Terms and Privacy
Dictum's Terms and Conditions, Privacy Policy, and Data Processing Addendum are collected on this page.
Terms and Conditions
These Terms govern access to and professional use of the Dictum website, dashboard, software development kit, transcription infrastructure, and related services.
Effective date: July 31, 2026 · Last updated: July 31, 2026
1. Legal notice and contact
The Services are intended to be operated by [[LEGAL_ENTITY_NAME]], [[LEGAL_FORM_AND_SHARE_CAPITAL]], with registered office at[[REGISTERED_OFFICE]], registered with the Trade and Companies Register of [[RCS_CITY]] under number [[RCS/SIREN]], and EU VAT number[[VAT_NUMBER]] (“Dictum”, “we”, “us”, or “our”).
Publication director: [[PUBLICATION_DIRECTOR]]. Legal and privacy contact:[email protected].
Hosting provider: Cloudflare, Inc., 101 Townsend Street, San Francisco, California 94107, United States, telephone +1 650 319 8930.
2. Agreement, business use, and eligibility
These Terms form a binding agreement between Dictum and the person or organisation creating an account, ordering a paid service, or otherwise using the Services (“Customer” or “you”). By creating an account or using the Services, you agree to these Terms and, where Dictum processes personal data on your behalf, theData Processing Addendum. ThePrivacy Policyexplains Dictum's processing as an independent controller.
The Services are offered only for business or professional purposes. You represent that you are at least 18 years old, have legal capacity, and have authority to bind the Customer. The Services are not available to consumers.
If an order form, checkout confirmation, or separately signed agreement contains additional terms, those terms apply to their subject matter. In case of conflict, the signed agreement or order form prevails for its subject matter, followed by the DPA for personal-data processing, then these Terms.
3. The Services
3.1 Dictum platform
Dictum provides a developer SDK, APIs, dashboard tools, project credentials, usage controls, optional webhooks, and infrastructure that lets Customers add voice capture and transcription to their products. Available features depend on the selected plan, provider, region, browser, and technical compatibility.
3.2 Bring Your Own Key
In BYOK mode, Dictum currently charges no service fee. Customer selects a compatible third-party provider, supplies its own provider credentials, and remains responsible for that provider's contract, charges, limits, availability, security settings, and data practices. Dictum retains the right to apply reasonable technical, security, and abuse-prevention limits even where the service is free.
BYOK is free at the effective date, but is not promised to remain free forever. Dictum will provide at least 30 days' notice before introducing any future Dictum fee. No new fee will apply retroactively or without Customer choosing to continue under the announced paid terms.
3.3 Managed mode
In Managed mode, Dictum supplies the provider infrastructure. After capture stops, Dictum sends the completed audio to Amazon Web Services' Bedrock service using In-Region processing in AWS Europe (Ireland), region eu-west-1, for transcription with Voxtral Mini 3B 2507. AWS, rather than the underlying model developer, receives and processes Customer Content in this flow.
Dictum's AWS Bedrock environment is configured for zero data retention. Model inputs and outputs are not written to durable storage by AWS, are not shared with the underlying model developer, and are not used to train foundation models. AWS model invocation logging for Customer Content is disabled. These commitments remain subject only to processing or preservation that AWS is legally required to perform.
3.4 Trials, beta features, and changes
Each new business account receives one Managed trial including 10 transcription hours, without a payment card. Dictum reserves the right to change, limit, or discontinue beta, preview, evaluation, and free features at any time. Those features have no service-level commitment.
4. Customer responsibilities and acceptable use
4.1 Accounts, credentials, and end users
Customer must provide accurate account and billing information, keep passwords, signing keys, API keys, webhook secrets, and provider credentials confidential, and promptly revoke credentials suspected of compromise. Customer is responsible for activity under its account and for configuring end-user identities, domains, quotas, and access rules.
4.2 Audio, transcripts, and lawful recording
Customer retains all rights it has in audio, transcripts, prompts, keywords, and other material submitted through the Services (“Customer Content”). Customer grants Dictum a limited, non-exclusive right to process Customer Content only to provide, secure, support, and maintain the Services and comply with law.
Customer must have every permission, notice, consent, and lawful basis required to record, transmit, transcribe, transform, and deliver Customer Content. Customer is responsible for informing its end users, responding to their rights requests, and complying with communications, employment, surveillance, biometric, confidentiality, and sector-specific laws. Dictum does not use Customer audio or transcripts to train Dictum models.
