Jeen Talk Data Processing Addendum (DPA)

This Data Processing Addendum (this “Addendum”or “DPA”) is incorporated into and forms part of the terms and conditions of service, or other principal agreement governing the provision of SaaS voice artificial intelligence services (the “Agreement”) by and between “Jeen AI Ltd.” (“Jeen” or the “Processor”) and the entity purchasing or accessing the services (“Customer”or the “Controller”).

Capitalized terms used in this Addendum shall have the meanings set forth herein. Capitalized terms used but not otherwise defined herein shall have the meanings given to them in the Agreement. Except as expressly modified below, the terms of the Agreement shall remain in full force and effect.

1. INTERPRETATION AND DEFINITIONS

1.1. Definitions:**

*   “Adequate Country” means a country or territory recognised by the European Commission, the United Kingdom, or the Israeli Privacy Protection Authority (as applicable) under Data Protection Laws as providing adequate protection for Personal Data.

*   “Biometric Vocal Data” means original audio and video recordings of natural human voices (“Inputs”)  and any biometric templates, voiceprints, mathematical vocal weights, or physiological/acoustic characteristics derived therefrom used to identify a natural person or generate a synthetic replica of their voice.

*   “Customer Personal Data” means any Personal Data processed by Jeen on behalf of the Customer in the course of providing the Services under the Agreement.

*   Data Protection Laws” means all applicable global privacy and data protection laws, including: (a) the EU General Data Protection Regulation (“GDPR**”); (b) the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection (“Swiss FADP**”; (d) the Israeli Protection of Privacy Law, 5741-1981, and its regulations ]; (e) US state privacy laws (including the California Consumer Privacy Act and California Privacy Rights Act) ; and (f) any other legislation applicable to the processing of Customer Personal Data under the Agreement.

*   “Data Subject Request”or “DSAR”means a request made by or on behalf of a Data Subject to exercise rights granted under Data Protection Laws.

*   “Security Incident” means a breach of Jeen’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in Jeen’s possession, custody, or control.

*   “Subprocessor” means any third-party processor appointed by Jeen to process Customer Personal Data under the Agreement.

*   “Synthetic Audio” means any artificial voice outputs, translated audio, dubbed soundtracks, or synthetic voice clones generated by the Platform (“Outputs”).

2. ROLES OF THE PARTIES AND COMPLIANCE

2.1. Roles of the Parties

The parties acknowledge and agree that, as between them, with regard to the processing of Customer Personal Data under the Agreement, Customer is the Controller and Jeen is the Processor. If Customer acts as a processor on behalf of a third-party controller, Jeen shall act as a sub-processor to Customer.

2.2. Compliance

Each party shall comply with the obligations applicable to it in its respective role under Data Protection Laws. Jeen shall process Customer Personal Data strictly as instructed by Customer and only to the extent necessary to provide the SaaS AI voice and dubbing services.

2.3. Customer Instructions

Customer hereby instructs Jeen to process Customer Personal Data: (a) to provide the Platform and related dubbing/voice clone Services; (b) to perform its contractual obligations under the Agreement and this Addendum; and (c) as necessary to prevent or address technical, performance, or security issues. Jeen shall notify Customer if, in its opinion, an instruction infringes upon Data Protection Laws.

2.4. Customer Responsibilities

Customer shall be solely responsible for:

2.4.1 Giving adequate notice and making all appropriate disclosures to Data Subjects (including voice actors, performers, and users) regarding the collection, use, and processing of their Vocal and Biometric Data by Jeen;

2.4.2 Obtaining all necessary rights, legal bases, permissions, and valid, explicit consents (including explicit biometric consents where required by law) to upload Vocal Data to the Services and permit Jeen to generate Synthetic Audio or Voice Clones;

2.4.3.Ensuring its instructions for the processing of Customer Personal Data comply with all applicable Data Protection Laws.

3. TECHNICAL AND OPERATIONAL AI EXCLUSIONS AND SAFEGUARDS

3.1. Training Restrictions

Jeen shall not use identifiable Customer Personal Data, original vocal recordings (Inputs), or custom voice models to train, fine-tune, or improve its base, generalized, or multi-tenant machine learning models for external commercialization, unless expressly agreed to in writing by the Customer.

