Data Processing Agreement
Last updated: 2026-08-05
This agreement governs how EDI Labs AB, company reg. no. 556972-4171 ("Sagt.ai", "we") processes personal data on your behalf when you use the service. It forms an integral part of our Terms of Service (Swedish) and applies automatically from the moment you start using the service — there is nothing to request or sign.
If your organisation needs a countersigned copy, request one at hej@sagt.ai.
1. Roles
You are the controller of the personal data contained in your content — recordings, transcripts, analyses, and whatever information about meeting participants that content happens to contain. You decide why and how it is processed.
We are the processor and process it only on your instructions.
If you process the content on behalf of someone else — as an employee, consultant or supplier — that organisation is the controller and we become a sub-processor. In that case you warrant, under the Terms of Service, that you have the controller's authorisation.
For your account, billing and use of the service we are ourselves the controller. That is described in the Privacy Policy (Swedish) and falls outside this agreement.
2. Subject matter of the processing
- Purpose: to deliver the service — transcription, speaker separation, summarisation and storage of the result according to your settings.
- Duration: for as long as you use the service, subject to the deletion periods in section 6.
- Types of data: audio recordings, transcribed text, speaker labels and generated summaries. The content is determined by you and may include special categories of personal data under Article 9.
- Categories of data subjects: you, and the people who take part in or are mentioned in your recordings.
3. Instructions
Your documented instruction under Article 28(3)(a) is to deliver the service in accordance with the Terms of Service and the settings you choose within it. You direct the processing by using the product — choose local mode and the audio never leaves your machine; choose cloud mode and it is processed under this agreement.
We do not process the data for any other purpose. In particular, we do not use it to train AI models, neither our own nor anyone else's, and we do not sell or share it.
If we consider an instruction to infringe data protection law we will inform you, and may suspend that instruction until the matter is resolved.
4. Your responsibilities
You are responsible for the lawfulness of your processing — for having a legal basis, for informing meeting participants under Article 13, and for having an applicable condition under Article 9(2) where the content includes special categories of data.
We cannot see whose data you process and therefore cannot assess this for you.
5. Security
We implement appropriate technical and organisational measures under Article 32, including:
- encryption in transit (TLS) and at rest with our storage providers;
- access control — only those of us who need access for operations and support have it;
- confidentiality undertakings for everyone who processes the data;
- logging of access to the production environment;
- separated test and production environments.
We currently hold no ISO 27001 or SOC 2 certification, and do not claim otherwise.
6. Retention and deletion
- Audio files are deleted automatically within 24 hours of completed processing. If you select immediate deletion, it happens right after transcription.
- Transcripts and analyses are stored only if you enable cloud sync. Otherwise they exist solely on your own machine.
- On account closure, all content is deleted within 30 days.
When processing ends we delete or return the data at your choice, unless retention is required by law (Article 28(3)(g)). If you want the data returned before deletion, tell us within 30 days of termination.
7. Sub-processors
You give us general prior authorisation to engage sub-processors under Article 28(2). Who they are, what they do and which category of data they see is set out in our sub-processor list.
We will give you at least 30 days' notice before adding or replacing a sub-processor. You may object during that period. If we cannot resolve your objection you may terminate the service without penalty and receive a refund for any unused prepaid period.
We impose the same obligations on every sub-processor as apply under this agreement, and remain responsible for their processing as for our own.
8. Transfers outside the EU/EEA
Your content is processed exclusively within the EU/EEA. We do not transfer it to third countries. Should that ever change, it will only happen on a valid transfer basis under Chapter V of the GDPR, and you will be notified in advance under section 7.
9. Assistance to you
Taking into account the nature of the processing, we assist you with:
- responding to data subject requests for access, rectification, erasure, restriction, objection and portability (Article 28(3)(e));
- meeting your obligations under Articles 32–36, including data protection impact assessments and prior consultation (Article 28(3)(f)).
If a data subject contacts us directly about content for which you are the controller, we refer them to you and notify you.
10. Personal data breaches
If we become aware of a personal data breach affecting your content we will notify you without undue delay (Article 33(2)), with the information you need to make your own notification to the supervisory authority within 72 hours: what happened, which categories of data and data subjects are affected, the likely consequences, and the measures we have taken.
Notification to the supervisory authority and, where required, to the data subjects is your responsibility, as you are the controller.
11. Audit
You have the right to verify our compliance with this agreement. In the first instance this is satisfied by us providing documentation and answering questions in writing — which is sufficient in the vast majority of cases and fastest for both parties.
Where an on-site audit is additionally required: no more than once per twelve-month period, on at least 30 days' written notice, during business hours, by an auditor bound by confidentiality who is not a competitor of ours. You bear the costs. If a material deficiency is established, we bear them instead.
12. Liability
Liability follows Articles 82 and 83 of the GDPR. Otherwise the limitation of liability in the Terms of Service (Swedish) applies.
13. Changes
We may update this agreement. Material changes are notified by email or in the service at least 30 days before they take effect. Sub-processor changes follow section 7.
14. Contact
Questions about this agreement, requests for a countersigned copy, or for audit documentation: hej@sagt.ai.
15. Language
This is a translation provided for convenience. In the event of any conflict, the Swedish version at sagt.ai/personuppgiftsbitradesavtal prevails.