Zum Inhalt springen

Auftragsverarbeitungsvertrag

Art. 28 DSGVO

Last Updated: 16.09.2026
Version: 1.0
Effective Date: 16.09.2026


This Data Processing Agreement ("DPA") governs the processing of personal data that cronio FlexCo carries out on behalf of a customer of the timelit service. It is concluded between:

cronio FlexCo
Eileen-Gray-Gasse 2/24
1220 Vienna
Austria
Commercial Reg. Nr: FN 669759s
Data protection contact: support@timelit.ai

(the "Processor", "we", "us") and the Customer identified in accordance with Section A.2 (the "Controller", "Customer", "you").

The DPA has two operative parts:

  • Part A: Framework Terms sets out how this DPA is concluded, what it covers, and the commercial and operational matters that the Clauses in Part B leave open.
  • Part B: The Clauses reproduces the Standard Contractual Clauses between controllers and processors adopted by the European Commission in Implementing Decision (EU) 2021/915 of 4 June 2021, without modification. Under Article 28(7) GDPR, a contract based on those clauses is deemed to meet the requirements of Article 28(3) and (4) GDPR.

Annexes I to IV are an integral part of the Clauses (Clause 1(d)).

Where Part B required the Parties to choose between options or to insert a time period, the choice has been made in the published text and is marked with an editorial note in square brackets and italics. Editorial notes are not part of the clause text. No other change has been made to the clauses.


Part A: Framework Terms

A.1 Scope and application

This DPA applies to Customer Content, which means the personal data that we process on your behalf in order to provide the Service, namely:

  • mailbox content, including message bodies, subjects, headers, recipients and attachments, and mailbox settings;
  • calendar events and contacts;
  • meeting audio that you or your Users upload or record through the Service, and meeting transcripts;
  • prompts submitted to, and content generated by, the AI features of the Service; and
  • data derived from any of the above, including embeddings, summaries, categorisations and extracted entities.

This DPA does not apply to Account Data, which means data for which we determine the purposes and means and for which we act as an independent controller: account and identity records, subscription and billing data, product telemetry, security and audit logs, and data processed to prevent abuse of the Service. Our processing of Account Data is described in the Privacy Policy (Webapp).

Where the Customer is a natural person processing personal data exclusively in the course of a personal or household activity within the meaning of Article 2(2)(c) GDPR, the GDPR does not apply to that processing and this DPA does not apply. In that case we process the data as a controller under the Privacy Policy.

Where the Customer is a natural person using a mailbox provided by a third party, the Customer warrants that it is the controller of the Customer Content or is authorised by the controller to conclude this DPA in the controller's name.

A.2 Identification of the Customer

The Customer is the legal or natural person identified in the acceptance record described in Section A.4, determined as follows:

  1. where a tenant administrator has granted admin consent for the Service in a Microsoft Entra ID tenant, the organisation that owns that tenant, identified by the tenant identifier (tid claim) recorded at the time of acceptance;
  2. otherwise, where a paid subscription exists, the entity named in the billing details;
  3. otherwise, the entity on whose behalf the accepting individual declared that they were acting.

Annex I is completed by reference to that record. On request, we will provide a copy of Annex I completed with the Customer's details and countersigned by us.

A.3 Incorporation and order of precedence

This DPA forms part of the agreement between the Parties for the use of the Service. In the event of a conflict, the following order applies:

  1. Part B (the Clauses), which prevail over any related agreement between the Parties by operation of Clause 4;
  2. Annexes I to IV;
  3. Part A (these Framework Terms);
  4. the General Terms and Conditions;
  5. the Privacy Policy (Webapp).

The Privacy Policy is information provided under Articles 13 and 14 GDPR. It is not a contractual term, not an instruction within the meaning of Clause 7.1, and not a consent.

A.4 Conclusion in electronic form and the acceptance record

Article 28(9) GDPR requires this DPA to be in writing, "including in electronic form". It is concluded electronically when you accept it in the Service. The full text is made available before acceptance, acceptance is a separate, unticked affirmative action, and each accepted version is archived unchanged.

For each acceptance we record: the document type and version, a SHA-256 hash of the exact text served, the acceptance timestamp in UTC, the Microsoft user and tenant identifiers, the account identifier, the acceptance channel (sign-up, admin consent, checkout or re-acceptance), the interface language, the IP address and the user agent.

We retain this record for three years after the end of the contract on the basis of Article 6(1)(f) GDPR, for the purpose of demonstrating that a valid Article 28 contract exists. A copy of the accepted version is available for download in your account area at any time.

A.5 Authority to conclude this DPA

This DPA is concluded with the Customer, not with the individual who accepts it. Authority is established as follows.

Tenant administrator acceptance. The Service is connected to a Microsoft 365 environment through Microsoft's own consent flow. In the standard onboarding path, the Service requests access to email, calendar and meetings together. The meetings permission (OnlineMeetingTranscript.Read.All) is treated by Microsoft as requiring administrator consent, so the combined authorisation request is refused until an administrator of the Customer's tenant approves it. Only after that approval are access tokens issued and stored and does the Service begin to read Customer Content.

Where acceptance takes place in connection with that administrator approval, the accepting individual holds an administrative role in the tenant and acceptance binds the organisation that owns it. This is the ordinary way in which this DPA is concluded with an organisational Customer.