4.3 Prohibited conduct
Customer must not use the Services to break the law; infringe intellectual property, privacy, publicity, or confidentiality rights; distribute malware; bypass security, identity, quota, or billing controls; probe or overload the Service; resell access outside an authorised integration; impersonate another person; generate unlawful surveillance; or submit content Customer is not entitled to process.
Use of Dictum in regulated or high-impact contexts is permitted only after Customer independently assesses accuracy, human oversight, security, and legal requirements. Dictum is not an emergency service and makes no representation that the standard Service is certified for medical diagnosis, legal determinations, financial decisions, biometric identification, life-safety systems, or other critical uses. Customer bears responsibility for such use unless a separate written agreement states otherwise.
5. Fees, usage, and payment
Managed prices, included usage, overage rates, currency, and billing period are shown on the Pricing page and in checkout when Customer subscribes. Prices exclude VAT, sales, withholding, and similar taxes unless expressly stated otherwise. Customer is responsible for applicable taxes, except taxes based on Dictum's net income.
Paid subscriptions renew automatically each month until cancelled. Customer authorises Dictum and Stripe to charge the selected payment method for recurring fees, measured usage, overages, and taxes. Usage is determined from Dictum's service records. Dictum corrects its usage records when it identifies duplicate, failed, fraudulent, or technically invalid events.
Customer has the right to cancel through the billing portal at any time. Cancellation takes effect at the end of the current paid period, and access continues until then. Fees already charged are non-refundable and are not prorated, except where mandatory law or a written agreement requires otherwise. Dictum will notify Customer of a payment failure. If payment remains outstanding for 7 days after notice, Dictum will suspend the affected paid Services until payment is received.
For invoices payable after receipt, late-payment interest accrues from the due date at the rate required by French commercial law, together with the statutory EUR 40 fixed recovery charge and any additional documented recovery costs permitted by law.
6. Intellectual property, feedback, and third parties
Dictum and its licensors own the Services, SDK, documentation, designs, trademarks, software, and related intellectual property. Subject to these Terms, Dictum grants Customer a limited, non-exclusive, non-transferable, revocable right during the agreement to access the Services and integrate the SDK into Customer's own products.
Customer must not copy, sell, sublicense, reverse engineer, or create a competing service from protected portions of Dictum except where applicable law expressly prohibits that restriction. Open-source components remain governed by their licences.
Customer is free to provide suggestions or feedback. Customer grants Dictum a perpetual, worldwide, royalty-free right to use that feedback without identifying Customer or disclosing Customer Confidential Information.
Third-party providers, OAuth services, payment services, websites, and Customer-selected webhook destinations are governed by their own terms. Dictum is not responsible for a third party's service outside Dictum's control.
7. Suspension, termination, and account deletion
Dictum reserves the right to suspend or limit access when reasonably necessary to prevent abuse, protect security, comply with law, respond to a provider outage, avoid harm, or address a material breach. Payment-related suspension follows Section 5. Where practicable, Dictum will notify Customer and allow a reasonable opportunity to cure.
Either party has the right to terminate this agreement if the other party fails to cure a material breach within 30 days after written notice, or immediately if cure is impossible, the use is unlawful, or the other party becomes insolvent. Customer can stop using free Services at any time. Customer has the right to cancel paid Services as described in Section 5.
Account deletion is available through the dashboard. Starting deletion immediately cancels active billing or expires an open checkout before runtime access and account-linked product data are removed, subject to security, dispute, backup, and legal retention obligations. Sections intended by their nature to survive termination—including fees, confidentiality, intellectual property, disclaimers, indemnities, liability, and dispute terms—remain effective.
8. Warranties, indemnity, and liability
The Services are provided on an “as is” and “as available” basis. To the maximum extent permitted by law, Dictum disclaims implied warranties of merchantability, fitness for a particular purpose, non-infringement, uninterrupted availability, and error-free or perfectly accurate transcription. Dictum does not provide a public availability SLA; any SLA must be in a separate written agreement.
Customer will defend, indemnify, and hold harmless Dictum and its personnel from third-party claims arising from Customer Content, Customer's product or end users, unlawful recording or processing, Customer-selected providers or webhooks, breach of these Terms, or infringement caused by Customer, except to the extent caused by Dictum's own breach or misconduct.
