Sprecho is built and operated in Germany by Melo Designer GmbH, and the GDPR is the baseline it was designed against rather than something added afterwards. This article sets out the roles, what the data processing agreement covers, and how to get one.
If you are filling in a vendor questionnaire, the Trust Center holds the underlying documents and is the faster route.
Who is the controller and who is the processor?
When your organisation uses Sprecho for work, your organisation is the controller of everything your people dictate, and Melo Designer GmbH is the processor, acting only on your documented instructions. That is the relationship the data processing agreement (Auftragsverarbeitungsvertrag, AVV) formalises under Art. 28 GDPR.
For the sprecho.ai website itself, and for private consumer accounts, Melo Designer GmbH is the controller. The privacy policy covers that side.
| Company | Melo Designer GmbH |
| Address | Alter Schützenweg 14, 49688 Lastrup, Germany |
| Register | Amtsgericht Oldenburg, HRB 216834 |
| VAT ID | DE331465335 |
| Data protection contact | dpo@sprecho.ai |
How do I get a DPA for my organisation?
- Open the Trust Center and click Request access.
- Enter your work email address. Personal mailboxes are not accepted — a corporate domain is what lets us verify the request.
- Confirm the six-digit code we email you. Verified corporate domains are approved automatically, usually within minutes; anything else goes to manual review.
- Sign in through the link you receive and download the DPA from the Documents list.
If you would rather do it by email, or you need a customer-specific variant of the agreement, write to dpo@sprecho.ai with the entity name and address that should appear on the contract.
A DPA is not something you have to negotiate before you can trial Sprecho. The agreement is pre-drafted, maintained in English and German from one source so the two versions cannot drift, and covers a standard trial as well as a production rollout.
What the agreement covers
- The subject matter, duration, nature and purpose of the processing, and the categories of data subjects and personal data — the Art. 28(3) minimum.
- The technical and organisational measures (Art. 32): encryption in transit and at rest, access control, and the retention and deletion mechanisms.
- Annex B, the sub-processor list. It is identical to the list published at the Trust Center; material changes are announced in writing with at least 30 days' notice so you can object or terminate.
- EU Standard Contractual Clauses (Module 2, controller to processor) and a UK addendum, so the paperwork is complete even where they are not strictly needed.
- Assistance with data-subject requests, breach notification, audit rights, and what happens to data at the end of the contract.
Sector addenda are available on request: a DORA addendum for EU financial entities and a Swiss revFADP addendum.
Where the data is processed
All processing takes place inside the EU/EEA — application, database and file storage in Germany, GPU inference in Germany and the Netherlands. Every sub-processor is established in the EU/EEA, so there is no third-country transfer to assess and no transfer impact assessment to file.
No third-party AI provider is involved. Speech recognition and formatting run on infrastructure Sprecho operates; audio, transcripts and account data are not shared with external AI services. Customer audio and transcripts are never used to train models.
For the full list of who processes what, see where Sprecho runs and who processes your data.
Data subject rights
Access, rectification, erasure, restriction, portability, objection and withdrawal of consent all apply, and Sprecho supports them directly rather than only on paper:
- Erasure — self-service, immediate. See delete your data or your account.
- Data minimisation — storage of transcripts and audio can be switched off entirely, enforced on the server. See turn off transcript and audio storage.
- Access and portability — request an export at dpo@sprecho.ai; it is delivered as a signed download link to your verified address.
As a controller, you can also point your own employees at those two articles — they answer most internal questions without needing your data protection team.
Requests to dpo@sprecho.ai are completed within 30 days, and you have the right to lodge a complaint with your supervisory authority at any time.