Adendo de processamento de dados (DPA)

O DPA entre a Reline AI, Inc. e clientes que atuam como controladores de dados.

Em vigor desde

Conforme o artigo 28 do RGPD. Assinado uma vez, aplica-se a todos os workspaces da sua conta. Escreva para legal@reline.so para formalizar.

Esta política é publicada em inglês. Esta tradução é apenas para fins informativos; em caso de conflito, a versão em inglês prevalecerá.

1. Parties & scope

This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the agreement between you ("Customer", the data controller) and Reline AI, Inc. ("Reline", the processor) governing Customer's use of the Reline service (the "Agreement"). It records the parties' obligations under Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR, and the Swiss FADP (together, "Data Protection Law") with respect to Customer Personal Data that Reline processes on Customer's behalf.

Where there is a conflict between this DPA and the rest of the Agreement on the subject of data protection, this DPA prevails. This DPA takes effect on the date the Agreement is entered into, or, if executed separately, on its signature date, and remains in force for as long as Reline processes Customer Personal Data.

2. Definitions

Capitalized terms not defined here have the meaning given in Data Protection Law. "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", and "Supervisory Authority" each have the meaning given in the GDPR.

"Customer Personal Data" means Personal Data contained within Customer's workspace content (notes, audio recordings, transcripts, summaries, chat threads and other AI outputs, uploaded files, calendar metadata and the contact records derived from it, and the permissions and activity attached to that content) that Reline processes solely on Customer's behalf as a Processor. Customer Personal Data excludes Account Data and Billing Data. "Account Data" means the data Reline needs to identify, authenticate and communicate with Customer's users (name, email, profile image, sign-in identifiers and credentials, preferences, security logs, product telemetry and marketing-communication settings). "Billing Data" means plan, seat, invoice and payment information. Reline is an independent Controller of Account Data and Billing Data and processes them under its Privacy Policy, not under this DPA. "Sub-processor" means any third party engaged by Reline to process Customer Personal Data. "SCCs" means the Standard Contractual Clauses approved by the European Commission in Decision 2021/914.

3. Roles & instructions

Customer is the Controller of Customer Personal Data and Reline is the Processor. Reline is an independent Controller of Account Data and Billing Data, as defined in Section 2. Each party complies with its respective obligations under Data Protection Law, and the parties are not joint controllers of anything.

Reline processes Customer Personal Data only on Customer's documented instructions — including with regard to international transfers — unless required to do otherwise by applicable law, in which case Reline informs Customer of that legal requirement before processing (unless the law prohibits such information on important grounds of public interest). The Agreement, this DPA, Customer's configuration of the service (including integrations, auto-post rules, webhooks and MCP authorisations enabled by Customer or its users), and Customer's use of the service constitute Customer's complete and documented instructions. Reline will inform Customer if, in its opinion, an instruction infringes Data Protection Law.

4. Details of processing (Annex I)

Subject matter & duration. Processing of Customer Personal Data as necessary to provide the Reline service under the Agreement, for the duration of the Agreement plus the deletion period in Section 10.

Nature & purpose. Recording and transcribing audio, generating AI summaries, embeddings and answers, storing and syncing notes, enabling search, sharing and collaboration, delivering content to the integrations Customer connects, and the related hosting, security, and support activities that operate the service.

Types of Personal Data. Workspace content authored, recorded or uploaded by Customer's users (notes, audio recordings, transcripts, summaries, action items, chat threads and other AI outputs, uploaded files, version history); calendar metadata and derived contact/company records where a user connects a calendar; the names and email addresses of Customer's users as they appear in that content, its permissions and its activity log; and speaker events from the browser extension. Customer controls the content it submits and may include other categories at its discretion. Account Data and Billing Data are excluded (Section 2).

Special categories. Reline does not require special-category data. Because Customer controls recording and content, such data may incidentally be present; Customer is responsible for ensuring an appropriate legal basis and any additional safeguards for such data.

Categories of Data Subjects. Customer's authorized users, and individuals whose Personal Data appears in Customer's content (e.g. meeting participants, calendar attendees, contacts, and people referenced in notes). Reline publishes a notice for meeting participants that Customer may use to meet its transparency obligations towards them.

5. Confidentiality

Reline ensures that persons authorized to process Customer Personal Data are bound by an appropriate obligation of confidentiality (whether contractual or statutory) and process the data only as instructed. Access is limited to personnel who require it to operate or support the service, and platform-admin access to Customer Personal Data is logged.

6. Security measures (Annex II)

Reline implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. These include: encryption of Customer Personal Data in transit (TLS 1.2+) and at rest; a private-by-default permission model with role-based access control and per-resource grants; short-lived, scoped credentials for third-party processors; signed, replay-protected webhooks; an append-only audit log of security-relevant actions; least-privilege administrative access with an admin access log; and a software development lifecycle with code review and automated checks.

