Data processing agreement (DPA)
Last updated: 29 September 2026
Draft: operator details marked [pending] will be filled in before publication.
This data processing agreement (“DPA”) under Article 28 GDPR applies when a business, professional or organisation (the “Controller”) uses Joyin (joyin.work) to hold meetings in the course of its activity and personal data of its clients, students, patients or staff is processed. It supplements the Terms of use. Consumers using Joyin privately do not need it; the Privacy policy applies to them.
How to conclude it: email [email protected] from your organisation's address with the subject “DPA” and your legal details; we return a countersigned PDF of this text. Until then, this published version applies to your use of the service as a Controller.
1. Parties
Processor: [pending], [pending] (“Joyin”). Controller: the account holder who uses Joyin for its professional or business activity.
2. Subject matter, duration, nature and purpose
Joyin processes personal data on behalf of the Controller to provide browser-based video meetings: real-time transmission of video, audio, screen sharing and chat; storage of chat, files and meeting history; recordings and AI transcription and summaries where the Controller turns them on; invitation and reminder emails. Processing lasts as long as the Controller's account exists and for the retention periods below.
3. Types of data and categories of data subjects
Data: names, email addresses, profile photos; guest names; device, browser and approximate country; video, audio and screen content in real time; chat messages and files; recordings; transcripts and summaries; meeting times and metadata. Data subjects: the Controller's staff, clients, students, patients, participants and guests. The Controller decides whether special categories of data (for example health data in a therapy session) are discussed and is responsible for the lawfulness of that processing.
4. Instructions of the Controller
Joyin processes personal data only on the Controller's documented instructions, which consist of the use of the service through its interface (creating rooms, admitting guests, turning recording or transcription on or off, deleting data) and of this DPA. Joyin informs the Controller if an instruction in its opinion infringes data protection law.
5. Obligations of the Processor (Art. 28(3) GDPR)
- Confidentiality: persons authorised to process the data are bound by confidentiality.
- Security: technical and organisational measures under Article 32 (Annex 1).
- Sub-processors: only those listed in Annex 2, under the conditions of section 6.
- Assistance: Joyin helps the Controller respond to data subject requests (self-service export and deletion in the dashboard, plus support by email) and to meet its obligations under Articles 32 to 36, including notifying the Controller without undue delay of a personal data breach affecting its data.
- Deletion: at the end of the service Joyin deletes the Controller's personal data (account deletion is immediate; recordings are deleted after 3 days in any case), unless EU or Member State law requires storage.
- Information and audits: Joyin makes available the information necessary to demonstrate compliance and allows audits by the Controller or an auditor mandated by it, on reasonable notice, not more than once a year unless a supervisory authority requires otherwise.
6. Sub-processors
The Controller gives general authorisation for the sub-processors in Annex 2. Joyin informs Controllers of any intended change at least 30 days in advance by updating this page and, for Controllers with a signed DPA, by email; the Controller may object on reasonable data protection grounds, in which case it may terminate the service. Joyin imposes the same data protection obligations on sub-processors by contract and remains liable for their performance.
7. International transfers
Video, audio, recordings, chat and account data are processed in the EU. Transfers outside the EEA take place only to the sub-processors marked in Annex 2, under the European Commission's standard contractual clauses (Decision 2021/914) and, where the recipient is certified, the EU-US Data Privacy Framework. AI transcription and summaries involve such a transfer and are used only when the Controller turns them on for a meeting; Controllers processing special categories of data are advised to leave them off.
8. Retention
Recordings: 3 days, then automatic deletion (the Controller can delete earlier). Audio for transcription: deleted after processing. Transcripts and summaries, chat, files, meeting history: until the Controller deletes them or the account. Technical logs: up to 90 days.
9. Liability and term
Each party is liable under Article 82 GDPR. This DPA applies for as long as Joyin processes personal data for the Controller and prevails over the Terms of use in case of conflict regarding personal data. It is governed by the law of [pending].
Annex 1. Technical and organisational measures
- Encryption in transit: DTLS-SRTP for media on every connection; TLS for the website, apps and email.
- Hosting in the EU (Germany); media servers operated by Joyin; access to servers limited to technical staff with key-based authentication.
- Private rooms by link only; waiting room and lock at the host's discretion; host controls (mute, remove, end for all).
- Recording and transcription off by default; visible indicators for all participants when on; automatic deletion of recordings after 3 days and of transcription audio after processing.
- No advertising, no third-party analytics, no tracking cookies on the website.
- Logging of security-relevant events; abuse and rate limits; regular software updates.
- Self-service export and deletion of all account data in the dashboard.
Annex 2. Sub-processors
| Sub-processor | Country | Processing | When | Transfer mechanism |
|---|---|---|---|---|
| Hetzner Online GmbH | Germany (data centre: Nuremberg) | Hosting of the website, database, media servers (self-hosted LiveKit), recordings and mail server | Always | None (EU) |
| Cloudflare, Inc. | USA (EU affiliates) | DNS, TLS termination and protection of the website; processes website connection metadata, not the video | Always (website traffic) | EU-US Data Privacy Framework and standard contractual clauses |
| ElevenLabs, Inc. | USA | Speech recognition (transcription) of meeting audio for AI meeting notes | Only when the host turns on transcription for a meeting | Standard contractual clauses (Decision 2021/914); DPF where certified |
| Anthropic, PBC | USA | Generating the meeting summary from the transcript text | Only when the host turns on transcription for a meeting | Standard contractual clauses (Decision 2021/914); DPF where certified |
| Google LLC / Apple Inc. | USA | Sign-in providers: pass name, email and photo when you sign in. Independent controllers for the sign-in itself; listed for transparency | When the host signs in | Under the providers' own terms (DPF / SCC) |
Not sub-processors: the media server software (LiveKit) is open source and runs on Joyin's own servers; transactional email is sent from Joyin's own mail server on the hosting above.
Changes to this list are published here with the date. Current version: 29 September 2026.