Legal

Q-Meet Data Processing Agreement

Version 1.0 – Effective 25 August 2026

This Data Processing Agreement ("DPA") forms part of the Q-Meet Terms of Service, applicable order form or other agreement governing the Customer's use of Q-Meet ("Agreement").

It applies whenever Qbim Aktiebolag (QBIM AB) processes personal data on behalf of a Customer in connection with Q-Meet.

1. Parties and Roles

The parties are:

Controller: the Customer using Q-Meet and determining the purposes and means of the relevant processing ("Customer" or "Controller"); and

Processor: Qbim Aktiebolag (QBIM AB), Swedish company registration number 556944-6981, Västra Torggatan 18, 652 24 Karlstad, Sweden ("QBIM" or "Processor").

Together, the "Parties".

Where the Customer itself acts as processor for another controller, QBIM acts as sub-processor and the Customer confirms that it is authorised to appoint QBIM.

2. Purpose and Scope

This DPA governs QBIM's processing of personal data on behalf of the Customer in connection with Q-Meet.

It is intended to fulfil the requirements applicable to processor agreements under Article 28 GDPR.

QBIM shall process Customer Personal Data only on documented instructions from the Customer except where processing is required by applicable Union or Member State law.

3. Documented Instructions

The Customer's documented instructions include:

  • this DPA;
  • the Agreement;
  • use and configuration of Q-Meet;
  • instructions submitted through the Service; and
  • other written instructions agreed between the Parties.

QBIM shall not process Customer Personal Data for purposes other than those instructed by the Customer.

Where applicable law requires QBIM to process Customer Personal Data other than on the Customer's instructions, QBIM shall inform the Customer before the processing unless prohibited by law.

If QBIM considers an instruction to infringe GDPR or other applicable data protection legislation, QBIM shall inform the Customer without undue delay.

QBIM may suspend the affected processing while the Parties clarify an instruction reasonably considered unlawful.

4. Customer Responsibilities

The Customer is responsible for:

  • determining the purposes of processing;
  • establishing an appropriate lawful basis;
  • providing required information to data subjects;
  • ensuring that meetings are recorded and processed lawfully;
  • obtaining consent or other approval where required;
  • ensuring that processing is necessary and proportionate;
  • responding to data subjects; and
  • providing lawful instructions to QBIM.

The Customer confirms that it is entitled to make Customer Personal Data available to QBIM for processing under this DPA.

5. Nature and Purpose of Processing

QBIM processes personal data for the purpose of providing Q-Meet and its associated functionality.

Processing may include:

  • receiving or recording audio;
  • processing uploaded recordings;
  • transcribing speech to text;
  • processing transcripts;
  • producing summaries;
  • identifying decisions;
  • identifying actions and follow-up points;
  • storing meeting information;
  • providing search and retrieval functionality;
  • displaying meeting information to authorised users;
  • enabling Customer-controlled sharing;
  • providing support; and
  • maintaining and securing the Service.

No automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR is performed by QBIM as part of the standard Q-Meet service.

Q-Meet does not use voice data for biometric identification or emotional profiling.

6. Categories of Data Subjects

Customer Personal Data may concern:

  • Customer employees;
  • consultants;
  • officers and representatives;
  • customers;
  • prospective customers;
  • suppliers;
  • partners;
  • meeting participants;
  • contact persons; and
  • other persons mentioned during meetings.

7. Categories of Personal Data

Depending on Customer use, processing may include:

  • names;
  • contact information;
  • employer and organisational information;
  • professional information;
  • meeting information;
  • calendar metadata;
  • voices during transcription;
  • recordings;
  • transcripts;
  • meeting notes;
  • summaries;
  • decisions;
  • action points;
  • activities;
  • deadlines;
  • information contained in uploaded material; and
  • other personal information included in meetings.

Voice data is not processed for biometric identification.

8. Special Categories of Personal Data

Q-Meet does not require special categories of personal data under Article 9 GDPR or data relating to criminal convictions and offences under Article 10 GDPR for its ordinary functionality.

Such information may nevertheless occur incidentally in meetings.

The Customer is responsible for determining whether such processing is necessary and lawful and for satisfying applicable additional legal requirements.

9. Duration and Retention

Customer Personal Data is processed for as long as the Customer uses the Service.

Depending on available functionality, the Customer may:

  • delete individual meetings;
  • delete users; and
  • request full deletion.

Following termination, Customer Personal Data shall be deleted or returned in accordance with the Customer's instructions.