To the maximum extent permitted by law, neither party is liable for indirect, consequential, special, exemplary, or punitive damages, or for lost profit, revenue, goodwill, anticipated savings, or data. Each party's aggregate liability arising from the Services is limited to the fees paid or payable by Customer to Dictum during the 12 months preceding the event giving rise to liability.
These exclusions and limits do not apply where prohibited by law, including liability that cannot be limited for fraud, wilful misconduct, gross negligence, death or personal injury, or breach of an essential contractual obligation to the extent French law prevents its limitation.
9. Confidentiality and general terms
Each party must protect the other's non-public information using at least reasonable care and use it only to perform the agreement. Confidentiality does not cover information that is public without breach, already lawfully known, independently developed, or lawfully received without restriction. Legally compelled disclosure is permitted after advance notice where lawful.
Dictum can update these Terms prospectively. Material changes will be announced through the Service or sent to the account email at least 30 days before taking effect. Continued use after the effective date constitutes acceptance; if Customer does not accept a material change, its remedy is to stop using free Services or cancel paid Services before renewal.
Neither party is liable for delay caused by events beyond reasonable control. Customer must not assign this agreement without Dictum's prior written consent. Dictum has the right to assign this agreement in connection with a merger, reorganisation, financing, or sale of relevant business assets. The agreement creates no partnership, agency, employment, or third-party beneficiary.
These Terms, the DPA, the applicable order, and documents incorporated by reference form the entire agreement. Failure to enforce a provision is not a waiver. Invalid provisions will be limited to the minimum extent necessary while the remainder continues in effect. Notices to Dictum must be submitted using the contact details in Section 1.
These Terms are governed by French law, without regard to conflict-of-law rules.FOR ANY DISPUTE BETWEEN PROFESSIONALS, THE COURTS HAVING JURISDICTION OVER DICTUM'S REGISTERED OFFICE AT [[REGISTERED_OFFICE]] HAVE EXCLUSIVE JURISDICTION, INCLUDING IN SUMMARY, MULTI-PARTY, OR THIRD-PARTY PROCEEDINGS.
Privacy Policy
This Policy explains how Dictum handles personal data relating to website visitors, business customers, account users, developers, and people whose audio is processed through a Customer integration.
Effective date: July 31, 2026 · Last updated: July 31, 2026
1. Who we are and how to contact us
The intended data controller is [[LEGAL_ENTITY_NAME]], [[LEGAL_FORM_AND_SHARE_CAPITAL]], with registered office at[[REGISTERED_OFFICE]], registered under[[RCS/SIREN]] (“Dictum”, “we”, “us”, or “our”).
For questions, privacy requests, or complaints, contact[email protected]. We have not appointed a Data Protection Officer unless this Policy is later updated to identify one.
2. Scope and our data-protection roles
This Policy applies to dictumflow.com, the Dictum dashboard, public demonstrations, SDK infrastructure, support interactions, billing administration, and related online Services. It does not govern a Customer's own website, application, webhook recipient, or independently selected BYOK provider.
Dictum acts as an independent controller for website security, account administration, customer relationships, billing, fraud prevention, legal compliance, and its own service operations. Dictum acts as a processor when it handles Customer Content—such as audio, transcripts, end-user identifiers, prompts, or keywords—solely on a Customer's instructions. Processor activities are governed by theData Processing Addendum.
Customers are responsible for their end users and normally act as controller for audio and other personal data submitted through their integrations. End users should first direct requests about Customer Content to the relevant Customer.
3. Personal data we process
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, business email, account ID, authentication method, OAuth profile fields | You and the OAuth provider you choose |
| Business and billing | Company name, billing address, country, VAT/tax ID, plan, Stripe customer and invoice references | You and Stripe |
| Project configuration | Project and site IDs, domains, model choices, quotas, prompts, keywords, webhook URL, key prefixes and status | Customer account users |
| Credentials | BYOK provider API keys and webhook signing secrets stored in an encrypted secrets vault | Customer account users |
| Usage and diagnostics | Session and request IDs, model, duration, status, error code, timestamp, pseudonymous end-user subject hash | SDK, browser, Workers, and service systems |
| Device and network | IP address, user agent, origin, browser signals, security events, and short-lived operational logs | Your browser, network, Cloudflare, and service systems |
| Customer Content | Audio, resulting transcript, context prompt, keywords, and optional signed webhook payload | Customer's integration and its end users |
| Communications | Support messages, legal requests, and information you provide when contacting us | You |
We do not intentionally collect government identifiers, payment-card numbers, precise location, or special-category data for our own purposes. If a Customer or speaker submits sensitive information, that information forms part of Customer Content.
