1. Parties and when it applies
This agreement applies when a company or organization (the Customer) uses Listenly for its work: the Customer decides why and how the data in its meetings is processed and is the controller; Tame SpA, RUT (Chilean tax ID) 78.216.642-5 (Listenly), processes it on the Customer's behalf as a processor, under Law 19.628 (Chile) and Law 21.719 (Chile) on the protection of personal data.
It forms part of the Terms and is accepted with them. If the Customer needs a signed version, it can request one at [email protected]. In the event of a conflict with the Terms regarding personal data, this agreement prevails.
2. Details of the processing
3. Customer instructions
Listenly processes the data only according to the Customer's documented instructions, which are these Terms, this agreement and what the Customer configures and does in the app (start, pause, delete, export), including with regard to international transfers, unless the law requires otherwise (in that case we will notify the Customer beforehand, if the law allows it). If an instruction seems to us to be contrary to the law, we will say so. Listenly does not use the Customer's data for its own purposes, for advertising or to train artificial intelligence models.
4. Confidentiality
Only the people at Listenly who need it to operate the service or assist the Customer have access to the data, and they are bound to keep it confidential, including after they stop working with us.
5. Security
Listenly applies, at a minimum, these technical and organizational measures:
- Encryption in transit (HTTPS/WSS) and backups encrypted with AES-256 that are kept for 14 days.
- Isolation by workspace in every query: one customer's data is not visible to another.
- Authentication with Firebase; the AI providers' keys live only on the servers.
- Audio is deleted after it is transcribed, unless the Customer chooses to keep it.
- Request limits, security headers and logs without the content of searches.
- Real deletion: deleting a meeting or an account deletes its data, audio files and derived memories.
- Automatic retention periods for technical logs (24 months) and server logs (weeks).
- Staff access limited to those who need it; providers bound by data processing agreements.
Listenly reviews and improves these measures when the service or the risks change.
6. Subprocessors
The Customer gives Listenly general authorization to use the providers listed in Subprocessors. Listenly imposes on them by contract data protection obligations equivalent to those in this agreement and is liable for them. Before adding or replacing one, it will give at least 30 days' notice; the Customer may object on reasonable grounds and, if there is no solution, terminate the service and receive a proportional refund of what was paid and not used.
7. Data subjects' rights and assistance
The app lets the Customer handle most requests by itself: search, export, rectify and delete excerpts, memories, meetings or accounts. If a data subject contacts Listenly, we will refer them to the Customer without responding on our own account, unless the law requires it.
Listenly will help the Customer, to a reasonable extent, comply with its obligations regarding security, breach reporting and impact assessments.
8. Security breaches
If Listenly detects a breach affecting the Customer's data, it will notify the Customer without undue delay and no later than 48 hours after becoming aware of it, with whatever is known: what happened, what data and how many data subjects, likely consequences, measures taken and a contact. It will complete the information as it becomes available and will cooperate so that the Customer can inform the authority and the data subjects within the legal deadlines.
9. Return and deletion upon termination
While it uses Listenly, the Customer can export all of its data in a structured format. Upon termination, or when the Customer deletes its account, Listenly deletes the data immediately from its active systems; it disappears from backup copies within a maximum of 14 days. Listenly keeps only what the law requires it to keep (for example, payment records), without linking it to the content of the meetings.
10. Information and audits
Listenly will make available to the Customer the information needed to demonstrate compliance with this agreement (including the security measures and the list of subprocessors) and will allow reasonable audits, with 30 days' prior notice, during business hours, at the Customer's expense and under confidentiality, primarily by means of questionnaires and documentation.
11. International transfers
Some subprocessors are outside Chile, mainly in the United States (see Subprocessors). The Customer authorizes those transfers, which are necessary to provide the service. Listenly bases them on contractual clauses that require each subprocessor to provide an adequate level of protection, in accordance with Law 21.719 (Chile), and will adapt them to the models approved by the Personal Data Protection Agency (Agencia de Protección de Datos Personales).
12. Customer obligations
- Have a legal basis for processing the data in its meetings and give lawful instructions.
- Inform the people in its meetings that they are being transcribed and obtain their consent when the law requires it (the app reminds it to do so and offers a ready-to-use notice).
- Handle data subjects' requests, with Listenly's help.
- Keep its access credentials secure.
13. Term and liability
This agreement remains in force for as long as Listenly processes data on the Customer's behalf and until its deletion. Each party's liability is governed by the Terms, except for what data protection law does not allow to be limited. For questions: [email protected].