Data Processing Agreement (DPA)

according to art. 28 GDPR

Date of publication for the current version: August 6, 2026

Data controller

For data processing responsible client

(hereinafter referred to as the client)

Data processor fonio GmbH Neustiftgasse 73-75/3/7 1070 Wien Wien Austria (hereinafter referred to as the contractor)

Unless otherwise agreed between the Client and the Contractor, this Data Processing Agreement forms an integral part of the Contractor’s General Terms and Conditions, which are available at https://www.fonio.ai/agbs. This Data Processing Agreement applies between the Client and the Contractor whenever the Contractor processes personal data on behalf of the Client in connection with the provision of its services.

1. BACKGROUND AND SPECIFICATION OF DATA PROCESSING

1.1 The contractor is a company that offers the following services:

1.2 The client is a company that plans to use the contractor's services in the areas specified.

1.3 This Data Processing Agreement specifies the conditions for the processing of personal data by the contractor with the client's approval in accordance with the General Data Protection Regulation (GDPR). The contractor acts as a processor within the GDPR's definition.

2. NATURE, PURPOSE, OBJECT, AND LEGAL BASIS OF DATA PROCESSING

2.1 The Contractor’s services are described in the Contractor’s General Terms and Conditions (GTC), which can be accessed at https://www.fonio.ai/agbs.

2.2 In the course of providing services, the client shall provide the contractor with the personal data required for the provision of services in the appropriate manner in each case, for example, by electronic or physical means, via discussions and analyses, the performance of other contractually regulated activities, verbally, or via software tools.

2.3 Personal data may be processed, in particular, by organizing, arranging, storing, and, if necessary, adapting or modifying, querying, linking, restricting, deleting, combining, copying, hiding, connecting, analyzing, reading, receiving, sending, and updating, insofar as this is necessary for the provision of the agreed services.

2.4 The purpose of the processing is the contractually agreed provision of services to the client.

2.5 The Contractor is not obliged to verify the lawfulness of the client's underlying data processing.

3. CATEGORIES OF PERSONAL DATA AND DATA SUBJECTS CONCERNED

3.1 As part of the agreed services, several categories of personal data may be processed. In particular, this can be the following categories:

3.2 In general, the processing covers all special categories of personal data (Art. 9 GDPR) necessary for the provision of the agreed services. In particular, the following special categories of personal data may be processed in connection with the provision of the agreed services (for example, for healthcare providers):

3.3 In general, all categories of data subjects necessary for the provision of the agreed services are covered by the processing. In particular, this includes the following categories of data subjects:

3.4 Given the nature of the agreed services, the client acknowledges that the contractor cannot review or maintain the list of categories of data subjects. Therefore, the client shall inform the contractor of any necessary changes to the list of categories of data subjects.

3.5 The contractor shall process the client's personal data regarding all data subjects listed above in accordance with the agreed services. If, due to changes to the list of categories of data subjects, changes to the agreed processing operations become necessary, the client shall issue additional instructions to the contractor accordingly.

3.6 No Voice Identification or Voice Verification

(a) The contractor does not perform voice identification or voice verification in connection with the agreed services. In particular, it does not create, store, or compare voice profiles ("voiceprints", voice templates) and does not deploy technical methods aimed at the unique identification of, or cross-conversation recognition of, a natural person on the basis of their voice. Audio voice data is processed exclusively for voice input and output as well as for transcription (speech-to-text/text-to-speech). A technically necessitated distinction between conversational contributions within a single conversation (e.g., separating caller and assistant) does not serve identification and does not enable recognition beyond the respective conversation.

(b) According to the contractor's own understanding, the audio voice data processed therefore does not constitute biometric data for the purpose of uniquely identifying a natural person within the meaning of Art. 4 No. 14, Art. 9 para. 1 GDPR. Point 3.6(a) contains a statement of fact, point (b) a legal opinion of the contractor; no warranty or representation in the legal sense is associated with it. The data-protection classification, in the individual case, of the processing operations initiated by the client is the responsibility of the client as controller; Point 2.5 remains unaffected.

(c) This is without prejudice to the fact that the processing may, for other reasons, comprise special categories of personal data within the meaning of Art. 9 GDPR, in particular health data (Point 3.2), and that the content of conversations may allow inferences to be drawn as to such data.

4. TERMS AND CONDITIONS OF DATA PROCESSING

4.1 The contractor shall comply with all requirements of the GDPR during the entire provision of services.

4.2 The contractor shall only process personal data based on written instructions in the form of a contract with the client. Deviations from these instructions require the client's prior written consent.

