Omi STT API — Data Processing Agreement
Version 2.0 — Effective date: 5 August 2026
This Data Processing Agreement ("DPA") forms part of the Omi STT API service
terms (the "Agreement") between Omi Health B.V., KVK 69497680, Eindhoven,
the Netherlands ("Omi") and the customer accepting the Agreement
("Customer"). It is built on the standard contractual clauses annexed to
Commission Implementing Decision (EU) 2021/915 and applies whenever Omi
processes personal data on Customer's behalf within the scope of Article 28
GDPR. It is concluded in electronic form in accordance with Article 28(9)
GDPR.
Section I — General
Clause 1 — Purpose and scope
(a) The purpose of this DPA is to ensure compliance with Article 28(3) and
(4) of Regulation (EU) 2016/679 (GDPR).
(b) Customer acts as controller and Omi acts as processor of the Customer
Personal Data described in Annex I.B. Where Customer itself acts as a
processor for a third-party controller, Customer is Omi's instructing party,
Omi is engaged as a sub-processor, and references to "controller" in this DPA
are read as references to Customer acting on the documented instructions and
with the authorisation of its controller. Customer warrants that its
instructions to Omi are authorised by that controller and that its own
contract with that controller permits Omi's engagement on these terms.
(c) This DPA applies to the processing of Customer Personal Data as specified
in Annex I.
(d) Annexes I to III are an integral part of this DPA.
(e) This DPA is without prejudice to obligations to which Customer is subject
under the GDPR.
(f) "Customer Personal Data" means personal data in Customer Content
processed by Omi on Customer's behalf. "Customer Content" means Job Content
(submitted audio, job-scoped custom vocabulary and job options, and the
transcripts and results generated from them) and persistent custom vocabulary
saved to Customer's account. Account, usage, and billing data that Omi
processes for its own purposes ("Service Data") is processed by Omi as an
independent controller under its Privacy Notice and is outside this DPA.
*Clause numbering follows the 2021/915 model clauses. The model's Clause 2
(invariability) and optional Clause 5 (docking) apply to the executed
standard clauses themselves and are not reproduced here.*
Clause 4 — Hierarchy
In the event of a contradiction between this DPA and the provisions of the
Agreement or any other agreement between the parties, this DPA prevails for
the processing of Customer Personal Data. Where the parties have separately
executed the standard contractual clauses of Commission Implementing Decision
(EU) 2021/915, those clauses prevail over this DPA.
Clause 3 — Interpretation
Terms defined in the GDPR have the same meaning in this DPA. This DPA shall
be read and interpreted in the light of the GDPR and shall not be interpreted
in a way that runs counter to rights and obligations provided for in the
GDPR or that prejudices the fundamental rights or freedoms of the data
subjects.
Section II — Obligations of the parties
Clause 6 — Description of processing
The details of the processing, in particular the categories of personal data
and the purposes for which it is processed on Customer's behalf, are
specified in Annex I. The rights and obligations of Customer as controller
are set out in this DPA, in particular in Clauses 7.1, 7.6, 7.7, 8, 9, and
10.
Clause 7 — Obligations of the parties
#### 7.1 Instructions
(a) Omi shall process Customer Personal Data only on documented instructions
from Customer, unless required to do so by Union or Member State law to which
Omi is subject; in that case, Omi shall inform Customer of that legal
requirement before processing, unless the law prohibits this on important
grounds of public interest. The Agreement, this DPA, each API request
(including the retention period selected for a job), and configuration made
through the console are Customer's documented instructions. Instructions
include any authorisation of international transfers under Clause 7.8.
Subsequent instructions may be given throughout the processing and shall be
documented.
(b) Omi shall immediately inform Customer if, in Omi's opinion, an
instruction given by Customer infringes the GDPR or other Union or Member
State data protection provisions.
#### 7.2 Purpose limitation
Omi shall process Customer Personal Data only for the purposes set out in
Annex I, unless it receives further documented instructions from Customer.
Omi does not use Customer Content to train, fine-tune, or evaluate any
model; does not sell it; does not use it for marketing; and does not derive
anything from it beyond the requested transcript and results.
#### 7.3 Duration of processing and deletion
(a) Processing takes place for the duration specified in Annex I.
(b) Submitted audio is deleted automatically upon completion or terminal
failure of processing. Transcripts from synchronous requests are not stored.
