PRIVACY POLICY

PRIVACY POLICY

Voice Soul is an AI-enabled voice, image and language assistance platform that enables users to record, upload, translate, process and receive audio, image-based, contextual and language-related outputs through artificial intelligence and third-party processing systems (the “Services”). The Services are owned and operated by Sohofi Global Technologies, a partnership firm based in India, with its registered office at Flat No. 203, 23/1, J R Makwoods Apartments, Old Mangammanapalya Road, Popular Colony, Mangammanapalya, Bengaluru, Bengaluru Urban, Karnataka, 560068 (“SOHOFI”, “Company”, “we”, “us” or “our”).

Please read this Privacy Policy carefully before accessing or using our Platform, to understand our policies and practices regarding your Information/Data and how we will treat it. This Policy is provided for transparency and information purposes. It is not, by itself, a consent instrument. Reading, accessing, or acknowledging this Policy, or registering on, or using the Platform does not constitute Your Consent to the processing of Your Personal Data for any purpose. This Policy is provided for transparency and information purposes only; it is not, of itself, a consent instrument. Where consent is the applicable legal basis under Article 6(1)(a) (or, for Sensitive Data, Article 9(2)(a)) GDPR/UK GDPR, or the equivalent standard under Article 6(6)-(7) FADP, we will separately obtain your free, specific, informed and unambiguous consent, through a dedicated, itemized consent notice presented at the relevant point of use, before processing your personal data for the relevant purpose. If you accept this Policy on behalf of another person, company or other legal entity, you represent and warrant that you have full authority to bind such person, company, or legal entity to this Policy.

This Privacy Policy (“Policy”) explains how we collect, use, disclose, retain and protect your personal Information/Data when you use the Voice Soul mobile application, website, web application, APIs, interfaces, software, tools, content and related services (the “Platform”). This Policy has been drafted not merely to explain what Information/Data we process, but also why we process it, the safeguards we apply to protect it, and the choices and rights available to you under Applicable Laws. For AI Processing features, Input Data is intended to be processed on a one-time, transient basis to generate the requested AI Output and is then deleted, de-identified or retained only in limited form as described in this Policy.

This Policy is provided electronically and should be read with the Terms and Conditions, consent notices, cookie notices, feature-specific notices and in-app disclosures. Nothing in this Policy limits any mandatory rights available to you under Applicable Laws.

In this Policy, “you” / “your” / “yourself” means the person using the Platform and/or the person on whose behalf you are acting. We process Personal Information/Data, Sensitive Data, third-party information and other Information/Data only for the relevant features and purposes described in this Policy and in accordance with Applicable Laws.

This Policy describes our current data protection policies and practices and may be amended/updated from time to time. Any changes to this Policy will become effective upon posting of the revised Policy on the Platform or upon such other date as may be notified by us. We suggest that you regularly check this Policy to apprise yourself of any updates.

1. CONSENT

This Policy is a privacy notice provided to you in accordance with Articles 13 and 14 of the GDPR/UK GDPR (and the equivalent transparency obligations under Articles 19-21 FADP). It describes our data practices so that you can understand how we process your Personal Data and make an informed decision about your use of the Platform. This Policy, by itself, does not constitute your consent to any processing that relies on consent as its lawful basis. We process your Personal Data on the basis of your consent, the performance of the Terms and Conditions, compliance with a legal obligation, our legitimate interests, or another lawful basis recognized under Article 6 GDPR/UK GDPR (and, for Sensitive Data, an applicable condition under Article 9 GDPR/UK GDPR or Article 6(7)/31 FADP). If you do not agree with the disclosures in this Policy or an applicable consent notice, please do not proceed with the use of the relevant feature or Service. This Policy shall be deemed to be incorporated into the Terms and Conditions of the Platform and shall be read together with them.