4. Why we process data and our legal bases
| Purpose | Legal basis where GDPR applies |
|---|---|
| Create accounts, authenticate users, provide projects and deliver the contracted Services | Performance of a contract and steps requested before contract |
| Process Customer Content on a Customer's documented instructions | Customer's legal basis; Dictum acts as processor |
| Measure usage, invoice Managed services, collect payment, and keep accounting records | Contract and legal obligations |
| Protect accounts, verify human traffic, prevent abuse, investigate errors, and maintain reliability | Legitimate interests in secure and reliable operations |
| Respond to support, privacy, and legal requests | Contract, legitimate interests, and legal obligations |
| Establish, exercise, or defend legal claims and comply with valid authority requests | Legitimate interests and legal obligations |
We do not sell personal data, share it for cross-context behavioural advertising, or use Customer audio or transcripts to train Dictum models. We do not make decisions producing legal or similarly significant effects about account users through automated profiling.
5. Audio, transcripts, identities, and webhooks
Dictum transports audio only for the requested transcription. In the Managed flow, capture completes before audio is sent to AWS Bedrock for In-Region processing inAWS Europe (Ireland), region eu-west-1, using Voxtral Mini 3B 2507. In BYOK mode, it is sent to the provider selected and funded by Customer. The resulting transcript is returned to the SDK client and, if Customer enables it, placed temporarily into a bounded Cloudflare Queue for signed delivery to Customer's webhook.
Dictum does not write raw audio or transcript text to its Supabase database, Durable Objects, or application logs. Transcript text leaves Dictum only through the SDK response and an optional Customer-configured webhook. When temporary in-memory, streaming, retry, or dead-letter handling retains content, it does so only for the time technically necessary to complete or troubleshoot the requested delivery.
Signed end-user identities are supplied by Customer. Dictum stores or records only the limited identifiers and hashes needed to authorise sessions, enforce configured quotas, and attribute usage; it does not treat the signed identity as a Dictum user account.
Dictum's AWS Bedrock environment is configured for zero data retention. AWS does not write model inputs or outputs to durable storage, share them with the underlying model developer, or use them to train foundation models. AWS model invocation logging for Customer Content is disabled, subject only to processing or preservation AWS is legally required to perform.
6. Recipients and service providers
We disclose only the data reasonably necessary to the following recipients:
- Cloudflare for Pages hosting, Workers, network security, queues, logs, and Turnstile.
- Supabase for authentication, PostgreSQL account and project records, and encrypted Vault secrets.
- Amazon Web Services for Managed transcription through Amazon Bedrock in AWS Europe (Ireland), region eu-west-1.
- Stripe for checkout, subscriptions, invoices, tax and payment administration.
- Apple, Google, or GitHub if an account user elects to sign in through that provider.
- Customer-selected BYOK providers and webhook recipients at Customer's express direction.
- Professional advisers, acquirers, courts, regulators, or authorities where reasonably necessary and lawful.
The DPA contains the subprocessors applicable when Dictum acts as processor. Dictum reserves the right to change its subprocessors, their functions, or their processing locations after providing advance notice as described in the DPA.
7. Retention and international transfers
- Raw audio and transcript text are not retained in Dictum's database or application logs after the requested flow, subject to temporary webhook delivery handling.
- Detailed pseudonymous usage events are automatically purged after 7 days.
- Account, project, credential, and configuration data remain while the account or feature is active and are deleted or deactivated following an eligible deletion request.
- Cloudflare Workers operational logs exclude raw audio and transcript text and are retained for no longer than 7 days.
- Dictum retains invoices, transaction evidence, and required accounting records for 10 years after the end of the relevant financial year, as required by French law.
- Support, dispute, fraud, and security records remain only as long as reasonably necessary for the applicable purpose and limitation period.
Managed audio and transcripts are processed exclusively in AWS Europe (Ireland), region eu-west-1. Cloudflare processes network and security data through its global network. Supabase processes account and project data in the configured project region. Stripe and the OAuth provider selected by the user process payment or authentication data under their respective privacy terms.
8. Your privacy rights and choices
Subject to applicable law, you have the right to request access, correction, deletion, restriction, portability, or a copy of your personal data; object to processing based on legitimate interests; withdraw consent where consent is the basis; and complain to a supervisory authority. In France, the lead authority is theCNIL.
