Data Processing Agreement

MLALab.ai acts as a data processor on behalf of our users (data controllers) under GDPR Article 28. This page outlines our data processing practices and sub-processor list.

Processing Purposes

Sub-Processors

Sub-ProcessorPurposeData ProcessedLocation
Cloud Database ProviderDatabase, Authentication, File StorageAll user dataUS / EU
Frontend Hosting ProviderWeb application hostingFrontend requests, logsGlobal CDN
Backend Hosting ProviderAPI hostingAPI requests, logsUS
Payment ProcessorPayment processingEmail, payment infoUS
AI Transcription ProviderSpeech-to-text, AI auditingAudio/text (ephemeral)US
Translation & TTS ProviderTranslation, text-to-speechText content (ephemeral)US
Premium TTS ProviderPremium voice synthesisText content (ephemeral)US / EU
Email Service ProviderTransactional emailUser email addressesUS
DNS & CDN ProviderDNS, DDoS protectionTraffic metadataGlobal

Sub-processor names available upon request for customers with active DPAs. Contact privacy@mlalab.ai.

Data Retention

Breach Notification

In the event of a personal data breach, we will notify affected data controllers within 72 hours of becoming aware of the breach, as required by GDPR Article 33.

Technical & Organizational Measures

Request a DPA

Enterprise customers requiring a signed Data Processing Agreement can contact us at privacy@mlalab.ai. We will provide a customized DPA including Standard Contractual Clauses (SCCs) for international data transfers.

Last updated: March 10, 2026