Data Processing Agreement (DPA) under Art. 28 GDPR
Document: Data Processing Agreement pursuant to Art. 28 GDPR Product: Nodl Provider / Processor: ex-nihilo GmbH, Effingergasse 18/2-3, 1160 Vienna, Austria Version: 1.0 Stand: 2026-06-11
This page reproduces the data processing agreement that ex-nihilo GmbH enters into with business customers of Nodl. It is published so that the agreement can be reviewed before signing up, for example by data protection offices at universities, clinical practices or companies.
The agreement is not concluded on this page. If you use Nodl in a business context and need a signed DPA, contact [email protected]. We will enter your organisation’s details in section 1 and send you the agreement for counter-signature.
The subprocessors currently engaged are listed separately in the subprocessor register. The technical and organisational measures are also available on the security measures page.
2. Data Processing Agreement pursuant to Art. 28 GDPR
2.1 Contracting Parties
This Data Processing Agreement (“DPA”) is entered into between:
Customer / Controller
Your organisation’s details (legal name, address, register and VAT identification number, data protection contact and, where applicable, data protection officer) are inserted here on conclusion.
– hereinafter “Customer”, “Controller”, or, where applicable, “Client” –
and
ex-nihilo GmbH
Effingergasse 18
1160 Vienna
Austria
Email: [email protected]
Company register number: FN 601306z
VAT ID: ATU79273723
– hereinafter “ex-nihilo”, “Nodl”, “Processor”, or “Contractor” –
together the “Parties”.
2.2 Conclusion and Effectiveness
This DPA is entered into electronically. It becomes effective as soon as a person authorised to accept on behalf of the Customer accepts the DPA in the Nodl dashboard and Nodl stores the acceptance.
The DPA supplements the applicable terms of use, service description, order, subscription, or other agreement governing use of Nodl (“Main Agreement”). In the event of conflicts between this DPA and the Main Agreement, this DPA shall prevail to the extent the conflict relates to the processing of personal data on behalf of the Customer.
2.3 Roles of the Parties
- The Customer determines the purposes and means of processing personal data that it or its users enter, upload, record, store, process, or have generated in Nodl. In this respect, the Customer is the controller within the meaning of the GDPR or, if it uses Nodl on behalf of third parties, itself a processor or intermediary processor.
- ex-nihilo processes Customer Data within the scope of Nodl principally as processor of the Customer.
- To the extent ex-nihilo processes personal data for its own purposes, in particular for account management, contract performance, billing, abuse prevention, security, legal enforcement, product communication, or website analytics, ex-nihilo acts as an independent controller. Such processing is not subject to this DPA and is described in the privacy policy.
2.4 Subject Matter, Nature, and Purpose of Processing
The subject matter of processing is the provision and operation of the SaaS application Nodl. Nodl enables in particular:
- audio recording in the browser,
- upload of audio files,
- storage of recordings, transcripts, and documents according to workspace settings,
- optional storage of original audio as a reference source,
- technical normalisation of audio files,
- live and batch transcription,
- speaker separation / diarisation to distinguish conversation segments,
- generation of structured documents from transcripts,
- display, playback, export, download, and deletion of audio, transcripts, and documents,
- workspace, user, authentication, admin, support, monitoring, and security functions.
The details are set out in Annex 1.
2.5 Duration of Processing
Processing begins upon effectiveness of this DPA and ends when the Main Agreement ends and all personal data have been deleted or returned in accordance with this DPA.
Original audio, normalised audio versions, transcripts, and generated documents are stored according to workspace settings and plan for the duration of the account or workspace, unless the Customer or an authorised user deletes them earlier. Original audio may be stored unchanged as a reference source where the Customer or user uses or configures this function. The Customer remains responsible for ensuring that storage, retention, and deletion are lawful for its specific purposes.
2.6 Customer Instructions
- ex-nihilo processes Customer Data only on documented instruction from the Customer, unless a legal obligation requires different processing.
