pibiMemo
Legal Privacy Terms Cookies DPA GDPR Language
ES EN
Data Processing Agreement applies to the app pibiMemo operated by
pibiCo Compañía de Inteligencia de Negocio y Control SL
CIF ES B52567831 · Avenida de La Costa, 35-6T, 33201 Gijón, Asturias, España
Support: soporte@pibico.es · DPO: soporte@pibico.es
Version: 2.1.0 · Effective from: 2026-08-29

Data Processing Agreement (DPA)

Annex to the service contract between Customer and pibiCo Compañía de Inteligencia de Negocio y Control SL for compliance with Regulation (EU) 2016/679 (GDPR).

Who this document applies to. This Agreement governs the case where the Service is contracted by an organisation that enrols its own people and uploads third-party data to the Platform: there, the organisation is the controller and pibiCo the processor. If you opened your account yourself — from the web or from the application — this annex does not describe your relationship with pibiCo: there, pibiCo is the data controller and what applies to you is the Privacy Policy.

1. Parties

  • Data Controller ("Customer"): the entity or organization that has contracted the Service.
  • Data Processor: pibiCo Compañía de Inteligencia de Negocio y Control SL, VAT ES B52567831, Avenida de La Costa 35-6T, 33201 Gijón, Asturias, Spain.

2. Subject matter

The Processor will process personal data on behalf of the Controller only to provide the contracted services (pibiMemo) per documented instructions of the Controller.

3. Data processed

  • Email address: address used by the User to create the account, authenticate and receive service notices.
  • Name: the name the User chooses to identify their account with.
  • User identifier: internal identifier linking stored content to the account that created it.
  • Audio recordings: voice notes recorded by the User and the automatic transcription generated from them.
  • Images: photographs the User expressly selects to attach to their notes or documents.
  • Documents: PDF, office or text files the User stores on the Platform.
  • Other User content: titles, written notes, categories, tags and any other content created by the User.
  • Technical data: IP address, user-agent, anti-abuse device fingerprint hash and session logs.

4. Categories of data subjects

  • Employees, collaborators and members of the Customer
  • End-clients of the Customer whose data is managed within the Service

5. Processor obligations

The Processor undertakes to:

  • Process data only per Controller's documented instructions
  • Ensure confidentiality by authorized personnel
  • Apply appropriate technical and organizational measures (encryption in transit, access control, operation logs, encrypted backups)
  • Assist the Controller in handling data subject rights
  • Notify security breaches without undue delay, max 72 hours
  • Delete or return data at end of service
  • Allow reasonable audits by the Controller or independent auditor

6. Sub-processors

The transcription, embeddings, document conversion and language model services are pibiCo's own software: content is not disclosed to any third party and is not used to train models, neither our own nor anyone else's. The machines they run on, however, are rented from IONOS Cloud, S.L.U., which has access to the physical media and therefore appears in the table. It is bound by its own data processing agreement, with obligations equivalent to those of this Annex pursuant to Article 28.4 GDPR. The Telegram bot is optional and only works if the User links it to their account. Telegram is not a pibiCo subprocessor: it is the channel the User chooses, just as their email provider would be, and it handles messages under its own terms and its own policy. Anything travelling through it leaves the European Union. Anyone who prefers not to use it has the same, complete service through the web and the app, with nothing going through Telegram.

Processing relies on the following services, each with a bounded purpose:

ServicePurposeWhat it receivesLocation
Transcription serviceTurn speech into text The audio fragmentEU
Embeddings serviceIndex the text so it can be searched The note textEU
Document conversion serviceTurn a document into text The documentEU
Language model serviceExtract reminders and hold the conversation The note textEU
pibiCo AuthIdentity, contract and usage Account data and usage figuresEU
IONOS Cloud, S.L.U.Servers where the Service runs and disks where its data resides All content, at rest and while being processedEU
Telegram Messenger Inc.Capture and conversation channel through the pibiMemo bot, when the User chooses to use it Whatever the User sends to the bot — text, audio, photos and documents — and everything the Service pushes back through that channel: the companion replies, the daily question, reminders —which carry the note title or its opening— the proof-of-life checks and the notices to the heirOutside the EU

Any change will be notified 30 days in advance. The Controller may object with reasoning; otherwise the change is deemed accepted.

7. International transfers

Where sub-processors are located outside the EEA, transfers are made under Standard Contractual Clauses (SCC) approved by the European Commission or Adequacy Decisions.

8. Security measures

The Processor applies among others:

  • Encryption in transit (TLS 1.2+)
  • Passwordless authentication (WebAuthn passkeys) and MFA
  • Role-based access control (RBAC)
  • Operation logging
  • Daily encrypted backups, kept off the server, with a documented and tested restore procedure
  • Dependency review

9. Security breach

In case of breach affecting Controller's personal data, the Processor will notify the Controller without undue delay, within 72 hours of becoming aware, including:

  • Nature of the breach
  • Categories and approximate number of affected data subjects
  • Measures taken or proposed
  • Processor contact point to coordinate response

10. Audit rights

The Controller may request documentary evidence of compliance (audit reports, certifications, technical descriptions) up to once a year or after any relevant breach. On-site audits require prior agreement and are performed during business hours without interrupting the Service.

11. Term and termination

This DPA enters into force upon contracting the Service and remains in force while the Customer maintains an active account. Upon termination, the Processor will delete or return personal data per Controller's documented instruction, except for legal retention obligation (billing data: 6 years).

12. Liability

Each party is liable for its own GDPR breaches. Processor liability is limited per the Service Terms.

Last updated: 2026-08-29 · Version 2.1.0

© 2026 pibiCo