Data Processing Agreement
Effective date: 2026-04-19 Last updated: 2026-04-19
This Data Processing Agreement ("DPA") forms part of the Terms of Service between M37 Tech Pty Ltd (ABN 88 696 420 363) ("Processor" or "dicted") and the subscribing customer ("Controller" or "Customer"). It applies where the Customer uploads personal data to dicted in their capacity as a data controller — for example, a business customer uploading meeting recordings that contain their employees' or clients' voices.
For self-serve consumers processing only their own data, this DPA is not separately required (Terms of Service + Privacy Policy govern that relationship).
This DPA is drafted around the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), with parallel coverage for New Zealand's Privacy Act 2020, Canadian PIPEDA + provincial privacy laws, and applicable US state privacy laws. dicted is not offered in the EEA or UK, so EU GDPR / UK GDPR do not apply; the APP framework and its cousins sit in their place.
1. Definitions
Terms used in this DPA carry the meanings given in the Australian Privacy Act 1988 and the APPs. Where the Customer is located in another supported region, equivalent local-law terms apply (NZ Privacy Act 2020; PIPEDA / Québec Law 25 in Canada; CCPA/CPRA and other state laws in the US). Key terms:
- Personal Information / Personal Data — information or an opinion about an identified individual, or an individual who is reasonably identifiable, that the Customer processes using the Service (APP definition; "personal data" is the equivalent term used in other regimes).
- Processing — any operation performed on Personal Information, including collection, storage, use, disclosure, and destruction.
- Data Subject / Individual — the natural person to whom Personal Information relates.
- Subprocessor — a third party engaged by dicted to process Personal Information in delivering the Service.
2. Subject-matter and duration
dicted processes Personal Data on behalf of the Customer for the duration of the subscription, solely to provide the Service as described in the Terms of Service. The categories of data and data subjects are:
| Category | Detail |
|---|---|
| Data subjects | Customer's users of dicted; attendees in uploaded meeting recordings; any person whose voice or name appears in content processed by the Service |
| Personal data types | Audio recordings; transcriptions; speaker labels; meeting metadata (titles, dates, attendee lists); account and authentication data |
| Special categories | None intentionally. Voice is not processed as biometric data — dicted does not generate voiceprints or identify individuals from voice (see Privacy Policy §2.1) |
| Nature of processing | Speech-to-text transcription, speaker diarisation, AI-generated summary, action-item extraction, storage, and retrieval |
| Purpose | Delivery of the Service to the Controller |
| Duration | Term of the Customer's subscription, plus any retention period the Customer chooses, plus the standard post-deletion wind-down period described in §10 |
3. Processor obligations
dicted will:
- Process Personal Data only on documented instructions from the Controller — the Terms of Service, this DPA, and any explicit settings the Controller chooses in the dashboard constitute those instructions. Any instruction outside that set requires a separate written agreement.
- Ensure persons authorised to process Personal Data are bound by confidentiality (contractual for employees, equivalent for contractors).
- Implement technical and organisational security measures appropriate to the risk, including those described in §6 below.
- Engage Subprocessors only with the Controller's authorisation — the Controller's entry into this DPA constitutes general authorisation for the current Subprocessor list at
dicted.ai/subprocessors. We will notify the Controller of any intended addition or replacement at least 30 days in advance; the Controller may object, in which case either party may terminate the affected subscription with pro-rata refund. - Assist the Controller in responding to Data Subject rights requests (access, rectification, erasure, restriction, portability, objection) by providing the Controller with self-service tools and, where the tools are insufficient, by acting on the Controller's written request.
- Assist the Controller with its security, Notifiable Data Breach (APP Part IIIC), Privacy Impact Assessment, and regulator-consultation obligations, taking into account the nature of processing and the information available to us.
- At the Controller's choice, delete or return all Personal Data at the end of the provision of services, and delete existing copies unless legal obligation requires continued retention.
- Make available to the Controller all information necessary to demonstrate compliance with Art. 28, and allow for and contribute to audits — see §8.
4. Controller obligations
The Controller:
- Warrants that its instructions to dicted are lawful and comply with applicable data-protection law.
- Is solely responsible for the lawful basis of the Controller's own processing — including obtaining any consents required to record and upload meeting content that contains third parties' voices (see Terms §6.4).
- Warrants that Personal Data provided to dicted is accurate, up to date, and relevant to the purposes of the Service.
- Will inform dicted without undue delay of any request received from a Data Subject that relates to Personal Data processed under this DPA and which requires dicted's assistance to answer.
5. Subprocessors
The current list of Subprocessors and the transfer mechanism for each is published at dicted.ai/subprocessors and described in the Privacy Policy §6.
dicted:
- Imposes contractual obligations on each Subprocessor that are substantially equivalent to those in this DPA (Art. 28(4)).
- Remains liable to the Controller for the Subprocessors' performance of those obligations.
- Selects Subprocessors from established, well-known providers with published privacy policies and demonstrable security practices.
6. Security measures
dicted implements and maintains:
- Encryption in transit — TLS 1.2 or higher for all endpoints, with HSTS preload on consumer-facing domains.
- Encryption at rest — for meeting files (Cloudflare R2 managed encryption) and database backups.
- Access controls — production systems accessible only via 2FA-protected accounts, principle of least privilege, audit logs retained for at least 12 months.
- Password handling — user passwords hashed with bcrypt (cost factor ≥12); never logged, never stored in plaintext.
- Audio handling for dictation — discarded from our servers the moment the transcript returns; not persisted to disk or backed up.
- Audio handling for meetings — stored encrypted at rest in R2; deleted within 48 hours of the Controller deleting the associated meeting record.
