Data Processing Agreement (DPA)
Annex to the service contract between Customer and pibiCo Compañía de Inteligencia de Negocio y Control SL for compliance with Regulation (EU) 2016/679 (GDPR).
Who this document applies to. This Agreement governs the case where the Service is contracted by an organisation that enrols its own people and uploads third-party data to the Platform: there, the organisation is the controller and pibiCo the processor. If you opened your account yourself — from the web or from the application — this annex does not describe your relationship with pibiCo: there, pibiCo is the data controller and what applies to you is the Privacy Policy.
1. Parties
- Data Controller ("Customer"): the entity or organization that has contracted the Service.
- Data Processor: pibiCo Compañía de Inteligencia de Negocio y Control SL, VAT ES B52567831, Avenida de La Costa 35-6T, 33201 Gijón, Asturias, Spain.
2. Subject matter
The Processor will process personal data on behalf of the Controller only to provide the contracted services (pibiMemo) per documented instructions of the Controller.
3. Data processed
- Email address: address used by the User to create the account, authenticate and receive service notices.
- Name: the name the User chooses to identify their account with.
- User identifier: internal identifier linking stored content to the account that created it.
- Audio recordings: voice notes recorded by the User and the automatic transcription generated from them.
- Images: photographs the User expressly selects to attach to their notes or documents.
- Documents: PDF, office or text files the User stores on the Platform.
- Other User content: titles, written notes, categories, tags and any other content created by the User.
- Technical data: IP address, user-agent, anti-abuse device fingerprint hash and session logs.
4. Categories of data subjects
- Employees, collaborators and members of the Customer
- End-clients of the Customer whose data is managed within the Service
5. Processor obligations
The Processor undertakes to:
- Process data only per Controller's documented instructions
- Ensure confidentiality by authorized personnel
- Apply appropriate technical and organizational measures (encryption in transit, access control, operation logs, encrypted backups)
- Assist the Controller in handling data subject rights
- Notify security breaches without undue delay, max 72 hours
- Delete or return data at end of service
- Allow reasonable audits by the Controller or independent auditor
6. Sub-processors
The transcription, embeddings, document conversion and language model services are pibiCo's own software: content is not disclosed to any third party and is not used to train models, neither our own nor anyone else's. The machines they run on, however, are rented from IONOS Cloud, S.L.U., which has access to the physical media and therefore appears in the table. It is bound by its own data processing agreement, with obligations equivalent to those of this Annex pursuant to Article 28.4 GDPR. The Telegram bot is optional and only works if the User links it to their account. Telegram is not a pibiCo subprocessor: it is the channel the User chooses, just as their email provider would be, and it handles messages under its own terms and its own policy. Anything travelling through it leaves the European Union. Anyone who prefers not to use it has the same, complete service through the web and the app, with nothing going through Telegram.
Processing relies on the following services, each with a bounded purpose:
| Service | Purpose | What it receives | Location |
|---|---|---|---|
| Transcription service | Turn speech into text | The audio fragment | EU |
| Embeddings service | Index the text so it can be searched | The note text | EU |
| Document conversion service | Turn a document into text | The document | EU |
| Language model service | Extract reminders and hold the conversation | The note text | EU |
| pibiCo Auth | Identity, contract and usage | Account data and usage figures | EU |
| IONOS Cloud, S.L.U. | Servers where the Service runs and disks where its data resides | All content, at rest and while being processed | EU |
| Telegram Messenger Inc. | Capture and conversation channel through the pibiMemo bot, when the User chooses to use it | Whatever the User sends to the bot — text, audio, photos and documents — and everything the Service pushes back through that channel: the companion replies, the daily question, reminders —which carry the note title or its opening— the proof-of-life checks and the notices to the heir | Outside the EU |
Any change will be notified 30 days in advance. The Controller may object with reasoning; otherwise the change is deemed accepted.
7. International transfers
Where sub-processors are located outside the EEA, transfers are made under Standard Contractual Clauses (SCC) approved by the European Commission or Adequacy Decisions.
8. Security measures
The Processor applies among others:
- Encryption in transit (TLS 1.2+)
- Passwordless authentication (WebAuthn passkeys) and MFA
- Role-based access control (RBAC)
- Operation logging
- Daily encrypted backups, kept off the server, with a documented and tested restore procedure
- Dependency review
9. Security breach
In case of breach affecting Controller's personal data, the Processor will notify the Controller without undue delay, within 72 hours of becoming aware, including:
- Nature of the breach
- Categories and approximate number of affected data subjects
- Measures taken or proposed
- Processor contact point to coordinate response
10. Audit rights
The Controller may request documentary evidence of compliance (audit reports, certifications, technical descriptions) up to once a year or after any relevant breach. On-site audits require prior agreement and are performed during business hours without interrupting the Service.
11. Term and termination
This DPA enters into force upon contracting the Service and remains in force while the Customer maintains an active account. Upon termination, the Processor will delete or return personal data per Controller's documented instruction, except for legal retention obligation (billing data: 6 years).
12. Liability
Each party is liable for its own GDPR breaches. Processor liability is limited per the Service Terms.
Last updated: 2026-08-29 · Version 2.1.0