Last updated 30 September 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") applies whenever NoteFish processes personal data on behalf of a business customer. It meets Article 28 of the EU General Data Protection Regulation (GDPR) and the equivalent rules of Moldova's Law no. 195/2024 on personal data protection.
It forms part of the Terms of Service and needs no separate signature: it takes effect when a business accepts the Terms. If you need a countersigned copy for your records, write to hello@notefish.ai.
1. Parties and roles
The customer is the business that uses NoteFish. It is the controller.
NoteFish is Întreprinzător Individual „LEONARDO CALANCEA”, IDNO 1026023047638, bd. Ștefan cel Mare și Sfânt 141/2, ap. 45, MD-2004 Chișinău, Republic of Moldova. It is the processor.
Where the customer is itself a processor for someone else, NoteFish is its sub-processor, and the customer passes on the obligations below accordingly.
2. What is processed
The details are in Annex I:
- the subject matter, nature and purpose of the processing;
- how long it lasts;
- the types of personal data;
- the categories of people concerned.
3. Instructions
NoteFish processes personal data only on the customer's documented instructions. These are the Terms, this DPA, and the settings the customer chooses in NoteFish, for example how long calls are kept.
There is one exception: where EU or Member State law, or Moldovan law, requires processing. In that case NoteFish tells the customer first, unless the law forbids it.
NoteFish tells the customer if it believes an instruction breaks data protection law.
4. Confidentiality
Anyone NoteFish allows to process the data is bound to confidentiality.
5. Security
NoteFish takes the technical and organisational measures in Annex II, and keeps them up to date with the state of the art and the risks.
6. Sub-processors
General authorisation. The customer authorises NoteFish to use the sub-processors listed at notefish.ai/subprocessors.
Adding or replacing a sub-processor.
- NoteFish announces it on that page and by email to the customer's admin at least 14 days in advance.
- The customer may object on reasonable data protection grounds within that time.
- If the objection cannot be resolved, the customer may end the affected service and receive a refund of any prepaid fees for the unused period.
NoteFish's responsibility. NoteFish binds each sub-processor to data protection obligations at least as protective as this DPA, and remains responsible to the customer for them.
7. Helping the customer
NoteFish helps the customer, as far as it reasonably can:
- To answer requests from data subjects. For example, it finds, exports or deletes calls. NoteFish forwards any request it receives directly.
- With security, impact assessments (DPIAs) and prior consultation with authorities, under Articles 32 to 36 GDPR, using the information NoteFish has.
8. Personal data breaches
Notifying the customer. NoteFish notifies the customer without undue delay, and within 48 hours of becoming aware of a breach affecting the customer's data.
What the notification includes. The information the customer needs to meet its own obligations, as far as NoteFish knows it at the time:
- what happened;
- the data and people affected;
- the likely consequences;
- the measures taken.
9. End of processing
When the service ends, NoteFish deletes the customer's personal data within 30 days, unless the law requires it to keep something.
The customer can export its calls before then.
Ended calls are also deleted during the service, automatically, after the retention period the customer sets. The default is 90 days.
10. Demonstrating compliance and audits
NoteFish makes available the information needed to show it meets this DPA.
On-site audits.
- Who. The customer, or an independent auditor bound to confidentiality.
- Notice. At least 30 days' written notice.
- How often. Once a year, or after a breach.
- Scope. During business hours, with minimal disruption.
- Cost. At the customer's cost, unless the audit shows a material breach by NoteFish.
11. International transfers
NoteFish is established in the Republic of Moldova, which does not have an EU adequacy decision.
EU and EEA customers. Where the customer is in the European Economic Area, or its transfer to NoteFish is otherwise subject to the GDPR, the transfer is covered by the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914:
- Module Two. Controller to processor.
- Module Three. Processor to processor, where the customer is itself a processor.
These clauses are incorporated into this DPA by reference, with the following choices:
- Clause 7 (docking clause): does not apply.
- Clause 9(a): Option 2, general written authorisation, with 14 days' notice as in section 6.