3.2. Separation of Environments:

Jeen shall maintain logical separation between Customer environments and data stores. Customer’s custom-trained voice models, biometric voiceprints, and script databases shall be isolated to prevent cross-tenant exposure or unauthorized access.

4. SUBPROCESSING

4.1. General Authorization

Customer grants Jeen general written authorization to engage Subprocessors to facilitate the delivery of the Services, subject to the conditions of this Section.

4.2. Approved Subprocessors

The current approved Subprocessors utilized by Jeen in the delivery of the SaaS Voice AI Platform are listed in Appendix 2of this Addendum. Customer hereby consents to Jeen’s use of the Subprocessors listed in Appendix 2.

4.3. Notification of Changes

Jeen shall notify Customer of any intended changes concerning the addition or replacement of Subprocessors at least ten (10) business days prior to authorizing such Subprocessor to process Customer Personal Data..

4.4. Objection Process:

4.4.1 If Customer has a legitimate, reasonable, and documented ground to object to a new Subprocessor (specifically related to the Subprocessor’s non-compliance with Data Protection Laws), Customer must notify Jeen in writing within ten (10) business days of receiving the notice.

4.4.2 Upon receipt of an objection, Jeen shall use reasonable endeavors to provide the Services without the contested Subprocessor.

4.4.3 If Jeen cannot address Customer’s objection within sixty (60) days, Customer may terminate the specific services that cannot be provided without the use of the objected-to Subprocessor by providing thirty (30) days’ prior written notice.

4.4.4 Liability for Subprocessors

Jeen shall enter into a written contract with each Subprocessor containing data protection obligations no less protective than those in this Addendum. Jeen shall remain fully liable to the Customer for the performance of the Subprocessor’s obligations to the extent Jeen would be liable under the Agreement

5. SECURITY AND CONFIDENTIALITY

5.1. Security Measures:

Jeen shall implement and maintain appropriate physical, organizational, and technical controls designed to protect Customer Personal Data against accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure, or access. The technical and organizational security measures implemented by Jeen are detailed in Appendix 3 of this Addendum.

5.2. Personnel Confidentiality:

Jeen shall ensure that its personnel authorized to process Customer Personal Data are subject to binding obligations of confidentiality or are under an appropriate statutory obligation of confidentiality.

5.3. Security Incident Management:

In the event of a confirmed Security Incident affecting Customer Personal Data in Jeen’s possession or control, Jeen shall:

5.3.1 Notify Customer without undue delay (and in any event, within seventy-two (72) hours of confirmation) via email;

5.3.2   Take immediate, reasonable steps to mitigate the effects, identify the cause, and minimize any resulting damage;

5.3.3   Provide Customer with reasonable information and cooperation as required under Data Protection Laws to enable Customer to fulfill its notification obligations to regulatory authorities or Data Subjects.

5.3.4  A notification under this Section shall not be construed as an admission of fault or liability by Jeen.

6. DATA SUBJECT RIGHTS (DSARs)

6.1. Reasonable Assistance:

Taking into account the nature of the processing and the functionality of the Platform, Jeen shall provide reasonable technical and organizational assistance to enable Customer to respond to Data Subject Requests (such as access, correction, deletion, or portability of Vocal and Biometric Data).

6.2. Direct Requests:

If Jeen receives a DSAR directly from a Data Subject whose voice or data is processed on behalf of the Customer, Jeen shall advise the Data Subject to submit their request directly to Customer, and Customer shall be responsible for responding to the request. Jeen shall not respond directly to any such DSAR unless expressly authorized in writing by the Customer or required by applicable law.

6.3. Time and Materials Cost:

To the extent that providing such DSAR assistance is exceptionally onerous, complex, or time-consuming, Jeen reserves the right to charge Customer for its assistance on a reasonable time-and-materials basis.

7. ASSESSMENTS AND PRIOR CONSULTATIONS

7.1. Impact Assessments:

Upon Customer’s written request, Jeen shall provide reasonable commercial assistance and information to enable Customer to carry out data protection impact assessments (DPIAs) or transfer impact assessments (TIAs) required under Data Protection Laws. Jeen may charge Customer on a time-and-materials basis if such assistance incurs excessive overhead .