Account holders can view their account identity, update their billing details, and delete their account through the authenticated dashboard. Where applicable law grants an additional privacy right that is not available through the dashboard, the request must be submitted using the contact details in Section 1. If the request concerns Customer Content, we will normally direct it to or assist the relevant Customer.
The Services are for professionals and are not directed to children. We do not knowingly create accounts for anyone under 18.
Data Processing Addendum
This DPA governs Dictum's processing of personal data on behalf of a professional Customer under the Terms and forms part of the agreement between the parties.
Effective date: July 31, 2026 · Last updated: July 31, 2026
1. Parties, definitions, and scope
This DPA is between the Customer identified by the applicable account, order, or signed agreement (“Customer”) and [[LEGAL_ENTITY_NAME]] (“Dictum”). It applies when Dictum Processes Customer Personal Data to provide the Services. Capitalised terms not defined here have the meanings in theTerms and Conditions.
“Data Protection Law” means the GDPR, UK GDPR, French Data Protection Act, and other privacy or data-protection law applicable to the Processing. “Customer Personal Data” means Personal Data contained in Customer Content or otherwise Processed by Dictum on Customer's behalf. “Controller”, “Processor”, “Process”, “Personal Data”, “Data Subject”, “Personal Data Breach”, and “Subprocessor” have the meanings under applicable Data Protection Law.
Customer is Controller or Processor, as applicable. Dictum is Customer's Processor or Subprocessor. Each party is independently responsible for its own controller activities. The subject matter, duration, nature, purposes, data types, and Data Subjects are in Annex I.
2. Instructions and party obligations
Dictum will Process Customer Personal Data only on documented instructions from Customer, including these Terms, Customer's configuration and API calls, an order, and further lawful written instructions accepted by Dictum. Dictum will immediately inform Customer if, in its opinion, an instruction violates Data Protection Law, unless prohibited.
Dictum Processes data when required by EU, Member State, or other applicable law. Where legally permitted, Dictum will notify Customer before that Processing. Dictum will ensure persons authorised to Process Customer Personal Data are subject to confidentiality and receive appropriate privacy and security instruction.
Customer is responsible for the lawfulness, fairness, accuracy, and transparency of its Processing; all required notices and lawful bases; Data Subject requests; the legality of recording and transcription; its chosen providers and webhooks; and ensuring its instructions comply with Data Protection Law. Customer will not instruct Dictum to Process data in violation of law.
3. Security and Personal Data Breaches
Taking into account the state of the art, implementation cost, nature, scope, context, purposes, and risks, Dictum will maintain the technical and organisational measures in Annex II. Dictum reserves the right to replace a measure with an equally or more protective measure without reducing overall security.
Dictum will notify Customer within 24 hours after becoming aware of a suspected or confirmed Personal Data Breach affecting Customer Personal Data. The notice will include information reasonably available about the nature of the breach, affected data and people, likely consequences, mitigation, and a contact point. When complete information is not available with the initial notice, Dictum provides the remaining information in phases. Notification is not an admission of fault.
Customer is responsible for securing its applications, end-user devices, credentials, identity signing process, webhook destination, and provider accounts, and for promptly notifying Dictum of suspected compromise relevant to the Services.
4. Subprocessors and international transfers
Customer gives general written authorisation for Dictum to engage the Subprocessors in Annex III. Dictum will require each Subprocessor to protect Customer Personal Data under written terms substantially no less protective than this DPA for the relevant Processing. Dictum remains responsible for its Subprocessors to the extent required by Data Protection Law.
Dictum will inform Customer of an intended addition or replacement of a Subprocessor before the change takes effect, giving Customer the opportunity to object on reasonable data-protection grounds.
Where Customer Personal Data is transferred from the EEA, United Kingdom, or Switzerland to a country without an applicable adequacy decision, the parties incorporate the appropriate 2021 European Commission Standard Contractual Clauses, UK International Data Transfer Addendum, or Swiss adaptations. The applicable module is Controller-to-Processor or Processor-to-Processor according to Customer's role. This DPA and its annexes complete the relevant appendices; the law and courts specified in the Terms apply where the clauses permit.
A BYOK provider selected and contracted directly by Customer is a Customer-appointed recipient. Customer instructs Dictum to transmit Customer Personal Data to that provider and is responsible for the provider's terms, lawful transfer mechanism, retention, and security configuration.