Consent” means a freely given, specific, informed and unambiguous indication of your wishes by a statement or by clear affirmative action, signifying agreement to the processing of Personal Information/Data for one or more specified purposes, as defined under Article 4(11) read with Article 7 of the GDPR/UK GDPR (and the equivalent standard of voluntary, informed agreement under Article 6(6)-(7) FADP).

Where consent is the lawful basis for processing, we will present you with a consent notice that: (a) itemizes each category of Personal Data, including any special category or Sensitive Data, proposed to be processed under that consent; (b) specifies each purpose for which it is processed; (c) explains that you may withdraw consent at any time, as easily as you gave it, without affecting the lawfulness of processing carried out before withdrawal; and (d) where processing is to be carried out by a Processor or third-party AI vendor on our behalf, identifies the categories of such recipients. Consent will not be bundled with acceptance of the Terms and Conditions or made a condition of a contract, including the provision of a service, where that consent is not necessary for such performance, and you will not be required to consent to processing beyond what is necessary for the feature or Service you are using. Consent obtained through acceptance of this Policy, app permissions or Terms and Conditions alone does not satisfy the separate, explicit consent standard required under Article 9(2)(a) of GDPR/UK GDPR (or Article 6(7) FADP) for special categories of data or other higher-consent processing; where required, we will separately obtain such consent through in-app prompts or a dedicated consent notice, distinguishable from this Policy.

We do not present consent requests as a single “accept all” or “agree and continue” choice covering unrelated processing activities, and we do not treat silence, inactivity, pre-ticked boxes or continued use of the Platform as an indication of consent. Consistent with this approach, we present separate, itemized consent requests at the point in the Platform where the relevant processing actually begins, rather than as a single blanket acceptance at account creation. These points include, without limitation: (i) account registration, for account-related communications and fraud/security logging incidental to account use; (ii) first use of a specific AI Processing feature, for transmission of your Input Data to the relevant AI Sub-processor; (iii) the cookie preference banner, for non-essential cookies and similar tracking technologies; and (iv) a dedicated marketing opt-in, presented separately from every other consent request, for promotional communications under Article 9(2)(a) of GDPR/UK GDPR (or Article 6(7) FADP). We review these consent points periodically to ensure they continue to reflect where decisions about your Personal Data are actually made.

Where the Platform transmits your Personal Data to an AI Sub-processor as part of providing the core AI Processing functions described in this Policy, such transmission forms an integral part of the Service you have requested. Before you use a feature that involves transmission of your Personal Information/Data to an AI Sub-processor for the first time, the Platform will, to the extent technically practicable and before such transmission commences: (a) inform you of the nature and categories of data to be sent; (b) identify the category of AI Sub-processor that will receive it; and (c) specify the purpose of such transmission. Where Applicable Laws require your consent for that transmission, including, for Sensitive Data or Biometric Data, explicit consent under Article 9(2)(a) of GDPR/UK GDPR or Article 6(7) of FADP, we will additionally obtain that consent by way of a separate, itemized consent notice before transmission commences, and will not activate the relevant feature until consent is given. Your Input Data will be sent to AI Sub-processors in the categories described in this AI Processing, Model Operations and Outputs Section, solely to provide the relevant features to you. Creating an account or using the Platform generally does not, by itself, constitute your consent to such transmission. You may withdraw your consent or decline to use AI Processing features at any time using the controls described in the User Rights and Choices Section of this Policy; such withdrawal will not affect the lawfulness of processing carried out before withdrawal but may limit or prevent your continued use of the relevant feature.

You may withdraw consent at any point of time through the controls made available for the relevant feature or by contacting us, at any time, which shall be as easy to execute as the granting of consent. Withdrawal does not affect processing undertaken before withdrawal and may limit the relevant Service, feature, Coin-related functionality, Offer Wall activity or Third-Party Service. We may continue processing where required or permitted by Applicable Laws, under an independent lawful basis or the extant statutory compliance. Where processing is based solely on your consent, you are free to refuse or withdraw that consent without affecting the lawfulness of processing carried out before withdrawal. Refusing or withdrawing consent will not affect processing carried out on another lawful basis or the continued provision of Services that do not depend on the relevant consent, although the specific feature for which consent is required may become unavailable.

