Data processing agreement · last updated 2026
Data processing
1. Who this is between
"We" and "us" mean WSAV, which operates Frasiey. "You" means the organisation that holds the Frasiey workspace. [FOR REVIEW: the WSAV legal entity name, its form, its registration number and its registered address.]
For the words spoken in your meetings, and everything around them, you decide what happens and we act on your instruction. In the language of the law you are the controller and we are your processor. For your own account, meaning the people who sign in, their names and email addresses and your billing, we decide and we answer for it ourselves; the privacy notice covers that half.
This agreement forms part of our terms. Where the two disagree about personal data in your meetings, this page wins.
2. What we handle for you, and why
We provide live captions, translation of those captions, and the transcript afterwards, for the meetings you run. We handle personal data only to do that, for as long as you hold a workspace with us, and on the terms below.
What that comes to in practice: recognised sentences and their translations, the schedule of the meeting, the names on that schedule, the list of names and terms a meeting keeps so they are spelled correctly, and the bookkeeping that shows which rooms captioned and for how long.
3. Whose information, and what kind
The people whose information we handle for you are the people who speak in your rooms, the people who read the captions, and your own staff who run the meeting. The kinds of information are: what was said and its translations, names, roles and affiliations on a schedule, the names and terms a meeting adds itself, and the email addresses and names of the people you invite to your workspace.
Captions carry whatever people say out loud, so a transcript can carry anything a meeting discusses. Treat one as you would treat minutes. If your rooms will discuss something that needs more care than minutes, tell us before you run them.
4. Only on your instructions
We handle your meetings' personal data only to provide Frasiey, and only as you instruct us, including where data goes to another country. Using the product is how most instructions are given: the settings a meeting chooses, the retention period it sets, the caption link an operator pastes. We do not use what your meetings say for any purpose of our own, and we do not use it to train anything.
If an instruction from you would put us in breach of the law, we will tell you rather than carry it out.
5. Confidentiality
The people at WSAV who can reach production data are the people who operate the service, they are bound to keep it confidential, and the list is kept as short as running the product allows. That duty does not end when somebody leaves.
6. Keeping it safe
The measures we take are written out on the security page, and that page is part of this agreement: audio stays on the room's own computer, every connection is encrypted in transit, every account's data is its own and a request for another organisation's meeting is answered as if it did not exist, sign-in codes and room laptop credentials are stored scrambled rather than as themselves, and access to production data is limited to the people who operate the service.
We will keep those measures at least as strong as they are today. If we change how something on that page works, the page changes with it.
7. Other providers
You agree that we use the providers listed on our providers page, which says what each one does and where. Each of the four providers that handle data for us is under written terms no weaker than this agreement, and we answer to you for what they do. Where your workspace signs in with Google or Microsoft, that is your own arrangement with them and their terms cover it.
We give account owners 30 days' notice by email before a new provider handles personal data. If you object during those 30 days, tell us why. If we cannot settle it, you can end your subscription without penalty.
8. Helping you answer people's requests
If somebody asks you for their data, or asks you to correct it, delete it, hand it over or stop using it, the product is built so that you can answer without us: a member can download a copy of the workspace, meaning its meetings, rooms, laptops, settings, schedule, list of names and terms, and every transcript with its translations, an operator can delete a meeting, and an owner can delete the workspace. Where the product cannot answer it, write to privacy@frasiey.com and we will help you in time for your own deadline.
If such a request reaches us directly, we pass it to you rather than answer it, unless you have told us otherwise.
We will also help you, so far as we reasonably can and with what we know, when you have to assess the risk of something you are planning, or consult your regulator about it.
9. Telling you when something goes wrong
If we learn of a breach affecting your data we will tell you without undue delay, and the relevant authority within 72 hours where the law requires it. We will tell you what happened, who it affected so far as we know, what we have done, and what we suggest you do, and we will keep telling you as we learn more rather than waiting until we know everything.
10. Giving it back, or deleting it
You can take a copy of the workspace at any time, and you do not need to ask us for it: its meetings, rooms, laptops, settings, schedule, list of names and terms, and every transcript with its translations. When you stop using Frasiey, deleting your workspace closes it at once and everything in it, meetings, rooms, laptops and transcripts, is deleted within 30 days. Owners can reopen it during those 30 days.
After that, what remains is our own record that an account existed and what was done to it, which we keep because we have to be able to show what happened, and the usage totals behind past invoices where tax law requires us to keep them.
11. Information for your own checks
We will give you the information you need to satisfy yourself that we are doing what this page says, and answer a security questionnaire, on request and within a reasonable time. If that is not enough for you, we will agree an audit with you, at a reasonable frequency and without disrupting other customers' meetings.
We answer a questionnaire in our own words, with our providers' certifications named as theirs. The security page says what we do and who our providers are.
12. Where the data goes
Your data may be processed in the United States. Cloudflare, Stripe, Anthropic and Resend have each signed the European Commission's standard clauses with us; Cloudflare, Stripe and Anthropic also rely on the Data Privacy Framework. Where your workspace signs in with Google or Microsoft, or an operator sends captions to a Zoom or Teams meeting, that transfer runs under your own agreement with that company rather than ours.
Where a transfer needs more than that, we will do it or we will stop the transfer.
13. How long this lasts
This agreement runs for as long as we handle personal data for you, and the duties that are meant to outlive it, confidentiality and deletion among them, do.
14. Governing law
[FOR REVIEW: governing law and venue for this agreement, which should follow the terms, and whether a separate transfer annex is needed for customers in Europe.]
15. Contact
privacy@frasiey.com. We read it.
Draft revision, not yet reviewed by counsel · 2026