DPA: Legal Requirements and What Leexi Provides
- Public since July 6, 2026, accepted from the free trial. What it includes and what it does not.

Leexi's DPA is a public document called the "Data Processing Agreement," version 2.0 since July 6, 2026, available before account creation: French version, English version. It applies upon online subscription, including free trials. It names Leexi's ten subprocessors, sets default retention to two years max, requires data breach notification within 24 hours, and grants an annual audit right.
Checking What the DPA Covers
The DPA sets the framework for how Leexi processes your meeting data on your behalf. You remain the data controller; Leexi is your processor.
The document states:
Leexi DPA, Article 4.2 "As a data processor, Leexi will process personal data on behalf of and according to the instructions of the Data Controller."
This means you decide the purpose of recording, retention duration, and who accesses the reports. Leexi executes.
What Data Does the DPA Cover?
Scope is defined in Article 3.
Leexi DPA, Article 3 "Leexi collects the following personal data: first and last name, email, phone number, role, company name, videoconference or VOIP conversation with metadata."
The data subjects are "employees, suppliers, and clients of the client." Operations include "collection, transfer, retention, and deletion."
How Do Buyers Request the DPA?
Between March and May 2026, six buyers requested Leexi's DPA. Examples include requests for the applicable signed DPA copy or confirmation, availability of a DPA among pre-purchase checks, or client DPOs asking Leexi to complete their subcontractor annex.
These boil down to three questions: which version applies, where is the subprocessor list, and how to keep proof. This page answers all.
Is the DPA a Legal Requirement?
Yes. Whenever a provider processes personal data for you, GDPR mandates a written contract with specified content.
GDPR, Article 28(3) "Processing by a processor shall be governed by a contract or legal act binding the processor to the controller, defining processing scope, duration, nature, purpose, data types, data subjects, and controller's rights and obligations."
This obligation applies to both you and Leexi. The controller must choose a processor offering sufficient guarantees.
GDPR, Article 28(1) "The controller shall use only processors providing sufficient guarantees to implement appropriate technical and organizational measures to meet GDPR requirements and protect data subject rights."
Three levels:
- By law: existence of contract and minimum clauses (Article 28(3), points a-h: documented instructions, confidentiality, security, onward processing, assistance with rights, deletion/return post-service, audit).
- By buyers: signed copy or written confirmation, subprocessor annex in their format, response time. Not legally required but common practice.
- By sector: financial and public sectors require effective audit rights and written policies on foreign authority requests. Leexi's DPA addresses both (Articles 10 and 15).
Must the DPA Include Audit Rights?
Yes, mandatory under point h) of Article 28(3).
GDPR, Article 28(3)(h) "Processor shall make available all information necessary to demonstrate compliance and allow audits by the controller or auditor mandated by the controller."
Obtaining Leexi's DPA
The DPA is online in two languages and accepted upon subscription.
Leexi DPA, Preamble "This data processing agreement ('agreement') is concluded between the client and Leexi at the date of online subscription to the Services, including free trials."
No need to wait for delivery. The applicable version is the one effective at subscription date, dated on the first page.
Who Signs?
The DPA identifies Leexi SA, headquartered at 2 avenue Herrmann Debroux, 1160 Brussels, Belgium, represented by CEO Xavier Lombard. Governed by Belgian law, disputes fall under Brussels courts (Article 13).
Which Subprocessors Are Named?
Ten subprocessors in Article 6.1, with roles and hosting regions, copied here:
- Amazon Web Services, infrastructure hosting, EU
- Microsoft Azure, transcription and generative AI, EU
- Google Workspace, identity provider, EU
- Gladia, speech-to-text provider, EU
- New Relic, application performance monitoring, EU
- Eleven Labs Inc., speech-to-text provider, Europe
- Scaleway SAS, cloud infrastructure (hosting, storage), EU (France)
- Cloudflare, perimeter security, Europe/UK
- Mailgun, transactional email management, EU (Frankfurt, Germany)
- Mistral, generative AI, EU
The up-to-date list is on Leexi's Trust Center as of September 2, 2026.
What If Leexi Changes a Subprocessor?
GDPR grants you objection rights.
GDPR, Article 28(2) "Processor shall not engage another processor without prior written authorization, and must inform controller of changes, allowing objections."
Leexi's DPA sets a 15-day objection period.
Leexi DPA, Article 6.2 "Client has fifteen (15) days from receipt to object and justify objections."
A good-faith meeting is required before refusal; refusal may prevent service provision dependent on that subprocessor.
What Security Measures Does the DPA Commit To?
GDPR Article 32 names encryption among expected measures.
GDPR, Article 32(1) "Controller and processor implement appropriate technical and organizational measures, including pseudonymization and encryption."
Leexi's DPA addresses this in Article 5.3.
Leexi DPA, Article 5.3 "Leexi has implemented appropriate technical and organizational measures to ensure security and confidentiality, including encryption, access controls, regular backups, employee training, and background checks. Security measures fully implemented following ISO 27001:2022 certification."
How Quickly Does Leexi Notify Data Breaches?
Leexi DPA, Article 5.4 "Leexi must notify the client of any personal data breach within twenty-four (24) hours by email."
Notification includes breach nature, categories and approximate number affected, contact point, probable consequences, and measures taken, enabling your own 72-hour authority notification.
How Long Does Leexi Retain Your Meetings?
Leexi DPA, Article 9.1 "By default, data is retained for a maximum of 2 years. Client may reduce this period on request or via Leexi platform settings."
