SiteMinutes · Legal
Data Processing Addendum
Version 1.0Effective 25 September 2026Draft
Contents
- 1. Roles and definitions
- 2. Details of the processing (Annex I)
- 3. SiteMinutes' obligations
- 4. The Customer's obligations
- 5. Sub-processors
- 6. Security measures (Annex II)
- 7. Personal Information Breach
- 8. Deletion and return
- 9. Audits
- 10. International transfers
- 11. US state privacy laws
- 12. Liability and precedence
Draft — to be reviewed by a qualified legal practitioner before publication.
Version 1.0 · Effective 25 September 2026
This Data Processing Addendum (DPA) forms part of the Terms of Service between the Customer and Water en Skaafsels, trading as SiteMinutes, a business registered in Namibia under [Namibian registration number] ("SiteMinutes"). It applies automatically when the Customer accepts the Terms. A Customer that needs a signed copy can ask at help@siteminutes.com. It is intended to meet Article 28 of the GDPR and UK GDPR, sections 20 and 21 of POPIA, the service-provider requirements of US state privacy laws, and comparable requirements of other data protection laws.
1. Roles and definitions
- The Customer is the controller (GDPR), responsible party (POPIA) or business (CCPA) for personal information contained in Customer Content.
- SiteMinutes is the processor (GDPR), operator (POPIA) or service provider (CCPA) of that information.
- Customer Content has the meaning in the Terms: recordings, transcripts, minutes, attendance lists, project records, plans, documents and messages that the Customer or its users put into the Service, and AI output generated from them.
- Data Protection Law means every law on personal information that applies to the processing, including POPIA (South Africa), the GDPR and UK GDPR, the Swiss Federal Act on Data Protection, US state privacy laws (such as the CCPA/CPRA), PIPEDA (Canada), the Australian Privacy Act, the Kenyan Data Protection Act 2019, the Nigeria Data Protection Act 2023, and any Namibian data protection law once in force.
- Sub-processor means a third party SiteMinutes engages to process Customer personal information.
- Personal Information Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer personal information (a "security compromise" under section 22 of POPIA).
2. Details of the processing (Annex I)
| Subject matter | Providing the SiteMinutes Service: recording support, transcription, AI drafting and editing of minutes, storage and sync of project records |
| Duration | For the term of the Terms, plus the deletion periods in the Data Retention & Deletion Policy |
| Nature and purpose | Collection (upload), storage, transcription, analysis by AI to draft minutes, retrieval, display, export and deletion — solely to provide the Service to the Customer |
| Data subjects | The Customer's users; meeting participants and project contacts (who may not be users) |
| Categories of personal information | Names, companies, roles, e-mail addresses, attendance status; voice recordings (temporary copy); statements made in meetings as transcribed and minuted; any personal information in uploaded plans and documents |
| Special categories / sensitive information | Not intended. The Customer must not deliberately record or upload special-category or sensitive personal information, or information about children, without a lawful basis. No biometric identifiers (voiceprints) are created |
| Frequency | Continuous, whenever the Customer uses the Service |
3. SiteMinutes' obligations
SiteMinutes will:
- process Customer personal information only on the Customer's documented instructions, which are these Terms and the Customer's use of the Service's features, including for transfers to third countries, unless the law requires otherwise (in which case SiteMinutes will tell the Customer first, unless the law forbids it);
- promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Law;
- not use Customer Content to train AI models, not sell or share it (as those terms are defined in US state privacy laws), not retain, use or disclose it for any purpose other than providing, securing and supporting the Service and complying with the law, not use it outside the direct business relationship with the Customer, and not combine it with personal information from other sources except as the law permits for a service provider;
- ensure that everyone authorised to process it is bound by confidentiality;
- implement the security measures in section 6 (GDPR Art. 32);
- assist the Customer, taking into account the nature of the processing and the information available to SiteMinutes, in responding to data subject requests, and in meeting its obligations on security, breach notification, data protection impact assessments and prior consultation with regulators (GDPR Arts. 32–36);
- notify the Customer of a Personal Information Breach as described in section 7;
- at the Customer's choice, delete or return Customer personal information at the end of the Service as described in section 8;
- make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as described in section 9; and
- comply with Data Protection Law applicable to it as a processor, and notify the Customer if it can no longer meet its obligations.
4. The Customer's obligations
The Customer:
- is responsible for having a lawful basis for all personal information it puts into the Service, and for giving data subjects the information the law requires, including the notice to and, where required, consent of meeting participants before recording (see the AI & Recording Policy);
- is responsible for the accuracy of the information and for responding to data subjects (with SiteMinutes' help);
- will not instruct SiteMinutes to process personal information in breach of Data Protection Law; and
- is responsible for reviewing AI-drafted transcripts and minutes before finishing, relying on or distributing them (Terms section 2).