- Documented instructions arise in particular from:
- this DPA,
- the Main Agreement,
- product configuration by the Customer or its users,
- uploads, recordings, deletions, exports, and other use of the product,
- support requests from the Customer,
- written or electronic individual instructions from the Customer.
- Oral instructions must be confirmed electronically or in writing without undue delay.
- ex-nihilo will inform the Customer if ex-nihilo considers that an instruction violates the GDPR or other data protection provisions of the EU or Member States. ex-nihilo may suspend implementation of an obviously unlawful instruction pending clarification.
2.7 Customer Obligations
The Customer is in particular responsible for:
- the lawfulness of processing, in particular legal bases, information obligations, and transparency towards data subjects;
- authorisation to record, store, and process conversations, including any consents or information obligations towards conversation participants;
- permissibility of processing special categories of personal data pursuant to Art. 9 GDPR, data relating to criminal convictions and offences pursuant to Art. 10 GDPR, and professional, business, client, patient, or other secrets;
- compliance with employment law, professional law, medical law, telecommunications law, copyright law, and other industry-specific requirements;
- conducting a data protection impact assessment where legally required;
- the accuracy, quality, necessity, and retention periods of content processed by the Customer;
- authorisation of its users and administrators;
- review of transcripts and AI-generated documents before further use.
Nodl is not a medical device, not a clinical decision support system, and not software for diagnosis, therapy, or emergency medical care. Where customers from the healthcare, legal, financial, or other regulated sectors use Nodl, they do so at their own responsibility and must review and comply with applicable regulatory requirements themselves.
2.8 Obligations of ex-nihilo as Processor
ex-nihilo undertakes to:
- process Customer Data only on documented instruction from the Customer;
- ensure that persons authorised to process Customer Data are bound by confidentiality or subject to an appropriate statutory duty of confidentiality;
- implement and maintain appropriate technical and organisational measures pursuant to Annex 2;
- use sub-processors only in accordance with this DPA;
- assist the Customer, taking into account the nature of processing, with appropriate technical and organisational measures in fulfilling data subject rights where possible;
- assist the Customer, taking into account the nature of processing and information available to ex-nihilo, in complying with obligations under Art. 32 to 36 GDPR;
- delete or return Customer Data after the end of processing according to the Customer’s choice and configuration, unless a statutory retention obligation applies;
- make available to the Customer the information necessary to demonstrate compliance with this DPA and enable audits in accordance with this DPA;
- inform the Customer if ex-nihilo considers an instruction to be unlawful.
2.9 Confidentiality and Access Restriction
ex-nihilo restricts access to Customer Data to persons who require such access for operation, security, support, error analysis, maintenance, billing, or legal obligations. Access is granted on a need-to-know basis.
Support access to Customer Data occurs only to the extent necessary to handle a support request, troubleshoot errors, secure the service, or fulfil legal obligations.
2.10 Technical and Organisational Measures
ex-nihilo implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The measures are described in Annex 2.
The Parties agree that security measures may change due to technical developments. ex-nihilo may use alternative or further developed measures provided the overall level of protection is not materially reduced.
2.11 Sub-processors
- The Customer grants ex-nihilo general written approval to use the sub-processors listed in Annex 3.
- ex-nihilo may engage additional sub-processors or replace existing sub-processors provided ex-nihilo informs the Customer via a sub-processor list, by email, in the dashboard, or through another suitable electronic channel.
- For material changes, in particular new sub-processors that obtain access to Customer Data or customer content, ex-nihilo will generally inform the Customer at least 30 days before planned use. In urgent cases, in particular to maintain security, availability, or compliance, a shorter period may be appropriate.
- The Customer may object within 14 days of notification for an important data protection reason. The objection must be substantiated.
- If the Parties cannot resolve the objection appropriately, the Customer may terminate the affected service or the Main Agreement to the extent use without the affected sub-processor is not reasonably possible.
- ex-nihilo ensures that sub-processors are subject to substantially the same data protection obligations as apply to ex-nihilo under this DPA. ex-nihilo remains liable to the Customer for fulfilment of sub-processors’ obligations.