8. AUDITS AND CERTIFICATIONS

8.1. Third-Party Audits

Jeen shall use independent, qualified external auditors to annually audit and verify the adequacy of its security controls. Such audits shall be performed according to AICPA SOC 2 standards or a substantially equivalent industry-recognized security standard.

8.2. Audit Reports

Upon written request (and no more than once per calendar year), Jeen shall make its latest SOC 2 Type II report (or equivalent summary report) available to Customer, subject to the confidentiality obligations of the Agreement.

8.3. Customer Audits:

If Customer requires an on-site audit to demonstrate compliance with Data Protection Laws, and the SOC 2 report is insufficient to satisfy Customer’s regulatory obligations, Jeen shall allow for and contribute to reasonable audits and inspections conducted by a qualified independent third-party auditor, subject to the following conditions:

8.3.1 Customer must provide Jeen with at least thirty (30) days’ prior written notice of its intent to audit, including the proposed scope and identity of the auditor (who must not be a competitor of Jeen).

8.3.2  The audit must be conducted during normal business hours, in a manner that does not disrupt Jeen’s operations, and in strict compliance with Jeen’s safety and security protocols;

8.3.3 Any records, system logs, or findings disclosed during the audit shall be deemed Jeen’s Confidential Information and subject to a mutual non-disclosure agreement;

8.3.4 Customer shall bear the entire financial cost of the audit, including any reasonable fees charged by Jeen on a time-and-materials basis for personnel support exceeding ten (10) hours.

9. INTERNATIONAL DATA TRANSFERS

9.1. Data Processing Facilities:

Customer acknowledges that Jeen processes Customer Personal Data in the jurisdictions where Jeen or its Subprocessors maintain operations. Jeen shall ensure that all cross-border data transfers of Customer Personal Data comply with the transfer mechanisms set forth under applicable Data Protection Laws.

9.2. EU/EEA, UK, and Swiss Transfers:

If Customer transfers Customer Personal Data to Jeen that is subject to European Data Protection Laws (GDPR, UK GDPR, Swiss FADP) to a jurisdiction not recognized as an Adequate Country:

9.2.1.  Standard Contractual Clauses (SCCs): The EU SCCs (Module Two: Controller-to-Processor; or Module Three: Processor-to-Processor, as applicable) are hereby incorporated by reference and shall apply;

9.2.2 The selections and modules applicable to the SCCs shall be completed as specified in Appendix 4 of this Addendum.

9.2.3 For UK transfers, the UK International Data Transfer Addendum (“UK Addendum**”) shall apply as incorporated in Appendix 4.

9.2.4 For Swiss transfers, the modifications in Appendix 4 shall apply.

9.3. Israeli Data Transfers:

For transfers of Customer Personal Data subject to Israeli Privacy Laws (PPL 5741-1981) outside of Israel, Jeen shall ensure compliance with the *Privacy Protection Regulations (Transfer of Data to Databases Abroad), 5761-2001. Customer authorizes transfers to Jeen’s cloud infrastructure in the EU (including Azure and RunPod Europe zones) and the United States, subject to the execution of appropriate subprocessor contracts and the protections of this DPA.

10. RETENTION, DELETION, AND RETURN

10.1. Deletion upon Termination:

Upon expiration or termination of the Agreement, Jeen shall, at Customer’s discretion, securely delete or return all Customer Personal Data (including original Vocal Inputs, derived Voiceprints, and custom-trained Voice Models) in Jeen’s possession.

10.2. Specific Biometric Voice Deletion:

For the avoidance of doubt, the deletion of Vocal Data and derived templates under Section 10.1 shall include:

10.2.1.  The permanent destruction of mathematical voiceprints, neural network weights, and synthetic profiles generated from Customer’s inputs

10.2.2.  A written certification of deletion signed by an authorized officer of Jeen, provided to Customer upon written request.

10.3. Immutable Backups:

Customer Personal Data may persist in immutable, encrypted electronic backups maintained by Jeen purely for disaster recovery and business continuity purposes. Jeen shall ensure that such backup copies are kept secure, are isolated from active processing, and are programmatically overwritten or destroyed within ninety (90) days following the termination of the Agreement.

