Skip to content

Data Processing Agreement

Version 1.1 · Last updated: 27 September 2026

This agreement sets out the parties’ data protection obligations when personal data is processed on behalf of the customer under Art. 28 of the General Data Protection Regulation (GDPR) in connection with the use of Discoverify.

1. Parties and conclusion

The controller (“customer”) is the company that has concluded the contract for the use of Discoverify with us under our Terms of Service.

The processor (“we”) is Make it Nice GmbH, An der Koppel 1, 53909 Zülpich, Germany, represented by its Managing Director Martin Förster, registered in the commercial register of the Amtsgericht Bonn (Local Court of Bonn) under HRB 28837.

This agreement forms part of the Terms of Service. It is concluded when the customer accepts the Terms of Service, i.e. upon registration, taking out a subscription or using the Service. Discoverify is aimed exclusively at entrepreneurs (Section 14 of the German Civil Code, BGB). On request, we will also send the customer this agreement as a PDF signed by us; an informal request to talktous@getdiscoverify.com is sufficient.

2. Subject matter and duration

The subject matter is the provision of Discoverify, web-based software for recording, transcribing and analyzing customer interviews, as described in the Terms of Service. In doing so, we process personal data that the customer and its users store in Discoverify or that the Service generates from it (“customer data”) exclusively on behalf of the customer.

This agreement applies for the term of the usage contract, including any free trial period. It ends with the usage contract. Obligations that by their nature continue to apply (in particular confidentiality and deletion under section 10) remain in force until all customer data has been deleted.

3. Nature and purpose of the processing, type of data, data subjects

3.1 Nature and purpose

We process customer data in order to provide the Service, in particular:

  • storing audio and video files uploaded or recorded in the browser, as well as transcripts,
  • transcription and speaker separation,
  • recognition of speakers within the customer’s workspace based on voice profiles,
  • extraction of statements, summaries, semantic search and answers to questions with quotes from the archive,
  • management of users and roles in the workspace, login via email link or with a Microsoft or Google account, access via personal access tokens (MCP),
  • import of transcripts and recordings from Microsoft Teams meetings at a user’s instigation (section 3.4),
  • export and deletion at the customer’s instigation, backups, logging for the security of the Service.

3.2 Type of data

  • audio and video recordings of conversations (voice, conversation content),
  • transcripts with timestamps and speaker assignment, as well as content derived from them (statements, summaries, saved answers),
  • names and roles of interviewees and other conversation participants, as well as interview metadata (e.g. date, company, segment),
  • voice profiles: mathematical features of the voice (voice embeddings) used exclusively to recognize speakers within the customer’s workspace. They are biometric data within the meaning of Art. 9 GDPR,
  • user accounts in the workspace: email address, name (optional), role, workspace membership, access tokens (as hashes only) and, for sign-in with Microsoft or Google, the link to the provider account (provider, account ID, email address at the time of linking),
  • for the Teams import: identifiers of the Microsoft 365 organization and the Microsoft account, an encrypted, short-lived Microsoft access token, import records (meeting ID, title, date, company, status) and speaker names from Teams transcripts,
  • usage metadata: timestamps, log entries with IDs and counters, counters for limits.

Where we process account, login and billing data for our own purposes, for example to perform the contract or prevent misuse, we are the controller for that processing. Details are set out in our Privacy Notice.

3.3 Categories of data subjects

  • the customer’s users (employees and agents who use Discoverify),
  • the customer’s interviewees, such as customers, prospects or users of its products,
  • other conversation participants and persons mentioned in conversations.

