Data Processing Agreement
This Data Processing Agreement outlines our commitments regarding the processing and security of your personal data when using Loka Note.
1. Scope and Applicability
This Data Processing Agreement (DPA) applies to the processing of personal data by Loka Note on behalf of the customer, in accordance with the Terms of Service. It outlines our commitments to data protection and compliance with applicable data privacy laws.
2. Data Processing Details
Loka processes personal data, including meeting recordings, transcripts, and summaries, solely to provide and improve the service as instructed by the customer. We do not use customer data for unauthorized purposes or sell it to third parties.
3. Subprocessors
To deliver our services, we engage the subprocessors below. Each is bound by written agreements that impose data protection obligations at least as restrictive as those in this DPA, and we restrict the data shared with each to the minimum necessary. List last updated July 14, 2026.
- SupabaseUnited States
Database, authentication, and storage of transcripts and account data
- VercelUnited States / global edge
Application hosting and content delivery
- Google Cloud PlatformUnited States
Meeting audio and export file storage (Cloud Storage), transcription (a speech-recognition model running in our own Cloud Run project, with Google Speech-to-Text as fallback), and AI summarisation and chat (Vertex AI Gemini — not used to train Google's models)
- Google (Meet / Calendar API)United States
Optional Google Meet and Calendar integration you can connect and disconnect at any time
- OpenRouter / AnthropicUnited States
Backup AI provider (zero data retention), used only if our primary AI provider is unavailable
- PolarUnited States / EU
Payment processing — card details are handled entirely by Polar and never reach our systems
- Apple (App Store)United States / global
In-app purchase processing for the iOS app; Apple is the merchant of record
- Meta Platforms (Messenger)United States / global
Optional customer-support channel — processes messages you choose to send us on Messenger
- ExpoUnited States
Mobile push-notification delivery (notification text only — never transcript or analysis content)
- SentryUnited States / EU
Error monitoring with personally identifiable information scrubbed before sending
- PostHogUnited States / EU
Product analytics inside the signed-in app only — never on public pages, never transcript or note content
4. Security Measures
We implement industry-standard technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Detailed security practices are available on our Security page.
5. Data Subject Rights
We assist our customers in fulfilling their obligations to respond to data subject requests (such as access, rectification, or deletion of data) by providing the necessary tools within the application or via prompt support.
6. Data Breach Notification
In the event of a personal data breach affecting customer data, we will notify the affected customers without undue delay and provide reasonable assistance to help them mitigate the impact and meet their breach notification obligations.
7. Term and Deletion
This DPA remains in effect as long as we process personal data on behalf of the customer. Upon termination of the service, we will delete or return all personal data in accordance with our retention policies, unless required by law to retain it.
Contact
If you have questions about this DPA or need a signed copy, please contact support@lokanote.com.