FREE today: upgraded Halo Productivity Pack worth £29 included with every Halo order
Up to 35 hours recording - 152 languages - 64GB storage
NERALVO
NERALVO
AI recorder guide

Data Processing Agreements for AI Transcription: What to Review

Reviewed and fact-checked: 21 July 2026.

When an AI transcription supplier processes personal data for an organisation, the data processing agreement should describe the real service—not an imaginary, simplified version of it. The contract needs to cover original audio, transcripts, summaries, metadata, support access, subprocessors, international transfers, backups, deletion and any use of customer content to train or improve AI systems.

Quick verdict: A generic privacy policy or consumer subscription page is not a substitute for a suitable processor contract. Match the agreement to the actual device-to-app-to-AI-to-export data flow and check that operational controls support the written terms.

This article provides general information, not legal advice. Organisations should obtain appropriate advice and review current UK GDPR, sector and international-transfer requirements.

First establish the parties’ roles

An organisation choosing why and how employee, customer or client conversations are recorded will often be the controller. A transcription supplier processing those recordings only on the organisation’s documented instructions will commonly act as a processor. Roles depend on the facts, not the labels in the contract.

If a supplier decides its own purposes and essential means—for example, independently reusing customer audio to train a general model—it may have separate controller responsibilities for that activity. The agreement should state clearly which party decides each purpose.

The ICO’s current guidance on controller–processor contracts explains the UK GDPR framework.

Core contract details

Contract item What to confirm
Subject matter and duration Which recording and transcription services are covered and how long processing continues
Nature and purpose Capture, transfer, transcription, summarisation, translation, support, storage and deletion purposes
Data and people Audio, text, account data and metadata; employees, customers, clients, patients, students or others
Documented instructions The supplier processes only as instructed and identifies any legally required exception
Confidentiality Authorised staff and contractors are bound by suitable confidentiality obligations
Security Technical and organisational measures, authentication, encryption, logging, resilience and testing
Subprocessors Authorisation, current list, change notices, objection route and equivalent contractual duties
International transfers Locations, restricted-transfer responsibility, safeguards and supporting assessments
Rights requests Search, access, correction, restriction, objection and deletion assistance
Compliance assistance Support for security, breach assessment, DPIAs and regulator enquiries
Return and deletion What happens to live data, device or app copies, exports, logs and backups during and after termination
Audit and evidence Information, assurance reports, testing evidence and proportionate audit rights

Match the agreement to the real AI data flow

Do not review the contract in isolation. Create a processing map covering:

  1. Audio captured on the recorder or phone.
  2. Temporary storage on the hardware and mobile device.
  3. Transfer to the supplier’s app or infrastructure.
  4. Speech-to-text processing.
  5. AI summaries, templates, translations, mind maps or other outputs.
  6. Human support or engineering access.
  7. User edits, exports and shares.
  8. Operational logs, analytics and backups.
  9. Deletion, account closure and supplier exit.

The wording should apply to every relevant copy. A clause referring only to “uploaded documents” may not clearly cover audio, generated text, speaker labels, timestamps, device identifiers or support logs.

AI training and product improvement

Ask whether customer audio, transcripts, prompts, corrections or summaries are used to train, fine-tune, evaluate or improve models. Check:

  • Whether that use is necessary to provide the contracted service
  • Whether it is enabled by default
  • Whether an administrator can disable it
  • Whether the supplier acts as processor or separate controller
  • What de-identification is applied and whether re-identification remains possible
  • Whether subcontracted model providers receive the content
  • What happens to previously contributed data after opt-out or termination

Do not treat “anonymised” as automatically safe without evidence about the method and residual re-identification risk.

Subprocessors and international transfers

The supplier should identify subprocessors and the services and locations they provide. The organisation needs a workable notice and objection process for material changes—not a list that can change silently after approval.

International-transfer obligations depend on which party initiates the restricted transfer and the processing chain. The ICO updated its international-transfer guidance in 2026. Contract review should be supported by the required transfer mechanism and risk assessment where applicable.

