Skip to content
← All legal documents

Data Processing Agreement

The Article 28 terms on which OakHive processes personal data for a customer, with the processing description, security measures and transfer terms.

Applies to
Customers
Last updated
1 September 2026
Questions
legal@oakhive.ai

This Data Processing Agreement forms part of the Subscription Agreement between Nambra, MB and the Customer. It sets out the terms required by Article 28 of the General Data Protection Regulation, and the equivalent provisions of UK GDPR and the Swiss Federal Act on Data Protection where they apply.

Annex IV is unusual, and deliberate. Most processor DPAs stop at the security annex. This one ends with a list of things that are not yet perfect — a region that is committed contractually but not enforced in code, a subprocessor retention setting that is one day rather than zero, a provider whose residency we have not been shown. A data protection officer will find these anyway. Finding them in our own document is a better start to that conversation than finding them in an audit.

1Roles and scope

1.1The Customer is the controller of personal data processed through OakHive. The Customer decides that an interview happens, who is interviewed, what is asked, and who may read the result.

1.2OakHive is the processor. It processes that personal data only to provide the Service, and only on the Customer’s instructions.

1.3Where the Customer is itself a processor for another controller, OakHive acts as a subprocessor and this Agreement applies as though references to the controller were to that other controller.

1.4OakHive is a separate and independent controller for a narrow set of data it decides about itself — account administration, billing contacts, security logging and its own website. That processing is described in the Privacy Policy and is outside the scope of this Agreement.

2Definitions

Data Protection Law
Regulation (EU) 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss FADP, and any other data protection law applicable to the processing.
Customer Personal Data
Personal data contained in Customer Data, as defined in the Subscription Agreement.
Data Subject
An identified or identifiable individual whose personal data is processed — principally interview Participants, and the Customer’s Users.
Subprocessor
A third party engaged by OakHive that processes Customer Personal Data.
EU SCCs
The standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
UK Addendum
The International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner.

3Processing on documented instructions

3.1OakHive processes Customer Personal Data only on the Customer’s documented instructions, including for transfers to a third country, unless required to do otherwise by law to which it is subject. Where law requires it, OakHive will inform the Customer before processing unless that law prohibits it on important grounds of public interest.

3.2The Subscription Agreement, this Agreement, the configuration the Customer sets in the Service, and the Customer’s use of the Service constitute the Customer’s complete documented instructions.

3.3OakHive will inform the Customer if, in its opinion, an instruction infringes Data Protection Law. It may suspend the affected processing until the instruction is amended or confirmed.

3.4OakHive does not use Customer Personal Data for its own purposes. In particular, it does not use Customer Personal Data to train, fine-tune or improve any machine learning model.

3.5The Customer warrants that it has a lawful basis for the processing, has satisfied its transparency obligations to Data Subjects, and has completed any assessment or consultation its own law requires — including any works council or employee representative consultation.

4Duration

4.1This Agreement applies for as long as OakHive processes Customer Personal Data, and survives termination of the Subscription Agreement until deletion is complete under section 13.

5Confidentiality of personnel

5.1OakHive ensures that everyone authorised to process Customer Personal Data is bound by an appropriate obligation of confidentiality, whether contractual or statutory, and that the obligation survives the end of their engagement.

5.2Access to Customer Personal Data by OakHive personnel is limited to those who need it to provide, secure or support the Service, is granted on a least-privilege basis, and is logged.

6Security of processing

6.1OakHive implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing.

6.2Those measures are described in Annex II and in the Security Overview. OakHive may update them, and will not materially weaken the overall level of protection during a paid term.

6.3The Customer is responsible for its own configuration of the Service, including who it grants view access to, who it assigns as a successor to a handover, and the retention period it sets.

7Subprocessors

7.1The Customer gives general authorisation for OakHive to engage Subprocessors. The current list is published at /legal/subprocessors, is versioned, and is reproduced in Annex III at version 2026-09-01.1.

7.2OakHive will give the Customer at least 30 days’ notice before a new Subprocessor begins processing Customer Personal Data, or before an existing one takes on a materially different role. Notice is given by email to the Customer’s registered administrator contacts and by updating the published list.

7.3The Customer may object to a proposed Subprocessor within 30 days of notice, on reasonable grounds relating to data protection. The parties will work in good faith to find an alternative. If none is available within 30 days, the Customer may terminate the affected part of the subscription without penalty and receive a pro-rata refund of prepaid fees for the unused term.