3.4 Import from Microsoft Teams

The customer’s users can import transcripts and recordings of their own Teams meetings. The source is the customer’s Microsoft 365 environment; to that extent, Microsoft is not our subprocessor, and processing at Microsoft is governed by the customer’s contract with Microsoft. The import requires that a workspace admin has approved the customer’s Microsoft 365 organization and that an administrator of that organization has granted the permissions. Discoverify accesses data only with a delegated, short-lived access token of the respective user, stores no refresh token, keeps the access token encrypted and deletes it as soon as no further import by that user is pending, at the latest in the daily clean-up run after it has expired. Only the meetings selected by the user are retrieved: the Teams transcript, if available, and, on request, the recording, which is transcribed like an upload. Discoverify does not delete anything in Microsoft 365. The import record per meeting (section 3.2) is deleted together with the imported interview, and at the latest with the user account or the workspace.

4. Instructions

We process customer data only on documented instructions from the customer, including with regard to transfers to third countries, unless we are required to process it by Union or Member State law; in such a case, we inform the customer of that legal requirement before processing, unless that law prohibits such information (Art. 28(3)(a) GDPR).

The instructions are conclusively set out in the Terms of Service, this agreement and the customer’s use of the features of the Service (e.g. uploading, deleting, exporting, settings). The customer issues further instructions in text form to talktous@getdiscoverify.com. We treat instructions that go beyond the agreed scope of services as a change request.

If, in our opinion, an instruction infringes the law, we inform the customer without undue delay (Art. 28(3), third sentence, GDPR). We may suspend its execution until the matter is clarified.

5. Obligations of the customer

The customer is responsible for the lawfulness of the processing. In particular, it informs the conversation participants about the recording and, where required, obtains their consent. For voice profiles, it requires the explicit consent of the persons concerned (Art. 9(2)(a) GDPR). It informs us without undue delay if it detects errors or irregularities in the processing.

6. Confidentiality

We ensure that the persons authorized to process customer data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR). Only persons who need access to customer data to provide the Service are given such access.

7. Security of processing

We take the technical and organizational measures under Art. 32 GDPR described in Annex 1. The measures are subject to technical progress. We may replace them with equivalent or better measures; the level of protection must not decrease. The current status is also described in our Trust Center.

8. Subprocessors

The customer approves the subprocessors listed in Annex 2. We impose on them obligations equivalent to those under this agreement, in particular sufficient guarantees for appropriate technical and organizational measures (Art. 28(2) and (4) GDPR). We remain responsible to the customer for their compliance with their obligations.

The customer grants us general authorization to engage additional subprocessors or replace existing ones. We will inform the customer of any intended change at least 30 days in advance by email to the workspace admins and by updating Annex 2. The customer may object to the change in text form within 30 days of receiving the information for an important reason relating to data protection. If the parties cannot find a solution, the customer may terminate the usage contract extraordinarily as of the date the change takes effect.

Ancillary services that we use from third parties as our own services, such as telecommunications, and service providers acting as independent controllers are not considered subprocessing. As reseller (Merchant of Record), Paddle is an independent controller for payment data and does not process customer data; it is listed in Annex 2 for the sake of completeness. Nor are Microsoft and Google subprocessors as providers of sign-in with a Microsoft or Google account, or Microsoft as the provider of the customer’s Microsoft 365 environment from which Teams imports originate (section 3.4).

9. Assistance to the customer

9.1 Rights of data subjects

We assist the customer with appropriate technical and organizational measures in responding to requests from data subjects (Art. 12 to 22 GDPR, Art. 28(3)(e) GDPR). For this purpose, the Service provides features: full export, deletion of interviews with all derived data, deletion of people and voice profiles. If a data subject contacts us directly, we forward the request to the customer without undue delay and do not answer it ourselves unless instructed by the customer.

9.2 Further obligations

Taking into account the nature of the processing and the information available to us, we assist the customer in complying with the obligations under Art. 32 to 36 GDPR, in particular in a data protection impact assessment and a prior consultation of the supervisory authority (Art. 28(3)(f) GDPR). Where the assistance goes beyond providing existing information and documents, we may charge a reasonable fee.