4.3 The contractor processes the personal data in accordance with the principle of data minimization pursuant to Art. 5 para. 1 lit c GDPR and therefore only to the extent necessary to provide the agreed services.

4.4 Access to the client's personal data is only granted to individuals who require this access due to contractual or legal obligations.

4.5 All individuals on the contractor's side who have access to the client's personal data shall be obliged to maintain confidentiality. In particular, the duty of confidentiality of the individuals entrusted with data processing shall remain even after termination of their activity with the contractor.

If the client is subject to a statutory professional duty of confidentiality, the Undertaking of Confidentiality and Data Protection referred to in Appendix 4, in the version provided for the client's state of domicile, shall additionally apply; it is retrievable, version-accurate, at the reference source indicated in Appendix 4. It shall be deemed agreed upon conclusion of the contract, without the need for a separate agreement or signature; a countersignature is provided at the client's request but is not required for its validity. For clients domiciled in Switzerland, the Addendum for Clients Domiciled in Switzerland shall apply in this respect.

4.6 The contractor shall implement and maintain all suitable, appropriate, and state-of-the-art technical and organizational measures to ensure the availability, confidentiality, and integrity of personal data. A list of the agreed technical and organizational measures is attached to this data processing agreement in Appendix 1.

4.7 The contractor shall support the client in complying with its obligations under the GDPR, in particular with regard to the rights of data subjects.

4.8 Unless otherwise required by law, the contractor shall inform the client immediately if it receives information or notification from a data subject, the data protection supervisory authority, or another authority or a third party, and this information or notification is directly or indirectly related to the processing of personal data under this Data Processing Agreement.

4.9 In the context of the contracted data processing, the contractor shall support the client—to the extent required by law—in the creation and updating of the record of processing activities, in the performance of the data protection impact assessment, and, if required, in prior consultations with the data protection supervisory authority within the meaning of Art. 36 GDPR. The contractor shall provide all necessary details and information for this purpose. In addition, the contractor shall maintain its own record of processing activities and, if required, carry out data protection impact assessments and appoint a data protection officer.

4.10 The contractor shall inform the client immediately, but at the latest within 24 hours, if the personal data provided to the contractor has been used unlawfully and/or the data subjects are at risk of harm. The contractor shall provide the client with all necessary information so that the Client can fulfill its reporting obligations to the data subjects in accordance with data protection laws.

4.11 Any transfer of personal data by the contractor to a third country or international organization shall be in accordance with Union or national law and must, in particular, comply with the provisions of the GDPR.

4.12 The parties may agree in Appendix 2 on other clauses concerning the provision of the personal data processing service, as long as they do not contradict directly or indirectly this data processing agreement or prejudice the fundamental rights or freedoms of the data subject and the protection afforded by the GDPR.

4.13 The contractor shall immediately inform the client if it believes that an instruction from the client violates data protection regulations of the Union or the Member States.

5. SUB-PROCESSORS

5.1 Depending on the contractually agreed service provision, a dedicated approved list of subprocessors is involved in the data processing.

5.2 The use of subprocessors may result in data being transferred to third countries. The contractor shall ensure that the requirements of Articles 44–49 GDPR are complied with when transferring personal data to third countries and shall inform the client of the guarantees used in each case (e.g., standard contractual clauses, adequacy decision).

5.3 A list of sub-processors approved by the client upon conclusion of the agreement is included in Appendix 3.

5.4 A contract shall be concluded between the Contractor and the subprocessors in accordance with Art. 28 (4) GDPR. The subcontract shall take into account the data protection requirements to the same extent as those agreed between the client and the contractor in this agreement, and data processing may only be carried out for the purpose specified in the separately contracted service.

5.5 The contractor shall regularly check that subprocessors comply with the data protection obligations applicable under this data processing agreement. If, in the course of this check, the contractor becomes aware that the subprocessor is not fulfilling, or is not sufficiently fulfilling, the data protection obligations incumbent upon it under this data processing agreement, it shall immediately inform the client without being asked to do so.

5.6 The outsourcing to subprocessors or / the change of the existing subprocessors is permissible insofar as:

6. AUDIT AND COMPLIANCE

6.1 The contractor shall permit the client or its designated representatives to conduct audits and inspections to verify compliance with the terms of this Data Processing Agreement. Such audits shall be conducted with reasonable advance notice and shall not unreasonably interfere with the contractor's operations. The client is aware that any inspections of sub-processors must be coordinated directly with these sub-processors, and that the contractor has no influence on the conditions applied.

