KYZON Space

Product details

Q: DPA and API

Hi,
First of all, congratulations on the great product - we have been testing it over the last few days and are very happy with the quality and functions. But now, of course, comes the big "but" :))

gdpr:
so that we can use this with customers, we have to deal with gdpr. gdpr-compliant is always a nice seal, but nothing more, and you had written that some cookie stuff is missing. Where we need to go is to a DPA (data processing agreement) - simple question: do you have one or not?

gdrp addendum:
in this context: if you are currently starting a recording, you as a participant will not be aware of it ... Some form of sign would be good.

Recording: are there any plans for an API that allows the file to be passed to a service for transcripts, summaries etc.? For example, we have transcript.lol (was on appsumo for a long time).

KlestPLUSMar 25, 2025
Founder Team
James_KYZONSpace

James_KYZONSpace

Mar 25, 2025

A: Hey Klest,

Appreciate the kind words and glad to hear you've had a great experience with us so far!

Great questions about GDPR and it's nice to hear you're more interested about the addendum than simply a seal.

To answer your question, yes we have a DPA with AWS. In our relationship with AWS, we are the data controllers while AWS is classified as the data processor. We're currently entered into the standard DPA agreement with AWS which you can find here. https://d1.awsstatic.com/legal/aws-dpa/aws-dpa.pdf

We also enter into the supplementary addendum with AWS which you can find here. https://d1.awsstatic.com/legal/aws-dpa/supplementary-addendum-to-the-aws-dpa.pdf

After an internal audit we realised we were not in compliance with 2 requirements of the GDPR. The age verification for children under 16 and the cookies consent. In Australia, unless you are a social media provider, we are not required to verify the age of users on our platforms and so we have simply just chosen not to collect the age data of our users - neither during sign up nor when updating their user profiles. Because of this, we are technically not verifying whether children under the age of 16 have received parental consent to use our platforms. The second requirement is cookie consents. We have the option to 'accept all' or 'accept only necessary' cookies but do not have the option to 'reject all' cookies which is a requirement of GDPR. We do this because some of our quality of life features are reliant on the necessary cookies and on top of that, with no cookies at all, it becomes incredibly difficult and time consuming to address any bugs should they occur for the user rejecting all cookies.

In terms of the GDPR addendum that requires participants to a recording be notified, we can definitely add a notice that the meeting is currently being recorded.

In terms of recording transcriptions, we are looking into ways of natively providing transcriptions that are that sustainable in the long-term. In the meantime though, we are actively exploring ways of integrating with 3rd party transcription services like transcript.lol, fireflies.ai and others to allow users to bring their own transcriptions service to Space calls. So yes, we definitely have plans of introducing the ability for users to bring their own transcription services like transcript.lol into Space calls.

Hope that provides some insight into our GDPR compliance practices and reasons behind not being fully compliant.

Let me know if there's anything else I can help clarify and appreciate the interest :)

Share
Helpful?
Log in to join the conversation
KlestKlestPLUS
Posted: Mar 25, 2025

Thank you for the very transparent explanation.
By DPA I actually meant do you have a template for an agreement between us (as users) and you (as processors)? gdpr actually requires an agreement directly between us.

Founder
Posted: Mar 27, 2025

Hey Klest,

Sorry for the delay. We are currently reviewing our DPA to make sure it reflects our current practices and the aspects that comply with the GDPR. We will need a couple of days to finalise it before it will be available as an Addendum to our T&Cs. I will provide an update when it is ready. Appreciate your patience in the meantime :)

KlestKlestPLUS
Posted: Mar 27, 2025

We are waiting, no stress, the first meetings with customers are planned for mid-May, where we want to test it