- Subprocessor vetting — contractual no-training, no-retention, and no-third-party-disclosure clauses with each AI provider.
- Incident response — documented internal process, on-call rotation, and breach-notification commitments described in §7.
- Vulnerability management — dependency scanning on every build; critical vulnerabilities patched within 7 days of published CVE, others within 30.
Specific controls are documented in an internal security-controls register available to business-tier Customers under NDA.
7. Breach notification
dicted will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Personal Data Breach affecting the Controller's data. Where full details are not yet available, we will provide an initial notification and follow up with further information as our investigation progresses. The notification will include, to the extent known:
- Nature of the breach, categories and approximate number of Data Subjects and records affected
- Contact point for further information
- Likely consequences
- Measures taken or proposed to address the breach and mitigate possible adverse effects
This gives the Controller time to meet its own Notifiable Data Breach obligations under the Privacy Act 1988 (Cth) Part IIIC (or equivalent local law).
8. Audits
The Controller has the right to audit dicted's compliance with this DPA. We satisfy the audit right primarily through:
- This DPA itself
- The published Privacy Policy and Subprocessor List
- An annual written attestation of compliance that we will provide on request
- Where the Controller has reasonable grounds to require more, a remote audit conducted by an independent third-party auditor at the Controller's cost, with at least 30 days' notice and no more than once per 12 months
On-site audits are available to enterprise customers under a separate negotiated addendum.
9. International transfers
Personal Data processed under this DPA may be transferred to the United States (all AI and infrastructure Subprocessors are US-based, with the single exception of Gladia — a speech-to-text fallback provider established in the European Union (France) — to which audio may be transferred on the fallback path). The transfer mechanism for each Subprocessor is disclosed in the Privacy Policy §6.3 (DPF certification where available, SCCs 2021/914 Module 3 and UK IDTA otherwise). The Controller authorises these transfers by entering this DPA.
dicted has conducted Transfer Impact Assessments covering each Subprocessor. Summaries are available to the Controller on written request.
10. Deletion and return at end of service
On termination of the subscription, or on the Controller's written request at any time, dicted will within 30 days:
- Delete all Personal Data stored in the primary databases
- Delete all meeting files stored in object storage (R2)
- Purge backups on the standard rotation cycle (all backups containing the data expire within a further 30 days)
- Retain only: (i) information required by law (invoice-level billing records — 7 years under Income Tax Assessment Act 1997 (Cth)), and (ii) aggregated statistics not linked to the Controller or Data Subjects
Before deletion, the Controller can request a final export of Personal Data in machine-readable format. We will provide this within 14 days of request.
11. Liability under this DPA
11.1 Where the Customer is a consumer-tier subscriber (Free, Pro)
The limits of liability in the Terms of Service §10 (as in effect from time to time, including the carve-outs in Terms §10.4) apply to claims arising under this DPA, except where applicable mandatory law imposes a higher liability that cannot be contractually limited (including the Privacy Act 1988 (Cth) and equivalent local-law obligations).
11.2 Where the Customer is a Business-tier subscriber under a separately negotiated agreement
Where a separately negotiated Business Agreement, Master Services Agreement, or order form between the Customer and dicted addresses liability for processing of Personal Data, the limits of liability in that separately negotiated agreement apply and override §11.1 for the duration of that agreement.
Where the separately negotiated Business Agreement is silent on liability for processing of Personal Data under this DPA, our aggregate liability to the Customer for all claims arising under this DPA in any 12-month period is capped at the greater of (a) AU$50,000, or (b) the fees paid by the Business Customer to dicted in the 24 months preceding the event giving rise to the claim, except for liability that cannot be limited under applicable mandatory law and except for the carve-outs in Terms §10.4 (which apply to this DPA as if set out in full).
The exclusion of indirect, consequential, special, exemplary, and punitive damages, and loss of profits, revenue, goodwill, anticipated savings, and data, in Terms §10.3 applies under this DPA in the same terms.
11.3 Each party remains individually liable
Each party remains individually liable to Data Subjects and regulators for its own breaches under the Privacy Act 1988 (Cth), the Notifiable Data Breaches scheme, and equivalent local laws. Nothing in §11 reduces a Data Subject's statutory rights against either party or limits a regulator's powers under applicable law.
12. Order of precedence
If there is conflict between this DPA and the Terms of Service, this DPA prevails in respect of the processing of Personal Data. If a separate negotiated data-protection schedule exists for an enterprise customer, that schedule prevails over this DPA.
13. Governing law
This DPA is governed by the laws of Victoria, Australia, aligned with the Terms of Service §13. Nothing in this clause deprives a Data Subject of statutory rights under their local law (such as access and complaint rights under the Australian Privacy Act).
14. Signature
For the Customer to execute this DPA:
- Download this document from
dicted.ai/dpaas PDF - Complete the signature block below (or sign electronically via DocuSign / Adobe Sign / equivalent)
- Email the signed copy to
[email protected] - We will countersign and return a fully executed copy within 5 business days
Alternatively, business customers on the future Business tier can execute this DPA through the billing portal as part of their subscription.
Signature block
Customer:
- Legal entity name: ____________________________
- Registered address: ____________________________
- Authorised signatory: ____________________________
- Title: ____________________________
- Signature: ____________________________
- Date: ____________________________
dicted (M37 Tech Pty Ltd):
- Authorised signatory: ____________________________
- Title: ____________________________
- Signature: ____________________________
- Date: ____________________________
Questions: [email protected] or [email protected].
© 2026 M37 Tech Pty Ltd, PO Box 1215, GREYTHORN VIC 3104, Australia. All rights reserved.
dicted