- Clause 11(a): the optional wording does not apply.
- Clause 13: the supervisory authority is the one competent for the customer.
- Clause 17: Option 2. The law of the EU Member State where the customer is established. If that law does not allow third-party beneficiary rights, the law of Ireland.
- Clause 18: the courts of that same Member State.
- Annexes. Annexes I to III of the clauses are Annexes I to III of this DPA.
UK and Switzerland. For transfers from the United Kingdom, the UK International Data Transfer Addendum to these clauses applies. For transfers from Switzerland, the clauses apply as adapted for the Swiss Federal Act on Data Protection, with the Swiss FDPIC as the competent authority for those transfers.
Onward transfers. Where NoteFish's sub-processors process data outside the EU and Moldova, NoteFish relies on an adequacy decision, such as the EU-US Data Privacy Framework for certified providers, or on the Standard Contractual Clauses.
12. Order of precedence and liability
If this DPA conflicts with the Terms, this DPA prevails. If the Standard Contractual Clauses conflict with either, the Clauses prevail.
Liability under this DPA is subject to the limits in the Terms, except where the Clauses or the law do not allow such limits.
Annex I: Description of the processing
Parties.
- The data exporter and controller is the customer. Its details are in its NoteFish account.
- The data importer and processor is NoteFish, as above. Contact: hello@notefish.ai.
Categories of data subjects.
- People who call, or are called by, the customer using NoteFish ("callers").
- The customer's staff who use NoteFish ("users").
Categories of personal data.
- What is said on calls. Live audio, processed and not stored.
- Written call records. Transcripts, translations and summaries.
- About the call. Call times, duration, language and the app the call came from.
- Callers. Callers' names or numbers where the customer records them.
- Users. Names, email addresses and roles.
- Voice. Users' voice recordings and the voice clones made from them.
Special categories. NoteFish does not ask for special categories of data. Callers may nonetheless mention them on a call, for example about their health. The customer decides whether to use NoteFish for such calls.
Voice clones are made only with the consent of the person whose voice it is. They are not used to identify anyone.
Frequency. Continuous, for as long as the customer uses NoteFish.
Nature and purpose of the processing. To make calls between people who speak different languages possible. That covers:
- speech recognition;
- machine translation;
- speaking translated replies in the user's cloned voice;
- captions;
- storing transcripts and summaries for the customer;
- deleting them.
Retention.
- Ended calls. Deleted automatically after the period the customer sets: 30 days to 2 years, with a default of 90 days.
- Voice clones. Deleted when the user or customer deletes them.
- Everything else. Deleted within 30 days after the end of the service.
Sub-processors. See Annex III.
Annex II: Technical and organisational measures
- Encryption in transit. All traffic to and from NoteFish, and between NoteFish and its providers, uses TLS. The database connection is verified against its certificate authority.
- Hosting. Servers in Frankfurt, Germany; database in the European Union. The providers' own locations and safeguards are listed in Annex III.
- Minimisation. Call audio is processed live and never stored. Voice recordings are sent to the voice provider and not kept by NoteFish. Retention is automatic and set by the customer.
- No secondary use by NoteFish. NoteFish does not use customer data to train AI models, sell it or use it for advertising. How each provider may use data is stated in Annex III.
- Access control. Accounts with roles (admin, lead, member), passwords stored as salted hashes, and signed session cookies. Each hosted desk is separate. Staff access to customer data is limited to what support or security requires.
- Separation of voices. A user's voice clone can be used only by that user. Deleting a voice also deletes it at the voice providers.
- Logging and monitoring. Errors and access are logged for security and kept for up to 30 days.
- Resilience. Managed hosting and database providers with backups.
- Incident response. A written breach procedure, with customer notification within 48 hours (section 8).
- Providers. Sub-processors are listed with their role, location, transfer safeguard and use of data in Annex III.
Annex III: Sub-processors
The current list, with each provider's role, location and transfer safeguard, is published at notefish.ai/subprocessors. It is part of this DPA.