9.3 Personal data breaches

We notify the customer of a breach of the security of customer data without undue delay, and no later than 48 hours after becoming aware of it (Art. 33(2) GDPR). The notification is sent by email to the workspace admins and contains, as far as known, the information under Art. 33(3) GDPR; we provide any missing information subsequently. We take measures without undue delay to contain the breach and mitigate its adverse effects. Notifying the supervisory authority and informing data subjects is the customer’s responsibility.

10. Deletion and return after the end of the contract

The customer can export its content in full at any time (ZIP with metadata as JSON and the media files). Voice profiles are not part of the export. After the end of the usage contract, we delete all customer data within 30 days (Art. 28(3)(g) GDPR), unless there is a legal obligation to store it. The customer should therefore export its data before the contract ends. Database backups are automatically deleted after 30 days; deleted data therefore also disappears from the backups after this further period at the latest. On request, we confirm the deletion in text form.

11. Evidence and audits

We make available to the customer all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allow for audits, including inspections (Art. 28(3)(h) GDPR). Evidence is primarily provided through written information, answers to questionnaires and the description of the measures in Annex 1 and in the Trust Center.

If this evidence is not sufficient in an individual case, the customer may carry out an on-site audit itself or through an auditor bound to confidentiality who is not a competitor of ours. The audit must be announced at least 30 days in advance, take place during normal business hours, must not disrupt operations and, except for a specific reason, takes place no more than once per calendar year. The customer bears the costs of the audit. Data centers of our subprocessors can only be audited within the scope of the audit rights they grant.

12. Place of processing and third countries

We process customer data in Germany and the European Union. A transfer to a third country takes place only through the service providers listed in Annex 2, only to the extent stated there, and only under the conditions of Art. 44 et seq. GDPR:

  • Resend (Plus Five Five, Inc., USA): Emails are sent from the EU (eu-west-1, Ireland); Resend stores metadata and logs in the USA. Resend is certified under the EU-U.S. Data Privacy Framework; in addition, the data processing agreement contains the European Commission’s Standard Contractual Clauses.
  • AssemblyAI Inc. (USA): We use only the EU endpoint; according to AssemblyAI, audio and transcripts are processed and stored in the EU. Access from the USA cannot be ruled out; AssemblyAI’s data processing agreement contains the European Commission’s Standard Contractual Clauses.
  • Amazon Web Services EMEA SARL (Luxembourg): Processing takes place in EU regions. AWS belongs to a US group; access from the USA cannot be completely ruled out. The parent company is certified under the EU-U.S. Data Privacy Framework; in addition, the European Commission’s Standard Contractual Clauses apply.
  • Paddle.com Market Limited (United Kingdom): An adequacy decision of the European Commission exists for the United Kingdom. Paddle processes payment data as an independent controller, not customer data.

13. Liability

The parties’ liability is governed by Art. 82 GDPR. Otherwise, the liability provisions of the Terms of Service (section “Liability”) also apply to this agreement, unless Art. 82 GDPR precludes this.

14. Final provisions

In the event of any conflict between this agreement and the Terms of Service, the provisions of this agreement take precedence in matters of data protection. We will communicate changes to this agreement by email at least 30 days in advance; the procedure for changes to the Terms of Service applies. Changes to Annex 2 are governed by section 8. German law applies; the place of jurisdiction is determined by the Terms of Service. Should any provision be invalid, the remaining provisions remain valid. The German version of this agreement is authoritative. Translations are provided for information only.

Contact for questions about this agreement: Make it Nice GmbH, An der Koppel 1, 53909 Zülpich, Germany, email: talktous@getdiscoverify.com, phone: +49 2252 8360-200.

Annex 1: Technical and organizational measures (Art. 32 GDPR)

This annex describes the measures that are in place. Planned measures are listed separately in the Trust Center.

1. Confidentiality

Physical access control: Servers and storage are located in data centers of Hetzner Online GmbH in Germany. Physical access is governed by Hetzner’s measures as subprocessor.