2. APPLICABILITY

This Policy applies to Information/Data collected through the Platform and Services, including account creation, app usage, Voice-to-Voice translation, the Image to Your Voice feature/the Visual Story Converser (image-based question-and-answer), image-to-voice functionality, contextual image assistance, language mapping, location-based language configuration, customer support, Coins, Premium Membership Plans, advertisements, Offer Wall activities and Third-Party Services. It is intended to apply on a Europe-wide basis, subject to mandatory local requirements.

This Policy does not apply to independent third-party applications, app stores, payment gateways, AI vendors, cloud providers, analytics providers, advertising partners, Offer Wall providers, survey providers, game providers, external websites or other Third-Party Services that process Information/Data for their own purposes. Where a third party processes Information/Data on our behalf as a Processor under Article 4(8) GDPR, we seek to apply appropriate contractual, technical and organizational safeguards, in accordance with Article 28 GDPR.

Where we engage any third-party AI Sub-processor, cloud infrastructure provider, analytics service provider, or customer support platform to process Personal Data exclusively on our behalf and strictly in accordance with our documented instructions, such entities act as Processors within the meaning of Article 4(8) GDPR/UK GDPR (or Article 9 FADP). We remain responsible for, and must be able to demonstrate, compliance with our obligations as Controller under Articles 5(2) and 24 GDPR/UK GDPR for all Personal Data processing carried out by such Processors on our behalf. All Processors are bound by enforceable data processing agreements requiring them, consistent with Article 28(3) GDPR/UK GDPR, to: (i) implement appropriate technical and organisational security measures under Article 32; (ii) maintain strict confidentiality; (iii) process Personal Information/Data solely on our documented instructions and for the specific authorised purposes we set; and (iv) afford data subjects protection no less stringent than under this Policy and as prescribed by the GDPR, UK GDPR and FADP.

If you submit, upload, record or process Content, including any person’s voice, image, likeness, biometric information, personal information, confidential information, sensitive information, prompts, files, messages, image links or other materials through the Platform, you are responsible for ensuring that you have all rights, consents, notices, permissions and lawful grounds required under Applicable Laws and the Terms and Conditions.

3. DEFINITIONS

a) Applicable Laws” means laws, rules, regulations, regulatory guidance, governmental directions, orders and legal requirements that apply to the Company, Platform, Services or relevant processing activity, including a) European privacy and data protection laws such as the GDPR (Regulation (EU) 2016/679) and related ePrivacy, consumer-protection, payment, cyber-security, platform and AI-related requirements, to the extent applicable; (b) United Kingdom privacy and data protection laws, including the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, to the extent applicable); (c) Swiss privacy and data protection laws, including the Federal Act on Data Protection (FADP) and its implementing Ordinance on Data Protection (ODP), and related Swiss requirements on data security, breach notification, and cross-border data transfers, to the extent applicable and d) Indian laws mandatorily applicable to the Company, such as the Digital Personal Data Protection (DPDP) Act, 2023.

b) Personal Data” or “Personal Information” means information relating to an identified or identifiable natural person including information treated as personal data under the GDPR/ UK GDPR/ FADP or other Applicable Laws, such as identifiers, contact details, device or online identifiers, usage information, location-related information, voice, image, likeness, account information, payment-related metadata, prompts, Content, AI Outputs and similar information. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, or an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, within the meaning of Article 4(1) GDPR/UK GDPR. Aggregated or anonymized information that cannot reasonably identify an individual is not treated as Personal Data for purposes of this Policy. De-identified or pseudonymized information may remain subject to Applicable Laws where it can reasonably be linked back to an individual by any means reasonably likely to be used.