2.12 Transfers to Third Countries
- ex-nihilo aims to process Customer Data primarily within the European Economic Area.
- Transfers of personal data to third countries or international organisations occur only to the extent necessary for service delivery and the requirements of the GDPR are met.
- Where no adequacy decision exists, appropriate safeguards are used, in particular EU Standard Contractual Clauses, supplementary measures, or other permissible transfer mechanisms.
- The Customer authorises ex-nihilo to conclude necessary transfer instruments with sub-processors to the extent required for service delivery.
2.13 AI Service Providers and Model Training
- Nodl uses AI service providers for transcription, speaker separation, and document generation.
- ex-nihilo will not use Customer Data to train its own or third-party AI models unless the Customer has expressly commissioned or approved this separately.
- ex-nihilo will configure and contractually bind AI sub-processors so that Customer Data is not used for model training. Where available and economically reasonable, ex-nihilo uses zero-data-retention, no-training, or comparable API / enterprise settings.
- AI outputs may contain errors. The Customer is responsible for reviewing and approving transcripts, documents, and other results.
2.14 Notification of Personal Data Breaches
- ex-nihilo will inform the Customer without undue delay after ex-nihilo has become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data affecting Customer Data.
- Where reasonably possible, initial notification will be provided within 48 hours of becoming aware.
- The notification will include, where available:
- nature of the breach,
- categories of data affected,
- affected systems or services,
- approximate number of data subjects or records affected, where known,
- likely consequences,
- measures already taken or proposed,
- contact point for enquiries.
- Information may be provided incrementally if not all details are immediately available.
- ex-nihilo will appropriately assist the Customer in fulfilling its own notification and communication obligations.
2.15 Assistance with Data Subject Rights
Where data subjects exercise rights of access, rectification, erasure, restriction, data portability, objection, or other data protection rights relating to Customer Data, ex-nihilo will appropriately assist the Customer.
Where possible, Nodl provides self-service functions, in particular export, download, and deletion of audio, transcripts, documents, and account data.
2.16 Deletion and Return
- During the contract term, the Customer may export, download, or delete Customer Data via available product functions.
- Original audio is stored according to workspace settings and plan for the duration of the account or workspace unless deleted by the Customer or an authorised user and where the applicable configuration provides for this.
- After deletion of individual recordings or documents, the affected active data will generally be deleted or logically removed from production systems within 30 days, unless legal obligations or security reasons prevent this.
- After deletion of the account or workspace, Customer Data will generally be deleted from production systems or made inaccessible for product purposes within 30 days.
- Backups are overwritten or deleted on a rolling basis. Deleted Customer Data may persist in backups for up to 35 days and will be processed there again only in the event of restoration.
- Temporary processing files, e.g. technical intermediate audio files, will generally be deleted within 7 days after completion or abort of processing, unless longer retention is required for error analysis, security, or support.
- Technical application and error logs are generally stored for up to 30 days. Security and incident logs generally for up to 12 months; audit events for admin and security purposes generally for up to 24 months where necessary for security, error analysis, legal enforcement, or compliance.
- Statutory retention obligations, in particular for billing, tax, accounting, or legal enforcement data, remain unaffected. Such data is generally not subject to processing of customer content on behalf of the Customer, but is processed by ex-nihilo as an independent controller.
2.17 Audit and Evidence
- ex-nihilo will provide the Customer with appropriate information on request that is necessary to demonstrate compliance with this DPA.
- Evidence will primarily be provided through documentation, security overviews, TOM descriptions, questionnaires, certifications, audit reports, or comparable materials, where available.
- The Customer may conduct audits itself or through an independent auditor bound by confidentiality to the extent necessary to fulfil legal obligations and proportionate.
- Audits must be announced at least 30 days in advance, conducted during normal business hours, and must not jeopardise security, availability, trade secrets, or data of other customers.
- On-site audits are permitted at most once per calendar year, except in the case of specific substantiated suspicion of a material data protection breach.
