1. What this is
This Data Processing Agreement ("DPA") is part of the Terms of Service. It applies when Bromance Studio SRL ("Kasset", "we") processes personal data on your behalf as your processor. By creating an account or using Kasset, you agree to this DPA. If you need a signed copy, email [email protected].
If this DPA and the Terms say different things about the processing of Conversation Data, this DPA prevails. Our Privacy Policy explains how we handle account data, where we are the controller.
2. Roles
You (the customer) are the controller of Conversation Data: audio, transcripts, speaker labels, notes, decisions, actions, and device records you send through the Service.
Kasset is your processor. We process Conversation Data only to provide the Service and only on your documented instructions: the Terms, this DPA, and the actions you take in the product (record, delete, invite a member, connect a tool, write an automation, confirm an action, set a retention period).
You are responsible for the lawfulness of what you send us, including notice and consent to record, and for the instructions you give us. We will tell you if, in our view, an instruction would break applicable data protection law, and we may refuse that instruction.
3. What we process
| Item | Detail |
|---|---|
| Subject matter | Providing Kasset: capture, store, transcribe, summarise, and search conversations, and act in the tools you connect |
| Nature | Collection, storage, transcription, interpretation, organisation, retrieval, deletion; and, when you connect an integration, execution of the actions your instructions require in that tool (transmission of the data those actions carry) |
| Purpose | To provide the Service on your instructions, including performing actions in connected tools when you instruct it |
| Duration | While your account is active, then deleted within 30 days of closure, except where the law requires a longer keep (for example invoices) |
| Data subjects | Your organisation's members, and the people whose voices or names appear in the conversations you capture |
| Categories of data | Audio; transcripts and speaker labels; notes, decisions, and actions; device pairing records; organisation membership needed to attribute a recording |
| Special categories | We do not ask for special-category data. It may appear in a recording you capture. That is your responsibility. |
Audio is kept for the period you choose, then deleted. Transcripts and notes remain until you or your organisation delete them, or the account is closed.
4. Our obligations
We will:
- Process Conversation Data only on your documented instructions, unless EU or Member State law requires otherwise. If the law requires us to process without your instruction, we will tell you unless the law forbids it.
- Ensure that people who handle Conversation Data are bound to confidentiality.
- Take appropriate technical and organisational measures to protect Conversation Data (see Security below).
- Use only the sub-processors listed below, under a written contract with data-protection obligations no less protective than this DPA. We remain responsible for their work.
- Help you respond to data-subject requests, and to assessments or consultations with a supervisory authority, to the extent the Service does not already let you do it yourself.
- Notify you of a personal-data breach involving Conversation Data without undue delay, and in any event within 72 hours of becoming aware of it, with the information we reasonably have at the time.
- Delete Conversation Data within 30 days of account closure, or earlier when you delete a conversation, unless the law requires us to keep a copy.
- Make available the information reasonably needed to show we meet this DPA.
We will not use Conversation Data to train AI models, sell it, or use it for our own purposes.
5. Your obligations
You will:
- Have a lawful basis, and the notice or consent required, to record and to instruct us to process Conversation Data.
- Tell the people in a conversation that you are recording, where the law or common courtesy requires it. We do not do this for you.
- Use the Service only in ways that do not cause us to break data protection law.
- Keep your accounts, passwords, and devices secure, and decide who in your organisation may access Conversation Data.
- Remain responsible for third-party tools you connect (for example through MCP). Those tools act on your instructions, not ours.
- Remain responsible for the outbound integrations you connect and the automation instructions you write: what they send, where they send it, and the actions they perform. This includes confirmations you grant and automations you set to run without a per-action confirmation. Kasset executes those instructions as your processor; their lawfulness is yours.
