Read this first. The personal data you are most likely worried about — what your clients or patients said — is never transmitted to us and never exists on our systems. Recognition happens on each Mac. What this Addendum covers is the small administrative remainder: a licence key, a hashed device identifier, and any support correspondence you choose to send us.
If your organisation requires its own DPA template instead, send it to us and we will work from yours.
1. Parties and scope
This Addendum forms part of the Terms of Service between Altypist (“Processor”) and the organisation licensing Altypist (“Controller”, “you”). It applies where and to the extent that Processor processes personal data on Controller's behalf in connection with the Altypist software and its licensing.
Where the parties' obligations under applicable data protection law conflict with this Addendum, that law prevails.
2. Roles
For the data described in Annex A, Controller is the controller and Processor is the processor. Processor processes that data only on Controller's documented instructions, of which this Addendum and the Terms are the standing instruction.
For the dictated content itself, Processor is neither controller nor processor, because it never receives it. Controller remains solely responsible for that content, which resides on Controller's own devices.
3. Subject matter, nature, purpose and duration
- Subject matter: issuing and validating software licences, and responding to support requests.
- Nature of processing: storage and lookup of licence records; receipt and reading of support correspondence.
- Purpose: to make activation work on Controller's devices, to enforce the number of seats purchased, and to provide support.
- Duration: for licence records, the life of the licence; for support correspondence, as long as needed to resolve the request and then deletion on request.
4. Processor obligations
Processor shall:
- process personal data only as necessary for the purposes in section 3 and on Controller's instructions, and not for its own purposes;
- not use any Controller data to train machine-learning models. For dictated content this is guaranteed by architecture rather than promise — it never arrives;
- ensure that personnel with access are bound by confidentiality;
- implement the security measures in Annex C;
- assist Controller in responding to data subject requests, which is generally straightforward given how little is held (see section 7);
- notify Controller without undue delay after becoming aware of a personal data breach affecting Controller's data, with the information available at the time and further detail as it emerges;
- on termination, delete or return the data in accordance with section 8.
5. Sub-processors
Controller gives general authorisation for the sub-processors in Annex B. Processor will give Controller reasonable prior notice of any addition or replacement, and Controller may object on reasonable data protection grounds; if the objection cannot be resolved, Controller may terminate the affected licence and receive a pro-rata refund of any prepaid, unused fees.
Processor remains responsible for its sub-processors' performance of these obligations.
6. International transfers
Annex B states where each sub-processor operates. Two things about it are worth reading before signing rather than discovering later.
Processor is established in the Republic of Serbia, which has no adequacy decision under the UK or EU GDPR. Transfers from the EEA or the UK to Processor therefore rely on the Standard Contractual Clauses or the UK International Data Transfer Addendum, which section 6 incorporates below. Processor's sub-processors are established in the United States and rely on their own transfer mechanisms, including the EU-US Data Privacy Framework where they are certified to it.
What this covers is narrow, and that is the point: a licence key, a hashed device identifier, and whatever Controller chooses to write to support. Dictated audio and text are not transferred anywhere at all — they are processed on Controller's own devices and never reach Processor or any sub-processor, so no transfer mechanism applies to them.
Controller should still avoid putting a data subject's personal data into support correspondence where it is not needed to answer the question. That is ordinary hygiene with any vendor's mailbox, not a limitation specific to this one.
Where a transfer requires them, the parties will enter into the applicable Standard Contractual Clauses or UK International Data Transfer Addendum, which are incorporated by reference and prevail over this Addendum in the event of conflict.
7. Data subject rights
Processor will, on Controller's request, provide the information it holds against a licence, correct it, or delete it. Because the record is a licence key, a hashed device identifier and timestamps, most such requests can be answered in full within a few working days. Deleting a licence record also deactivates the licence, so Processor will confirm before doing so.
Processor cannot identify a data subject from a hashed device identifier, and neither can anyone else — the hash is one-way and the underlying identifier is never transmitted.
8. Deletion and return
On termination or expiry, Processor will delete Controller's licence and activation records within 90 days, except where retention is required by law, and will delete support correspondence on request. Because Processor holds no dictated content, there is nothing further to return.
9. Audits
Processor will make available the information reasonably necessary to demonstrate compliance with this Addendum, including the architecture documentation. Given that the software runs entirely on Controller's hardware, Processor holds no service for a conventional audit to examine; Controller may verify the software's behaviour independently, and the architecture page describes how. Where Controller nonetheless requires an audit, Processor will cooperate on reasonable notice, no more than once a year absent a specific concern, at Controller's cost.
Processor does not hold a SOC 2 or ISO 27001 report and does not claim to.
10. Liability and term
This Addendum takes effect when the Terms do and continues while Processor processes personal data on Controller's behalf. Liability under this Addendum is subject to the limitations in the Terms, except where applicable law does not permit that.
Annex A — Data processed
| Category | Data | Data subjects |
|---|---|---|
| Licence record | Licence key, tier, number of seats, status, an internal note such as an order reference, timestamps, and any subscription end date | None directly identifiable |
| Activation record | An instance identifier and a SHA-256 hash of the Mac's hardware UUID, with the time of activation | Controller's personnel, only indirectly and not identifiable by Processor |
| Support correspondence | Email address, message content, and anything else Controller chooses to include | Whoever writes in |
| Payment confirmation | Confirmation that payment succeeded, and the billing email address supplied to the payment provider | Controller's billing contact |
Not processed, at all: dictated audio, transcribed or formatted text, custom vocabulary, which applications are dictated into, usage analytics, or any telemetry. No such data is transmitted by the software.
Annex B — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Website hosting, licence server (Workers) and licence database (D1) | United States, with global edge processing |
| Google Ireland Ltd / Google LLC | The support mailbox (Google Workspace) | United States and the EU |
| Lemon Squeezy | Merchant of record: taking payment, VAT and receipts | United States |
Hugging Face hosts the recognition model that each Mac downloads once. That is a file download initiated by Controller's device and carries no personal data, so it is not a sub-processing arrangement.
Annex C — Security measures
- Data minimisation as the primary control. The strongest measure here is architectural: content is processed on Controller's devices, so the great majority of the data at issue is never created on Processor's side.
- Pseudonymisation. Devices are identified only by a one-way hash; the raw hardware identifier is never transmitted or stored.
- Encryption in transit. All licence traffic is over HTTPS.
- Encryption at rest as provided by the hosting platforms named in Annex B.
- Access control. Administrative endpoints require a bearer token; access is limited to personnel who need it.
- Signed, notarised software. Releases are signed with an Apple Developer ID and notarised by Apple; updates are cryptographically signed and refused if the signature does not verify.
- No analytics or crash-reporting SDKs in the software, so no incidental data collection channel exists.
Signing
Write to privacy@altypist.com with your organisation's details and we will return a countersigned copy, or work from your own template if you prefer.
Processor: ALTYPIST DOO Beograd, Milutina Milankovića 7 DJ, 11070 Belgrade, Republic of Serbia. PIB 115878048 · registration number 22323695. Data protection contact: privacy@altypist.com.