Legal
Data Processing Addendum
Last updated August 23, 2026
This addendum forms part of the Terms of Service and governs how Proxy processes personal data on your behalf. If your organization requires a countersigned copy or your own paper, email legal@useproxy.co.
1. Roles
2. Subject matter, duration, nature and purpose
Subject matter. Providing the Proxy service: joining meetings you designate, answering questions grounded in the code you connect, and drafting follow-up work.
Duration. For as long as your account is active, plus the retention windows in section 7.
Nature and purpose. Recording and transcribing designated meetings; reading the repositories you select; generating answers and draft artifacts; storing the results so your team can review them.
3. Categories of data and data subjects
Data subjects: your personnel and any other participants in meetings Proxy joins.
Categories of personal data:
- Account data — name, work email, organization, role.
- Meeting content — audio, transcripts, and anything said in a meeting Proxy attends.
- Connected-tool content — repository contents and metadata for the repos you select; workspace and channel identifiers for messaging tools you connect.
- Calendar metadata — where you enable auto-join: event times, titles and attendees, read-only.
- Usage and diagnostic data — logs, error reports and performance traces.
Proxy is not designed for special-category data. Please do not direct it at systems whose primary purpose is health, biometric, financial-account or government-identifier data.
4. Our obligations as processor
- Process personal data only on your documented instructions, including for transfers.
- Bind everyone with access to confidentiality.
- Maintain the technical and organizational measures in section 5.
- Engage sub-processors only under section 6.
- Assist you, so far as we reasonably can, with data-subject requests and with your obligations on security, breach notification and impact assessments.
- Delete or return personal data at the end of the service, per section 7.
- Make available the information reasonably needed to demonstrate compliance, and allow audits under section 9.
5. Security measures
- Tenant isolation. Every record carries a tenant identifier and is enforced at the database layer by row-level security. Each meeting runs in its own isolated sandbox.
- Encryption. In transit with TLS; at rest by the cloud provider. Third-party access tokens are additionally encrypted with per-purpose application keys.
- Credential boundary. The sandbox where Proxy works holds no credential that can push code or send a message. Every world-touching action is staged as a draft that a person approves.
- Least privilege. Repository access is a short-lived, read-scoped token minted per operation. Calendar access, where enabled, is read-only and revocable by your admin.
- Secrets management. Secrets live in a managed secret store, never in source or logs.
- Logging and monitoring. Authentication, connection and administrative events are recorded to an audit trail.
See the security overview for current certification status, which we state plainly rather than imply.
6. Sub-processors
You authorize the sub-processors below. We will give notice before adding or replacing one, and you may object on reasonable data-protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Hosting, database, object storage, and the Claude models we run inside our own cloud project | United States |
| Recall.ai | Joining meetings and carrying audio | United States |
| AssemblyAI | Speech-to-text, engaged through Recall.ai | United States |
| OpenAI | The live voice session: receives the meeting's audio and transcript, and produces Proxy's spoken replies | United States |
| E2B | Isolated per-meeting compute sandboxes | United States |
| Sentry | Error monitoring | United States |
Because we run Claude inside our own Google Cloud project, your code content is not sent to a separate model vendor as a distinct sub-processor. Proxy's voice is the one exception, and we name it plainly: the live voice session runs on OpenAI, so while Proxy is in a meeting the audio of that meeting and its transcript are processed by OpenAI in order to hear you and to speak.
7. Retention, return and deletion
- Transcripts, notes and drafts are retained while your account is active, so your team can go back to them.
- The working copy of your code is a rebuildable cache and is discarded when a sandbox ends.
- On written request, or within 30 days of termination, we delete or return personal data, except where law requires us to keep it.
- Backups age out on their own cycle; deleted data stays isolated until it does.
8. International transfers
9. Audits
10. Personal-data breach
11. Order of precedence
Proxy is an early-stage company and this document reflects how the product actually works today rather than an aspiration. If your procurement process needs changes to this paper, we would rather negotiate it than have you sign around it.