6. Sub-processors
You authorise us to use the following sub-processors. Those that handle Conversation Data for the core Service (storage, transcription, notes) are in France; Composio handles only the Conversation Data your instructions send to tools connected from the integrations gallery.
| Sub-processor | Role | Location | Conversation Data |
|---|---|---|---|
| Scalingo | Application hosting, PostgreSQL, Redis | France | Yes (transcripts, notes, metadata; not audio files) |
| Scaleway | Temporary audio storage | France | Yes (audio only) |
| Mistral AI | Speech to text and interpretation | France | Yes (one recording at a time; no account identifiers) |
| Letter | Transactional email and product events | Belgium (last-mile AWS SES, US / EU) | No (counts and account fields only) |
| Composio | Integration execution and OAuth token custody for tools connected from the gallery (configured for zero payload retention) | United States | Yes: only the Conversation Data your instructions send to connected tools |
| Google Identity | Optional sign-in | United States | No |
| Microsoft Identity | Optional sign-in | United States | No |
We will give you reasonable prior notice before we add or replace a sub-processor that processes Conversation Data. You may object on reasonable data-protection grounds. We will try to address the objection. If we cannot, you may stop using the affected part of the Service or close your account.
7. International transfers
Conversation Data is hosted and processed in France. Transcription, storage, and note generation never leave the European Economic Area. Conversation Data leaves the EEA only when you connect an integration and instruct Kasset to send data to it: gallery connections transit Composio in the United States under the Standard Contractual Clauses (Module Three, processor to processor); custom MCP connections go directly from our French servers to the endpoint you configure, wherever you chose to point them.
Optional sign-in and last-mile email delivery use providers in the United States. Those transfers carry account fields or system email, never a transcript or note. Where a transfer leaves the EEA, we rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as the case requires, governed by Belgian law, with disputes before the courts of Brussels and the Belgian Data Protection Authority (APD / GBA) as the competent supervisory authority.
8. Security
Our measures include:
- TLS for data in transit
- Credentials and secrets encrypted at rest
- Audio in a private bucket, with no public URLs, keyed opaquely
- Conversation Data hosted in the EU; no US hosting for recordings, transcripts, or notes
- Access limited to a small set of administrators, under confidentiality
- Structured logs that record identifiers and error codes, not audio, transcripts, or note text
- No advertising, session replay, or analytics on Conversation Data
We may update these measures as technology changes, without reducing the overall protection. You are responsible for how you use the Service, including who you invite and which tools you connect.
9. Personal-data breaches
If we become aware of a breach of Conversation Data, we will notify you without undue delay and within 72 hours, with: what happened, the categories and approximate volume of data affected, the likely consequences, and the steps we have taken or plan to take. A notice is not an admission of fault. You remain responsible for notifying data subjects or a supervisory authority when the law requires the controller to do so.
10. Assistance and audits
We will help you with data-subject requests, data-protection impact assessments, and consultations with a supervisory authority, to the extent the information is not already in this DPA, the Privacy Policy, or the product.
On reasonable written request, we will provide information to demonstrate compliance with this DPA. If that is not enough, you may audit the processing of your Conversation Data no more than once per calendar year, with reasonable notice, during ordinary business hours, without disrupting the Service, under confidentiality. You bear the cost. We may satisfy an audit with existing documentation where that answers the question.
11. Artificial intelligence
Speech recognition and language understanding run in France, per request. Each request carries one recording's audio, or that recording's transcript. No user identifier or history is sent with it. Conversation Data is not used to train models.
When you connect an integration, an agent may act in that tool on your instructions: it can read notes and transcripts to prepare an action, and executes actions with effects outside Kasset only after your confirmation, unless you have set a specific automation of yours to run without one. Without a connected tool, the model returns text and can act on nothing outside Kasset.
Notes are assistive, and so are the actions the agent proposes. They can be incomplete or wrong. You are responsible for reviewing them. Kasset does not make automated decisions that produce legal or similarly significant effects.
12. Return and deletion
You can delete conversations, and the audio that remains with them, from the product. When you close your account, we delete Conversation Data within 30 days, except for the minimal records the law requires us to keep. Backups age out on their ordinary cycle. If return of a copy is practicable, we will provide it on written request before closure completes.
13. Liability and term
Liability under this DPA follows the limitation of liability in the Terms, to the extent the law allows. Each party is responsible for its own breaches. This DPA lasts as long as we process Conversation Data on your behalf.
We will notify you by email at least 30 days before a significant change to this DPA takes effect. You may close your account if you do not accept the change.
14. Governing law
This DPA is governed by Belgian law. Disputes fall under the competent courts of Brussels, without prejudice to any mandatory rights under the GDPR.
15. Contact
Bromance Studio SRL · VAT BE1040.904.426 · [email protected]