c) Special Categories of Personal Data” or “Sensitive Personal Data” means (i) under the GDPR and UK GDPR, special category data within the meaning of Article 9(1) such as data revealing racial or ethnic origin, religious beliefs, health, biometric or genetic data, or sex life/sexual orientation and data relating to criminal convictions or offences within the meaning of Article 10; and (ii) under other Applicable Laws, any additional categories of personal information designated as sensitive or subject to heightened protection under those laws.

d) Data Subject” means the identified or identifiable individual to whom Personal Data relates and includes, where applicable, a parent, lawful guardian or authorized representative.

e) Controller” means the natural or legal person, public authority, agency or other body, that alone or jointly with others, determines the purposes and means of processing Personal Data, pursuant to Article 4(7) GDPR.

f) Processor” means a natural or legal person, public authority, agency or other body which is processing Personal Data on behalf of a Controller, including service providers, vendors, contractors and other processors engaged by us pursuant to Article 4(8) GDPR.

g) “Recipient” means a natural or legal person, public authority, agency or another body to which Personal Data is disclosed, whether a third party or not, within the meaning of Article 4(9) GDPR. Public authorities that may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients for the purposes of this Policy where applicable.

h) Processing” means any operation or set of operations, performed on Personal Data whether or not by automated means, such as collection, recording, storage, adaptation, alteration, use, disclosure, transmission, restriction, erasure or destruction, pursuant to Article 4(2) GDPR.

i) “Profiling” means any form of automated processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements, within the meaning of Article 4(4) of the GDPR. Unless expressly stated in this Policy or required for the functioning of a specific Service, we do not carry out profiling that produces legal effects concerning you or similarly significantly affects you.

j) Content” means audio, voice recordings, speech, images, image links, prompts, text, metadata, feedback, files, messages, names, likenesses, instructions and other material submitted, uploaded, recorded or transmitted through the Platform.

k) AI Outputs” means translations, audio responses, transcriptions, descriptions, contextual responses, language-related outputs, image-related outputs, text, voice outputs or other outputs generated or assisted by artificial intelligence, translation, speech, computer-vision or related systems.

l) AI Processing” means processing of Content, Personal Data, device information, technical data, prompts, voice recordings, images, metadata and other inputs by or through AI systems, machine-learning models, translation engines, speech systems, computer-vision systems, safety tools and related Third-Party Services. Unless stated otherwise, raw Input Data is intended to be processed temporarily for the requested Service.

m) Input Data” means prompts, audio, voice recordings, images, image links, text, instructions, metadata, files, feedback and other information provided to the Platform for processing by a Service or AI system. Input Data used to generate an AI Output is not retained as permanent history by default.

n) Model Improvement Data” means data used to monitor, test, evaluate, debug or improve the quality, reliability, safety, latency, usability or performance of the Platform, Services, AI Outputs and related systems. We seek to use aggregated, anonymized, de-identified or minimized data wherever reasonably practicable.

o) Human Review” means review by authorized personnel, contractors or service providers for limited operational, support, quality, safety, abuse-prevention, legal, security or rights-protection purposes, subject to safeguards. Human Review may not be available where raw Input Data has been processed transiently and deleted.

p) Coins”, “Offer Wall”, “Premium Membership Plan”, “Third-Party Services”, “User” and “Visitor” shall have the meanings assigned to them in the Terms and Conditions.

4. INFORMATION WE COLLECT

We collect only such Personal Data as is reasonably necessary for the purposes for which it is processed, consistent with the principles of lawfulness, fairness, transparency, purpose limitation and data minimisation under the GDPR, UK GDPR, the FADP and other Applicable Laws. We will not collect Personal Data beyond what is described in this Policy, the applicable consent notice, the Terms and Conditions, or any feature-specific notice, and we will not process Personal Data for any purpose other than the purpose for which it was collected, another compatible purpose permitted under Applicable Laws, or another lawful basis available under Applicable Laws. Depending on your use of the Platform, we may collect the following categories of Personal Data:

a) Information You Provide to Us

i) Account Information: Information about you that you provide to us when creating, maintaining or using an account, including name, username, account ID, profile information, email address, mobile number, language preferences, country or region selection, authentication information and any other information provided by you.