Results of asynchronous requests are stored solely for retrieval and deleted
automatically at the end of the retention period selected by Customer (1 to
72 hours; default 24 hours). Job-scoped custom vocabulary is deleted with
the job. Content is never written to operational logs or backups. The
retention period selected by Customer is Customer's documented instruction.
Retention particulars, including the effective minimum retention for jobs
configured with webhook delivery, are stated in the Service documentation
and Annex I.
(c) Persistent custom vocabulary saved to Customer's account outside an
individual job is account configuration, not Job Content. Its content,
storage, and deletion behaviour are described in Annex I. Customer may
delete it through the Service at any time, and Omi deletes it on account
termination.
#### 7.4 Security of processing
(a) Omi shall implement at least the technical and organisational measures
specified in Annex II to ensure the security of Customer Personal Data,
including protection against a breach of security leading to accidental or
unlawful destruction, loss, alteration, unauthorised disclosure, or access
(personal data breach). In assessing the appropriate level of security, the
parties take due account of the state of the art, the costs of
implementation, the nature, scope, context, and purposes of processing, and
the risks involved for data subjects.
(b) Omi grants its personnel access to Customer Personal Data only to the
extent strictly necessary for implementing, managing, and monitoring the
Agreement. Omi ensures that persons authorised to process Customer Personal
Data have committed themselves to confidentiality or are under an
appropriate statutory obligation of confidentiality.
#### 7.5 Sensitive data
The Service is designed to process audio that contains data concerning
health and other special categories of personal data (Article 9 GDPR). Omi
applies the specific restrictions and additional safeguards identified in
Annex II for such data, including strict purpose limitation, the deletion
scheme in Clause 7.3, encryption in transit and at rest, role-based access
restriction with logging, and audit logs designed to contain no Customer
Content.
#### 7.6 Documentation, compliance, and audits
(a) The parties shall be able to demonstrate compliance with this DPA. Omi
shall deal promptly and adequately with inquiries from Customer about the
processing of Customer Personal Data.
(b) Omi shall make available to Customer all information necessary to
demonstrate compliance with the obligations in this DPA and stemming
directly from the GDPR, including this DPA, the current sub-processor list,
Annex II, deletion (purge-probe) evidence, and third-party audit reports or
certifications when available.
(c) At Customer's request, Omi shall permit and contribute to audits of the
processing activities covered by this DPA, at reasonable intervals or if
there are indications of non-compliance. Customer may conduct the audit
itself or mandate an independent auditor; audits may include inspections at
Omi's premises or physical facilities and shall, where appropriate, be
carried out with reasonable notice. Absent indications of non-compliance,
audits occur no more than once per twelve months, on at least thirty (30)
days' notice, during business hours, without unreasonable disruption, under
confidentiality, and at Customer's cost. These limits do not apply where an
audit is prompted by a personal data breach affecting Customer Personal
Data, a request or investigation by a competent supervisory authority,
credible indications of material non-compliance, or a binding legal deadline
of Customer; in those cases Omi contributes without the frequency and
notice limits, and Omi bears the costs where material non-compliance is
found.
(d) The parties shall make the information referred to in this Clause,
including the results of any audits, available to the competent supervisory
authority or authorities on request.
#### 7.7 Use of sub-processors
(a) Customer grants Omi general written authorisation to engage
sub-processors from the agreed list in Annex III. Omi shall specifically
inform Customer in writing of any intended change of that list through the
addition or replacement of sub-processors at least thirty (30) days in
advance, giving Customer sufficient time to object before the engagement.
Omi shall provide the information necessary to enable Customer to exercise
its right to object.
(b) If Customer objects on reasonable data-protection grounds, the parties
shall discuss the objection in good faith and Omi shall, where reasonably
possible, offer an alternative that avoids the objected-to sub-processor. If
no reasonable alternative exists, Customer may terminate the affected
Service, retrieving its results first in accordance with Clause 10(d).
(c) Where Omi engages a sub-processor to carry out specific processing
activities on behalf of Customer, it shall do so by way of a contract that
imposes on the sub-processor, in substance, the same data protection
obligations as those imposed on Omi under this DPA. Omi shall ensure that
the sub-processor complies with the obligations to which Omi is subject
under this DPA and the GDPR.