This is Microsoft's consent mechanism, not a restriction operated by us, and it depends on the permissions selected and on the Customer's own tenant settings. A User who selects a narrower set of permissions may, on a tenant that permits user consent, grant access to their mailbox without an administrator being involved. The Customer controls which consent settings apply in its tenant.

User acceptance. Any individual who accepts this DPA when first using the Service does so in the name of the Customer and warrants that they are authorised to do so. An individual who accepts without the required authority is personally liable for the resulting damage in accordance with § 1019 ABGB and shall indemnify us against third-party claims arising from the absence of a valid controller relationship.

Ratification. A subsequent grant of admin consent for the Service in the Customer's tenant, or continued use of the Service by the Customer after we have notified a tenant administrator, constitutes ratification within the meaning of § 1016 ABGB with retroactive effect.

Confirmation and suspension. We may at any time require confirmation of the acceptance from a tenant administrator of the Customer, and may suspend the affected accounts if that confirmation is not provided within a reasonable period stated in our request.

Signed form. On request we will provide this DPA as a countersigned document for signature by the Customer.

A.6 Instructions

The Customer's documented instructions under Clause 7.1 consist of:

  • this DPA including its Annexes;
  • the configuration of the Service by the Customer and its Users, including feature settings, categorisation rules, indexing scope and working hours; and
  • the actions and prompts of Users in the Service.

Additional instructions outside the standard functionality of the Service require a written agreement and may be subject to a charge. We may decline instructions that are technically infeasible. Clause 7.1(b) obliges us to inform you if we consider an instruction unlawful, and Clause 10(c) entitles us to terminate if you insist on it.

A.7 Customer obligations

The Customer is responsible for:

  • establishing and documenting a legal basis for the processing of Customer Content, including the data of persons who are not its Users;
  • providing the information required by Articles 13 and 14 GDPR to Users and, where applicable, to other data subjects;
  • informing participants of meetings that they are being recorded or transcribed and obtaining any consent required. In Austria this obligation is independent of data protection law: recording a non-public conversation without the participants' knowledge is a criminal offence under § 120 StGB;
  • consulting and, where required, obtaining the agreement of the works council before introducing the Service. Under § 96(1)(3) ArbVG, control measures and technical systems that affect human dignity require the works council's consent to be legally effective, and a system that systematically evaluates employees' email and calendar data is objectively capable of monitoring them. § 96a ArbVG applies to systems that process employee data going beyond general personal details;
  • establishing a legal basis under Article 9(2) GDPR where special categories of personal data are processed, and not connecting mailboxes whose content consists predominantly of special categories of personal data (for example occupational health, works council or legal and HR investigation mailboxes) to the Service;
  • keeping tenant permissions and User accounts accurate and revoking access when a User leaves.

A.8 Term, termination, deletion and return

This DPA takes effect on acceptance, applies for as long as we process Customer Content on your behalf, and survives termination of the subscription until all Customer Content has been deleted or returned.

On termination, Clause 10(d) applies, with the following modalities:

  • Return. For 30 days after termination the Customer may export Customer Content using the export functions of the Service. This is the return mechanism under Clause 10(d).
  • Deletion. Unless the Customer has instructed return within that period, we delete all Customer Content after it expires. Deletion is performed by an automated sweep that runs at intervals of no more than six hours across all data stores holding Customer Content, including stored meeting audio.
  • Certification. On request we confirm the deletion in writing.
  • Backups. Customer Content contained in platform backups is not available for processing and is removed on the ordinary backup rotation. Backups of the primary database are taken periodically, two copies are kept, and the retention period is eight hours. Backup storage is zone-redundant, so backups remain within the same Azure region as the live data.
  • Statutory retention. Where Union or Member State law requires us to retain data, we retain only that data, only for the required period, and only for that purpose.

A.9 Liability

This DPA does not create a separate limitation of liability. Section 11 of the General Terms and Conditions applies to contractual claims under this DPA, subject to the following:

  • it does not apply to claims of data subjects under Article 82 GDPR;
  • it does not apply to administrative fines imposed directly on a Party;
  • it does not apply where liability cannot be limited under mandatory law, including personal injury, intent, and the mandatory provisions of the Austrian Consumer Protection Act (KSchG);
  • the reduced liability cap for free plans in Section 11.2 of the General Terms and Conditions does not apply to claims arising out of the processing of Customer Content.

For claims arising out of the processing of Customer Content, our liability is limited to the fees paid by the Customer in the twelve months preceding the event giving rise to the claim.

A.10 Costs

Self-service functions of the Service, including export, deletion and the functions that support responses to data subject requests, are provided at no charge.

Assistance handled individually beyond the scope set out in Annex III, and audits beyond the allowance set out in Annex III, are charged at EUR 100 per hour against a written estimate provided in advance.

The following are never charged: notification of a personal data breach under Clause 9; the information we are required to make available under Clause 7.6(c) as part of the standard information package; and any assistance necessitated by a breach on our side.

A.11 Changes and versioning

  • Part B is frozen. We will not amend the Clauses. Clause 2(a) permits changes only to add or update information in the Annexes.
  • Annex IV may be changed on 30 days' notice with the right to object set out in that Annex.
  • Annexes II and III may be changed on 30 days' notice. Annex III may only be changed in a way that maintains or improves the level of security, as required by Clause 7.4(a).
  • Part A may be changed on 30 days' notice. A material change requires your active acceptance of the new version. Because Article 28(9) GDPR requires this DPA to be in writing, an amendment requires the same form; the passive acceptance mechanism in Section 14.2 of the General Terms and Conditions does not apply to this DPA.
  • Changes must be objectively justified. If you do not accept a material change, either Party may terminate the affected part of the Service with effect from the date the change takes effect, and we will refund prepaid fees pro rata.

