This template is provided for review by prospective customers and vendor audits. For an individually signed copy, contact info@heydiane.ai. It supplements the Terms of Service and applies wherever HeyDiane processes personal data on behalf of a customer.
Processor: S&C Holding GmbH, Halbgasse 1a, 1070 Vienna, Austria
("HeyDiane").
Controller: the customer operating a HeyDiane workspace.
The customer decides which conversations are recorded, uploaded or connected and remains the controller for that content — including the personal data of third parties whose voices appear in recordings. HeyDiane processes this content exclusively on the customer's documented instructions as expressed through the product's functions.
Hosting, transcription (including speaker detection), AI summarization, assistant answers, search, export and deletion of conversation recordings and derived data, as offered by the HeyDiane application.
For the duration of the customer's use of HeyDiane. Deletion obligations under §9 survive termination.
The controller grants general authorization for the sub-processors listed in the Trust Center (Annex 2 by reference). HeyDiane announces intended changes at least 30 days before a new sub-processor processes personal data; the controller may object on reasonable data-protection grounds. Every sub-processor is bound by a contract imposing materially the same obligations as this agreement.
Content data (recordings, transcripts, summaries, chat) is stored and processed exclusively in the EU. Some infrastructure providers have US parent companies; for those, EU Standard Contractual Clauses are in place as a safeguard for residual intra-group access scenarios. No content data is transferred to a third country in the ordinary course of the service.
Deletion in the product is effective immediately and complete (rows, storage objects, derived artifacts); exports auto-delete after 7 days; backups rotate within 7 days. On termination, the controller can export the full archive (JSON) and delete the workspace; HeyDiane deletes any remainder within 30 days unless EU or member-state law requires storage.
HeyDiane supports audits by making the Trust Center, TOMs, DPIA and this agreement publicly available, answering security questionnaires, and — where a controller demonstrates that this is insufficient — permitting audits by the controller or a mandated auditor with 30 days' notice, at the controller's expense, during business hours, without access to other customers' data.
Liability follows Art. 82 GDPR and the Terms of Service. Austrian law applies; place of jurisdiction is Vienna. Should individual provisions be invalid, the remainder stays unaffected.
Annex 1: Technical and Organizational Measures · Annex 2: Sub-processor list (Trust Center)