1. Scope and roles
This DPA forms part of the CleanWave Terms. The customer is controller and Independent Entrepreneur MARIUS CERESCU, provider and correspondence address 20 Prisăcarului Street, MD-6526, Anenii Noi, Republic of Moldova, operating CleanWave, is processor for personal data in customer audio and project content. For account, billing, security and service-administration data, CleanWave remains an independent controller.
2. Processing details
Subject: multilingual audio transcription, PII detection, review and silence redaction. Duration: from upload until deletion, normally no more than 24 hours. Data: voices, transcripts, names, contact details, identifiers, locations and potentially medical, legal, financial, biometric or other sensitive facts. Data subjects: speakers and persons discussed in recordings.
3. Documented instructions
CleanWave processes customer content only to provide, secure and support the requested service, according to the Terms, selected categories, written custom instructions and documented support requests. If an instruction appears unlawful, CleanWave may suspend it and notify the customer.
4. Confidentiality and security
Access is limited to authorized persons subject to confidentiality. Measures include browser-side encryption for Zero-Access projects, verified confidential processing, encryption in transit, private storage, tenant isolation, signed authentication, least-privilege secrets, rate limits, logging and automated deletion. CleanWave retains no usable project key outside confidential processing, so its ordinary systems and operators cannot decrypt stored Zero-Access content. Approved subprocessors may temporarily handle content only to provide the analysis requested by the customer. Current providers and purposes are disclosed on the Subprocessors page, while the safeguards and their boundaries are summarized on the Security page.
5. Subprocessors and transfers
The customer gives general authorization to the subprocessors listed on the Subprocessors page. CleanWave will provide reasonable advance notice of a material new subprocessor and an opportunity to object on legitimate data-protection grounds. International transfers must use an applicable lawful mechanism.
6. Assistance
Taking into account the nature of processing, CleanWave will reasonably assist with data-subject requests, security, breach assessment, DPIAs and consultations with authorities. The customer remains responsible for responding to data subjects and establishing the lawful basis for recordings.
7. Incidents
CleanWave will notify the customer without undue delay after confirming a personal-data breach affecting customer content and will provide available information about its nature, likely consequences and mitigation. This does not constitute an admission of fault.
8. Return, deletion and audits
The customer can download results or delete projects during the retention window. CleanWave deletes customer project data after the service ends or within 24 hours, subject to narrowly applicable legal obligations and provider retention disclosed in the Privacy Policy. CleanWave will provide information reasonably necessary to demonstrate compliance and may satisfy audit requests through documentation, third-party reports or a proportionate coordinated audit subject to confidentiality and security restrictions.
9. Priority and execution
If this DPA conflicts with the Terms on processing customer personal data, this DPA prevails. Using CleanWave as a controller constitutes acceptance of this DPA. Customers requiring a separately signed copy may contact [email protected].