Unless continued retention is required by law:

  • active Customer Personal Data shall be deleted no later than 30 days after termination; and
  • backups shall be progressively deleted no later than 90 days after termination.

Copies remaining temporarily in protected backups remain subject to this DPA until deleted.

10. Geographical Processing and International Transfers

Personal data is primarily processed within the EU/EEA.

Transfers outside the EU/EEA may occur only where:

  • technically necessary for Q-Meet functionality;
  • permitted under Chapter V GDPR; and
  • appropriate safeguards are implemented.

Where required, transfers shall be based on:

  • an adequacy decision adopted by the European Commission;
  • the European Commission's Standard Contractual Clauses ("SCC"); or
  • another lawful transfer mechanism.

Supplementary safeguards may include encryption, restricted access, pseudonymisation where possible and minimised retention.

11. Restriction on Use

QBIM shall not use Customer Personal Data for its own purposes, including:

  • independent product development;
  • independent analytics;
  • independent statistics;
  • marketing;
  • profiling; or
  • AI model training.

Such activities may only be performed on information that has been anonymised or aggregated so that it no longer constitutes personal data.

AI models are not trained on Customer Personal Data.

12. Confidentiality

QBIM shall ensure that persons authorised to process Customer Personal Data:

  • are subject to appropriate contractual or statutory confidentiality obligations;
  • receive access only where required for their duties; and
  • process personal data only in accordance with authorised instructions.

13. Technical and Organisational Measures

Taking into account the nature, scope, context and purposes of processing and the relevant risks, QBIM shall implement and maintain appropriate technical and organisational safeguards.

Measures include:

Encryption

  • TLS 1.2 or higher for data in transit;
  • AES-256 encryption or equivalent protection for stored data.

Access Management

  • logical tenant separation;
  • role-based access controls (RBAC);
  • multi-factor authentication for administrative accounts;
  • least-privilege access for operational personnel; and
  • appropriate management of privileged access.

Monitoring and Security

  • access logging and traceability;
  • vulnerability scanning;
  • patch management;
  • incident management; and
  • security monitoring appropriate to the Service.

Development

  • secure development practices;
  • code review;
  • version control; and
  • management of identified software vulnerabilities.

Data Protection and Resilience

  • pseudonymisation where identification is unnecessary;
  • data minimisation;
  • confidentiality requirements;
  • continuity procedures; and
  • recovery procedures.

QBIM shall periodically review its security measures and may adapt them as technology and relevant threats evolve, provided that the overall level of protection is not materially reduced.

14. Sub-processors

The Customer grants QBIM general written authorisation to use the sub-processors identified in the Q-Meet Sub-processor List.

QBIM shall ensure that each sub-processor processing Customer Personal Data is contractually bound by data protection obligations providing substantially the same level of protection required of QBIM under this DPA.

QBIM remains responsible towards the Customer for the performance of its sub-processors' data protection obligations to the extent required by Article 28 GDPR.

15. Changes to Sub-processors

QBIM shall provide the Customer with written notice at least 30 days in advance before:

  • appointing a new material sub-processor processing Customer Personal Data; or
  • making a material change to such processing.

Notification may be made:

  • by email;
  • through Q-Meet;
  • through the Customer account; or
  • through another reasonable electronic channel.

The Customer may object during the notice period where there are reasonable and documented data protection grounds.

The Parties shall seek in good faith to resolve the objection.

If no reasonable solution is available, the Customer may terminate the affected part of the Service before the new sub-processor begins the relevant processing.

16. International Processing by Sub-processors

Where a sub-processor processes Customer Personal Data outside the EU/EEA, QBIM shall ensure that an appropriate transfer mechanism and applicable safeguards are in place.

For AI-based language processing, processing in the United States may occur where technically necessary for the Service.

Where such processing constitutes an international transfer under GDPR, it shall be protected by an appropriate Chapter V transfer mechanism, including SCC where applicable.

Customer Personal Data processed by an AI sub-processor shall not be used for model training.

17. Data Subject Rights

Taking into account the nature of processing, QBIM shall provide reasonable assistance to the Customer in responding to data subject requests concerning:

  • information;
  • access;
  • rectification;
  • erasure;
  • restriction;
  • portability;
  • objection; and
  • other rights under applicable data protection law.

Where QBIM receives a request directly concerning Customer Personal Data, QBIM shall normally refer the individual to the Customer unless otherwise required by law or instructed by the Customer.

