Data Processing Agreement
This agreement applies when an organization uses Kalamo to translate for an audience. It sets out how we process personal data on the organization's behalf under Article 28 of the GDPR.
Roles and scope
For personal data processed inside a room or event the Customer runs (for example the speech captured and the resulting translations and any attendee context), the Customer is the controller and ProConf is the processor. The Customer is responsible for having a lawful basis and any required notices or consents for that processing. The details of the processing are set out in Annex I.
Processing on instructions
We process the Customer's personal data only to provide Kalamo and only on the Customer's documented instructions, which include these terms and the Customer's use of the service. We will tell the Customer if an instruction appears to infringe data-protection law, and we will not process the data for our own purposes.
Confidentiality
We ensure that anyone authorized to process the Customer's data is bound by an appropriate duty of confidentiality and processes it only as needed to provide the service.
Security
We implement appropriate technical and organizational measures to protect personal data, taking account of the state of the art and the risks of the processing. These measures are summarized in Annex II and include encryption in transit, access controls, a least-data design in which audio is processed transiently and not stored by us, and transcripts that remain on the user's device.
Sub-processors
The Customer gives general authorization for us to engage the sub-processors listed at kalamo.ai/legal/subprocessors, each under a written agreement that imposes data-protection obligations equivalent to these. We keep that list current and will give reasonable notice before adding or replacing a sub-processor, so the Customer can object on reasonable data-protection grounds. We remain responsible for our sub-processors' performance.
International transfers
We process data in the European Union by default. Where a sub-processor processes data outside the European Economic Area, that transfer is made under the European Commission's Standard Contractual Clauses or another approved safeguard, with supplementary measures where appropriate.
Assistance to the Customer
We help the Customer, taking the nature of the processing into account, to:
- respond to requests from individuals exercising their rights;
- meet its security, breach-notification, and data-protection-impact-assessment duties;
- and demonstrate compliance with Article 28.
Personal data breaches
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, with the information the Customer reasonably needs to meet its own notification obligations.
Return and deletion
On termination, and at the Customer's choice, we delete or return the Customer's personal data and delete existing copies, unless the law requires us to keep them. Because Kalamo does not store room audio and keeps transcripts on the user's device, the data we hold for a Customer is largely limited to account, billing, and room-metadata records.
Audits
We make available the information needed to demonstrate compliance with Article 28 and allow for reasonable audits by the Customer or its appointed auditor, on reasonable prior notice, no more than once a year unless a regulator requires otherwise or there has been a breach, and in a way that respects the confidentiality and security of other customers' data.
Annexes
Annex I - Details of processing
- Subject matter: providing live speech translation for the Customer's audience through Kalamo.
- Duration: for as long as the Customer uses Kalamo, plus any short legally required retention.
- Nature and purpose: capturing speech, producing translations, and delivering them to listeners and any connected display or broadcast output.
- Types of personal data: the content of speech translated in a room and the resulting text; account and contact data of the Customer's users; technical data such as IP and device type. Kalamo is not intended for the deliberate processing of special-category data, and the Customer should not use it for that.
- Categories of data subjects: the Customer's speakers, attendees, and staff who use Kalamo.
Annex II - Security measures
- Encryption of data in transit (HTTPS and secure transport to all providers).
- Transient handling of audio: it is sent to the translation provider to produce the translation and is not stored by us afterward.
- Transcripts kept on the end user's device rather than on our servers.
- Access controls and least-privilege access to systems and data.
- Use of reputable infrastructure and a limited, contracted set of sub-processors.
- Logical separation of customers' data and isolation of room sessions.
Annex III - Sub-processors
The authorized sub-processors are published and kept current at kalamo.ai/legal/subprocessors.
