This English text is a translation. Only the Dutch version is legally binding. Nederlands
Data Processing Agreement
Last updated: 8 October 2026
This Data Processing Agreement is part of Notulist’s Terms & Conditions and applies to every business user and organisation using Notulist (“the customer”). You don’t need to sign it separately: it applies as soon as you use Notulist for business. If you’d like a signed copy anyway, email hello@notulist.io.
1. Parties and roles
- The customer is the controller for the personal data in the content it records with Notulist.
- KKX B.V., Keulenstraat 1, Deventer, the Netherlands, Chamber of Commerce number 93019424 (“KKX”), is the processor and processes that personal data only on the customer’s behalf.
- Terms from the General Data Protection Regulation (GDPR) have the same meaning in this agreement.
2. Subject and duration
- Subject and purpose: providing Notulist: recording and storing meetings, transcribing them with speakers, creating reports, searching, sharing and connecting with calendars and other apps, as described on notulist.io.
- Types of personal data: voice and spoken content in recordings; transcripts and reports and any personal data in them; names, email addresses, companies and descriptions of people in the library; speakers and talk time; invitees of linked calendar events; tags, vocabularies and chats.
- Data subjects: users, participants in recorded meetings, people in the library, invitees of calendar events and others who appear in the content.
- Special categories of data: Notulist isn’t meant for them, but they may come up in spoken content. The customer assesses whether it may process them. Notulist does not create voiceprints and does not process biometric data to identify people.
- Duration: for as long as the customer uses Notulist, and after that until the data is deleted under section 10.
3. Instructions
- KKX processes the personal data only on documented instructions from the customer. The customer’s and its users’ use and settings of Notulist count as those instructions.
- KKX informs the customer if, in its opinion, an instruction infringes the GDPR or other law.
- If the law requires KKX to process data beyond the instructions, KKX informs the customer in advance, unless the law prohibits that.
4. Confidentiality
KKX ensures that everyone with access to the personal data on its behalf is bound to confidentiality. KKX staff only look at content if a user explicitly asks for it in a support request, or if the law requires it.
5. Security
KKX takes appropriate technical and organisational measures to secure the personal data, taking into account the state of the art, the costs and the risks (Article 32 GDPR). The main ones are listed in Annex 2. KKX may change the measures as long as the level of security doesn’t decrease.
6. Sub-processors
- The customer gives KKX general authorisation to engage the sub-processors in Annex 1.
- KKX announces a new or different sub-processor at least 14 days in advance on this page, and by email to the admins of organisations. The customer can object on reasonable grounds within that period. If we can’t resolve it together, the customer may stop using Notulist.
- KKX imposes on sub-processors in writing at least the same obligations as in this agreement, and remains responsible towards the customer for their compliance.
7. Transfers outside the EEA
Some sub-processors process data in the United States (see Annex 1). These transfers are based on the EU-US Data Privacy Framework, where the sub-processor is certified under it, and otherwise on the European Commission’s Standard Contractual Clauses with supplementary measures.
8. Assistance
- Data subject rights. Notulist lets the customer view, edit, export and delete data itself. KKX further assists the customer with data subject requests, and forwards requests it receives directly to the customer.
- DPIA and prior consultation. KKX gives the customer the information it reasonably needs for a data protection impact assessment or a consultation of the supervisory authority.
9. Personal data breaches
- KKX notifies the organisation’s admins or the user of a breach of security affecting the customer’s personal data without undue delay, and at the latest 48 hours after becoming aware of it.
- KKX provides all information the customer needs to meet its own notification duties: the nature of the breach, the data and data subjects concerned, the likely consequences and the measures taken or proposed. Whatever isn’t known at once follows as soon as possible.
- KKX takes immediate measures to limit the consequences and prevent recurrence.
10. End of processing
- When it stops using Notulist, the customer can export its data in Settings.
- When the customer deletes an account, it is permanently deleted after 7 days, with all its content. Backups and deleted audio are gone at most 14 days later.
- KKX keeps no copies unless the law requires it.
11. Information and audits
- On request, KKX gives the customer written information demonstrating compliance with this agreement, such as a description of its security measures.
- Only if that information is demonstrably insufficient, or a supervisory authority asks for it, may the customer have compliance checked by an independent auditor bound to confidentiality. The customer announces the audit at least 30 days in advance and bears its costs. An audit doesn’t disrupt the service unnecessarily and gives no access to data of other customers, or to confidential KKX information the audit doesn’t need.
12. Liability and precedence
- The parties’ liability is governed by the Terms & Conditions.
- If the Terms & Conditions and this agreement conflict on the processing of personal data, this agreement prevails.
- This agreement is written in Dutch and English. In case of differences, the Dutch text prevails.
Annex 1: sub-processors
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Microsoft (Azure) | Hosting, database, audio storage | EU (Netherlands) |
| ElevenLabs | Audio transcription | United States |
| Anthropic | Reports, chat, titles, tag and speaker suggestions (Claude) | United States |
| OpenAI | Embeddings for searching by meaning | United States |
| Lettermint | Sending email (notifications of shared meetings, invitations) | EU |
| Sentry | Error reports, with only a user ID and no content | EU (Germany) |
Annex 2: security measures
- Encryption: all connections over TLS; database and audio storage encrypted; access keys for calendars and Apple encrypted with a separate key; sign-in and connection tokens stored only as hashes.
- User access: sign-in with Microsoft, Google or Apple, without passwords at KKX; short-lived access tokens and rotating sessions with reuse detection; organisations decide which sign-in methods their members use; sharing only explicitly, per person, and always revocable.
- Staff access: only for those who need it; the admin portal runs separately from the service, with its own sign-in, and shows no meeting content.
- Hosting: Microsoft Azure in the EU (Netherlands), with separate containers for the parts of the service.
- Backups and recovery: 14 days of point-in-time database backups; deleted audio can be recovered for 14 days; periodic restore tests.
- Monitoring: availability checks and alerts on outages; error reports without content or personal data other than a user ID.
- Data minimisation: no tracking or analytics; server logs are deleted after 30 days; unfinished recordings after 30 days.
- Audit log: admin changes within an organisation are recorded for a year and visible to owners and admins.