A.12 Confidentiality and personnel

All personnel with access to production systems are bound by written confidentiality undertakings that survive the end of their engagement. Access is granted on a least-privilege basis, only to the extent necessary to implement, manage and monitor the contract, and is withdrawn on a change of role or on departure.

A.13 Contact

All notices under this DPA, including inquiries under Clause 7.6(b), notifications of a personal data breach, data subject requests forwarded under Clause 8(a) and accession notices under Clause 5, are to be sent to support@timelit.ai.


Part B: The Clauses

Standard Contractual Clauses between controllers and processors under Article 28(7) of Regulation (EU) 2016/679, as set out in the Annex to Commission Implementing Decision (EU) 2021/915 of 4 June 2021 (OJ L 199, 7.6.2021, p. 18). Reproduced without modification. Text in square brackets and italics is an editorial note recording a choice the Clauses require the Parties to make; it is not part of the clause text.

SECTION I

Clause 1: Purpose and scope

[The Parties have selected OPTION 1.]

(a) The purpose of these Standard Contractual Clauses (the Clauses) is to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

(b) The controllers and processors listed in Annex I have agreed to these Clauses in order to ensure compliance with Article 28(3) and (4) of Regulation (EU) 2016/679 and/or Article 29(3) and (4) of Regulation (EU) 2018/1725.

(c) These Clauses apply to the processing of personal data as specified in Annex II.

(d) Annexes I to IV are an integral part of the Clauses.

(e) These Clauses are without prejudice to obligations to which the controller is subject by virtue of Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725.

(f) These Clauses do not by themselves ensure compliance with obligations related to international transfers in accordance with Chapter V of Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725.

Clause 2: Invariability of the Clauses

(a) The Parties undertake not to modify the Clauses, except for adding information to the Annexes or updating information in them.

(b) This does not prevent the Parties from including the standard contractual clauses laid down in these Clauses in a broader contract, or from adding other clauses or additional safeguards provided that they do not directly or indirectly contradict the Clauses or detract from the fundamental rights or freedoms of data subjects.

Clause 3: Interpretation

(a) Where these Clauses use the terms defined in Regulation (EU) 2016/679 or Regulation (EU) 2018/1725 respectively, those terms shall have the same meaning as in that Regulation.

(b) These Clauses shall be read and interpreted in the light of the provisions of Regulation (EU) 2016/679 or Regulation (EU) 2018/1725 respectively.

(c) These Clauses shall not be interpreted in a way that runs counter to the rights and obligations provided for in Regulation (EU) 2016/679 / Regulation (EU) 2018/1725 or in a way that prejudices the fundamental rights or freedoms of the data subjects.

Clause 4: Hierarchy

In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties existing at the time when these Clauses are agreed or entered into thereafter, these Clauses shall prevail.

Clause 5: Docking clause

[This clause is optional. The Parties have included it. Section A.2 of Part A sets out how an acceding entity is identified and how our agreement under point (a) is given.]

(a) Any entity that is not a Party to these Clauses may, with the agreement of all the Parties, accede to these Clauses at any time as a controller or a processor by completing the Annexes and signing Annex I.

(b) Once the Annexes in (a) are completed and signed, the acceding entity shall be treated as a Party to these Clauses and have the rights and obligations of a controller or a processor, in accordance with its designation in Annex I.

(c) The acceding entity shall have no rights or obligations resulting from these Clauses from the period prior to becoming a Party.

SECTION II: OBLIGATIONS OF THE PARTIES

Clause 6: Description of processing(s)

The details of the processing operations, in particular the categories of personal data and the purposes of processing for which the personal data is processed on behalf of the controller, are specified in Annex II.

Clause 7: Obligations of the Parties

7.1. Instructions

(a) The processor shall process personal data only on documented instructions from the controller, unless required to do so by Union or Member State law to which the processor is subject. In this case, the processor shall inform the controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. Subsequent instructions may also be given by the controller throughout the duration of the processing of personal data. These instructions shall always be documented.

(b) The processor shall immediately inform the controller if, in the processor's opinion, instructions given by the controller infringe Regulation (EU) 2016/679 / Regulation (EU) 2018/1725 or the applicable Union or Member State data protection provisions.

7.2. Purpose limitation

The processor shall process the personal data only for the specific purpose(s) of the processing, as set out in Annex II, unless it receives further instructions from the controller.

7.3. Duration of the processing of personal data

Processing by the processor shall only take place for the duration specified in Annex II.

7.4. Security of processing

(a) The processor shall at least implement the technical and organisational measures specified in Annex III to ensure the security of the personal data. This includes protecting the data against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to the data (personal data breach). In assessing the appropriate level of security, the Parties shall take due account of the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risks involved for the data subjects.

(b) The processor shall grant access to the personal data undergoing processing to members of its personnel only to the extent strictly necessary for implementing, managing and monitoring of the contract. The processor shall ensure that persons authorised to process the personal data received have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

7.5. Sensitive data

If the processing involves personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person's sex life or sexual orientation, or data relating to criminal convictions and offences ("sensitive data"), the processor shall apply specific restrictions and/or additional safeguards.

7.6. Documentation and compliance

(a) The Parties shall be able to demonstrate compliance with these Clauses.