5. Sub-processors
The Customer gives general written authorisation for SiteMinutes to use the following sub-processors:
| Sub-processor | Service | Location of processing | Personal information |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage, server functions | Frankfurt, Germany (AWS eu-central-1) | All stored Customer Content |
| Vercel, Inc. | Web app hosting | Frankfurt (fra1) functions; worldwide edge network | Customer Content in transit to web browsers |
| OpenAI, L.L.C. | Speech-to-text (whisper-1) | United States | Temporary audio copy; attendee names and terms as a transcription hint |
| Anthropic, PBC | Drafting and editing minutes (Claude) | United States | Transcript, attendance, actions, agenda and project details of the meeting being minuted; review-chat messages |
| PayGate (Pty) Ltd / DPO Group | Card payments | South Africa | Billing owner's e-mail and payment data (account information, not Customer Content) |
SiteMinutes will impose on each sub-processor, by written contract, the same data protection obligations as in this DPA (in particular sufficient guarantees of appropriate security measures), and remains fully liable to the Customer for its sub-processors' performance. SiteMinutes will announce any intended addition or replacement of a sub-processor at least 30 days in advance (by updating this page and e-mailing account owners who have asked for notices). The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected Service and receive a pro-rata refund of any prepaid, unused period.
6. Security measures (Annex II)
SiteMinutes maintains technical and organisational measures organised along ISO/IEC 27001 and SOC 2 lines, described in the Security Overview, including at least:
- encryption of data in transit (TLS) and at rest (provider-managed AES-256 encryption);
- row level security in the database so that each company's data is visible only to its own active members;
- secrets (AI and payment keys) stored encrypted in Supabase Vault and readable only by server functions;
- least-privilege access: no client can hard-delete project data, administrative functions check the administrator's identity on every call, and administrative provider accounts use multi-factor authentication;
- temporary audio copies deleted after the minutes are written, and in any case within 7 days;
- no logging of transcripts, minutes, API keys or payment secrets by SiteMinutes' own functions;
- tested database changes, daily backups by Supabase, and local-first apps for resilience;
- supplier review; and
- a documented incident response process.
7. Personal Information Breach
SiteMinutes will notify the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a Personal Information Breach affecting Customer personal information. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. SiteMinutes will provide further information as it becomes available and will take reasonable steps to contain and remedy the breach. This allows the Customer to meet its own obligations (for example to notify the Information Regulator under section 22 of POPIA, or a supervisory authority within 72 hours under the GDPR). Notification is not an admission of fault.
8. Deletion and return
- During the term, the Customer can export its content at any time (minutes as PDF, meeting packs, project records), and may ask for a complete machine-readable export.
- After termination, the Customer has 30 days to export (return). SiteMinutes then deletes Customer personal information from its live systems within a further 30 days, and it is removed from backups as they expire (within 7 days after that), unless the law requires SiteMinutes to keep it, in which case it remains protected by this DPA.
- Workspaces that stop paying are handled as set out in the Data Retention & Deletion Policy (kept for at least 12 months, with 30 days' notice before deletion).
- On request, SiteMinutes will confirm the deletion in writing.
9. Audits
SiteMinutes will answer the Customer's reasonable written security questionnaires once a year, and provide the relevant sub-processors' certifications or reports where available (for example Supabase's SOC 2 report under a non-disclosure agreement). If that is not enough to demonstrate compliance, or a regulator requires it, the Customer may carry out an audit at its own cost, on 30 days' notice, during business hours, no more than once a year (or after a Personal Information Breach), by an auditor bound by confidentiality.
10. International transfers
Customer personal information is processed in the European Union and, for AI processing, in the United States. Where Data Protection Law requires a transfer mechanism, the parties rely on:
- EU: the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (Module 2 controller-to-processor, or Module 3 processor-to-processor where the Customer is itself a processor), incorporated by reference, with Clause 7 (docking) not used, Clause 9 option 2 (general authorisation, 30 days' notice), Clause 11 optional language not used, Clauses 17 and 18 governed by the law and courts of Ireland, and Annexes I and II as set out in sections 2 and 6 of this DPA;
- UK: the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner;
- Switzerland: the SCCs as adapted for the Swiss FADP, with the Federal Data Protection and Information Commissioner as the competent authority;
- South Africa: section 72(1)(a) of POPIA (binding agreements providing adequate protection) and 72(1)(b) (necessary for the performance of the contract);
- other countries (for example Kenya and Nigeria): the transfer mechanisms their laws recognise, using equivalent contractual safeguards.
SiteMinutes' sub-processors are bound by equivalent transfer terms. If a transfer mechanism is invalidated, the parties will cooperate to put an alternative in place.
11. US state privacy laws
For the purposes of the CCPA/CPRA and similar US state laws, SiteMinutes is a service provider (or processor). SiteMinutes certifies that it understands and will comply with the restrictions in section 3, item 3, will provide the same level of privacy protection as those laws require, will notify the Customer if it can no longer meet its obligations, and allows the Customer to take reasonable steps to stop and remedy unauthorised use.
12. Liability and precedence
The limitations of liability in the Terms apply to this DPA, except where Data Protection Law does not allow them. If this DPA conflicts with the Terms on the processing of personal information, this DPA prevails; if the Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses prevail.