
This DPA is accepted on acceptance of the Terms of Service. For a counter-signed copy, contact legal@actions-app.com.