Security schedule: require usable detail

A clause promising “industry-standard security” is difficult to test. The security schedule should provide enough information to assess:

  • Encryption in transit and at rest
  • Account authentication and administrator controls
  • Role-based access and least privilege
  • Support-access approval and logging
  • Secure software and firmware updates
  • Vulnerability management and independent testing
  • Backup, resilience and recovery
  • Tenant separation
  • Employee confidentiality and training
  • Retention and secure deletion
  • Incident detection, investigation and notification

Breach notification

The contract should require the processor to notify the controller without undue delay after becoming aware of a personal data breach and to provide the information needed for assessment and response. A vague promise to notify only after the supplier decides a breach is “serious” can delay the controller’s own obligations.

The ICO’s personal data breach guidance explains the controller and processor responsibilities.

Return, deletion and backups

Question Why it matters
Can administrators delete individual recordings? Supports retention and rights-request workflows
Does deletion cover audio and generated outputs? Text copies can survive after audio is removed
How are backups handled? Immediate physical deletion may be impossible, but access and expiry should be controlled
What happens at termination? The organisation needs export, return, transition and final deletion
Is deletion evidenced? A documented confirmation supports accountability

Common contract red flags

Unlimited product-improvement rights Customer recordings may be reused for an undefined independent purpose
Silent subprocessor changes The approved processing chain can change without review
No processing locations Transfer responsibilities cannot be assessed
Deletion only at account closure Purpose-based retention cannot be implemented
Security entirely at supplier discretion Material reductions may occur without notice
Breach notice only after confirmed harm The controller may receive information too late
No exit assistance Data and workflows can become locked into the service

NERALVO Halo and DOWAY

NERALVO Halo is an ultra-slim AI voice recorder with 64GB local storage, up to 35 hours of recording, NOTE mode, supported CALL mode, Bluetooth synchronisation with the DOWAY app, and AI transcription, summaries, templates, translation, mind maps and exports. One year of DOWAY Max access is included.

Organisations considering Halo should review the applicable DOWAY terms, privacy information, subprocessors, processing locations, security controls, retention and deletion options, and assess whether the complete workflow meets their intended use. Halo is a general productivity tool and is not automatically approved for confidential, regulated or highly sensitive processing.

Turn the contract into operational controls

  • Configure accounts and permissions to match the agreement.
  • Disable optional processing that is not approved.
  • Document approved and prohibited recording uses.
  • Train users to verify AI output and avoid uncontrolled exports.
  • Apply the retention schedule in device, app and official systems.
  • Maintain the current subprocessor and transfer record.
  • Test rights-request, deletion and breach workflows.
  • Monitor material changes to features, terms and processing.

Frequently asked questions

Does every consumer user need a bespoke data processing agreement?

No. The requirement depends on the parties’ roles and the context. An organisation using the service as part of its own processing should determine whether the standard terms provide the required processor provisions and professional safeguards.

Can a contract replace technical due diligence?

No. Contractual promises, product configuration, security evidence and operational testing must support one another.

What if the supplier changes its terms or AI features?

Use a monitoring process and reassess material changes to purpose, subprocessors, locations, model use, retention, security or deletion.

Final review checklist

  • Controller, processor and any independent-controller roles are accurate.
  • The agreement covers audio, text, metadata, AI outputs, support and backups.
  • All required processor clauses are present.
  • Subprocessor and transfer arrangements are understood.
  • Model-training and product-improvement use is explicit.
  • Security and breach terms are operationally usable.
  • Rights requests, retention, return, deletion and exit are workable.
  • Internal configuration and training match the contract.

A strong agreement connects legal wording to the real recording and transcription lifecycle.

Ready to capture meetings properly?

View the NERALVO Halo AI voice recorder with 64GB local storage, meeting capture, compatible phone-call recording workflows and one year of DOWAY Max included.

View NERALVO Halo

Continue reading

Newer guide How to Create Training Materials from Recorded Sessions Older guide Voice Recording Retention Policy: A Practical Template Guide
Browse all AI Recorder Guides articles

Official sources and further reading

Product specifications, policies and legal guidance can change. Check the current official source before making a purchasing, workplace, privacy or compliance decision.