(b) The processor shall deal promptly and adequately with inquiries from the controller about the processing of data in accordance with these Clauses.

(c) The processor shall make available to the controller all information necessary to demonstrate compliance with the obligations that are set out in these Clauses and stem directly from Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725. At the controller's request, the processor shall also permit and contribute to audits of the processing activities covered by these Clauses, at reasonable intervals or if there are indications of non-compliance. In deciding on a review or an audit, the controller may take into account relevant certifications held by the processor.

(d) The controller may choose to conduct the audit by itself or mandate an independent auditor. Audits may also include inspections at the premises or physical facilities of the processor and shall, where appropriate, be carried out with reasonable notice.

(e) The Parties shall make the information referred to in this Clause, including the results of any audits, available to the competent supervisory authority/ies on request.

7.7. Use of sub-processors

[The Parties have selected OPTION 2 and have specified a period of 30 days. Annex IV sets out how we inform you, how you may object, and what happens if you do.]

(a) GENERAL WRITTEN AUTHORISATION: The processor has the controller's general authorisation for the engagement of sub-processors from an agreed list. The processor shall specifically inform in writing the controller of any intended changes of that list through the addition or replacement of sub-processors at least 30 days in advance, thereby giving the controller sufficient time to be able to object to such changes prior to the engagement of the concerned sub-processor(s). The processor shall provide the controller with the information necessary to enable the controller to exercise the right to object.

(b) Where the processor engages a sub-processor for carrying out specific processing activities (on behalf of the controller), it shall do so by way of a contract which imposes on the sub-processor, in substance, the same data protection obligations as the ones imposed on the data processor in accordance with these Clauses. The processor shall ensure that the sub-processor complies with the obligations to which the processor is subject pursuant to these Clauses and to Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725.

(c) At the controller's request, the processor shall provide a copy of such a sub-processor agreement and any subsequent amendments to the controller. To the extent necessary to protect business secret or other confidential information, including personal data, the processor may redact the text of the agreement prior to sharing the copy.

(d) The processor shall remain fully responsible to the controller for the performance of the sub-processor's obligations in accordance with its contract with the processor. The processor shall notify the controller of any failure by the sub-processor to fulfil its contractual obligations.

(e) The processor shall agree a third party beneficiary clause with the sub-processor whereby - in the event the processor has factually disappeared, ceased to exist in law or has become insolvent - the controller shall have the right to terminate the sub-processor contract and to instruct the sub-processor to erase or return the personal data.

7.8. International transfers

(a) Any transfer of data to a third country or an international organisation by the processor shall be done only on the basis of documented instructions from the controller or in order to fulfil a specific requirement under Union or Member State law to which the processor is subject and shall take place in compliance with Chapter V of Regulation (EU) 2016/679 or Regulation (EU) 2018/1725.

(b) The controller agrees that where the processor engages a sub-processor in accordance with Clause 7.7. for carrying out specific processing activities (on behalf of the controller) and those processing activities involve a transfer of personal data within the meaning of Chapter V of Regulation (EU) 2016/679, the processor and the sub-processor can ensure compliance with Chapter V of Regulation (EU) 2016/679 by using standard contractual clauses adopted by the Commission in accordance with of Article 46(2) of Regulation (EU) 2016/679, provided the conditions for the use of those standard contractual clauses are met.

Clause 8: Assistance to the controller

(a) The processor shall promptly notify the controller of any request it has received from the data subject. It shall not respond to the request itself, unless authorised to do so by the controller.

(b) The processor shall assist the controller in fulfilling its obligations to respond to data subjects' requests to exercise their rights, taking into account the nature of the processing. In fulfilling its obligations in accordance with (a) and (b), the processor shall comply with the controller's instructions.

(c) In addition to the processor's obligation to assist the controller pursuant to Clause 8(b), the processor shall furthermore assist the controller in ensuring compliance with the following obligations, taking into account the nature of the data processing and the information available to the processor:

[The Parties have selected OPTION 1 in point (4).]

(1) the obligation to carry out an assessment of the impact of the envisaged processing operations on the protection of personal data (a 'data protection impact assessment') where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons;

(2) the obligation to consult the competent supervisory authority/ies prior to processing where a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk;

(3) the obligation to ensure that personal data is accurate and up to date, by informing the controller without delay if the processor becomes aware that the personal data it is processing is inaccurate or has become outdated;

(4) the obligations in Article 32 of Regulation (EU) 2016/679.

(d) The Parties shall set out in Annex III the appropriate technical and organisational measures by which the processor is required to assist the controller in the application of this Clause as well as the scope and the extent of the assistance required.

Clause 9: Notification of personal data breach

In the event of a personal data breach, the processor shall cooperate with and assist the controller for the controller to comply with its obligations under Articles 33 and 34 of Regulation (EU) 2016/679 or under Articles 34 and 35 of Regulation (EU) 2018/1725, where applicable, taking into account the nature of processing and the information available to the processor.

9.1 Data breach concerning data processed by the controller

In the event of a personal data breach concerning data processed by the controller, the processor shall assist the controller:

[The Parties have selected OPTION 1 in points (b) and (c).]

(a) in notifying the personal data breach to the competent supervisory authority/ies, without undue delay after the controller has become aware of it, where relevant/(unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons);

(b) in obtaining the following information which, pursuant to Article 33(3) of Regulation (EU) 2016/679, shall be stated in the controller's notification, and must at least include:

(1) the nature of the personal data including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;

(2) the likely consequences of the personal data breach;

(3) the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.

