kalamo.ai

Data Processing Agreement

This agreement applies when an organization uses Kalamo to translate for an audience. It sets out how we process personal data on the organization's behalf under Article 28 of the GDPR.

Version 1.0, effective 16 June 2026.

This DPA forms part of the Terms of Service between the organization (the "Customer", acting as controller) and Profesionalūs audiovizualiniai sprendimai, MB (the "Processor"). It takes effect automatically when an organization subscribes. Organizations that need a counter-signed copy on their own paper can request one at kristijonas@proconf.lt.

Roles and scope

For personal data processed inside a room or event the Customer runs (for example the speech captured and the resulting translations and any attendee context), the Customer is the controller and ProConf is the processor. The Customer is responsible for having a lawful basis and any required notices or consents for that processing. The details of the processing are set out in Annex I.

Processing on instructions

We process the Customer's personal data only to provide Kalamo and only on the Customer's documented instructions, which include these terms and the Customer's use of the service. We will tell the Customer if an instruction appears to infringe data-protection law, and we will not process the data for our own purposes.

Confidentiality

We ensure that anyone authorized to process the Customer's data is bound by an appropriate duty of confidentiality and processes it only as needed to provide the service.

Security

We implement appropriate technical and organizational measures to protect personal data, taking account of the state of the art and the risks of the processing. These measures are summarized in Annex II and include encryption in transit, access controls, a least-data design in which audio is processed transiently and not stored by us, and transcripts that remain on the user's device.

Sub-processors

The Customer gives general authorization for us to engage the sub-processors listed at kalamo.ai/legal/subprocessors, each under a written agreement that imposes data-protection obligations equivalent to these. We keep that list current and will give reasonable notice before adding or replacing a sub-processor, so the Customer can object on reasonable data-protection grounds. We remain responsible for our sub-processors' performance.

International transfers

We process data in the European Union by default. Where a sub-processor processes data outside the European Economic Area, that transfer is made under the European Commission's Standard Contractual Clauses or another approved safeguard, with supplementary measures where appropriate.

Assistance to the Customer

We help the Customer, taking the nature of the processing into account, to:

  • respond to requests from individuals exercising their rights;
  • meet its security, breach-notification, and data-protection-impact-assessment duties;
  • and demonstrate compliance with Article 28.

Personal data breaches

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, with the information the Customer reasonably needs to meet its own notification obligations.

Return and deletion

On termination, and at the Customer's choice, we delete or return the Customer's personal data and delete existing copies, unless the law requires us to keep them. Because Kalamo does not store room audio and keeps transcripts on the user's device, the data we hold for a Customer is largely limited to account, billing, and room-metadata records.

Audits

We make available the information needed to demonstrate compliance with Article 28 and allow for reasonable audits by the Customer or its appointed auditor, on reasonable prior notice, no more than once a year unless a regulator requires otherwise or there has been a breach, and in a way that respects the confidentiality and security of other customers' data.

Annexes

Annex I - Details of processing

  • Subject matter: providing live speech translation for the Customer's audience through Kalamo.
  • Duration: for as long as the Customer uses Kalamo, plus any short legally required retention.
  • Nature and purpose: capturing speech, producing translations, and delivering them to listeners and any connected display or broadcast output.
  • Types of personal data: the content of speech translated in a room and the resulting text; account and contact data of the Customer's users; technical data such as IP and device type. Kalamo is not intended for the deliberate processing of special-category data, and the Customer should not use it for that.
  • Categories of data subjects: the Customer's speakers, attendees, and staff who use Kalamo.

Annex II - Security measures

  • Encryption of data in transit (HTTPS and secure transport to all providers).
  • Transient handling of audio: it is sent to the translation provider to produce the translation and is not stored by us afterward.
  • Transcripts kept on the end user's device rather than on our servers.
  • Access controls and least-privilege access to systems and data.
  • Use of reputable infrastructure and a limited, contracted set of sub-processors.
  • Logical separation of customers' data and isolation of room sessions.

Annex III - Sub-processors

The authorized sub-processors are published and kept current at kalamo.ai/legal/subprocessors.