Data Processing Agreement – Axilero

Last updated: 31-08-2026

This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions between Axilero (“Processor”) and the customer using Axilero’s transcription service (“Controller”), and applies whenever the Controller uses the Service to process personal data relating to third parties on the Controller’s behalf, within the scope of Article 28 of Regulation (EU) 2016/679 (“GDPR”). It applies automatically upon acceptance of the Terms — no signature is required.

1. Roles of the parties

For personal data contained in content the Controller uploads to the Service (audio, video, and the resulting transcripts and summaries, together “Customer Content”), the customer acts as data controller and Axilero acts as data processor.

For account data (the customer’s own email address, login credentials, and billing information), Axilero acts as an independent controller as described in our Privacy Notice.

2. Details of the processing

  • Subject matter: automated transcription of audio and video content, and, where enabled by the Controller, speaker labelling, translation, and AI-generated summaries.
  • Duration: for the duration of the Controller’s use of the Service, until deletion of the relevant content or the account.
  • Nature and purpose: converting spoken audio into text on the Controller’s documented instructions, which are constituted by the Controller’s use of the Service’s features.
  • Categories of data: any personal data contained in uploaded recordings, which may include voice recordings, names, contact details, and — depending on the recording’s content — special categories of personal data.
  • Categories of data subjects: speakers in and persons mentioned in the uploaded recordings, as determined by the Controller.

3. Obligations of the Processor

Axilero shall:

  • process Customer Content only on the Controller’s documented instructions, unless required otherwise by EU or member state law, in which case Axilero will inform the Controller unless legally prohibited from doing so;
  • ensure that persons authorised to process Customer Content are bound by confidentiality obligations;
  • implement appropriate technical and organisational measures as required by Article 32 GDPR (see Section 5);
  • assist the Controller, insofar as reasonably possible, in responding to data subject requests under Chapter III GDPR;
  • assist the Controller in ensuring compliance with Articles 32–36 GDPR, taking into account the nature of the processing and the information available to Axilero;
  • notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Content;
  • delete Customer Content at the end of the provision of the Service as described in Section 6;
  • make available to the Controller information reasonably necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality obligations.

4. Where processing takes place

All AI inference — speech-to-text transcription and AI summarisation — is performed on infrastructure operated by Axilero within the EU. Customer Content is never sent to third-party AI providers (such as OpenAI, Google, or other external model APIs).

5. Technical and organisational measures

  • All data in transit is encrypted using TLS.
  • Uploaded audio and video files are processed temporarily and automatically deleted after transcription completes; they are not retained after the job finishes.
  • Transcripts and summaries are stored in the Controller’s account until the Controller deletes them or the account.
  • Access to production systems is restricted to authorised personnel.
  • Processing of Customer Content takes place on servers located in the EU.

6. Deletion and return

  • Uploaded audio and video files are deleted automatically after processing.
  • Transcripts and summaries can be deleted by the Controller at any time from within the Service, and can be exported before deletion.
  • Upon account deletion, all remaining Customer Content is deleted.
  • Deleted transcripts and summaries may persist in routine database backups for up to 35 days after deletion, after which they are permanently removed. Backups are stored within the EU and are not used for any purpose other than disaster recovery.

7. Sub-processors

The Controller grants Axilero general authorisation to engage the sub-processors listed below. Axilero will inform the Controller of intended changes to this list by updating this page, giving the Controller the opportunity to object to such changes.

  • Contabo GmbH (Germany) — hosting of the application and storage of transcripts. Processing location: EU.
  • Paddle.com Market Ltd (United Kingdom) — merchant of record for payment processing. Paddle does not process Customer Content.
  • Resend (United States) — delivery of transactional emails (account and job notifications). Resend does not process Customer Content. Transfers are safeguarded by standard contractual clauses.
  • Cloudflare, Inc. (United States) — bot protection on account signup and the contact form (Cloudflare Turnstile). Cloudflare does not process Customer Content. Transfers are safeguarded by standard contractual clauses.

Where a sub-processor processes personal data, Axilero imposes data protection obligations on it that are consistent with this DPA.

8. International transfers

Customer Content is processed and stored within the EU. Limited personal data other than Customer Content (such as the Controller’s email address) may be transferred outside the EU/EEA via the sub-processors listed above, in each case subject to appropriate safeguards under Chapter V GDPR, such as standard contractual clauses.

9. Controller responsibilities

The Controller is responsible for:

  • ensuring it has a lawful basis for processing the personal data contained in uploaded content;
  • providing any required information to, and obtaining any required consents from, data subjects;
  • not uploading content it is not legally permitted to process through a processor.

10. Liability and precedence

The liability provisions of the Terms & Conditions apply to this DPA. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails.

11. Governing law

This DPA is governed by the laws of Denmark, without prejudice to mandatory provisions of the GDPR.

12. Contact

For questions about this DPA or to exercise audit rights, contact us at: contact@axilero.com

We use only essential cookies to keep you signed in. We don't use advertising or cross-site tracking. See our Privacy policy for details.