(c) in complying, pursuant to Article 34 of Regulation (EU) 2016/679, with the obligation to communicate without undue delay the personal data breach to the data subject, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons.

9.2 Data breach concerning data processed by the processor

In the event of a personal data breach concerning data processed by the processor, the processor shall notify the controller without undue delay after the processor having become aware of the breach. Such notification shall contain, at least:

(a) a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and data records concerned);

(b) the details of a contact point where more information concerning the personal data breach can be obtained;

(c) its likely consequences and the measures taken or proposed to be taken to address the breach, including to mitigate its possible adverse effects.

Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.

The Parties shall set out in Annex III all other elements to be provided by the processor when assisting the controller in the compliance with the controller's obligations under Articles 33 and 34 of Regulation (EU) 2016/679.

SECTION III: FINAL PROVISIONS

Clause 10: Non-compliance with the Clauses and termination

(a) Without prejudice to any provisions of Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725, in the event that the processor is in breach of its obligations under these Clauses, the controller may instruct the processor to suspend the processing of personal data until the latter complies with these Clauses or the contract is terminated. The processor shall promptly inform the controller in case it is unable to comply with these Clauses, for whatever reason.

(b) The controller shall be entitled to terminate the contract insofar as it concerns processing of personal data in accordance with these Clauses if:

(1) the processing of personal data by the processor has been suspended by the controller pursuant to point (a) and if compliance with these Clauses is not restored within a reasonable time and in any event within one month following suspension;

(2) the processor is in substantial or persistent breach of these Clauses or its obligations under Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725;

(3) the processor fails to comply with a binding decision of a competent court or the competent supervisory authority/ies regarding its obligations pursuant to these Clauses or to Regulation (EU) 2016/679 and/or Regulation (EU) 2018/1725.

(c) The processor shall be entitled to terminate the contract insofar as it concerns processing of personal data under these Clauses where, after having informed the controller that its instructions infringe applicable legal requirements in accordance with Clause 7.1 (b), the controller insists on compliance with the instructions.

(d) Following termination of the contract, the processor shall, at the choice of the controller, delete all personal data processed on behalf of the controller and certify to the controller that it has done so, or, return all the personal data to the controller and delete existing copies unless Union or Member State law requires storage of the personal data. Until the data is deleted or returned, the processor shall continue to ensure compliance with these Clauses.


Annex I: List of Parties

Controller

The Customer, as identified in accordance with Section A.2 of Part A. The identity of the Customer, the tenant identifier and the date of accession are recorded in the acceptance record described in Section A.4. On request we will issue this Annex completed with the Customer's details and countersigned.

The Customer has not appointed a data protection officer for the purposes of this DPA unless it notifies us of one at support@timelit.ai.

Processor

Name: cronio FlexCo
Address: Eileen-Gray-Gasse 2/24, 1220 Vienna, Austria
Commercial Register: FN 669759s
Contact: data protection contact, support@timelit.ai
Accession date: the date of acceptance recorded under Section A.4

cronio FlexCo has not appointed a data protection officer. It is not required to do so under Article 37 GDPR and does not hold itself out as having one.

The competent supervisory authority for the Processor is the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna.


Annex II: Description of the Processing

Categories of data subjects whose personal data is processed

  1. Users: the natural persons authorised by the Customer to use the Service with a Microsoft Work or School account.
  2. Correspondents of Users: senders and recipients of email processed through the Service, including persons outside the Customer's organisation who have never interacted with the Service.
  3. Meeting and event participants: attendees and participants of calendar events and meetings, including external participants.
  4. Persons referred to in content: any natural person named or described in message bodies, attachments, calendar entries, meeting audio or transcripts.

Categories of personal data processed

Data is obtained from the Customer's Microsoft 365 environment through Microsoft Graph, on the basis of the permissions the Customer or its tenant administrator grants. The categories correspond to the permission scopes actually requested by the Service:

Source Microsoft Graph scope Personal data processed
Identity User.Read Name, email address, Microsoft user identifier, tenant identifier, job title, language, time zone
Mailbox Mail.ReadWrite, MailboxSettings.ReadWrite Message bodies, subjects, headers, sender and recipient addresses including copy recipients, flags and folder assignment, attachments and text extracted from them, mailbox settings
Calendar Calendars.ReadWrite Events, titles, descriptions, locations, attendees, recurrence, free/busy information, working hours
Contacts and relationships Contacts.ReadWrite, People.Read Contact records and relationships inferred from communication patterns
Meetings OnlineMeetings.ReadWrite, OnlineMeetingTranscript.Read.All Meeting metadata and Microsoft Teams meeting transcripts

All of the above are delegated permissions granted by the Customer or its tenant administrator, and they are the only permissions the Service holds in the Customer's tenant. The Service does not hold the Mail.Send permission for the Customer's mailboxes; drafts are written to the User's Drafts folder and only the User sends them.

Messages the Service itself sends, such as briefings and account notifications, are sent from mailboxes in cronio FlexCo's own Microsoft tenant, using application permissions held in that tenant. The personal data involved is the recipient's address and the content of the message.

Derived data. The Service generates further personal data from the above: vector embeddings of email, attachment text and transcripts (model text-embedding-3-small, 1536 dimensions), AI-generated summaries, categorisations and extracted entities, and the prompts and model outputs of the assistant, which are stored. Embeddings and summaries derived from personal data are themselves personal data and are subject to the same retention and deletion rules as the content they are derived from.