11. GENERAL TERMS

11.1. Governing Law & Jurisdiction:

This Addendum shall be governed by, and construed in accordance with, the governing law and jurisdiction set forth in the Terms and Conditions, unless otherwise required by applicable Data Protection Laws.

11.2. Conflict:

In the event of any conflict or inconsistency between the terms of this Addendum and the master Agreement with respect to the processing of Customer Personal Data, the terms of this Addendum shall prevail.

11.3. Limitation of Liability:

Any liability of Jeen arising under or in connection with this Addendum (including under Data Protection Laws) shall be subject to the limitations, exclusions, and caps set forth in the master Agreement.

 APPENDIX 1: DETAILS OF PROCESSING

  1. Subject Matter and Purpose of Processing

The provision of SaaS voice AI, synthesis, and dubbing services by Jeen to Customer, including the generation of synthetic voice clones, speech-to-text transcription, translation, and localized audio alignment.

**2. Duration of Processing:

The term of the Agreement, plus any additional post-termination data retrieval or backup retention window specified in Section 10 of this Addendum.

  1. Categories of Data Subjects:

*   Authorized admin and operational users of the Customer.

*   Voice actors, performers, narrators, and any other individuals whose vocal recordings are uploaded to the Platform by Customer.

  1. Categories of Customer Personal Data:

*   Vocal Data (Inputs):** Original audio and video files containing human voices.

*   Biometric Data (Voiceprints):** Derived mathematical, algorithmic, or template representations of a natural person’s voice used for AI voice synthesis .

*   Synthetic Audio (Outputs):** AI-dubbed soundtracks, generated vocal clones, and localized audio files.

*   Text and Script Data:** Texts, transcripts, and metadata used for translation, transcription, or synchronization.

*   Account and Authentication Data:** Usernames, business emails, passwords, access logs, and security metadata.

  1. Sensitive Data:

Vocal recordings and voiceprints may constitute Biometric Data (special category data under Article 9 GDPR and biometric information under Israeli and US state privacy laws) to the extent they are processed using technical means to uniquely identify or replicate an individual.

  1. Frequency of Transfer:

Continuous, cloud-hosted SaaS access for the duration of the Agreement.

 APPENDIX 2: APPROVED SUBPROCESSORS

Jeen AI Ltd. utilizes the following Subprocessors to deliver the Platform infrastructure, voice processing, transcription, and translation services:

*Microsoft Azure | Core hosting, cloud databases, Enra ID authentication. Germany / Netherlands | www.microsoft.com/privacy |

*RunPod | GPU cloud infrastructure for AI rendering. | Europe / United States  www.runpod.io/legal/privacy-policy |

*Cartesia Inc.| Realtime Text-to-Speech voice engines. | United States www.cartesia.ai/legal/privacy

*OpenAI, LLC | Language translation, STT, and voice agents. | United States | openai.com/policies/row-privacy-policy/ |

*Deepdub Ltd | Realtime voice localization and dubbing. | Israel / US / Europe | deepdub.ai/legal/privacy |

*Soniox Inc.| Realtime STT and speech-to-text models. | United States | soniox.com/policies/privacy-policy |

*Speechmatics| Batch transcription and async processing. | United Kingdom / EU www.speechmatics.com/legal/privacy-policy |

*WorkOS Inc. | SSO and federated authentication . | United States  | workos.com/legal/privacy |

*Twilio Inc. | PSTN telephony routing and voice connections . | United States | www.twilio.com/en-us/legal/privacy |

*Braintrust | AI agent logging, evaluation, and monitoring | United States  | www.braintrust.dev/legal/privacy-policy |

*Note: On-premise or local deployments utilizing local GPU nodes (such as Whisper-Ivrit running on Customer-controlled infrastructure) do not result in data egress and do not engage external Subprocessors.

 APPENDIX 3: SECURITY MEASURES

Jeen shall maintain the following technical, organizational, and physical security measures to protect Customer Personal Data:

  1. Access and Identity Control

*   Assignment of a unique user ID to each authorized administrator or user.

*   Role-based access controls (RBAC) restricting access to system configurations, vocal assets, and biometric templates solely to personnel who have a verified “need to know”.

