LiveInterpret.AI ← back

Data Processing Addendum (DPA)

Version 1.3, published 2026-07-23 (replaces v1.2 of 2026-07-19). Between the organization using the service ("Controller") and Ondřej Plevka, sole trader, IČO 88181782, registered seat Nad úžlabinou 445/20, 108 00 Praha 10 – Malešice, Czech Republic ("Processor"). Applies whenever the service processes personal data on the Controller's behalf (Art. 28 GDPR). Forms part of the Terms of Service.

1. Subject matter and instructions

Processing is limited to operating the live-translation service: relaying and translating event audio in real time, optional transcript archiving, operator account management, and usage metering. The Controller's documented instructions are given through the service's settings and these documents; the Processor processes personal data only on those instructions and for no purpose of its own beyond security and billing records, and will inform the Controller if an instruction appears to infringe data-protection law.

2. Duration, nature, and categories

Processing lasts for the term of the service and the applicable retention settings. Data subjects: speakers at the Controller's events; the Controller's operators and volunteers. Data: live speech audio, caption text (only when archiving is enabled, which is off by default for LiveInterpret.AI organizations), operator account names and hashed credentials, sender-device names, and usage records. For live audio: the service itself writes no audio to disk; the translation subprocessor (Google, §4) may retain session state, including audio and text, for up to 24 hours to support session resumption (which the service uses for reconnect reliability), performs limited security and abuse logging, and does not use paid-tier data for model training. Speech at religious events may reveal special-category data (Art. 9); the Controller is responsible for the lawful basis for capturing, translating, and archiving its event audio.

3. Security and confidentiality

TLS on all connections; per-organization isolation (separate service instances and data directories); per-device revocable sender credentials; operator authentication with salted password hashes; audit logging of control actions; EU-only primary hosting; nightly backups; and access limited to the Processor. Any person the Processor authorizes to process Controller data is bound by a statutory or contractual duty of confidentiality (Art. 28(3)(b)). Event audio is never written to disk by the service itself (see §2 for the translation subprocessor's short-lived session retention).

4. Subprocessors

The Controller authorizes the following subprocessors of the personal data processed under this DPA:

SubprocessorPurposeLocation
Google (Gemini API, developer API, paid tier)real-time speech translation; session state (incl. audio/text) retained up to 24 h for session resumption; limited security/abuse logging; no use of Controller data for model training per Google's paid-services termsglobal processing per Google's Gemini API terms; DPF for eligible U.S. recipients, SCCs as fallback
Hetzner Online GmbHhosting and computeGermany (EEA)
DigitalOcean, LLCmanaged PostgreSQL for account, credit and billing recordsGermany (fra1, EEA)
Cloudflare, Inc.DNS, TLS, CDN/proxy and bot protection (liveinterpret.ai)global edge; SCCs
Sentry (Functional Software, Inc.)error monitoring and diagnosticsUS; SCCs

Stripe (payment processing) and Resend (account e-mail) handle account and payment data for which the Operator is the controller; they are not subprocessors of the Controller's event data under this DPA and are listed in the Privacy Policy instead.

The Processor imposes data-protection terms on each subprocessor no less protective than this DPA and remains liable for their performance. Changes are announced 14 days in advance to the contact e-mail on file; the Controller may object on reasonable data-protection grounds. If an objection cannot be resolved — by the Processor forgoing the change for the Controller or offering a reasonable alternative — the Controller may terminate the affected service and receives a pro-rata refund of prepaid amounts for the unused remainder.

5. International transfers

Primary hosting, storage, and payments use EU infrastructure and entities. Real-time translation uses the Google Gemini API (developer API) on a paid (billed) plan, under which Google does not use Controller data to train its models; Google processes this data on a global basis that may occur outside the EEA under Google's Gemini API terms. Google's data-processing terms rely on the EU–U.S. Data Privacy Framework for eligible U.S. recipients (Google LLC is certified; Art. 45 GDPR) and on the EU Standard Contractual Clauses (Art. 46 GDPR) as a fallback for other restricted transfers. An EEA data-residency option for this translation model is not currently available (it is not yet offered on Google Vertex AI). Error monitoring (Sentry) and edge/DNS/CDN (Cloudflare) may also process limited data outside the EEA under the EU Standard Contractual Clauses (Art. 46 GDPR) in their data processing agreements.

6. Assistance, breaches, deletion

The Processor assists the Controller with data-subject requests and DPIAs to the extent the service holds relevant data. The Processor notifies the Controller of personal data breaches without undue delay after becoming aware; the notification describes the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed (Art. 33(3) GDPR). On termination the Processor, at the Controller's choice, returns or deletes the Controller's instance data (transcripts, accounts, devices), except billing records retained under accounting and tax law; deletion extends to copies and backups, which are purged as they roll off the regular backup cycle. Usage ledgers contain no audience personal data.

7. Audits

On request, the Processor provides a written description of measures and relevant logs to demonstrate compliance with Art. 28; on-site audits are limited to once per year, at the Controller's cost, with 30 days' notice, subject to confidentiality and without access to other organizations' data. This limit does not apply where an audit is required following a personal data breach affecting the Controller's data or by a competent supervisory authority.

Internal compliance and legal review completed through 2026-07-23. This DPA is maintained by the Processor and reviewed against the live platform. Changelog: v1.3 (2026-07-23) records the platform's domain migration from liveinterpret.app to liveinterpret.ai (.app remains a serving alias; the Cloudflare subprocessor entry now references the liveinterpret.ai origins); no substantive changes. v1.2 (2026-07-19) incorporates the legal review — the processing description discloses Google's up-to-24 h session-state retention and security logging; the subprocessor list is limited to processors of Controller event data (Sentry added; Stripe and Resend carved out to the Privacy Policy); and it adds the subprocessor-objection termination with pro-rata refund, breach-notification content (Art. 33(3)), return-or-delete at the Controller's choice including backups, and audit-limit exceptions. v1.1 (2026-07-18) adds the Art. 28(3)(b) confidentiality commitment and the EU–U.S. Data Privacy Framework note for Google's U.S. processing. v1.0 published 2026-07-12. Signed copies on request.