Meeting audio. Two distinct paths exist and they differ in their sub-processors and in what is stored:

  1. Microsoft Teams meetings. The transcript is retrieved from Microsoft Graph after the meeting. The Service does not join the call and does not record audio.
  2. Uploaded or browser-recorded audio. Audio or video provided by the User is uploaded to our Azure Blob Storage and transcribed by Azure AI Speech with speaker diarization. The audio file is stored until the User deletes the recording or the account is deleted.

Speaker diarization separates speakers within a single recording. It does not produce a voice template and is not used to uniquely identify a natural person. It therefore does not constitute the processing of biometric data within the meaning of Article 4(14) GDPR.

Sensitive data processed and applied restrictions or safeguards

The Service does not seek and does not require special categories of personal data. Because it processes mailboxes, calendars and meeting content, however, such data may occur incidentally, for example in sick notes, correspondence with employee representatives, or references to trade union membership.

Applied restrictions and safeguards: special categories are not sought, not separately indexed, not used for classification or profiling, and not used to train any model. Content is held in a logical partition per connected mailbox, is not accessible across customers, is encrypted in transit and at rest, and is accessible to our personnel only under the conditions in Annex III.

The Customer's corresponding obligations are set out in Section A.7 of Part A: establishing a basis under Article 9(2) GDPR, typically Article 9(2)(b) in conjunction with § 11 DSG in Austria, and not connecting mailboxes whose content consists predominantly of special categories of personal data.

Nature of the processing

Collection from Microsoft Graph, storage, structuring, indexing including the generation of vector embeddings, analysis and categorisation, generation of drafts and summaries by large language models, transcription of audio, retrieval in response to User queries, transmission to sub-processors as set out in Annex IV, and erasure.

Purposes for which the personal data is processed on behalf of the controller

Solely to provide the Service to the Customer in accordance with the Customer's instructions under Section A.6: categorising and prioritising email, drafting replies, proposing and scheduling meetings, transcribing and summarising meetings, generating briefings, and answering User queries over the indexed content.

We do not process Customer Content for our own purposes. We do not use Customer Content to train, retrain or improve any model, whether our own or a third party's. Our sub-processor Microsoft is contractually bound not to use prompts, completions or embeddings to train its foundation models.

Accuracy. Outputs generated by the AI features are drafts for human review. They are not held out as accurate statements of fact about any person and are not written back to any system of record without an action by a User. Where we become aware that personal data we process is inaccurate or outdated, we inform the Customer in accordance with Clause 8(c)(3).

Location of processing and international transfers

All Customer Content at rest is stored in the Microsoft Azure region Sweden Central.

The Service uses five Azure OpenAI model deployments: gpt-4o-mini, gpt-5, gpt-5-mini, gpt-5.6-terra and text-embedding-3-small.

Inference may take place outside the EEA. All five deployments are configured with the GlobalStandard deployment type. According to Microsoft, for a deployment of this type prompts and responses may be processed in any geography in which the relevant model is deployed, while data stored at rest remains in the designated geography. Any resulting transfer to a third country is covered by the standard contractual clauses adopted under Article 46(2) GDPR that form part of the Microsoft Products and Services Data Protection Addendum, as contemplated by Clause 7.8(b).

Abuse monitoring by Microsoft. By default, the Azure OpenAI service stores a sample of prompts and completions for up to 30 days where its automated systems flag possible abuse, so that the sample can be reviewed. Review is automated by default; authorised Microsoft employees may review flagged data where necessary. The store is located in the geography of our Azure resource, and for models deployed in the EEA the authorised reviewers are located in the EEA.

Duration of the processing

For the duration of the Customer's subscription, and thereafter for the export and deletion period set out in Section A.8 of Part A: a 30-day period during which the Customer may export Customer Content, after which all Customer Content is deleted by an automated sweep that runs at intervals of no more than six hours.

Processing by sub-processors

Subject matter, nature and duration of the processing carried out by each sub-processor are set out in Annex IV.


Annex III: Technical and Organisational Measures

The Clauses require these measures to be described concretely and not in a generic manner. What follows describes the measures as they are implemented at the date of this version. We keep this Annex current and, under Clause 7.4(a), may change it only in a way that maintains or improves the level of security.

All Customer Content is processed and stored on Microsoft Azure in the region Sweden Central. cronio FlexCo stores no Customer Content on its own premises or equipment.

Measures of pseudonymisation and encryption of personal data

Data in transit is protected by TLS. HTTPS is enforced on the application, and the storage account requires a minimum of TLS 1.2. Data at rest, including the access tokens used to connect to Microsoft 365, is encrypted by the Azure platform with AES-256 using Microsoft-managed keys.

Measures for ensuring ongoing confidentiality, integrity, availability and resilience of processing systems and services

Customer Content is separated logically, by one database partition per connected mailbox, keyed on the combination of Microsoft user identifier and tenant identifier. This is logical separation: there is no separate encryption key per customer and no physical separation. Organisations in the Service exist for billing and membership and are not a security boundary: they do not grant an administrator access to another member's mailbox content.

The application runs as a single instance of an Azure App Service with a managed TLS certificate. Availability is monitored through Azure Application Insights.