At contract end, Article 11.2 allows choice between return or deletion. Leexi may keep backup copies if deletion is materially difficult, following a deletion process and reasonable anonymization efforts.
Can You Audit Leexi?
Leexi DPA, Article 10.1 "Client may appoint an independent auditor with reasonable notice (at least 20 days). Audit limited to once per 12 months; client bears costs unless a security incident is found, then Leexi bears costs."
Audit requires confidentiality agreement and excludes access to other clients' data. Notice may extend to 30 days year-end.
What If a Foreign Authority Requests Your Data?
Article 15 addresses Cloud Act concerns common among buyers. Leexi commits to notify you "without undue delay" of legally binding requests, seek exemptions if legally barred from notifying, document efforts, and maintain a written policy available to you.
Knowing the DPA's Limits
The DPA is a standard document. It does not cover everything; better to know before sharing.
- It lacks a clause on non-training of AI models on your meetings. This commitment is in the privacy policy and compliance FAQ, with a dedicated page. If your legal requires it in contract, request it as an annex.
- It has no handwritten signature; accepted online. DPOs wanting countersigned copies or their annex model can request at hello@leexi.ai. Leexi has fulfilled such requests.
- It does not replace SecNumCloud qualification (which Leexi lacks) nor specific HDS certification for health data.
- Audit limited to once per 12 months, at your expense unless incident.
- Does not specify license threshold for Scaleway replacing AWS hosting; addressed in commercial contract.
Documents to Provide Your DPO
| Document | What It Proves | How to Obtain |
|---|---|---|
| DPA version 2.0 dated July 6, 2026 | Processor contract required by GDPR Article 28, with security, notification, retention, audit, and transfer clauses | dpa_en.pdf or dpa_fr.pdf, accepted at subscription |
| List of ten subprocessors with roles and hosting regions | Subprocessing chain and no processing outside EU except Cloudflare (Europe and UK) | Article 6.1 of DPA and Trust Center |
| ISO 27001:2022 Certificate | Certification referenced in DPA Article 5.3 | Provided by sales team with Trust Center access, on request at hello@leexi.ai |
| Privacy Policy | AWS hosting in Europe and non-training commitment | leexi.ai/en/privacy-policy |
| Processing Activities Register | GDPR Article 30 obligation, declared in DPA Article 14.3 | On request at hello@leexi.ai |
| Terms of Service version 2.0 dated July 6, 2026 | Commitment on EU AI regulation, Annex 1.1 | terms_of_service_en.pdf |
Non-training absent from DPA is covered on non-training AI on your meetings. Recording rules, participant info, legal basis, and retention are on record a professional meeting. Certifications and audits gathered in security and compliance section.
You can test Leexi on a real meeting during your DPO's review: DPA applies from free trial. Book a demo
Frequently Asked Questions
Does the DPA Apply During the Free Trial?
Yes. The DPA preamble states it is concluded at online subscription date, "including free trials." Meetings recorded during the trial are covered by the same security, retention, and deletion clauses as paid accounts.
Is the DPA Signed or Accepted Online?
Accepted online at subscription, no handwritten signature. If your procurement requires a signed copy or written confirmation, request it at hello@leexi.ai with your subscription date; the version effective then applies.
What If Leexi Adds a Subprocessor?
Leexi informs you; you have 15 days from receipt to object with justification (Article 6.2). A good-faith meeting precedes refusal. Refusal prevents service dependent on that subprocessor.
How Quickly Does Leexi Notify Data Breaches?
Within 24 hours of awareness, by email, detailing breach nature, affected categories and numbers, contact point, and measures taken (DPA Article 5.4). This leaves you 48 hours for your own authority notification.
Can I Audit Leexi with My Own Firm?
Yes, once per 12 months, with at least 20 days' notice, confidentiality agreement, and at your expense unless a security incident is found (DPA Article 10.1). You may also rely on ISO 27001:2022 certification cited in DPA Article 5.3.
What Happens to My Meetings at Contract End?
You choose between return or deletion of all personal data (DPA Article 11.2). Leexi may keep backup copies if deletion is materially difficult, following deletion processes and anonymization efforts.
Does the DPA Allow Transfer of My Data Outside the EU?
Only to countries deemed adequate by the European Commission or under standard contractual clauses (June 2021 version) (DPA Article 6.4). The ten subprocessors listed host in the EU, Europe, or UK. For third-country authority requests, Leexi commits to notify you without undue delay (Article 15).
Summary
Leexi's DPA exists, is public, and applies from the free trial.
It complies point-by-point with GDPR Article 28: documented instructions, ten named subprocessors with 15-day objection right, ISO 27001:2022-based security, 24-hour breach notification, default two-year retention, return or deletion at contract end, and annual audit.
What it lacks, you request as annex: non-training clause and countersigned copy.
Sources
Texts reviewed from primary sources on August 22 and September 2, 2026.
- Leexi, Data Processing Agreement, version 2.0 effective July 6, 2026, dpa_en.pdf
- Leexi, Terms of Sale and Use, version 2.0 effective July 6, 2026
- Leexi, Privacy Policy, leexi.ai/en/privacy-policy
- Leexi, Trust Center, trust.leexi.ai, accessed September 2, 2026
- GDPR, Articles 5, 28, 30, and 32, text published by CNIL
This page describes the applicable framework. It does not constitute legal advice.
Ready to boost your productivity with Leexi?
Leexi AI Notetaker takes notes for you