Legal
Data Processing Terms
Version 1 · Last updated: 18 September 2026
These Data Processing Terms, version 1, form part of the Terms of Service between you and WEYD Industries Limited (“WEYD”, “we”, “us”, or “our”); see Who we are, in the Privacy Policy.
They are the written contract required by Article 28(3) of the UK GDPR (and the EU GDPR where it applies) for the personal data we process on your behalf when you run a session. They apply automatically to every host — you do not have to ask for them or sign anything separately.
1. Roles and scope
You are the controller of the session content described in Annex 1; we are your processor.
These terms do not cover data where WEYD is the controller in its own right, which our Privacy Policy explains. The record of a room and of the sessions run in it is processed in both capacities: as your processor, to run and meter the session, and as controller of our own billing and account records. An email address a guest gives us for a copy of a session is processed in both capacities too: as your processor, to send the guest what you have offered, and as controller of our own rules for how long we keep it and how it is removed, which Roles, in the Privacy Policy, states.
Where you are yourself a processor for someone else, you confirm you have that party’s authority to appoint us as a sub-processor on these terms.
“Data protection law” means the UK GDPR, the Data Protection Act 2018, and the EU GDPR where it applies to your use of the Service. Terms it defines carry those meanings here.
2. Processing only on your instructions
We process the session content only on your documented instructions, including as to transfers to a third country. Your instructions are the Terms of Service, these terms, and the settings and actions you take in the product.
Keeping the Service working is part of that instruction. We may examine the session content involved in a fault you report, or one the Service detects itself, in order to diagnose and fix it, and we use what we see for nothing else.
Beyond that we do not use session content for any purpose of our own. We do not train our models on it. Operational and technical data about how the Service performed is ours as controller and outside these terms (Roles and scope); Data we process, in the Privacy Policy, describes it.
We will tell you immediately if we believe an instruction infringes data protection law, and may pause the processing concerned until it is resolved. If law requires us to process the data otherwise than on your instructions, we will tell you before we do so unless that law forbids it.
Where that requirement is a demand from a public authority for session content — a court or a regulator included — we tell you before we comply unless the law forbids it.
3. Confidentiality
We ensure that the people authorised to process the session content are bound by an appropriate duty of confidentiality, whether by contract or by statute.
4. Security
We take the technical and organisational measures Article 32 requires, appropriate to the risk. They are summarised on our Security page, which is information and not part of these terms, and described in detail on request.
5. Sub-processors
You give general written authorisation for us to appoint sub-processors. The providers that may process session content, where they are, what we send each and what it keeps, are on our sub-processor list, which forms part of these terms; each dated version stays available there so you can see what applied when. Which listed provider serves a session is our configuration choice, not a new appointment.
We impose data protection obligations on each sub-processor no less protective than these terms for the processing it does on our behalf, and we remain fully liable to you for a sub-processor’s performance. Where the list records that a provider keeps what it receives and uses it to improve its own models, it is a controller for that purpose; What you are responsible for covers the basis you need for that disclosure. Where a provider gives us a way to pass a deletion on, we pass yours on.
Before we add or replace a sub-processor we will give you at least 30 days’ notice by email and update the list. Tell us of a reasonable data-protection objection within that period at hello@parlabase.com: we will work with you on it, and if we cannot resolve it you may terminate the affected part of the Service and we will refund any prepaid unused period.
6. Helping you with requests, breaches, and assessments
Taking into account the nature of the processing, we will assist you so far as possible, by appropriate technical and organisational measures, with requests to exercise the rights in Chapter III of the UK GDPR, and — taking into account also the information available to us — with your obligations under Articles 32 to 36 (security, breach notification, impact assessments and prior consultation). If someone contacts us directly about content from your event, we refer them to you and tell you.
We will notify you without undue delay after becoming aware of a personal data breach affecting the session content we process for you.
7. Deletion and return
At your choice we delete or return the session content we hold for you, at any time including when the Service ends, and delete existing copies, unless law requires us to keep them. Ask us in writing at hello@parlabase.com.
The copies we control are our own and our backups, which expire on their rotation (Annex 1, Retention). Where a provider on our sub-processor list is marked as accepting a deletion request, we ask it to delete its copy; we can promise only that we ask. A deletion does not reach a provider the list does not mark that way.
If you have not told us your choice within 30 days of the Service ending, we delete. Deletion does not reach the billing and account records we keep as controller, which follow the Privacy Policy’s Retention section.
8. Audits and information
We will make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In the first instance we will answer a reasonable written request. If that does not resolve the point, you may audit on 30 days’ notice, no more than once in any 12 months unless a breach or a regulator requires otherwise, at your cost unless the audit finds material non-compliance, and without access to other customers’ data.
9. International transfers
Session content is processed in the United Kingdom and, for parts of the pipeline, outside it; our sub-processor list says where, for each provider.
For each destination we rely on UK adequacy where the UK’s adequacy regulations cover it — they cover the EEA, and a United States recipient certified under the UK Extension to the EU–US Data Privacy Framework — and otherwise on the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures our transfer risk assessment identifies. For a copy of the transfer agreement we rely on for a particular destination, email hello@parlabase.com.
You instruct us to make those transfers by using the Service.