(d) At Customer's request, Omi shall provide a copy of such a sub-processor
agreement and subsequent amendments, redacted to the extent necessary to
protect business secrets or other confidential information, including
personal data.
(e) Omi remains fully responsible to Customer for the performance of each
sub-processor's obligations under its contract with Omi, and shall notify
Customer of any failure by a sub-processor to fulfil its contractual
obligations.
(f) Omi shall agree a third-party beneficiary clause with each sub-processor
whereby, in the event Omi has factually disappeared, ceased to exist in law,
or become insolvent, Customer has the right to terminate the sub-processor
contract and to instruct the sub-processor to erase or return the personal
data.
#### 7.8 International transfers
(a) Any transfer of Customer Personal Data to a third country or an
international organisation by Omi shall take place only on the basis of
documented instructions from Customer or to fulfil a specific requirement
under Union or Member State law to which Omi is subject, and shall comply
with Chapter V GDPR.
(b) Steady-state processing of Customer Content takes place in the EU (AWS
eu-central-1, Frankfurt). During the disclosed preview transition period,
processing may also occur in AWS us-east-1 (United States). Customer agrees
that, where processing by a sub-processor involves a transfer within the
meaning of Chapter V GDPR, Omi and the sub-processor ensure compliance with
Chapter V by means of the applicable module of the standard contractual
clauses adopted under Article 46(2)(c) GDPR as incorporated in that
sub-processor's data processing agreement with Omi — for AWS, the AWS GDPR
Data Processing Addendum, which incorporates the SCC modules applicable to
the parties' roles — provided the conditions for the use of those clauses
are met. Omi documents the transfer assessments for such transfers and
makes them available under Clause 7.6.
(c) This Clause remains in effect after the preview transition ends. It
governs any non-EEA processing that may arise, including support, remote
access, or disaster recovery, for as long as this DPA is in force.
Clause 8 — Assistance to Customer
(a) Omi shall promptly notify Customer of any request it receives from a
data subject relating to Customer Personal Data. Omi shall not respond to
the request itself, unless authorised to do so by Customer.
(b) Omi shall assist Customer in fulfilling its obligations to respond to
data subjects' requests to exercise their rights, taking into account the
nature of the processing. Where Customer Content has already been deleted
under Clause 7.3, Omi's assistance consists of promptly confirming that
fact; nothing in this DPA requires Omi to recreate deleted data.
(c) Omi shall furthermore assist Customer in ensuring compliance with the
following obligations, taking into account the nature of the processing and
the information available to Omi:
1. the obligation to carry out a data protection impact assessment where a
type of processing is likely to result in a high risk to the rights and
freedoms of natural persons (Article 35 GDPR);
2. the obligation to consult the competent supervisory authority prior to
processing where a data protection impact assessment indicates a high
residual risk (Article 36 GDPR);
3. the obligation to ensure that personal data is accurate and up to date,
by informing Customer without delay if Omi becomes aware that personal
data it is processing is inaccurate or has become outdated;
4. the obligations in Articles 32 to 34 GDPR.
(d) The measures by which Omi provides this assistance, and its scope and
extent, are set out in Annex II.
Clause 9 — Notification of personal data breach
In the event of a personal data breach, Omi shall cooperate with and assist
Customer so that Customer can comply with its obligations under Articles 33
and 34 GDPR, taking into account the nature of the processing and the
information available to Omi.
(a) In the event of a personal data breach concerning Customer Personal
Data processed by Omi, Omi shall notify Customer without undue delay and in
any event within 48 hours after having become aware of the breach. The
notification shall contain, at least: (1) a description of the nature of
the breach, including where possible the categories and approximate number
of data subjects and data records concerned; (2) the details of a contact
point where more information can be obtained; and (3) the likely
consequences of the breach and the measures taken or proposed to address
it, including, where appropriate, measures to mitigate its possible adverse
effects.
(b) Where, and insofar as, it is not possible to provide all of this
information at the same time, the initial notification shall contain the
information then available, and further information shall be provided
subsequently without undue delay as it becomes available.
(c) Omi shall assist Customer in notifying the breach to the competent
supervisory authority and, where required, in communicating it to affected
data subjects, and in obtaining the information that Article 33(3) GDPR
requires the controller's notification to state.