18. Assistance With Compliance

Taking into account the nature of processing and information available to QBIM, QBIM shall provide reasonable assistance to the Customer concerning its obligations under Articles 32–36 GDPR, including where applicable:

  • security of processing;
  • assessment of Personal Data Breaches;
  • notification of Personal Data Breaches;
  • data protection impact assessments; and
  • prior consultation with supervisory authorities.

Extraordinary assistance materially exceeding normal Service support may be subject to reasonable fees agreed in advance.

19. Personal Data Breaches

QBIM shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

Where available, QBIM shall provide information reasonably necessary for the Customer to fulfil its legal obligations, including:

  • the nature of the incident;
  • relevant categories of data;
  • relevant categories of data subjects;
  • known or reasonably anticipated consequences;
  • measures taken or proposed; and
  • a contact point for further information.

Information may be provided in phases where complete information is not immediately available.

QBIM shall take reasonable measures to investigate, contain, mitigate and remediate the incident.

Notification does not constitute an admission of fault or liability.

20. Government and Authority Requests

Where legally permitted, QBIM shall notify the Customer if it receives a binding request from a public authority requiring disclosure of Customer Personal Data.

QBIM shall disclose only the information legally required.

Where appropriate and reasonably possible, QBIM may challenge a request that it reasonably considers unlawful or disproportionate.

21. Demonstrating Compliance

QBIM shall make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA.

Such information may include:

  • security documentation;
  • relevant policies;
  • questionnaires;
  • assessments;
  • certifications; and
  • other appropriate compliance evidence.

22. Audits

Where the information provided under Section 21 is not reasonably sufficient, the Customer may audit QBIM's relevant processing or appoint an independent auditor.

Audits shall:

  • be limited to processing relevant to the Customer;
  • be subject to confidentiality obligations;
  • normally require at least 30 days' advance notice;
  • take place during normal business hours;
  • not unreasonably disrupt QBIM;
  • not provide access to other customers' data;
  • respect QBIM's reasonable security requirements; and
  • normally occur no more than once during any twelve-month period.

The frequency limitation does not apply where:

  • required by a competent supervisory authority;
  • justified by a material Personal Data Breach; or
  • there are reasonable grounds to suspect a material breach of this DPA.

The Customer shall normally bear its own audit costs and QBIM's reasonable costs resulting from extraordinary audit assistance, unless the audit demonstrates a material breach by QBIM.

23. Liability for Data Protection

Where compensation to a data subject is payable following a breach of GDPR, Article 82 GDPR shall apply.

Responsibility between the Parties shall be allocated according to each Party's responsibility for the processing giving rise to the damage.

Administrative fines shall be borne by the Party upon which the competent authority imposes the relevant fine, subject to mandatory law.

Each Party shall inform the other without undue delay of circumstances reasonably likely to cause material harm relating to the processing and shall cooperate to prevent or minimise such harm.

For the internal allocation of responsibility specifically relating to violations of applicable data protection legislation, this Section shall take precedence over inconsistent general liability provisions in the Agreement to the extent required by applicable law.

24. Return and Deletion

Upon termination, QBIM shall, at the Customer's written instruction and where technically feasible:

  • return Customer Personal Data; or
  • delete Customer Personal Data.

The Customer is responsible for exporting information it wishes to retain before termination where export functionality is available.

Data required by law may be retained for the legally required period but shall remain protected and shall not be processed for other purposes.

25. Records and Regulatory Cooperation

QBIM shall maintain records of processing activities where required by Article 30 GDPR. QBIM shall cooperate with competent supervisory authorities to the extent required by applicable law.

26. Term

This DPA applies for as long as QBIM processes Customer Personal Data on behalf of the Customer. Confidentiality, security, deletion and other obligations concerning retained Customer Personal Data survive termination for as long as QBIM retains such information.

27. Order of Precedence

In the event of conflict regarding processing of Customer Personal Data:

  1. mandatory applicable data protection legislation takes precedence;
  2. applicable Standard Contractual Clauses take precedence;
  3. this DPA takes precedence over the Q-Meet Terms of Service; and
  4. the remainder of the Agreement applies thereafter.

28. Governing Law and Disputes

This DPA is governed by Swedish law.

The dispute resolution provisions in the Q-Meet Terms of Service or applicable separately negotiated agreement shall apply.

29. Contact

Qbim Aktiebolag (QBIM AB)
Company registration number: 556944-6981
Västra Torggatan 18
652 24 Karlstad
Sweden
Phone: +46 (0)54 87 07 25