Measures for ensuring the ability to restore the availability and access to personal data in a timely manner

Data is held in Azure Cosmos DB and Azure Blob Storage. The database is backed up periodically, two copies are kept, and the retention period is eight hours. Backup storage is zone-redundant, so backups remain within the same Azure region as the live data. Blob storage for meeting audio is configured as locally redundant storage within Sweden Central.

Processes for regularly testing, assessing and evaluating the effectiveness of the measures

Changes are reviewed before deployment and deployed through an audited pipeline. We review this Annex and the underlying measures whenever the architecture of the Service changes materially, and at least once a year.

Measures for user identification and authorisation

Users authenticate exclusively with a Microsoft Work or School account through Microsoft Entra ID using the OAuth 2.0 authorisation code flow. cronio does not store or verify passwords. Access to Microsoft 365 data requires the Customer's or its tenant administrator's grant of the permission scopes listed in Annex II, which the Customer can revoke at any time in its tenant. Sessions expire after seven days.

Measures for the protection of data during transmission

All connections between the application, the data stores and the sub-processor APIs use HTTPS/TLS. No unencrypted transport path exists.

Measures for the protection of data during storage

Storage is in Azure Cosmos DB (application data, email and calendar content, transcripts, summaries, embeddings, chat history) and Azure Blob Storage (meeting audio, in a container that is not publicly accessible; uploads use short-lived signed URLs that expire). Both are encrypted at rest as described above. Access from the application to the data stores and to the Azure AI services is authenticated and encrypted in transit.

Measures for ensuring physical security of locations at which personal data are processed

Physical security is provided entirely by Microsoft for the Azure region Sweden Central and is covered by Microsoft's ISO/IEC 27001 certification and SOC 2 reporting. cronio holds no Customer Content on its own premises.

Measures for ensuring events logging

Application logs are written as structured events and collected in Azure Log Analytics with a retention period of 30 days, after which they are deleted. Telemetry ingestion is authenticated by managed identity and local authentication keys are disabled. Secrets and API keys are redacted before logging. Application logs record technical events and identifiers; they are not designed to carry the content of messages, calendar entries or transcripts.

Measures for ensuring system configuration, including default configuration

Infrastructure is defined declaratively as code (OpenTofu) and applied through a deployment pipeline. Deployment to Azure authenticates through GitHub OIDC federation; no long-lived Azure credential is stored in the source repository. Deployment to production is a manually triggered workflow against a protected environment.

Measures for internal IT and IT security governance and management

cronio FlexCo is a small company and does not operate a formally certified information security management system. All personnel with access to production systems are bound by written confidentiality undertakings, access is granted on a least-privilege basis, and it is withdrawn on a change of role or departure.

Measures for certification/assurance of processes and products

cronio FlexCo holds no certification. It is not certified under ISO/IEC 27001, has not undergone a SOC 2 examination, and does not participate in an approved certification mechanism under Article 42 GDPR. Any statement to the contrary is incorrect.

For the infrastructure layer, which cronio does not operate, the relevant certifications are those held by Microsoft for Azure, which we make available under the information package below. Clause 7.6(c) expressly permits the Controller to take those certifications into account when deciding on a review or audit.

Measures for ensuring data minimisation

Only the Microsoft Graph permission scopes required for the features the Customer activates are requested. Attendees' calendars are not queried when the Service proposes meeting times; only the signed-in User's own calendar and working hours are used.

Measures for ensuring data quality

Content is read from the Customer's Microsoft 365 environment and is not altered there by the Service except where a User performs an action. AI-generated output is presented as a draft for review, as described in Annex II.

Measures for ensuring limited data retention

Customer Content is retained while the account is active and is deleted in accordance with Section A.8 of Part A. Deletion of an account is scheduled with a 30-day window during which the Customer can cancel it; an automated sweep running at intervals of no more than six hours then deletes the data across all stores holding Customer Content, including the account's stored meeting audio.

A User can remove individual recordings, messages and conversations from the Service at any time. Meeting audio that a User has uploaded or recorded is not subject to a time-based expiry: the stored audio file is deleted when the account is deleted.

Measures for ensuring accountability

The acceptance record described in Section A.4 evidences the conclusion of this DPA. Sub-processor engagements are documented in Annex IV. This Annex, Annex II and Annex IV together document the processing we carry out on the Controller's behalf, and we make them available to a competent supervisory authority on request.

Measures for allowing data portability and ensuring erasure

The Customer can export Customer Content through the Service and can trigger deletion of individual items or of the entire account, as described above. On request we confirm deletion in writing.

Assistance to the Controller (Clause 8(d))

We assist the Controller as follows.

Data subject requests (Clause 8(a) and (b)). A request received by us is forwarded to the Controller without undue delay and is not answered by us. The Service provides functions through which the Controller can access, correct, export and delete Customer Content itself; this is the primary form of assistance and is provided at no charge. Where a request cannot be fulfilled through those functions, we assist individually within the scope set out below.

Data protection impact assessments and prior consultation (Clause 8(c)(1) and (2)). We provide this Annex, Annex II and Annex IV, which together contain the information about the nature, scope, context and purposes of the processing that an assessment requires, and we answer written questions about them.

Accuracy (Clause 8(c)(3)). Where we become aware that personal data we process is inaccurate or outdated, we inform the Controller without delay.

Security (Clause 8(c)(4)). We maintain the measures set out in this Annex and inform the Controller of material changes to them in accordance with Section A.11.