ii) Content and AI Processing Information: Voice recordings and speech you provide for translation or conversation; photos or images you capture or upload for the Image to Your Voice feature/Visual Story Converser; the text of any follow-up questions you ask; and the AI-generated translations, transcriptions and answers (AI Outputs) we return to you. Your voice recordings and images are not stored; they are processed in real time and deleted after the relevant AI Output is generated.

iii) Communication Information: If you communicate with us, such as by email, in-app support, phone, grievance channels or other means, we may collect your contact information, communication content and related records.

iv) Payment, Subscription, Coins and Offer Wall Information: Premium Membership Plan selection, subscription status, invoice identifiers, transaction references, app-store or payment-provider confirmations, refund status, Coin balance, Coin allocations, usage deductions, reward history, Offer Wall completion status, anti-fraud checks, eligibility criteria, attribution identifiers, third-party verification status and related records.

v) Any Other Information: Additional Information/Data voluntarily provided in connection with the Platform or Services such as customer support communications, feedback, or survey responses, which shall be collected and used solely for the purposes described in this Policy.

b) Information We Collect Through Automated Means

When you use the Platform or Services, we may collect device identifiers, advertising identifiers (where permitted), app instance identifiers, IP address, operating system, browser type, app version, device model, network information, crash logs, diagnostics, usage patterns, cookies, SDK data, analytics data, attribution information, app permission status and similar technical logs, which we collect and use for the purposes described in this Policy, including operating and securing the Platform, diagnosing and fixing technical issues, improving features and performance, and understanding usage patterns.

The Platform may request device permissions such as microphone, camera, photo library, file access, storage, location and notifications. You may enable, disable or modify such permissions through your device settings or Platform settings. If you disable a permission, the relevant feature may not function or may function only in a limited manner.

c) Information We Collect from Other Sources

We may receive Information/Data from app stores, payment providers, Advertising Partners, Offer Wall providers, survey providers, game providers, AI vendors, cloud providers, analytics providers, fraud-prevention providers, support tools and other Third-Party Services, where permitted under Applicable Laws and verified against compliance with secondary user choice metrics.

5. HOW WE USE YOUR INFORMATION

In processing your Personal Data, we adhere to the data protection principles set out in Article 5 GDPR/UK GDPR and Art. 6 FADP. We process your data lawfully, fairly and transparently. We collect it only for specified, explicit and legitimate purposes and do not further process it in a manner incompatible with those purposes. We limit collection to what is adequate, relevant and necessary. We take reasonable steps to keep it accurate and up to date. We do not keep it in identifiable form for longer than necessary, and we process it with appropriate security. We are responsible for, and able to demonstrate, our compliance with these principles.

Sr. No.

Purpose

GDPR / UK GDPR Basis

a

To create, authenticate, maintain, secure and administer your account and provide account-related support.

Performance of contract (Article 6(1)(b))

b

To provide and maintain the Services, including Voice-to-Voice translation, the Image to Your Voice feature (image-based question-and-answer), image-to-voice functionality, contextual image assistance, language mapping, location-based language configuration and customer support.

Performance of contract (Article 6(1)(b))

c

To process Content, prompts, voice recordings, images, metadata and other inputs through AI, translation, speech, computer-vision and related third-party systems to generate AI Outputs on a one-time and transient basis.

Performance of contract (Article 6(1)(b)) consent (Article 6(1)(a)) and where Sensitive Data is involved (Article 9(2)(a))

d

To allocate, deduct, verify and administer Coins, Usage Charges, Premium Membership Plans, subscriptions, Offer Wall rewards, refunds, disputes and account balances.

Performance of contract (Article 6(1)(b))

e

To display, measure, attribute and manage advertisements, rewarded advertisements, Offer Wall tasks, surveys, games, promotions and other monetization features, subject to your choices and Applicable Laws.