*   Mandatory multi-factor authentication (MFA) or SSO (via WorkOS) for all admin access from outside the corporate firewall.

*   System-enforced strong passwords (minimum 8 characters, requiring uppercase, lowercase, numbers, and special symbols) with mandatory lockout policies after repeated incorrect attempts.

  1. Encryption and Transmission Security:

*   Mandatory encryption of Customer Personal Data at rest within all production storage volumes (utilizing AES-256 standard or equivalent).

*   Encryption of all data in transit utilizing TLS 1.3 or higher for all web, platform, and API connections.

*   Separate hosting and testing environments distinct from active production databases.

  1. Infrastructure and Network Defense:

*   Firewall configurations protecting all internet-facing instances and services.

*   Regular vulnerability patching, security updates, and automated anti-malware programs deployed across all host virtual machines.

*   Proactive static application security testing (SAST) via Snyk and container scanning via JFrog to detect dependencies and CVE vulnerabilities prior to code deployment.

  1. Monitoring and Compliance:

*   Continuous logging of administrative and operational events, API requests, and access logs.

*   At least annual penetration testing conducted by independent third-party security professionals, with executive summary reports available to Customer.

*   Vulnerability Disclosure Program maintained to gather, analyze, and resolve bugs reported by external security researchers.

  1. Business Continuity and DR:

*   Disaster Recovery (DR) plan reviewed and tested at least annually.

*   Automated daily backup systems creating encrypted, retention-controlled copies of databases and assets for recovery from catastrophic system failure.

 APPENDIX 4: STANDARD CONTRACTUAL CLAUSES (SCCs)

  1. Incorporation of Clauses:

For transfers of Customer Personal Data out of the EU, EEA, or Switzerland to a third country not subject to an adequacy decision, the EU Standard Contractual Clauses (notified under Commission Implementing Decision (EU) 2021/914) are incorporated by reference and completed as follows:

*Module Two (Controller-to-Processor) applies if Customer is a Controller and Jeen is a Processor.

*Module Three (Processor-to-Processor) applies if Customer is a Processor acting on behalf of a third-party Controller and Jeen is a sub-processor.

  1. Selections under the SCCs:

*Clause 7 (Docking Clause): Optional docking language is omitted.

*Clause 9(a) (Subprocessors):The parties select Option 2 (General written authorization) and the specified notice period shall be ten (10) business days, as set forth in Section 4.3 of this Addendum.

*   Clause 11(a) (Redress):The optional language regarding independent dispute resolution is omitted.

*   Clause 17 (Governing Law The parties select the governing law of the Netherlands.

*   Clause 18(b) (Choice of Forum):The parties select the competent courts of the Netherlands (The Hague).

  1. Annexes to the SCCs:

*   Annex I.A (List of Parties):The Sponsoring Customer is the Data Exporter (Controller), and Jeen AI Ltd. is the Data Importer (Processor).

*   Annex I.B (Description of Transfer):** The details are populated using the information in Appendix 1 of this Addendum.

*   Annex I.C (Supervisory Authority): The competent supervisory authority shall be determined in accordance with the GDPR and Clause 13 of the SCCs (defaulting to the Dutch Data Protection Authority – *Autoriteit Persoonsgegevens* if unclear).

*   Annex II (Technical & Organizational Security):The measures set forth in Appendix 3of this Addendum shall apply.

*   Annex III (List of Subprocessors): The subprocessors approved in Appendix 2 of this Addendum are incorporated.

  1. UK International Data Transfer Addendum (UK Addendum):

If the transfer is subject to UK Data Protection Laws, the UK Addendum is incorporated by reference, modifying the EU SCCs solely to the extent required to establish a lawful transfer mechanism. Tables 1 to 4 of the UK Addendum shall be completed using the corresponding parties, transfer descriptions, security measures, and subprocessors defined in this DPA. Either party may terminate the UK Addendum in accordance with Section 19 thereof .

  1. Swiss FADP Modifications:

If the transfer is subject to the Swiss FADP, the SCCs are modified as follows: (a) references to the EU or Member States include Switzerland; (b) Data Subjects in Switzerland may sue for their rights in their habitual residence; and (c) the competent supervisory authority under Annex I.C shall be the Swiss Federal Data Protection and Information Commissioner.