How StenoDesk processes personal data on your behalf when you act as the controller.
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Service between StenoDesk LLC ("StenoDesk," "Processor," "we," "us," or "our") and you, the account holder ("Controller," "you," or "your"), regarding the processing of personal data through the StenoDesk platform at stenodesk.com and related subdomains (the "Service"). This DPA reflects the controller/processor roles described in our Privacy Policy (§9). Where there is a conflict on data-protection matters, this DPA controls.
a. Controller and Processor. You are the Controller of the Personal Data you upload, enter, connect, or otherwise provide through the Service. StenoDesk acts as your Processor and processes that data only on your documented instructions and as described in this DPA. For our own account-administration and billing data, StenoDesk is an independent controller as described in the Privacy Policy.
b. Categories of Personal Data. Personal Data processed under this DPA may include client and law-firm records (names, emails, phone numbers, addresses, EIN/tax IDs), contacts, case captions and numbers, witnesses/deponents, cast-of-characters and appearance details, exhibits, transcript and case-file content (which may contain sensitive third-party information), job and scheduling details, notes, invoices, and, if you connect a mailbox/calendar, the messages, contacts, and calendar events in those connected accounts.
c. Categories of Data Subjects. Your clients (attorneys, law firms, agencies, courts), witnesses and deponents, individuals named in case materials, subcontractors you connect with, and other people whose information you enter into the Service.
d. Duration. We process Personal Data for the duration of your account plus any retention period described in the Privacy Policy (§7) and this DPA.
a. Permitted processing. We process Personal Data only (i) to provide the Service under the Terms, (ii) in accordance with your documented instructions (which include your configuration and use of Service features), and (iii) as required by applicable law (in which case we will inform you of that requirement unless legally prohibited).
b. Conflicting instructions. If we reasonably believe an instruction violates applicable data-protection law, we will notify you and may suspend the affected processing until the instruction is modified.
c. No sale; no model training. We do not sell Personal Data, and we do not use the contents of your connected email, calendar, or uploaded case files to train generalized AI/ML models or for advertising.
We implement appropriate technical and organizational measures to protect Personal Data, including:
Personnel authorized to process Personal Data are bound by confidentiality obligations. You are responsible for the security of your own systems and for safeguarding your account credentials, and for configuring access appropriately (for example, which subcontractors you connect and what they can see). No method of transmission or storage is fully secure.
a. Authorization. You authorize us to engage the Subprocessors listed below to process Personal Data on your behalf. We share only what is necessary for each Subprocessor's stated purpose. This list mirrors the subprocessor table in our Privacy Policy (§6) and may be updated as the Service evolves.
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage, realtime | Account, client/case, transcript files, app data |
| Cloudflare R2 | Media/file object storage | Uploaded media/files |
| Firebase Hosting (Google) | Static web hosting / CDN | App delivery; technical logs |
| Nylas | Email & calendar brokering for connected accounts | Connected mailbox/calendar data |
| Google / Microsoft | OAuth for your connected mailboxes/calendars | Email, contacts, calendar |
| Stripe | Subscription billing | Billing details (card data held by Stripe) |
| Anthropic (Claude API) | AI processing of content you submit to AI features (proofing/extraction) | Task-specific content |
| Resend | Transactional email delivery | Recipient email, message content |
| Sentry | Error/crash monitoring | Diagnostic data (IP storage disabled) |
| PostHog | Product analytics | Usage events (no session replay) |
b. Subprocessor obligations. We impose data-protection terms on each Subprocessor that are no less protective than those in this DPA, and we remain responsible for their performance of those obligations.
c. Changes and right to object. We will notify you of intended additions or replacements of Subprocessors and give you a reasonable opportunity to object on reasonable, data-protection grounds. If we cannot resolve a legitimate objection, you may terminate the affected processing as your sole remedy.
d. AI Subprocessor posture. Anthropic processes content you submit to AI features as a Subprocessor under its standard commercial API terms, which provide that inputs and outputs are not used to train its models and are retained only for a limited period before deletion. Zero-Data-Retention (ZDR) is not available to us at our current scale, so we do not represent that ZDR is in effect. Anthropic maintains a Trust Center documenting its security program (including SOC 2).
Taking into account the nature of the processing, we will assist you with appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights (access, rectification, erasure, restriction, portability, and objection). Account holders can edit and delete most data directly in the Service. If we receive a request directly from a Data Subject relating to your data, we will, unless legally prohibited, redirect that person to you as the Controller. We will respond to your requests for assistance within a reasonable timeframe given the nature of the request.
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting your Personal Data. The notification will include, to the extent known: the nature of the incident, the categories and approximate number of Data Subjects and records affected, likely consequences, the measures taken or proposed to address it and mitigate its effects, and a contact point for further information. We will cooperate with you and provide reasonable assistance in investigating and mitigating the incident and in meeting any notification obligations you may have.
Personal Data is primarily processed in the United States, where our infrastructure providers operate. By using the Service, you authorize transfer to the United States. For transfers of Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland, we will rely on a lawful transfer mechanism (such as the European Commission's Standard Contractual Clauses, with applicable UK and Swiss addenda) together with any supplementary measures necessary to ensure an adequate level of protection. [counsel: confirm the final SCC module/mechanism, UK/Swiss addenda, and any supplementary-measures language before relying on this section for EEA/UK/Swiss customers.]
Upon your reasonable written request, and no more than once per year unless required by a supervisory authority or following a Security Incident, we will make available information reasonably necessary to demonstrate compliance with this DPA. Where you reasonably require an on-site or independent audit, it must be on at least 30 days' advance notice, under appropriate confidentiality terms, during normal business hours, in a manner that does not unreasonably interfere with our operations, and at your cost. We may satisfy audit requests by providing relevant third-party audit reports or certifications (including those of our Subprocessors, such as SOC 2 reports) where available.
On termination of your account, and at your choice, we will return or delete Personal Data we process on your behalf, subject to any retention required by law. You can export your data using in-app tools where available, or request an export before closure. Account deletion is scheduled with a 30-day recoverable grace period, after which your data is permanently removed from active systems; residual copies in backups are deleted on our backup-rotation schedule. We will certify deletion on written request. We may retain limited data as required by law or for billing, tax, dispute-resolution, and security purposes.
Each party is liable for its own breach of this DPA or of applicable data-protection law. Liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service.
This DPA remains in effect for as long as we process Personal Data on your behalf. Provisions relating to confidentiality, security, deletion, liability, audit rights, and transfers survive termination to the extent necessary.
This DPA is governed by the same law that governs the Terms of Service. [counsel: confirm governing-law/venue alignment, including for EEA/UK customers where local mandatory law may apply.]
StenoDesk LLC
Email: privacy@stenodesk.com
[Mailing address]