Data Processing Agreement
Effective July 7, 2026
For the meeting content MeetCrew handles on your behalf, you are the controller and MeetCrew is your processor. You decide why and how that content is processed; we process it only on your documented instructions. Our Data Processing Agreement ("DPA") puts that relationship in writing and forms part of the agreement under which you use the Service. This page is a summary — the executed DPA governs.
Controller and processor, clearly divided
You determine the purposes and means of processing the meeting content, participant identities, and memory that flow through a teammate; that makes you the controller. MeetCrew processes that data solely to provide the Service as you configured it, which makes us your processor. Because MeetCrew fronts a chat agent you supply and control, the AI reasoning applied to your content remains yours — MeetCrew provides the presence, not the reasoning. Separately, for data we handle as our own business (sales, contact, and website data), MeetCrew acts as a controller under our Privacy Policy.
What the executed DPA covers
Roles and responsibilities of controller and processor, and the requirement that we process only on your documented instructions.
Subject matter and details of processing — the scope, nature, purpose, and duration; the categories of personal data (transcripts, structured extractions, and participant platform identities); and the categories of data subjects (your meeting participants).
Confidentiality, binding personnel who handle the data.
Security measures — per-tenant isolation, access governed through Microsoft Entra, region-pinned residency with no cross-region replication, customer-managed encryption keys, double-wrapped exports, watermarked synthesized speech, and a tamper-evident, nightly-verified audit log.
Subprocessors — our use of vetted subprocessors under written terms, and notice of changes so you can object.
Assistance with data-subject requests and, where they apply, data protection impact assessments.
Breach notification, committing us to notify you without undue delay after we become aware of a breach affecting your data.
Audit rights, giving you a means to verify our compliance.
International transfers, incorporating the appropriate mechanism where a cross-border transfer occurs. In v1 the Service is offered only in the US (excluding Illinois) and Canada, with residency pinned per deployment, so cross-border transfer is limited by design.
Return or deletion of data on termination, including cryptographic shredding of records at the end of the applicable retention period.
How to put it in place
Enterprise and pilot customers execute the DPA as part of the order. If you would like to review our current DPA before signing, request it and we will send it.
Request the full DPA: legal@meetcrew.ai. This page summarizes our DPA for convenience; the executed agreement is the binding document and governs in the event of any conflict.