Assistly
Back to home

Legal

Data Processing Addendum

Last updated: September 23, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Zigzag Technologies(“Processor,” “we”) and any customer that uses Assistly for business purposes and acts as a controller of personal data processed through it (“Customer,” “you”). It applies automatically when you accept the Terms, and no signature is needed. If you would like a signed copy, email support@tryassistly.com.

Terms such as “controller,” “processor,” “personal data,” and “personal data breach” have the meaning given in the GDPR (Regulation (EU) 2016/679) and, for UK data, the UK GDPR. If this DPA and the Terms conflict, this DPA wins on data protection.

1. Scope and roles

You are the controller and we are your processor for Customer Personal Data: the personal data we process on your behalf when your users use Assistly. We are an independent controller for account administration, billing, security, and the website, as described in our Privacy Policy.

2. Details of the processing

  • Subject matter: providing Assistly, a live meeting assistant, to you.
  • Duration: for as long as you use the Service, plus the deletion period in Section 10.
  • Nature: collection, transcription, storage, indexing, retrieval, AI analysis, display, and deletion.
  • Purpose: to transcribe your users’ meetings, generate answers, recaps, and action items, make them searchable, and run the integrations you connect.

3. Your instructions

We process Customer Personal Data only on your documented instructions. The Terms, this DPA, and your use and configuration of the Service are those instructions. If we think an instruction breaks data protection law, we will tell you. If the law requires us to process data in another way, we will tell you first unless the law forbids it.

You are responsible for having a lawful basis for the processing, including telling meeting participants and getting their consent where the law requires it.

4. Confidentiality

Anyone we authorise to process Customer Personal Data is bound by confidentiality and has access only as far as their work needs it.

5. Security

We maintain the technical and organisational measures in Annex II, which meet Article 32 of the GDPR. We may improve them over time but will not reduce the overall level of protection.

6. Sub-processors

You give us general authorisation to use sub-processors. The current list is on our sub-processors page (Annex III). When we add or replace one, we update that page and, if you have asked to be notified, email you. You can object on reasonable data protection grounds within 30 days of the update. If we cannot resolve the objection, you may stop using the Service and close your account.

Each sub-processor is bound by written terms that protect the data at least as well as this DPA, and we remain responsible to you for its work.

7. Helping you

Taking into account the nature of the processing, we help you respond to requests from people exercising their rights, mainly through the self-serve export and deletion tools in the Service. If we receive a request directly, we pass it to you and do not respond to it ourselves except to redirect the person. We also give you the information you reasonably need for data protection impact assessments and consultations with a supervisory authority.

8. Personal data breaches

We notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. We tell you what we know, what we are doing about it, and a contact for more information, and we keep you updated as we learn more.

9. International transfers

We are based in Canada, and we and our sub-processors process data in Canada and the United States. To the extent Customer Personal Data from the EU or EEA is transferred to a country without an adequacy decision, the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914) are incorporated into this DPA by reference: Module 2 (controller to processor) where you are a controller, and Module 3 (processor to processor) where you are a processor. For those Clauses: the optional clause 7 does not apply; option 2 of clause 9 (general written authorisation, with changes notified as in Section 6) applies; the optional wording in clause 11 does not apply; clauses 17 and 18 are governed by and resolved in the courts of Ireland; and Annexes I to III of this DPA complete the Clauses’ annexes.

For UK data, the UK International Data Transfer Addendum to the Standard Contractual Clauses (version B1.0) is incorporated by reference, with the tables completed by this DPA. For Swiss data, the Clauses apply with references to the GDPR read as the Swiss Federal Act on Data Protection. Where a sub-processor is certified under the EU-US Data Privacy Framework, we may rely on that instead.

10. Deletion and return

You can export and delete Customer Personal Data in the Service at any time. When the Service ends, we delete it from live systems straight away and from backups within 30 days, unless the law requires us to keep it.

11. Audits

On request, we give you the information you reasonably need to show that we meet this DPA, such as written answers to security questionnaires and descriptions of our measures. If that is not enough, or a supervisory authority requires it, we will agree to a reasonable audit with at least 30 days’ notice, during business hours, under confidentiality, and at your cost.

Annex I: Parties and processing

  • Data exporter (controller): the Customer, as identified in its account. Contact: the account owner’s email.
  • Data importer (processor): Zigzag Technologies, a sole proprietorship in British Columbia, Canada. Contact: support@tryassistly.com.
  • Data subjects: the Customer’s users; other participants in meetings and calls those users run Assistly on; people named in uploaded documents or connected Slack channels and calendars.
  • Categories of data: names, email addresses, and job details; meeting audio (streamed for transcription, not stored); transcripts, speaker names, questions and answers, recaps, and action items; screenshots taken at a user’s request; uploaded documents such as CVs; calendar events; Slack messages; usage data.
  • Sensitive data: none is intended. Meeting content may contain it incidentally, and it is protected by the measures in Annex II.
  • Frequency: continuous, while the Service is used.
  • Retention: until the Customer or its users delete it, or the Service ends, as set out in Section 10 and the Privacy Policy.
  • Competent supervisory authority: the authority of the EU member state where the Customer is established or, if it is not established in the EU, the authority where its data subjects are.

Annex II: Technical and organisational measures

  • Encryption in transit: all connections use TLS 1.2 or higher.
  • Encryption at rest: the database (Supabase) and file storage (Amazon S3) are encrypted at rest by the hosting provider. Integration tokens are stored encrypted.
  • Access control: least-privilege access to production, limited to the people who need it; each user’s data is scoped to their own account or workspace.
  • Secrets: API keys and credentials are held in AWS Systems Manager Parameter Store, never in code or client apps.
  • Logging: server logs are kept for 30 days to investigate errors and security events.
  • Backups and resilience: the database is backed up automatically by the hosting provider; the service runs on managed AWS infrastructure.
  • Vendors: sub-processors are chosen for their security and bound by written terms, and none may use Customer Personal Data to train AI models.
  • Incidents: a documented process for handling and reporting security incidents, described on our Security page.

Annex III: Sub-processors

The authorised sub-processors are listed on our sub-processors page.

Assistly

Real-time AI for your live conversations

Product

  • Download
  • Features
  • Integrations
  • Pricing
  • Enterprise
  • FAQ

Compare

  • vs Cluely
  • vs Interview Coder
  • vs Granola
  • vs Fathom
  • vs InterviewMan
  • All comparisons

Resources

  • Free meeting transcription
  • What is a live meeting assistant?
  • Meeting AI without the bot
  • AI for meetings & sales
  • Best AI meeting assistants
  • Read the blog

Company

  • Support
  • Security
  • Privacy
  • Terms
  • Cookies
  • Refund Policy

© 2026 Assistly, operated by Zigzag Technologies. Use responsibly and in accordance with the rules of any meeting, call, or interview you take part in.

  • Data Processing Addendum
  • Sub-processors