Scope and extent. Tier 1 and the breach-notification obligations below are provided at no charge and without limit. Individually handled assistance beyond that is provided at no charge up to eight hours per twelve-month period per Customer group, and thereafter on the terms in Section A.10.

Audits and inspections (Clause 7.6)

The Controller's rights under Clause 7.6 apply in full. The following modalities apply to their exercise. They reflect that the systems which hold Customer Content are operated by Microsoft, and that cronio cannot grant access to Microsoft's facilities.

Tier 1: Information package. On request, at no charge, within 30 days: this Annex in its current version; Annex IV and the sub-processor agreements in the form permitted by Clause 7.7(c); Microsoft's current ISO/IEC 27001 certificate, SOC 2 report and data protection documentation for Azure; a description of the deletion procedure; a summary of the breach register; and our completed standard security questionnaire.

Tier 2: Written questions and a remote session. Once per twelve-month period, within the free allowance stated above.

Tier 3: Audit or inspection. The Controller may conduct an audit itself or mandate an independent auditor, once per twelve-month period and at any time where there are indications of non-compliance or where a competent supervisory authority so requires by binding decision. Modalities: at least 30 days' notice except where a supervisory authority requires otherwise; during business hours; the auditor is bound by confidentiality and is not a competitor of cronio; no access to other customers' data or to systems containing it; no access to Microsoft's facilities, which we cannot grant. The Controller bears its own costs and those of its auditor; our own effort is charged in accordance with Section A.10 except where the audit establishes a material breach on our side, in which case we bear our own costs and remediate the finding.

We make the information referred to in Clause 7.6, including the results of any audits, available to the competent supervisory authority on request.

Elements provided on notification of a personal data breach (Clause 9.2)

In addition to the elements required by Clause 9.2, our notification will state, as far as known at the time: the time the breach occurred and the time we became aware of it; the systems and data categories affected; whether Customer Content was affected and, if so, which categories; the number of Users and, as far as determinable, of other data subjects affected; the measures already taken to contain the breach; our assessment of the likely consequences; a named contact for further information; and the further information the Controller requires for a notification under Article 33(3) GDPR. We provide subsequent information as it becomes available without undue delay.


Annex IV: List of Sub-processors

The Controller has given a general written authorisation under Clause 7.7 Option 2 for the engagement of the sub-processors listed below and for changes to that list, subject to the notification and objection procedure in this Annex.

The authoritative list is published at Sub-processors. The table below is a snapshot as at the date of this version.

Sub-processor Entity and location Processing carried out Data categories Duration
Microsoft Microsoft Ireland Operations Ltd., Ireland, with processing in Azure Sweden Central. Azure OpenAI inference may take place in other geographies, see Annex II. Hosting of the application and all data stores (Azure App Service, Cosmos DB, Blob Storage); retrieval of Microsoft 365 data through Microsoft Graph; AI inference and embeddings (Azure OpenAI); transcription of uploaded audio (Azure AI Speech); telemetry and logs (Application Insights, Log Analytics) All categories of Customer Content set out in Annex II For the term of the DPA
Stripe Stripe Payments Europe Ltd., Ireland Payment processing and subscription billing Account and billing data only. No Customer Content. For the term of the DPA and any statutory retention period

Apache Tika, used to extract text from attachments, runs as a container alongside the application within the same Azure App Service and under our sole control. It is a component of the Service, not a sub-processor, and transmits no data to any third party.

Notification of changes

We inform the Customer of any intended addition or replacement of a sub-processor in writing at least 30 days in advance, by email to the administrative or billing contact registered for the account and by a notice in the Service. Publication on the sub-processor page alone is not treated as notification for the purposes of Clause 7.7(a). The notice states the identity and place of establishment of the sub-processor, the processing it will carry out and the data categories involved, so that the Customer can decide whether to object.

Emergency substitution. Where a sub-processor fails, ceases operations, becomes insolvent or has to be replaced for security reasons, we may engage a replacement immediately and will notify the Customer as soon as possible. The right to object then applies after the fact.

Right to object

The Customer may object to a change within the 30-day period on reasonable grounds relating to data protection. We will then either not engage the sub-processor, or offer a workaround that avoids the processing objected to. If neither is possible, either Party may terminate the part of the Service affected with effect from the date the change would take effect, and we will refund prepaid fees for that part pro rata.

We say plainly that for a sub-processor on which the Service depends, in particular Microsoft, the third option is the only realistic one: the Service cannot be provided without Azure and Azure OpenAI.

Third party beneficiary clause under Clause 7.7(e)

Clause 7.7(e) requires us to agree with each sub-processor that, if we disappear, cease to exist in law or become insolvent, the Controller may terminate the sub-processor contract directly and instruct the sub-processor to erase or return the personal data.

We contract with Microsoft and Stripe on their standard data protection terms, which do not contain such a clause and which they do not negotiate. We disclose this rather than warrant something we cannot deliver. We will pass on the substance of the obligation to the extent a sub-processor accepts it, and will do so with any sub-processor we engage in future where it is negotiable. In the insolvency scenario the Controller's practical protection derives from its own direct contractual relationship with Microsoft for its Microsoft 365 tenant, from which the Customer Content originates, and from Clause 10(d).


This Agreement incorporates the Standard Contractual Clauses set out in the Annex to Commission Implementing Decision (EU) 2021/915 of 4 June 2021 (OJ L 199, 7.6.2021, p. 18).

Wählen Sie, ob Analyse-Cookies erlaubt werden. Essenzielle Cookies sind immer aktiv.