- The Customer bears its own audit costs. ex-nihilo may charge reasonable effort where the audit goes beyond usual information and evidence and no material breach by ex-nihilo is established.
2.18 International Customers and Representatives
Where the Customer is established outside the European Economic Area but processes data of persons in the EEA or uses Nodl for processing subject to the GDPR, the Customer is responsible for reviewing its own obligations, in particular representative obligations, information obligations, transfer mechanisms, and local data protection requirements.
2.19 Liability
Liability of the Parties is governed by the statutory provisions of the GDPR and the Main Agreement. This DPA does not limit mandatory rights of data subjects or supervisory authorities.
2.20 Amendments to this DPA
ex-nihilo may amend this DPA to the extent necessary to adapt to product changes, legislative changes, new case law, regulatory requirements, or security requirements, and provided the level of protection for the Customer is not materially reduced.
Material amendments will be communicated to the Customer in advance electronically. If the Customer continues to use Nodl after amendments take effect, this constitutes consent where legally permissible. Where amendments materially reduce the level of data protection, the Customer receives an appropriate right to object or terminate.
2.21 Final Provisions
- Austrian law applies, unless mandatory data protection provisions provide otherwise.
- The place of jurisdiction is, where permissible, Vienna, Austria.
- If any provision of this DPA is or becomes invalid, the validity of the remaining provisions shall remain unaffected.
- This DPA may be entered into and stored electronically.
Annex 1 — Description of Processing
1. Subject Matter of Processing
Provision, operation, maintenance, securing, support, and further development of Nodl as an AI-native voice-to-document SaaS.
2. Purpose of Processing
- recording and upload of audio,
- storage of recordings, transcripts, and documents according to workspace settings,
- optional storage of original audio as a reference source,
- technical audio processing and normalisation,
- transcription of audio,
- speaker separation / diarisation to distinguish conversation segments,
- generation of structured documents from transcripts,
- display, playback, search, download, export, and deletion of content,
- account, workspace, authentication, admin, and usage management,
- support, error analysis, monitoring, security, abuse prevention,
- billing and plan management to the extent relevant for service delivery.
3. Nature of Processing
Collection, receipt, storage, organisation, structuring, normalisation, transcription, analysis, conversion, display, provision, transmission to sub-processors, retrieval, reconciliation, export, deletion, restriction, backup, restoration, and logging.
4. Categories of Personal Data
Depending on use, the following may be processed:
- account data: name, email address, password hash, language settings, roles, workspace membership;
- organisation data: workspace name, team / organisation name, roles and permissions;
- audio content: original audio files, microphone recordings, uploads, normalised audio versions, technical audio metadata;
- speech and conversation content: spoken content, voices, speaker segments, timestamps, speaker labels;
- transcripts: recognised text, segments, timestamps, speaker assignment;
- AI context data: selected output type, prompts, transformation instructions, recording timestamp, context information;
- generated documents: Markdown documents, summaries, meeting notes, task lists, customer summaries, or other document types;
- usage and metadata: number and duration of recordings, processing status, upload time, file type, file size, technical IDs;
- technical data: IP address, user agent, session data, logs, error data, security events;
- support data: support requests, communication, error descriptions, voluntarily provided attachments;
- billing and contract data to the extent relevant within the scope of the service.
5. Special Categories of Personal Data
Nodl does not specifically request special categories of personal data. However, since customers may record or upload any audio content, content may include special categories of personal data pursuant to Art. 9 GDPR, in particular health data, political opinions, religious or philosophical beliefs, trade union membership, biometric data, data concerning sex life or sexual orientation.
Nodl does not use speaker separation to identify natural persons, for authentication, or for biometric categorisation. Speaker separation is used solely to technically distinguish different speaker segments within a recording.
6. Categories of Data Subjects
Depending on use, the following may be affected:
- users and administrators of the Customer,
- employees, contractors, freelancers, and consultants of the Customer,
- customers, prospects, leads, and business partners of the Customer,
- conversation participants in meetings, calls, interviews, dictations, or recordings,
- patients, clients, mandate holders, or other persons in regulated professional sectors if the Customer processes such data,
- support contacts and communication partners.
