Data Processing Agreement (DPA)
Version 1.1 – 24 August 2026
This DPA is attached to the Customer's monthly SaaS subscription when PolaVuo processes personal data relating to Customer-initiated session content, authorised users or end users on the Customer's behalf.
1. Purpose and scope
This Data Processing Agreement forms part of the agreement between the Customer and PolaVuo Oy concerning PolaParla Broadcast. It sets out the terms required by Article 28 GDPR where the Customer acts as controller and PolaVuo as processor.
2. Roles and documented instructions
The Customer determines the purposes and means of processing and is responsible for a lawful basis, transparency, data subject rights and any required impact assessment. PolaVuo processes personal data only on the Customer's documented instructions, this DPA and the service agreement, including documented instructions on international transfers.
If PolaVuo considers that an instruction infringes data protection law, it will inform the Customer without undue delay and may suspend the affected processing while a lawful solution is agreed.
3. Subject matter, nature and duration
The processing details are set out in Annex 1. This DPA applies for the monthly subscription. The Customer independently decides when Broadcast sessions are started; content processing for each session lasts only for the live session and immediate technical delivery. PolaVuo does not create a persistent recording of session content.
4. Confidentiality of personnel
PolaVuo ensures that persons authorised to process personal data are bound by confidentiality or an appropriate statutory duty of confidentiality and that access is limited to what their duties require.
5. Security
PolaVuo implements and maintains the measures described in Annex 2 and other measures appropriate to the risk in accordance with Article 32 GDPR. The measures specifically address the confidentiality of live speech, non-retention of content, access control, encrypted transmission and incident management.
6. Subprocessors
The Customer grants PolaVuo general written authorisation to use subprocessors required to provide the Service. PolaVuo provides the current subprocessor list with the SaaS subscription and on request. PolaVuo gives reasonable advance notice of a material addition or replacement so that the Customer may object on reasonable data protection grounds.
PolaVuo enters into a written agreement with each subprocessor imposing materially the same data protection obligations as this DPA, including non-retention of session content and the prohibition on model training. PolaVuo remains responsible to the Customer for its subprocessors to the extent required by the GDPR.
7. International transfers
PolaVuo does not transfer personal data outside the EEA without a transfer mechanism under Chapter V GDPR and any necessary supplementary safeguards. The transfer mechanism and processing region are identified in the subprocessor list. PolaVuo provides available information reasonably required for the Customer's transfer assessment.
8. Data subject rights
Taking into account the nature of processing, PolaVuo assists the Customer through appropriate technical and organisational measures with data subject requests. If PolaVuo receives a request concerning the Customer's data, it forwards the request to the Customer and does not respond except on the Customer's documented instruction or as required by law. Because content is not retained, event speech and translations cannot be retrieved after the session.
9. Impact assessments and authority cooperation
PolaVuo assists the Customer with available information in data protection impact assessments, prior consultations and supervisory authority enquiries, taking into account the nature of processing. Extensive work outside the ordinary Service may be charged separately unless the need for assistance results from PolaVuo's breach.
10. Personal data breach
PolaVuo notifies the Customer of a personal data breach without undue delay after becoming aware of it and, where feasible, within 24 hours. The notice contains available information on the nature and likely effects of the breach, affected data categories, remedial measures taken or proposed and a contact point. Information may be provided in phases as it is confirmed.
11. Demonstrating compliance and audits
PolaVuo makes available reasonable information necessary to demonstrate compliance with this DPA. Once per calendar year, the Customer may audit the processing itself or through an independent auditor upon at least 30 days' notice, during normal business hours, and without compromising other customers' data, security or trade secrets. The Customer bears the audit costs unless the audit identifies a material breach by PolaVuo.
12. Deletion and return
Because PolaVuo does not retain Broadcast source audio, transcripts or translations, they cannot be returned and are discarded when processing ends. At termination, PolaVuo deletes or returns other personal data retained on the Customer's behalf, at the Customer's choice, unless Union or Member State law requires retention. Contract and accounting data processed by PolaVuo as an independent controller are outside this deletion obligation.
13. Special categories
The Customer informs PolaVuo in advance if the planned use systematically includes data under Articles 9 or 10 GDPR. The Customer is responsible for an applicable legal basis and additional safeguards. PolaVuo may refuse the processing or require a separate risk assessment and agreement.
14. Liability
The liability limitations in the service agreement apply between the parties to the extent permitted by law. Nothing limits the rights of data subjects or supervisory authorities under the GDPR or liability that cannot lawfully be limited.
15. Term and precedence
This DPA takes effect with the service agreement and remains in force for as long as PolaVuo processes personal data on the Customer's behalf. In the event of a conflict regarding personal data processing, this DPA prevails.
16. Governing law
This DPA is governed by Finnish law. Disputes are subject to the dispute resolution clause in the service agreement.
Annex 1 – Description of processing
- Subject matter
- Live speech recognition, translation, speech synthesis and delivery through PolaParla Broadcast.
- Duration
- For the monthly subscription; content processing for an individual session lasts only for the live session and immediate technical delivery, with no persistent content storage.
- Purpose
- Allowing Customer-initiated sessions to be followed in the plan languages as text and/or synthetic speech.
- Data subjects
- Customer administrators and authorised SaaS users, speakers, persons participating in discussions or questions, Customer contacts and end users insofar as technical connection data are processed.
- Data categories
- User-account identifiers and access-right data; voice and speech content; personal data mentioned in speech; transient text and translation; language/audio preferences; and necessary technical connection metadata.
- Special data
- Speech may incidentally contain data under Articles 9 or 10 GDPR; PolaVuo does not seek to infer or profile such data.
- Deletion
- Content is automatically discarded when processing ends; technical metadata is deleted or anonymised when its purpose ends.
Annex 2 – Technical and organisational measures
- encryption in transit over public networks
- content processing only in transient buffers or volatile memory without persistent storage
- prohibition on using event content for model training, fine-tuning or a subprocessor's own purposes
- role-based access, least privilege and confidentiality obligations
- separation of Customer user accounts from room-specific participant access and abuse controls
- secure development, change management, vulnerability remediation and incident response
- assessment and contractual control of subprocessors' privacy and security obligations
- recovery and continuity procedures appropriate to a live service.
Annex 3 – Subprocessor procedure
With the SaaS subscription or on request, PolaVuo provides the Customer with a current list of infrastructure, speech recognition, language, translation and speech synthesis providers, their processing regions and applicable transfer mechanisms. Material changes are notified reasonably in advance. Non-retention of content and prohibition of training use are mandatory selection criteria.