7.4OakHive imposes on each Subprocessor data protection obligations no less protective than those in this Agreement, and remains fully liable to the Customer for a Subprocessor’s performance.

8Assisting with data subject rights

8.1Taking account of the nature of the processing, OakHive assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests to exercise Data Subject rights.

8.2The Service gives the Customer the ability to access, correct, export and delete an individual interview and the artefacts generated from it, without needing OakHive’s involvement.

8.3Where OakHive receives a request directly from a Data Subject, it will not respond to the substance itself. It will tell the individual to contact their employer, and inform the Customer promptly.

Stated plainly: there is no self-service route for a Participant inside the product today. The export exists and is reachable by the Customer, not by the Data Subject directly. That is a normal position for a processor — the controller owns the relationship with the individual — but it means the Customer must be able to action a request itself, and should say so in its own privacy notice.

9Assisting with your other obligations

9.1OakHive assists the Customer, taking into account the nature of processing and the information available to it, in complying with its obligations under Articles 32 to 36 GDPR — security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.

9.2This document, the Security Overview, the Interview Privacy Notice and the AI Transparency Statement are provided so a Customer can complete an impact assessment without a bespoke request. OakHive will answer reasonable follow-up questions in writing.

10Personal data breach

10.1OakHive notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

10.2The notification describes, so far as known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where the full picture is not available at once, OakHive provides it in phases without undue further delay.

10.3OakHive does not notify a supervisory authority or Data Subjects on the Customer’s behalf unless the Customer instructs it to in writing. That decision belongs to the controller.

10.4Breaches are reported to security@oakhive.ai. Reports from security researchers are welcome and will not be treated as hostile where the researcher acts in good faith and does not access more data than necessary to demonstrate the issue.

11International transfers

11.1Customer Personal Data is stored at rest within the European Economic Area. Some processing takes place outside the EEA where a Subprocessor listed in Annex III performs it, as that Annex records.

11.2Where OakHive transfers Customer Personal Data to a Subprocessor outside the EEA in a country without an adequacy decision, the transfer is made under the EU SCCs, Module Three (processor to processor), with the UK Addendum where UK data is involved and the Swiss amendments where Swiss data is involved.

11.3Where the Customer is established outside the EEA and personal data is transferred to it, the EU SCCs Module Four (processor to controller) apply.

11.4For the purposes of the SCCs: the docking clause applies; the optional independent audit wording is not selected; the governing law and forum are those of the Republic of Lithuania; Annex I of the SCCs is populated by Annex I of this Agreement; Annex II of the SCCs by Annex II; and the list of Subprocessors by Annex III.

11.5OakHive will tell the Customer if it becomes subject to a legally binding request from a public authority for Customer Personal Data, unless prohibited from doing so, and will challenge a request that appears unlawful.

12Where the data is stored

12.1The Service runs on Microsoft Azure, West Europe (Netherlands). Interview transcripts, generated artefacts, the search index and audit records are stored there.

12.2OakHive will not move the primary storage region for Customer Personal Data outside the EEA. It will give at least 30 days’ notice of a change of region within the EEA, and the Customer may object on the same terms as clause 7.3.

12.3The browser interview channel sends live speech to a Subprocessor outside the EEA for transcription during the session, as Annex III records. That is transient processing; the resulting text is stored in the region in clause 12.1.

13Deletion and return

13.1During the term, interviews are deleted according to the retention period the Customer sets for its tenant. Where the Customer sets none, the Service applies a default of 730 days from the interview.

13.2At that point the interview content — transcript, generated artefacts, feedback — is removed and only minimal record-keeping metadata remains. That record is destroyed 30 days later. Entries in the knowledge search index are removed when the interview is deleted.

13.3At the Customer’s choice, OakHive deletes or returns all Customer Personal Data at the end of the Subscription Agreement, and deletes existing copies. The export window is 30 days; deletion from live systems completes within 60 days; backup copies age out within 90 days.

13.4OakHive may retain Customer Personal Data to the extent required by law to which it is subject, and only for as long as that law requires, applying the protections in this Agreement for as long as it holds it.

14Audit and information rights

14.1OakHive makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates.

14.2In the first instance, OakHive will satisfy an audit request with written responses, documentation, and the answers to a security questionnaire. It will respond within 30 days of a request.