Section III — Final provisions
Clause 10 — Non-compliance, termination, and deletion or return
(a) Without prejudice to the GDPR, if Omi is in breach of its obligations
under this DPA, Customer may instruct Omi to suspend the processing of
Customer Personal Data until Omi complies with this DPA or the Agreement is
terminated. Omi shall promptly inform Customer if it is unable to comply
with this DPA, for whatever reason.
(b) Customer is entitled to terminate the Agreement insofar as it concerns
processing under this DPA where: (1) processing was suspended under point
(a) and compliance is not restored within a reasonable time and in any
event within one month of suspension; (2) Omi is in substantial or
persistent breach of this DPA or its GDPR obligations; or (3) Omi fails to
comply with a binding decision of a competent court or supervisory
authority regarding its obligations under this DPA or the GDPR.
(c) Omi is entitled to terminate the Agreement insofar as it concerns
processing under this DPA where, after informing Customer that an
instruction infringes applicable legal requirements under Clause 7.1(b),
Customer insists on compliance with that instruction.
(d) At the end of the provision of the Services, Omi shall, at Customer's
choice, delete all Customer Personal Data processed on Customer's behalf
and certify that it has done so, or return it and delete existing copies,
unless Union or Member State law requires storage. Retrieval of results
through the API before termination constitutes return of Job Content; any
remaining Customer Content is deleted by the standing mechanics of Clause
7.3, and persistent custom vocabulary is deleted on account termination.
Written confirmation of deletion is available on request. Until deletion or
return is complete, Omi continues to ensure compliance with this DPA.
Clause 11 — Governing law
This DPA is governed by the law of the Netherlands, as provided in the
Agreement, without prejudice to mandatory provisions of the GDPR.
Annex I — List of parties and description of processing
A. List of parties
Controller / instructing party (Customer): the legal entity accepting
the Agreement, as recorded at acceptance (legal name, registered address,
contact person, and, where designated, data protection officer). Where
Customer acts as processor for a third-party controller, Clause 1(b)
applies.
Processor: Omi Health B.V., KVK 69497680, Eindhoven, the Netherlands.
Privacy contact: as published at /legal (privacy contact address).
B. Description of processing
Subject matter and nature. Automated conversion of speech to text:
receipt of audio submitted through the API, transcription (including
optional speaker diarization, formatting, and application of custom
vocabulary), and delivery of transcripts and results. Transcription runs on
Omi-operated infrastructure; no third-party model APIs are in the inference
path.
Purpose. Solely to provide, secure, and support the Service for
Customer.
Categories of data subjects. Speakers in submitted audio, including
patients, healthcare professionals, and other individuals whose speech or
personal details are captured in a recording; individuals mentioned in
audio or vocabulary entries.
Categories of personal data.
- Audio recordings of speech (voice), including any personal data spoken in
them: identifiers, contact details, dates, and clinical narrative.
- Transcript text and structured results (including timestamps and speaker
labels) derived from the audio.
- Job-scoped custom vocabulary and job options submitted with a request
(may contain names, drug names, diagnoses, and other patient-related
terms).
- Persistent custom vocabulary saved to Customer's account (may contain the
same kinds of terms).
- Job metadata (job identifiers, timestamps, durations, model and language
settings, status).
Special categories of data. Data concerning health (Article 9 GDPR) is
expected in submitted audio, transcripts, and vocabulary; the Service is
designed for it. Safeguards: Clause 7.5 and Annex II.
Duration of processing.
- Job Content: per Clause 7.3(b) — audio deleted automatically on
completion or terminal failure of processing; synchronous transcripts not
stored; asynchronous results stored solely for retrieval and deleted at
the end of the Customer-selected retention period (1 to 72 hours; default
24 hours); job-scoped vocabulary deleted with the job. Jobs configured
with webhook delivery have an effective minimum retention of 9 hours to
cover webhook retry mechanics; the Service documentation states the
current values.
- Persistent custom vocabulary: for the life of the account configuration;
deletable by Customer in the console at any time; deleted on account
termination.
- Job metadata: content-free usage records are retained up to 90 days;
content-free result tombstones up to 96 hours.
- Overall: for the duration of the Agreement, ending per Clause 10(d).
Annex II — Technical and organisational measures
Concrete measures implemented by Omi for the EU production environment (AWS
account region eu-central-1, Frankfurt). Omi may update these measures
provided the level of protection is not reduced.