The client shall bear the costs of conducting the audit, unless the audit reveals a serious breach of this Data Protection Agreement by the contractor.

6.2 Any third-party auditors shall be subject to confidentiality agreements.

6.3 The contractor shall provide the client with all necessary information and work with the client to demonstrate compliance with the GDPR.

7. DURATION AND TERMINATION OF CONTRACT

7.1 This Data Processing Agreement shall remain in force for the duration of the data processing activities and shall terminate upon completion of the provision of the services or as otherwise agreed by the parties.

7.2 Upon termination of the Data Processing Agreement (or at any time prior thereto at the client's request), the contractor shall, at the client's discretion, either destroy the processed personal data (including any copies) itself or hand them over to the client in their entirety, provided that this does not conflict with any statutory obligation to retain them. The contractor shall continue to guarantee compliance with these clauses until the data is deleted or returned. If the client does not comment on the procedure, the contractor shall destroy the data 30 days after termination of the agreement, subject to statutory obligations to retain the data.

7.3 The contractor shall arrange the destruction or handover of data by any sub-processors.

8. FINAL CLAUSES

8.1 Amendments and supplements to this data processing agreement and all its components require a written agreement, which may also be in an electronic format (text form), and the express indication that it is an amendment or supplement to this data processing agreement. This also applies to the waiver of this formal requirement.

Clause 2.3 of the Terms and Conditions (amendment by fictitious consent) does not apply to this Agreement and its Appendices.

8.2 This Data Processing Agreement shall be governed by and construed in accordance with applicable law in Austria. The place of jurisdiction is Wien.

8.3 In case individual provisions of this Data Processing Agreement become invalid or unenforceable, the remainder of the Data Processing Agreement shall remain unaffected. These provisions shall be deemed to be replaced by valid and enforceable provisions that best achieve the economic purpose intended by the contracting parties.

Appendix

Appendix 1: Technical and Organisational Measures(TOMs)

Technical Measures

Organizational Measures

Appendix 2: Additional clauses

Appendix 3: Sub-processors

Version date of this appendix: September 16, 2026

Clarification for clients domiciled in Switzerland: The guarantees indicated in this Appendix for transfers to the United States refer to the EU-US Data Privacy Framework and the EU Standard Contractual Clauses. For clients domiciled in Switzerland, the corresponding Swiss transfer instruments apply in addition to, or in place of, these, namely the Swiss-U.S. Data Privacy Framework (for correspondingly certified recipients; the U.S. was added to Annex 1 of the Swiss Data Protection Ordinance by the Federal Council on 14 August 2024) and, for non-certified recipients and other third countries, the standard contractual clauses recognized by the FDPIC (EU SCCs in the version dated 4 June 2021, including the so-called "Swiss Finish"). Details are governed by the Addendum for Clients Domiciled in Switzerland.

Main Providers for Service Provision

The following providers are always used. In the event that a fallback provider has been selected as the primary provider at the customer’s express request, it is also possible—again at the customer’s express request—to exclude the previous provider from the list of primary providers below.

Fallback Providers to Increase Availability

The following providers serve as a fallback in the event that a main provider fails or is unable to deliver the required service quality. This serves to increase the availability and quality of the Service. The use of fallback providers is deactivated by default for holders of a professional duty of confidentiality and can be activated at the customer's request. For all other customers, who are not subject to a professional duty of confidentiality, fallback providers are activated by default but can be deactivated at the customer's request. It is also possible to use the providers mentioned as the primary provider upon the customer's express request.

Optional Providers

The following providers are used only optionally and solely at the customer's express request.

Additions Regarding Failover Mechanisms

To ensure the availability of our service and its service quality, we deploy a US failover (temporary rerouting of the affected provider's data flow to US server locations) for the following providers in the event of unavailability or insufficient availability of the EU locations — and only in that event:

Failover mechanisms are used only for the minimum time necessary. Deactivation of the US failover is possible at any time at the customer's request.

For holders of a professional duty of confidentiality, a US failover is deactivated by default.

Appendix 4: Undertaking of Confidentiality and Data Protection

The following Undertakings of Confidentiality are attached to this Agreement as Appendix 4. The client may rely on the version applicable to it, without any substantive modification:

For clients domiciled in Switzerland, no separate declaration is maintained; the corresponding provision (Art. 321 of the Swiss Criminal Code (chStGB)) is contained in Point 4 of the Addendum for Clients Domiciled in Switzerland.

This Data Processing Agreement was created using the Metasoul DPA-Generator.