7. Retention Periods / Deletion Criteria
| Data category | Standard period / criterion |
|---|---|
| Original audio | According to workspace settings and plan for duration of account / workspace until deletion by customer / user; active deletion generally within 30 days of deletion request |
| Normalised audio versions | For duration of account / workspace until deletion by customer / user; active deletion generally within 30 days of deletion command |
| Transcripts | For duration of account / workspace until deletion by customer / user; active deletion generally within 30 days of deletion command |
| Generated documents | For duration of account / workspace until deletion by customer / user; active deletion generally within 30 days of deletion command |
| Temporary processing files | generally 7 days after completion / abort, unless required for support / security |
| Technical application and error logs | generally up to 30 days |
| Security and incident logs | generally up to 12 months |
| Audit events for admin and security purposes | generally up to 24 months |
| Backups | rolling, generally up to 35 days |
| Billing / tax data | according to statutory retention obligations; processing generally as independent controller |
Annex 2 — Technical and Organisational Measures
The following measures describe the target level of protection and the essential safeguards of Nodl. Details may change due to technical development without materially reducing the level of protection.
1. Access Control
- user accounts with authentication and password protection.
- workspace-based tenant separation.
- role and permission concept for users and administrators.
- administrative access only on a need-to-know basis.
- separation of customer workspaces.
- access to production systems only for authorised persons.
- secrets and credentials are not stored in source code.
2. Access to Customer Data
- Customer Data is processed only to the extent necessary to provide Nodl, support, security, error analysis, or fulfil legal obligations.
- support access occurs on a case-by-case basis.
- access to original audio, transcripts, and documents is restricted to authorised systems and persons.
3. Transport and Storage Protection
- encrypted transmission via HTTPS / TLS.
- storage in controlled server / storage infrastructure.
- appropriate encryption or comparable safeguards for stored data where technically available and appropriate.
- protection of API keys and provider credentials.
4. Tenant Separation
- workspace tenancy as logical tenant separation.
- database queries and product logic are scoped to the current workspace.
- prevention of cross-workspace access.
5. Integrity and Traceability
- original audio may be stored unchanged as a reference source according to workspace settings for as long as the Customer does not delete it or the account / workspace ends.
- technical processing may produce additional normalised versions; original audio remains separate.
- status and audit information may be stored for traceability of processing operations.
- optionally or in future, integrity evidence such as hashes, timestamps, or tamper-evident exports may be used.
6. Availability and Recovery
- operation on suitable server infrastructure.
- regular backups according to defined backup cycle.
- recovery processes for technical incidents.
- monitoring of availability, errors, and system status.
7. Logging and Monitoring
- technical logs for error analysis, security, and stability.
- security / incident logs for detection and investigation of abuse or attacks.
- self-hosted or controlled monitoring where possible.
- logs should not contain customer content where technically avoidable.
8. AI and Provider Protection
- transmission to AI service providers only to deliver commissioned functions, in particular transcription and document generation.
- no use of Customer Data for model training by ex-nihilo.
- contractual and technical configuration of AI service providers with no-training / zero-data-retention or comparable settings where available.
- no intentional biometric identification, emotion recognition, or profiling by Nodl.
9. Secure Development and Operations
- code reviews or agentic quality gates before deployment.
- automated tests, linting, and security checks where implemented.
- regular updates of security-relevant components.
- separation of development, test, and production environments where possible.
- no use of real Customer Data in development or tests where avoidable.
10. Incident Response
- procedures for detection, assessment, and handling of security incidents.
- escalation to responsible technical and organisational personnel.
- documentation of incidents and measures.
- notification of the Customer pursuant to the DPA.
11. Sub-processor Management
- selection of service providers taking into account data protection, security, and service requirements.
- conclusion of appropriate contracts with sub-processors.
- maintenance of a sub-processor list.
- notification of the Customer of material changes.