Encryption in transit. TLS for all external API, console, and webhook
traffic; internal service traffic within a private VPC.
Encryption at rest. Customer-managed AWS KMS keys (CMK) with automatic
rotation for all content-bearing stores: S3 (SSE-KMS with bucket keys),
DynamoDB tables, SQS queues, EBS volumes, and CloudWatch log groups. A
dedicated audit CMK protects audit storage.
Access control and least privilege. Role-based access control;
least-privilege IAM policies; no standing human access to Customer Content;
human access only for security or abuse investigation, logged.
Administrative access to hosts via AWS Systems Manager (no public SSH);
administrative command output is kept content-free.
Authentication and key management. Customer API keys are stored as
SHA-256 hashes only; the plaintext key is shown once at creation and cannot
be retrieved by Omi staff. Secrets are held in AWS Secrets Manager.
Customer identity for the console is managed in an Omi-operated Keycloak
instance (identity data only; no Customer Content).
Audit logging. Immutable, content-free audit trail: security and
compliance events are delivered to an S3 bucket with Object Lock in
COMPLIANCE mode (2,192-day retention); CloudTrail with log-file validation.
The audit schema is designed to contain no audio, transcript, filename, or
URL content. Regular automated log-redaction sweeps verify that operational
logs contain no Customer Content.
Tenant isolation. Per-customer API keys scope every request; jobs,
results, and vocabulary are partitioned per account; authorisation is
enforced on every retrieval.
Data minimisation and retention. The retention scheme of Clause 7.3:
automatic deletion of audio on completion or terminal failure; no storage
of synchronous transcripts; Customer-selected retention (1-72 hours,
default 24 hours) for asynchronous results, enforced by an application
reaper with a short independent storage-lifecycle backstop; job queues and
dead-letter queues capped at 72 hours; operational logs retained 3 days;
content-free usage metadata 90 days; no backup tier is configured for the
Customer Content store, and Customer Content is not written to operational
logs or backups. An automated hourly purge probe verifies deletion
end-to-end and produces exportable evidence.
EU processing. Customer Content is processed in eu-central-1
(Frankfurt) in steady state; any non-EEA processing is governed by Clause
7.8. Identity data for the console is hosted on Microsoft Azure (Sweden
Central); website static assets are served via CDN; neither path carries
Customer Content. The API hostname is DNS-only and API traffic does not
transit the website CDN.
Availability and resilience. Multi-AZ load balancing for the API;
encrypted managed database with automated backups (identity/account data
only, 7-day retention); infrastructure as code with drift monitoring;
queue-based retry semantics for asynchronous work.
Personnel. Confidentiality undertakings for all persons authorised to
process personal data; written workforce training and sanctions program.
Assistance measures (Clauses 8 and 9). Named privacy contact; breach
intake and escalation runbook with templates for Article 33(3) content;
console and API access for Customer self-service retrieval and deletion;
deletion confirmations on request; sub-processor list with change
notification.
Testing and evaluation. Scheduled purge-probe verification of the
deletion scheme; periodic log-redaction and temp/spool sweeps; conformance
runs with evidence packs stored in the immutable audit bucket.
Annex III — Sub-processors
Customer authorises the following sub-processors (Clause 7.7(a)). The live
list, with the change-notification mechanism (at least 30 days' advance
notice), is published at /legal/sub-processors.
1. Amazon Web Services EMEA SARL (Luxembourg) — cloud infrastructure
hosting and processing of Customer Content. Location: eu-central-1
(Frankfurt) primary; interim us-east-1 (United States) during the
disclosed preview transition, under the AWS GDPR Data Processing
Addendum, which incorporates the applicable SCC modules (Clause 7.8).
2. Microsoft Ireland Operations Ltd — Microsoft Azure (Sweden Central)
— hosting for the Omi-operated Keycloak identity service. Processes
customer-user account and identity data only (name, business email,
credential and authentication-event data). Never processes audio,
transcripts, or PHI.
3. Cloudflare, Inc. — website content delivery network and Turnstile
bot protection for the public website and console assets. The API
hostname is DNS-only: API traffic, including all Customer Content, does
not transit Cloudflare.
4. Stripe (Stripe Payments Europe, Ltd.) — billing and payment
processing for the Service. Processes billing contact and transaction
data; card data is collected directly by Stripe and never touches Omi
systems. Never processes Customer Content.