Reviewed and fact-checked: 21 July 2026.
When an AI transcription supplier processes personal data for an organisation, the data processing agreement should describe the real service—not an imaginary, simplified version of it. The contract needs to cover original audio, transcripts, summaries, metadata, support access, subprocessors, international transfers, backups, deletion and any use of customer content to train or improve AI systems.
Quick verdict: A generic privacy policy or consumer subscription page is not a substitute for a suitable processor contract. Match the agreement to the actual device-to-app-to-AI-to-export data flow and check that operational controls support the written terms.
This article provides general information, not legal advice. Organisations should obtain appropriate advice and review current UK GDPR, sector and international-transfer requirements.
First establish the parties’ roles
An organisation choosing why and how employee, customer or client conversations are recorded will often be the controller. A transcription supplier processing those recordings only on the organisation’s documented instructions will commonly act as a processor. Roles depend on the facts, not the labels in the contract.
If a supplier decides its own purposes and essential means—for example, independently reusing customer audio to train a general model—it may have separate controller responsibilities for that activity. The agreement should state clearly which party decides each purpose.
The ICO’s current guidance on controller–processor contracts explains the UK GDPR framework.
Core contract details
| Contract item | What to confirm |
|---|---|
| Subject matter and duration | Which recording and transcription services are covered and how long processing continues |
| Nature and purpose | Capture, transfer, transcription, summarisation, translation, support, storage and deletion purposes |
| Data and people | Audio, text, account data and metadata; employees, customers, clients, patients, students or others |
| Documented instructions | The supplier processes only as instructed and identifies any legally required exception |
| Confidentiality | Authorised staff and contractors are bound by suitable confidentiality obligations |
| Security | Technical and organisational measures, authentication, encryption, logging, resilience and testing |
| Subprocessors | Authorisation, current list, change notices, objection route and equivalent contractual duties |
| International transfers | Locations, restricted-transfer responsibility, safeguards and supporting assessments |
| Rights requests | Search, access, correction, restriction, objection and deletion assistance |
| Compliance assistance | Support for security, breach assessment, DPIAs and regulator enquiries |
| Return and deletion | What happens to live data, device or app copies, exports, logs and backups during and after termination |
| Audit and evidence | Information, assurance reports, testing evidence and proportionate audit rights |
Match the agreement to the real AI data flow
Do not review the contract in isolation. Create a processing map covering:
- Audio captured on the recorder or phone.
- Temporary storage on the hardware and mobile device.
- Transfer to the supplier’s app or infrastructure.
- Speech-to-text processing.
- AI summaries, templates, translations, mind maps or other outputs.
- Human support or engineering access.
- User edits, exports and shares.
- Operational logs, analytics and backups.
- Deletion, account closure and supplier exit.
The wording should apply to every relevant copy. A clause referring only to “uploaded documents” may not clearly cover audio, generated text, speaker labels, timestamps, device identifiers or support logs.
AI training and product improvement
Ask whether customer audio, transcripts, prompts, corrections or summaries are used to train, fine-tune, evaluate or improve models. Check:
- Whether that use is necessary to provide the contracted service
- Whether it is enabled by default
- Whether an administrator can disable it
- Whether the supplier acts as processor or separate controller
- What de-identification is applied and whether re-identification remains possible
- Whether subcontracted model providers receive the content
- What happens to previously contributed data after opt-out or termination
Do not treat “anonymised” as automatically safe without evidence about the method and residual re-identification risk.
Subprocessors and international transfers
The supplier should identify subprocessors and the services and locations they provide. The organisation needs a workable notice and objection process for material changes—not a list that can change silently after approval.
International-transfer obligations depend on which party initiates the restricted transfer and the processing chain. The ICO updated its international-transfer guidance in 2026. Contract review should be supported by the required transfer mechanism and risk assessment where applicable.
Security schedule: require usable detail
A clause promising “industry-standard security” is difficult to test. The security schedule should provide enough information to assess:
- Encryption in transit and at rest
- Account authentication and administrator controls
- Role-based access and least privilege
- Support-access approval and logging
- Secure software and firmware updates
- Vulnerability management and independent testing
- Backup, resilience and recovery
- Tenant separation
- Employee confidentiality and training
- Retention and secure deletion
- Incident detection, investigation and notification
Breach notification
The contract should require the processor to notify the controller without undue delay after becoming aware of a personal data breach and to provide the information needed for assessment and response. A vague promise to notify only after the supplier decides a breach is “serious” can delay the controller’s own obligations.
The ICO’s personal data breach guidance explains the controller and processor responsibilities.
Return, deletion and backups
| Question | Why it matters |
|---|---|
| Can administrators delete individual recordings? | Supports retention and rights-request workflows |
| Does deletion cover audio and generated outputs? | Text copies can survive after audio is removed |
| How are backups handled? | Immediate physical deletion may be impossible, but access and expiry should be controlled |
| What happens at termination? | The organisation needs export, return, transition and final deletion |
| Is deletion evidenced? | A documented confirmation supports accountability |
Common contract red flags
| Unlimited product-improvement rights | Customer recordings may be reused for an undefined independent purpose |
| Silent subprocessor changes | The approved processing chain can change without review |
| No processing locations | Transfer responsibilities cannot be assessed |
| Deletion only at account closure | Purpose-based retention cannot be implemented |
| Security entirely at supplier discretion | Material reductions may occur without notice |
| Breach notice only after confirmed harm | The controller may receive information too late |
| No exit assistance | Data and workflows can become locked into the service |
NERALVO Halo and DOWAY
NERALVO Halo is an ultra-slim AI voice recorder with 64GB local storage, up to 35 hours of recording, NOTE mode, supported CALL mode, Bluetooth synchronisation with the DOWAY app, and AI transcription, summaries, templates, translation, mind maps and exports. One year of DOWAY Max access is included.
Organisations considering Halo should review the applicable DOWAY terms, privacy information, subprocessors, processing locations, security controls, retention and deletion options, and assess whether the complete workflow meets their intended use. Halo is a general productivity tool and is not automatically approved for confidential, regulated or highly sensitive processing.
Turn the contract into operational controls
- Configure accounts and permissions to match the agreement.
- Disable optional processing that is not approved.
- Document approved and prohibited recording uses.
- Train users to verify AI output and avoid uncontrolled exports.
- Apply the retention schedule in device, app and official systems.
- Maintain the current subprocessor and transfer record.
- Test rights-request, deletion and breach workflows.
- Monitor material changes to features, terms and processing.
Frequently asked questions
Does every consumer user need a bespoke data processing agreement?
No. The requirement depends on the parties’ roles and the context. An organisation using the service as part of its own processing should determine whether the standard terms provide the required processor provisions and professional safeguards.
Can a contract replace technical due diligence?
No. Contractual promises, product configuration, security evidence and operational testing must support one another.
What if the supplier changes its terms or AI features?
Use a monitoring process and reassess material changes to purpose, subprocessors, locations, model use, retention, security or deletion.
Final review checklist
- Controller, processor and any independent-controller roles are accurate.
- The agreement covers audio, text, metadata, AI outputs, support and backups.
- All required processor clauses are present.
- Subprocessor and transfer arrangements are understood.
- Model-training and product-improvement use is explicit.
- Security and breach terms are operationally usable.
- Rights requests, retention, return, deletion and exit are workable.
- Internal configuration and training match the contract.
A strong agreement connects legal wording to the real recording and transcription lifecycle.
Ready to capture meetings properly?
View the NERALVO Halo AI voice recorder with 64GB local storage, meeting capture, compatible phone-call recording workflows and one year of DOWAY Max included.
View NERALVO Halo