See the security page for the live posture matrix. Reline may update its measures over time provided the level of protection is not materially reduced.

7. Sub-processors

Customer provides general authorization for Reline to engage Sub-processors to process Customer Personal Data. Reline imposes data protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains liable for each Sub-processor's performance. The current Sub-processors, with their locations and transfer mechanisms, are published at reline.so/subprocessors and are, at the date of this DPA:

  • Convex (USA) — primary database, authentication, and realtime sync; stores account data, calendar metadata, notes, transcripts and summaries.
  • Cloudflare R2 (USA) — object storage for audio recordings, uploaded files and data-export bundles.
  • Speech-to-text provider (USA) — real-time transcription of audio streamed during a recording using a temporary, session-scoped key. The provider is identified by name and address in the sub-processor annex that Reline provides with this DPA on request.
  • Vercel (USA) — hosting for the web application, the AI Gateway through which every language-model request is routed, and cookieless Web Analytics and Speed Insights.
  • OpenAI (USA) — embeddings of notes, transcripts and summaries for search and chat; meeting-prep intelligence, which includes attendee email addresses; chat titles and some generations.
  • Z.ai GLM models served by Baseten (USA) and DeepInfra (USA) — summaries, chat answers and other generations, reached through the Vercel AI Gateway.
  • WorkOS (USA) — enterprise SSO and directory authentication, where Customer enables it.
  • Lemon Squeezy (USA, a Stripe company) — merchant of record and payment processing for billing.
  • Resend (USA) — transactional and product email delivery.
  • PostHog (USA) — product analytics and session replay, where the user has consented.

Language-model providers process content only to return the requested result; under their API terms they do not use it to train models, and their retention is limited to what each provider's policy specifies.

Changes. Reline notifies Customer at least 30 days before adding or replacing a Sub-processor by updating the sub-processor page, which carries a dated change log, and by emailing the owners of Customer's workspaces. Customer may object on reasonable data-protection grounds within that period; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected service.

Recipients that are not Sub-processors. Integrations that Customer or its users connect (Slack, Notion, Linear, Zapier, outbound webhooks, MCP clients) receive Customer Personal Data on Customer's instruction and are Customer's own processors or third-party recipients, not Reline Sub-processors.

8. Data subject requests

Taking into account the nature of the processing, Reline assists Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests from Data Subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, and objection). Customer can action most such requests directly in the product (including self-serve data export, complete export bundles, note deletion and account deletion); where Reline receives a request directed to Customer's data, including from a meeting participant who is not a Reline user, it logs the request, promptly forwards it to Customer, and does not respond on the merits except on Customer's instruction or as legally required.

9. Security, breach & DPIA assistance

Taking into account the nature of processing and the information available to it, Reline assists Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR, including security of processing, breach notification, data protection impact assessments, and prior consultation with Supervisory Authorities. Reline maintains its own data protection impact assessment and incident response procedure for the service and shares a summary on request.

Reline notifies Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provides sufficient information to enable Customer to meet its own notification obligations to Supervisory Authorities and Data Subjects.

10. Return & deletion of data

At Customer's choice, Reline deletes or returns all Customer Personal Data after the end of the provision of the service, and deletes existing copies, unless storage is required by applicable law. Customer may export its data at any time during the term in a machine-readable format. On termination, Customer content is deleted in accordance with Reline's retention practices (deleted content is purged from trash after 30 days). Platform backups are retained for up to 30 days, are used only for disaster recovery, and are never restored to recover deleted Customer content, so Customer Personal Data ages out of backups on that cycle. On written request Reline will confirm deletion.

11. Audits & information

Reline makes available to Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by Customer or an auditor mandated by Customer. To satisfy this obligation, Reline may make available its security documentation, its records of processing, and any third-party certifications or audit reports it holds; on-site inspections are limited to once per year (absent a Personal Data Breach or Supervisory Authority requirement), on reasonable notice, during business hours, and subject to confidentiality.

12. International transfers

Reline and its Sub-processors are located in the United States. For transfers of Customer Personal Data from the EEA, UK, or Switzerland, Reline relies on the EU Standard Contractual Clauses (Module Two, controller-to-processor, between Customer and Reline; Module Three, processor-to-processor, between Reline and its Sub-processors), the UK International Data Transfer Addendum, and the Swiss adaptations as applicable, which are incorporated into this DPA by reference, together with supplementary measures where required. Where a Sub-processor is certified under the EU-U.S. Data Privacy Framework, that mechanism may also apply.

13. How to execute

This DPA is offered as a pre-signed agreement on Reline's behalf and takes effect for Customer on acceptance of the Agreement. If your organization requires a counter-signed copy, the sub-processor annex naming the speech-to-text provider, or a negotiated version, email legal@reline.so with your organization name and signing authority. We countersign within two business days. Reline's registered postal address is available on request.

Dúvidas? Envie e-mail para legal@reline.so.