Legal

Q-Meet Sub-processor List

Version 1.0 – Effective 25 August 2026

This Q-Meet Sub-processor List forms part of the Q-Meet Data Processing Agreement.

The Customer grants QBIM general authorisation to engage the sub-processors listed below for the purposes specified.

1. Cloudflare, Inc.

Purpose

Cloudflare is used for network, security and performance services in connection with Q-Meet, including:

  • content delivery;
  • network infrastructure;
  • traffic management;
  • performance optimisation; and
  • protection against malicious traffic and unauthorised intrusion.

Categories of Personal Data

Depending on the relevant functionality, processing may include:

  • IP addresses;
  • network metadata;
  • technical identifiers;
  • requests to and from the Service; and
  • other technical information necessary to provide network and security functionality.

International Transfers

Where Cloudflare's processing results in an international transfer of personal data under GDPR, an appropriate transfer mechanism under Chapter V GDPR shall apply.

Data Processing Terms

Cloudflare's applicable data processing terms govern its processing on behalf of QBIM.

2. Google LLC

Purpose

Google is used for identity and access management functionality, including:

  • authentication;
  • user administration;
  • identity management;
  • secure login; and
  • related account security functionality.

Categories of Personal Data

Processing may include:

  • name;
  • email address;
  • user identifier;
  • authentication information;
  • account metadata; and
  • technical information required for authentication and access management.

International Transfers

Where Google's processing results in an international transfer of personal data under GDPR, an appropriate transfer mechanism under Chapter V GDPR shall apply.

Data Processing Terms

Google's applicable data processing terms govern its processing on behalf of QBIM.

3. OpenAI, L.L.C.

Purpose

OpenAI is used for AI-based functionality within Q-Meet, including:

  • language processing;
  • processing of meeting transcripts;
  • generation of meeting summaries;
  • identification and structuring of relevant meeting information;
  • identification of decisions;
  • extraction of action points; and
  • generation of other AI-supported meeting outputs.

Categories of Personal Data

Depending on the content of the relevant meeting, processing may include text-based personal data contained in meeting transcripts, including:

  • names;
  • contact information;
  • professional information;
  • organisation information;
  • meeting information;
  • decisions;
  • action points; and
  • other information discussed during meetings.

International Transfers

Processing in the United States may occur where technically necessary for AI functionality.

Where such processing constitutes an international transfer under GDPR, an appropriate transfer mechanism under Chapter V GDPR shall apply, including the European Commission's Standard Contractual Clauses where applicable.

Supplementary safeguards may include, where appropriate:

  • encryption during transmission;
  • restricted access;
  • pseudonymisation where possible; and
  • minimised retention.

AI Model Training

Customer Personal Data submitted by QBIM for processing through Q-Meet is not used by QBIM for AI model training.

QBIM configures and uses the relevant AI service for the purpose of providing the requested Q-Meet functionality.

Any provider-side processing or technical retention is subject to the applicable agreement between QBIM and the provider and applicable law.

4. Changes to Sub-processors

QBIM may appoint additional sub-processors or replace existing sub-processors in accordance with the Q-Meet DPA.

QBIM shall notify affected Customers at least 30 days before a material new sub-processor begins processing Customer Personal Data.

The Customer may object during the notice period on reasonable and documented data protection grounds.

The Parties shall seek in good faith to resolve any objection.

If no reasonable solution is available, the Customer may terminate the affected part of the Service before the relevant new processing begins.

5. Sub-processor Obligations

QBIM shall ensure that sub-processors processing Customer Personal Data are contractually bound by data protection obligations providing substantially the same protection required of QBIM under Article 28 GDPR and the Q-Meet DPA.

QBIM remains responsible towards the Customer for its sub-processors' data protection obligations to the extent required by applicable law.

6. Contact

Questions concerning Q-Meet sub-processors may be directed to:

Qbim Aktiebolag (QBIM AB)
Västra Torggatan 18
652 24 Karlstad
Sweden