Data Processing Agreement
Version 1.1 · 2026-09-03
Version 1.1 · effective 2026-09-03
This is the version in force. If we revise it, the new version appears here with a new number and date, and we give notice of material changes before they take effect. Ask us if you want to know how a clause works in practice, and we will tell you plainly.
Customers who need a signed DPA get one before any of their data is processed. This outline records the commitments the signable document will carry.
Intended structure
- Roles: the customer as controller, Routenna as processor.
- Processing scope and purpose: providing the meeting-intelligence service, on the customer’s documented instructions, and nothing else.
- Confidentiality and security measures, matching what the security page describes of the shipped product: tenant isolation, encryption of credentials at rest, audited access, verified deletion.
- Subprocessors: only those on the public register, each under its own DPA, with notice of changes.
- Assistance with data subject requests and breach notification duties.
- Deletion or return of customer data at termination, with verification.
- Audit and information rights appropriate to the customer’s obligations.
To be completed with counsel
- Standard contractual clauses / transfer mechanisms where applicable
- Liability allocation consistent with the Terms of Service
- The signable (downloadable) execution version