Consent (Article 6(1)(a)); or legitimate interests (Article 6(1)(f)), where contextual advertising not requiring consent is used

f

To detect, prevent, investigate and respond to fraud, abuse, spam, unauthorized recordings, unlawful surveillance, impersonation, payment fraud, Offer Wall manipulation, security incidents and other prohibited conduct.

Legitimate interests (Article 6(1)(f)); compliance with legal obligations (Article 6(1)(c))

g

To improve, maintain, test, monitor, debug and develop the Platform, Services, safety systems, language quality, translation accuracy, performance and user experience, using minimized or de-identified data where reasonably practicable.

Legitimate interests (Article 6(1)(f))

h

To communicate with you about account activity, service updates, security alerts, support, policy changes, subscriptions, rewards, offers, marketing communications and administrative matters, subject to your choices.

Performance of contract (Article 6(1)(b)) for transactional communications; consent (Article 6(1)(a)) for marketing

i

To comply with Applicable Laws, court orders, governmental directions, regulatory requirements, cyber-security obligations, audit, taxation, accounting, record-keeping and law-enforcement requests.

Compliance with legal obligations (Article 6(1)(c))

j

To enforce the Terms and Conditions, this Policy and other applicable terms, and to establish, exercise or defend legal claims.

Legitimate interests (Article 6(1)(f)); legal claims (Article 9(2)(f)) where Sensitive Data is involved

k

To create aggregated, anonymized or de-identified analytics, statistics and service-improvement insights that do not reasonably identify an individual.

Legitimate interests (Article 6(1)(f)); note that truly anonymized data falls outside the scope of GDPR/UK GDPR

Where we rely on legitimate interests (Art 6(1)(f) GDPR / UK GDPR), those interests are: operating and securing a safe, functional and commercially sustainable AI-enabled platform and protecting the rights of the Company, its users and third parties. Where consent is the stated basis above, you may withdraw it at any time without affecting processing already carried out on that basis.

Switzerland: Unlike the GDPR and UK GDPR, the FADP does not require a specific enumerated lawful basis for each processing purpose. Under Swiss law, processing of personal data is generally permitted provided it complies with the data protection principles under Article 6 FADP (good faith, proportionality, purpose limitation, accuracy and security). A specific justification under Article 31 FADP is required only where processing infringes a data subject’s personality rights, for example, where Sensitive Personal Data under Article 5(c) FADP is involved, where high-risk profiling occurs, or where processing continues against a data subject’s explicit objection. In such cases, we rely on explicit consent under Article 6(7) FADP, an overriding private or public interest, or another statutory justification recognized under Swiss law, together with any additional safeguards required by Applicable Laws.

Unless expressly disclosed in a consent notice, feature-specific notice or applicable setting, we do not use your voice recordings, images, prompts or Content containing Personal Data to train third-party public foundation models, and we do not retain raw Input Data for model training by default.

6. ACCOUNTABILITY AND GOVERNANCE

Consistent with our accountability obligations under Articles 5(2) and 24 GDPR/UK GDPR, we maintain a record of processing activities describing, for each purpose of processing set out in this Policy, the categories of Personal Data, categories of Data Subjects, categories of recipients, applicable retention periods and a general description of the technical and organisational security measures applied, in accordance with Article 30 GDPR/UK GDPR.

Where a type of processing, in particular AI Processing using new technologies, is likely to result in a high risk to your rights and freedoms, we shall endeavour to carry out a Data Protection Impact Assessment before commencing that processing, in accordance with Article 35 GDPR/UK GDPR, assessing the necessity and proportionality of the processing, the risks involved and the measures envisaged to address those risks. Where a Data Protection Impact Assessment indicates a high risk that cannot be mitigated by reasonably available measures, we shall consult the competent supervisory authority in accordance with Article 36 GDPR/UK GDPR before proceeding.