5. Rights requests, compliance assistance, and audits
Taking into account the nature of Processing, Dictum will provide reasonable assistance through technical measures and information so Customer can respond to Data Subject requests. Dictum will not independently respond regarding Customer Personal Data unless instructed or legally required and will redirect the requester to Customer where practical.
Dictum will reasonably assist Customer with security obligations, breach notifications, data-protection impact assessments, and prior consultation, taking into account the information available to Dictum.
Dictum will make available information reasonably necessary to demonstrate Article 28 compliance. No more than once annually, unless required by a regulator or following a material breach, Customer has the right to request an audit by an independent qualified auditor bound by confidentiality. Audits require at least 30 days' notice, must avoid disruption and access to other customers' data, and are at Customer's cost unless they reveal a material Dictum breach.
6. Return, deletion, liability, and priority
During the agreement, Customer can retrieve outputs delivered through the SDK or its webhook and manage account data through available tools. At termination or eligible account deletion, Dictum will delete or render inaccessible Customer Personal Data unless Customer requests return before deletion or law requires retention.
Dictum does not maintain a database archive of raw audio or transcript text. Customer Personal Data present in a provider backup, security record, or webhook retry system remains protected until it is overwritten or expires under the applicable retention cycle.
The liability provisions in the Terms apply to this DPA, except where Data Protection Law requires otherwise. If this DPA conflicts with the Terms on Processing of Customer Personal Data, this DPA controls. Standard Contractual Clauses control over both where they expressly require.
Annex I — Details of Processing
| Subject matter | Voice capture, transcription, transcript delivery, SDK identity and quota enforcement, project configuration, optional webhooks, and related support. |
|---|---|
| Duration | For the agreement and the limited retention periods described in the Privacy Policy, unless law requires longer. |
| Nature | Receipt, transmission, temporary buffering, inference, transcription, organisation, pseudonymisation, usage measurement, signed delivery, deletion, and troubleshooting. |
| Purposes | Provide, secure, meter, support, and maintain the Customer-configured Dictum Services. |
| Data Subjects | Customer account users, developers, employees, contractors, customers, website or application users, speakers, and other people whose data Customer submits. |
| Personal Data | Audio and speech content, transcript text, pseudonymous end-user identity and subject hash, prompts, keywords, project/site identifiers, domain, device and network metadata, usage duration, model, timestamps, status and errors. |
| Sensitive data | Dictum does not require sensitive data. If speakers state or Customer submits sensitive information, Customer Content includes that information. |
| Frequency | Continuous or occasional, as initiated and configured by Customer and its end users. |
Annex II — Technical and organisational measures
- Encryption in transit using HTTPS/WSS and provider-secure transport.
- Provider API keys and webhook secrets stored in Supabase Vault with only prefixes exposed to the dashboard.
- Least-privilege service bindings, restricted internal routes, scoped credentials, and separated production services.
- Signed project identities, bounded token lifetime, domain controls, per-session and daily quotas, request validation, and rate or abuse controls.
- No raw audio or transcript text in Supabase tables, Durable Objects, or application logs; diagnostic fields are minimised and credentials are redacted.
- Signed webhook payloads, bounded queue messages, retry controls, dead-letter handling, and encrypted persistent secret retrieval.
- Role-based account access, Supabase row-level security, ownership checks, credential rotation, and hard account-deletion controls.
- Short retention for detailed usage and operational logs, monitoring, incident investigation, dependency error isolation, and recoverable infrastructure configuration.
Managed transcription uses AWS Bedrock In-Region processing in AWS Europe (Ireland), region eu-west-1, with zero data retention active and AWS model invocation logging for Customer Content disabled. AWS does not write model inputs or outputs to durable storage or share them with the underlying model developer, subject only to processing or preservation AWS is legally required to perform. Dictum does not claim a security certification that it has not obtained.
Annex III — Authorised Subprocessors
| Subprocessor | Purpose | Data/location |
|---|---|---|
| Cloudflare, Inc. and affiliates | Pages, Workers, network transport, security, Turnstile, queues, and operational logs | Global network, including EEA and United States |
| Supabase, Inc. and affiliates | Authentication, PostgreSQL account/project records, and encrypted secrets vault | Configured project region |
| Amazon Web Services EMEA SARL and affiliates | Managed audio inference and transcription through Amazon Bedrock using Voxtral Mini 3B 2507 with zero data retention | AWS Europe (Ireland), region eu-west-1, In-Region processing |
Stripe and OAuth providers process controller-side account or payment data as described in the Privacy Policy rather than Customer audio under this DPA.