14.3Where a written response is insufficient for a Customer to meet a specific regulatory obligation, the Customer may conduct an on-site or remote audit not more than once in any twelve-month period, on 30 days’ notice, during business hours, subject to confidentiality undertakings, and without accessing another customer’s data. A regulator may audit at any time as its law provides.

14.4Each party bears its own costs. Where an audit reveals a material non-compliance by OakHive, OakHive bears the reasonable costs of the audit.

14.5OakHive does not currently hold an ISO 27001 certification or a SOC 2 report, and does not claim one. Where certification is a requirement, it should be raised before signature.

15Liability and precedence

15.1Each party’s liability under this Agreement is subject to the limitations and exclusions in the Subscription Agreement.

15.2Where a term of this Agreement conflicts with the Subscription Agreement, this Agreement prevails on any question of data protection. Where a term of the SCCs conflicts with this Agreement, the SCCs prevail.

15.3Nothing in this Agreement limits a Data Subject’s rights under the SCCs or under Data Protection Law.

16Annex I — Description of the processing

A. The parties

Data exporter: the Customer, acting as controller. Contact details are those on the Order Form.

Data importer: Nambra, MB, acting as processor, Vilnius, Lithuania. Contact: privacy@oakhive.ai.

B. Description of the processing

ElementDetail
Subject matterConducting knowledge-transfer and exit interviews, generating written artefacts from them, and making the resulting knowledge searchable within the Customer’s organisation.
Nature of processingCollection by conversation, speech-to-text transcription, storage, generation of summaries by a large language model, indexing for retrieval, disclosure to the people the Customer authorises, and deletion.
PurposeCapturing what a departing or transitioning employee knows about their work, so that colleagues and successors are not left guessing.
Categories of data subjectInterview Participants (typically employees who are leaving or changing role); the Customer’s Users — managers, HR staff, administrators, viewers and successors; people mentioned by a Participant during an interview.
Categories of personal dataName, work email address, job title, department, manager’s email address, and the directory identifier of the Participant. The interview transcript and everything generated from it. Manager notes and questions. Interview feedback. Access configuration. Audit records of who read or changed what, and when.
Special category dataNot requested, not required, and not a purpose of the processing. Because a transcript is free-form speech, a Participant may nonetheless volunteer something that falls into a special category. Material marked sensitive during an interview is routed to a restricted section, excluded from the handover document, and never added to the searchable index.

One field is a deliberate exception and is called out rather than folded into the above: where an interview reaches an acute distress or crisis moment, the record stores that it occurred — a tier and a timestamp — and never what was said. It is visible to the Customer’s manager and HR roles only, is excluded from the search index, the viewer payload and the successor handover, and is included in the manager-side notification. Depending on the circumstances this may constitute data concerning health. See Annex IV, item 7, and section 4 of the AI Transparency Statement.
FrequencyContinuous for the duration of the subscription.
RetentionAs set by the Customer; default 730 days, then destruction 30 days later. See section 13.
Automated decision-makingNone. The Service does not score, rank, rate or profile individuals, and produces no decision or recommendation about a person.

C. Competent supervisory authority

For OakHive as data importer: Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate), Lithuania. For the Customer as exporter: the authority competent for the Customer’s establishment.

No data protection officer is appointed. Article 37 GDPR requires one where the core activity involves large-scale systematic monitoring or large-scale processing of special categories, and neither describes this processing. Data protection enquiries reach privacy@oakhive.ai. A UK Article 27 representative is [ TO BE COMPLETED: UK Article 27 representative — name and address ].

17Annex II — Technical and organisational measures

The measures below are the ones implemented in the Service today. The Security Overview describes them in more operational detail.

Access control and tenancy

  • Every stored record carries a tenant identifier and every query is scoped to it. Tenant identity is taken from a validated token, never from a request body.
  • Authentication is delegated to the Customer’s own Microsoft Entra ID. OakHive issues no passwords and stores none.
  • Access to an interview is deny-by-default and role-based. What a role may see is decided on the server and shaped into the response; material a role may not see is absent from the payload rather than hidden in the interface.
  • Knowledge search follows interview access: the ability to retrieve something through search is the same grant as the ability to read it in the portal.