System access control:

  • Passwordless login to the Service via magic link: valid for 15 minutes, single use, at most 5 requests per email address in 15 minutes.
  • Alternatively, sign-in with Microsoft or Google (OpenID Connect, authorization code with PKCE, verification of the ID token’s signature, issuer and nonce); a first-time link to an existing account only if the provider reports the email address as verified, with an email notification to the account holder.
  • Session cookie httpOnly, Secure and SameSite=Lax; cross-origin write requests are rejected.
  • Personal access tokens (MCP) are stored only as SHA-256 hashes, are read-only, limited to the workspace and revocable at any time.
  • Server access only via SSH key, no password login, no direct root login, a single deploy user; fail2ban blocks repeated failed attempts.
  • Only ports 80, 443 and 22 are reachable from outside; database, API and workers have no public ports; the host firewall blocks everything else.

Data access control:

  • Tenant isolation in the database: every table containing customer data is restricted to its own workspace via Postgres row-level security. The application uses a database role without superuser or bypass privileges.
  • Role model in the workspace: admins manage the workspace, billing and members; members work with the archive.
  • Voice profiles are computed and stored only on our server and used only within the workspace to recognize speakers.
  • Teams import: delegated access on the user’s behalf only, no refresh token; the access token is stored encrypted with a per-workspace key. Only a workspace admin can approve a new Microsoft 365 organization; a revocation immediately deletes all access tokens stored for it.

Separation control: Logical separation of customers via row-level security (see above). Only text excerpts from transcripts are sent to language models, no audio. According to AWS, Amazon Bedrock inputs and outputs are not used to train models and are not shared with the model providers; we do not train models on customer data ourselves.

2. Integrity

Transfer control: Transmission only in encrypted form via TLS 1.2 or 1.3 with automatically renewed certificates; HTTP is redirected to HTTPS, HSTS is enabled. A Content Security Policy prevents embedding in third-party sites. Transcription via AssemblyAI’s EU endpoint, AI processing via Amazon Bedrock EU inference profiles.

Input control: An audit log records security-relevant events such as deletions and every MCP call, with IDs and counters, without conversation content or search terms. Database error logs contain no bound parameters, and therefore no quotes or email addresses from queries.

Integrity of results: Quotes in answers come verbatim from the stored transcript, not from the language model. If there is no evidence, the answer is “not found”.

3. Availability and resilience

  • The database is backed up daily and encrypted. Restoring from backup has been tested. Backups are automatically deleted after 30 days.
  • All services run in hardened containers without Linux capabilities (with a few documented exceptions), with a read-only file system and without privilege escalation.
  • Operating system security updates are installed automatically.

4. Procedures for regular review, deletion and data minimization

  • The measures were reviewed in an internal security review before launch, including on the live system. There is no external certification (such as SOC 2 or ISO 27001).
  • Interviews can be deleted with all derived data: transcript, statements, media and references in saved answers. The same applies to voice profiles and people.
  • After a voice profile or a person has been deleted, the person is no longer recognized automatically.
  • After transcription, we request deletion of the audio at AssemblyAI.
  • Privacy-friendly defaults: no analytics, tracking or advertising tools, only technically necessary cookies.

Annex 2: Subprocessors and service providers

Last updated: 27 September 2026. The same list is published in the Trust Center.

ProviderPurposeRegionRole
Hetzner Online GmbHServers, storage and backupsGermanyProcessor
AssemblyAI Inc.Transcription and speaker separationEU (EU endpoint, AWS eu-west-1 Dublin)Processor
Resend (Plus Five Five, Inc.)Sending login and system emailsData: Email address, email content including login linkSending in the EU (eu-west-1, Ireland); metadata and logs in the USAProcessor
Amazon Web Services EMEA SARL (Amazon Bedrock)AI models for summaries, answers and semantic search (Claude, Cohere Embed)EU regions (source region eu-west-1, EU inference profile)Processor
Paddle.com Market LimitedOrdering, payment, taxes, invoices (Merchant of Record)United Kingdom (adequacy decision)Independent controller for payment data