10. What you are responsible for
As controller, you warrant and undertake that:
- you have a lawful basis under Article 6 for capturing speech at your event and having it recognised and translated, and, where what is spoken reveals special category data, a condition under Article 9 as well;
- that basis and condition also cover every disclosure that running your sessions and the settings you choose cause us to make — including to a provider on our sub-processor list that keeps what it receives and uses it to improve its own models, and to a guest you have offered a copy of the session;
- you have given the people at your event the information required by Articles 13 and 14, including that automated speech recognition and machine translation are in use, that a third-party provider processes the audio, and what each feature you switch on does with their data;
- your instructions to us, and the processing they require, comply with data protection law; and
- you control who receives a session code, link, or QR code.
A live session is not a private channel: anyone holding the code can read what is being said.
If you rely on Article 9(2)(d) as a not-for-profit body, note that the condition is lost where the data is disclosed outside the body without the consent of the people it is about — and sending what is said at your event to a provider that keeps it and learns from it is such a disclosure. Take your own advice before you run a session.
11. Liability, term, and changes
These terms take effect when the Terms of Service do, and continue for as long as we process session content for you. The sections on confidentiality, deletion, audits, and liability survive their end.
The limitations and exclusions in Disclaimers, liability, and indemnity, in the Terms of Service, apply to claims under these terms, except where data protection law does not permit them to.
If you are a business user (“business user” and “consumer” have the meanings the Terms of Service give them), our total aggregate liability to you for all claims arising out of these terms or out of our processing of session content is limited to £25,000. That figure includes a sub-processor’s performance under Sub-processors and any contribution claimed from us under Article 82(5). That limit replaces the general limit in the Terms of Service for those claims rather than adding to it, and applies however the claim arises, in contract, tort or otherwise. It does not apply to anything English law does not allow us to limit.
Nothing here limits the right of a person whose personal data we process to claim compensation from either of us under Article 82(1), and nothing in these terms excludes or limits your statutory rights if you are a consumer — the consumer protections in the Terms of Service prevail over anything here that would reduce them.
If these terms conflict with the Terms of Service on the processing of session content, these terms prevail.
We do not, without your agreement: reduce the protections in these terms; change your documented instructions under Processing only on your instructions; or change what happens to personal data for a host who takes no action. You are the controller; we do not get to rewrite your own instructions to us.
Three things change without that agreement. Our sub-processor list changes on the notice, and with the objection-and-terminate right, in Sub-processors. Corrections and clarifications that do not change what either of us must do are republished with a dated note at the foot of the page and no new version.
And a capability we add is described in Annex 1, reaches a session only where you use it, and your use of it is your instruction; adding that description changes nothing else in Annex 1. None of those three may be used to reduce a protection in these terms. For any other change we give the notice and follow the process in the Changes to these Terms section of the Terms of Service, and raise the version and the date above.
Annex 1 — Details of the processing
Subject matter and duration
Live speech recognition and machine translation for the sessions you run, for as long as you use the Service as a host.
Nature and purpose
Receiving audio from your chosen source while a session is live, having it transcribed and translated, and delivering that text to the people who joined — with the session and timing data needed to run the session and measure the session minutes it uses.
Types of personal data
- Voice and speech — the audio of whoever speaks into your source;
- the content of that speech, as transcribed and translated text, which can be about the speaker or about anyone they mention;
- special category data, where what is spoken reveals it — as at an act of worship, or in a clinical, care or safeguarding setting;
- session data — identifiers and codes, whether a session is live, paused or ended and when, and the languages selected;
- a guest’s email address and language, where a guest gives them to us so we can send them what you have offered.
Categories of data subjects
- speakers whose voices your source captures;
- anyone whose personal data is spoken aloud and so passes through the pipeline;
- guests who ask us for what you have offered them; and
- your own staff and volunteers who operate the Service on your behalf.
Your obligations and rights as controller
Your obligations are in What you are responsible for. Your rights are to give and change our instructions (Processing only on your instructions), object to a new sub-processor (Sub-processors), choose deletion or return (Deletion and return), and require information demonstrating our Article 28 compliance and audit us (Audits and information).
Retention
Session audio is not written to disk. The live text is held only in memory and is gone no more than 60 minutes after the last person leaves, or sooner if the server restarts.
The transcript of a broadcast has no retention period of its own: it stays until you delete it — a single broadcast (one go-live of a session) or the whole session — and in any event it goes when your account closes, as Deletion and return describes.
A guest’s email address is confirmed before we use it and removed if it has not been confirmed within 7 days of the last request to it. A confirmed address is used only to send what was asked for and removed after no more than 365 days without a further request; a guest can ask us to remove it sooner.
Backups cover account and configuration data, not session audio, the live transcript, or the transcript of a broadcast. Where a backup nonetheless holds personal data, it is isolated from active use and every backup copy is gone within 120 days.
The exact current figures are on How Parlabase handles data. Records where WEYD is the controller — account, billing and session records — follow the Privacy Policy’s Retention section.
Annex 2 — Sub-processors
Annex 2 is our sub-processor list, which forms part of these terms under Sub-processors.
Contact
Data protection questions, sub-processor objections, audit requests, and breach queries: hello@parlabase.com
Version 1 · Last updated 18 September 2026
- 18 September 2026 — First published.