Encryption

  • In transit: TLS on every connection, including to subprocessors.
  • At rest: platform encryption on all stores, managed by the cloud provider.
  • Secrets are held in a managed key vault and injected as environment configuration.

Data minimisation in the system itself

  • Interview content and personal data are excluded from operational logging by policy, and that exclusion is enforced by a check that runs in the deployment pipeline rather than by reviewer discipline.
  • Exceptions are scrubbed through a single sanitising chokepoint before being stored.
  • IP address and user agent are no longer retained in audit records.
  • No participant audio is stored. No participant video is ever captured.

Segregation of sensitive material

  • Material marked sensitive during an interview is mechanically routed to a restricted section, excluded from the search index, and stripped from the viewer and successor payloads.
  • Manager notes are treated as a private briefing: they never appear in a generated artefact, an invitation, or anything shown to the Participant.
  • Transcript disclosure outside the administrative plane passes through a sanitiser.

Integrity and availability

  • Managed database with platform-level redundancy and backup.
  • Webhook payloads are signature-validated; event handling is serialised per call.
  • Rate limits on portal, administrative and chat surfaces.
  • Input validation and injection filtering on every externally supplied value.

Accountability

  • Audit records on every write and on sensitive reads, retained without expiry.
  • Correlation identifiers on every request, so an incident can be reconstructed.
  • Change control through version-controlled deployment with automated checks.

18Annex III — Subprocessors

Authorised Subprocessors as at list version 2026-09-01.1. The current version always governs and is published at /legal/subprocessors.

SubprocessorPurposeLocationApplies to
Microsoft AzureCloud hosting, database (Cosmos DB), search index, the large language model that writes the interview artefacts (Azure OpenAI), speech-to-text and text-to-speech, secret storage and application telemetry.European Union — Azure West Europe region (Netherlands)All interviews, all channels.
ElevenLabsSpeech recognition, conversational turn-taking and the interviewer’s synthetic voice in browser interviews.United StatesAll interviews.
AnamGenerates the animated face of the interviewer where a video interviewer is used.[ TO BE COMPLETED: Anam processing location ]Interviews that use a video interviewer.

19Annex IV — Known limitations, stated openly

Every statement here was checked against the running system rather than against a vendor brochure. Where a fact could only come from a vendor, it is marked as such.

1. The storage region is a contractual commitment, not a technical lock

All infrastructure is deployed in Microsoft Azure, West Europe (Netherlands) and clause 12.2 commits OakHive to keeping it in the EEA. There is no code-level control that would prevent a misconfigured deployment landing elsewhere. The commitment is real and enforceable against us; it is enforced by contract and process rather than by the platform.

2. The browser channel’s speech provider retains for one day, not zero

The speech provider used on the browser channel is configured with one-day retention. Zero-retention mode is available on that provider and is not currently enabled. A Customer that requires true zero retention should raise it before signature: it is a configuration change on our account with that provider, not a change of wording here.

3. The video interviewer’s residency is unverified

The optional animated interviewer relies on a provider whose subprocessor list and data residency have not been made available to us. That question is open, and it is recorded here rather than left for a security review to find. Any change to that provider is notified under clause 7.2.

4. Data subject requests run through the Customer

As clause 8.3 says, there is no self-service route for a Participant inside the product. The Customer can action every request; the Participant cannot action one directly. A Customer’s own privacy notice should therefore route employees to the Customer, not to us.

5. Retention has a floor but no ceiling

The Customer sets the retention period. The Service applies a default of 730 days where none is set, but does not cap how long a Customer may choose. If a maximum matters, it belongs on the Order Form.

6. The welfare signal is sensitive by nature, and the participant notice predates it

The crisis safeguard described in the AI Transparency Statement writes a welfare flag to the interview record. The design is deliberately minimal — the fact and its timestamp, never the words — and it is restricted to the Customer’s manager and HR roles. It is nonetheless a record that a named individual experienced a crisis moment at work, and a Customer should treat it accordingly in its own records of processing and impact assessment.

The Customer, as controller, is responsible for telling Participants that this happens. The published Interview Privacy Notice at its current version does not yet describe it, because the safeguard was added after that revision. We have recorded this rather than left the Customer to discover it, and the notice will be revised.

7. No third-party certification yet

There is no ISO 27001 certificate and no SOC 2 report. The measures in Annex II are implemented and can be evidenced, but they have not been attested by an external auditor.

The rest of the pack