NoteFish

Last updated 30 September 2026

Data Processing Agreement

This Data Processing Agreement ("DPA") applies whenever NoteFish processes personal data on behalf of a business customer. It meets Article 28 of the EU General Data Protection Regulation (GDPR) and the equivalent rules of Moldova's Law no. 195/2024 on personal data protection.

It forms part of the Terms of Service and needs no separate signature: it takes effect when a business accepts the Terms. If you need a countersigned copy for your records, write to hello@notefish.ai.

1. Parties and roles

The customer is the business that uses NoteFish. It is the controller.

NoteFish is Întreprinzător Individual „LEONARDO CALANCEA”, IDNO 1026023047638, bd. Ștefan cel Mare și Sfânt 141/2, ap. 45, MD-2004 Chișinău, Republic of Moldova. It is the processor.

Where the customer is itself a processor for someone else, NoteFish is its sub-processor, and the customer passes on the obligations below accordingly.

2. What is processed

The details are in Annex I:

3. Instructions

NoteFish processes personal data only on the customer's documented instructions. These are the Terms, this DPA, and the settings the customer chooses in NoteFish, for example how long calls are kept.

There is one exception: where EU or Member State law, or Moldovan law, requires processing. In that case NoteFish tells the customer first, unless the law forbids it.

NoteFish tells the customer if it believes an instruction breaks data protection law.

4. Confidentiality

Anyone NoteFish allows to process the data is bound to confidentiality.

5. Security

NoteFish takes the technical and organisational measures in Annex II, and keeps them up to date with the state of the art and the risks.

6. Sub-processors

General authorisation. The customer authorises NoteFish to use the sub-processors listed at notefish.ai/subprocessors.

Adding or replacing a sub-processor.

NoteFish's responsibility. NoteFish binds each sub-processor to data protection obligations at least as protective as this DPA, and remains responsible to the customer for them.

7. Helping the customer

NoteFish helps the customer, as far as it reasonably can:

8. Personal data breaches

Notifying the customer. NoteFish notifies the customer without undue delay, and within 48 hours of becoming aware of a breach affecting the customer's data.

What the notification includes. The information the customer needs to meet its own obligations, as far as NoteFish knows it at the time:

9. End of processing

When the service ends, NoteFish deletes the customer's personal data within 30 days, unless the law requires it to keep something.

The customer can export its calls before then.

Ended calls are also deleted during the service, automatically, after the retention period the customer sets. The default is 90 days.

10. Demonstrating compliance and audits

NoteFish makes available the information needed to show it meets this DPA.

On-site audits.

11. International transfers

NoteFish is established in the Republic of Moldova, which does not have an EU adequacy decision.

EU and EEA customers. Where the customer is in the European Economic Area, or its transfer to NoteFish is otherwise subject to the GDPR, the transfer is covered by the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914:

These clauses are incorporated into this DPA by reference, with the following choices:

UK and Switzerland. For transfers from the United Kingdom, the UK International Data Transfer Addendum to these clauses applies. For transfers from Switzerland, the clauses apply as adapted for the Swiss Federal Act on Data Protection, with the Swiss FDPIC as the competent authority for those transfers.

Onward transfers. Where NoteFish's sub-processors process data outside the EU and Moldova, NoteFish relies on an adequacy decision, such as the EU-US Data Privacy Framework for certified providers, or on the Standard Contractual Clauses.

12. Order of precedence and liability

If this DPA conflicts with the Terms, this DPA prevails. If the Standard Contractual Clauses conflict with either, the Clauses prevail.

Liability under this DPA is subject to the limits in the Terms, except where the Clauses or the law do not allow such limits.

Annex I: Description of the processing

Parties.

Categories of data subjects.

Categories of personal data.

Special categories. NoteFish does not ask for special categories of data. Callers may nonetheless mention them on a call, for example about their health. The customer decides whether to use NoteFish for such calls.

Voice clones are made only with the consent of the person whose voice it is. They are not used to identify anyone.

Frequency. Continuous, for as long as the customer uses NoteFish.

Nature and purpose of the processing. To make calls between people who speak different languages possible. That covers:

Retention.

Sub-processors. See Annex III.

Annex II: Technical and organisational measures

Annex III: Sub-processors

The current list, with each provider's role, location and transfer safeguard, is published at notefish.ai/subprocessors. It is part of this DPA.