Data Processing Agreement (DPA)
Art. 28 GDPR A GDPR-compliant Data Processing Agreement is available for every customer and strongly recommended before processing personal data. Below you will find a summary of the key contents, roles, annexes, and download links.
What does the DPA cover?
Legally compliant DPA template for all customers, also available as PDF download.
Purpose limitation, deletion obligations, security measures, and subprocessor management.
Contact our Data Protection Officer: Norton Engele, privacy@sally.io
Key Contents
Transcription and analysis of online meetings using AI, only on your documented instruction.
Sally AI (Aliru GmbH) acts as Processor. You, the customer, are the Controller.
Meeting conversation data: audio, video, transcripts, and participant details.
Exclusively within the EU (preferably Germany). Encrypted storage. No third-country transfers.
Documented in Annex 1: access control, encryption, backups, audit logging, and more.
Listed in Annex 3: Microsoft Azure, AWS, DeepL, Stripe, and others. All EU-based.
Data is deleted or returned within 30 days after contract end, with written confirmation.
Your data is never used to train or improve language models. Contractually guaranteed.
You may review compliance and request certifications, audit reports, and other evidence.
We notify you of any personal data breach within 24 hours of becoming aware.