Before relying on legitimate interests as a lawful basis under Article 6(1)(f) GDPR/UK GDPR for a purpose described in this Policy, we carry out and document a balancing test weighing our interest, the necessity of the processing, and your interests, rights and freedoms, including any reasonable expectations you may have, consistent with Recital 47 GDPR and applicable guidance of the European Data Protection Board and the Information Commissioner’s Office. A summary of that assessment is available on request, subject to redaction of confidential or commercially sensitive information.

Consistent with the accuracy principle under Article 5(1)(d) GDPR/UK GDPR, we take reasonable steps to ensure that the Personal Data we process is accurate and, where necessary, kept up to date, and we will correct or erase inaccurate Personal Data without undue delay once we become aware of it, whether because you have exercised your right to rectification or otherwise. Since Content such as prompts, voice recordings and images is provided by you and reflects your own account of matters, we do not independently verify its accuracy, and the usefulness of any related AI Output depends on the completeness and accuracy of what you choose to submit.

7. DISCLAIMER

WHERE THE PLATFORM PROVIDES VOICE, IMAGE OR LANGUAGE ASSISTANCE, SUCH ASSISTANCE IS AN AUTOMATED AID AND NOT A GUARANTEED DESCRIPTION, TRANSLATION OR ASSESSMENT. USERS REMAIN RESPONSIBLE FOR INDEPENDENT JUDGMENT AND HUMAN ASSISTANCE WHERE ACCURACY OR SAFETY MATTERS.

THE PLATFORM IS NOT A SUBSTITUTE FOR PROFESSIONAL TRANSLATORS, INTERPRETERS, LAWYERS, DOCTORS, FINANCIAL ADVISERS, EMERGENCY SERVICES, GOVERNMENT AUTHORITIES OR OTHER QUALIFIED PROFESSIONALS, AND MUST NOT BE RELIED UPON FOR REGULATED, SAFETY-CRITICAL, LIFE-CRITICAL OR HIGH-RISK DECISIONS.

AI OUTPUTS MAY CONTAIN ERRORS, MISTRANSLATIONS, OMISSIONS, HALLUCINATIONS, INCORRECT IMAGE OR TEXT INTERPRETATIONS, MISSED NUANCES, BIAS, OFFENSIVE CONTENT OR OTHER LIMITATIONS. YOU SHOULD VERIFY AI OUTPUTS BEFORE RELYING ON THEM.

AI OUTPUTS ARE GENERATED ALGORITHMICALLY AND MAY VARY BASED ON MODELS, THIRD-PARTY SYSTEMS, LANGUAGE SETTINGS, PROMPTS, SAFETY FILTERS, NETWORK CONDITIONS, REGIONAL AVAILABILITY, DEVICE SETTINGS OR PRODUCT CONFIGURATION.

8. AI PROCESSING, MODEL OPERATIONS AND OUTPUTS

The Platform is an AI-enabled service and necessarily involves AI Processing. When you use Voice-to-Voice translation and the Image to Your Voice feature/Visual Story Converser (image-based question-and-answer) voice-to-voice translation, image-to-voice functionality, contextual image assistance, language mapping, location-based language configuration or related functionality, your Input Data may be processed by a combination of Company systems and Third-Party Services. These may include speech-to-text and text-to-speech systems, translation and multimodal AI models (which interpret both voice and images), content-moderation and safety-filtering systems, required to provide the Service.

When you speak into Voice Soul, or take a photo for the Image to Your Voice feature/Visual Story Converser, that audio or image is held in temporary memory on our servers, or those of our AI providers, just long enough to generate your translation, transcription or answer. It is not written to permanent storage, and it is dropped immediately after we deliver the response to you; the only exception being that, within an active conversation, we keep it briefly so you can ask follow-up questions about that same recording or photo, after which it is dropped too. We do not use your voice recordings or images to train AI models, and there is no setting, on our side or yours, that keeps them for that purpose.

When your Input Data is transmitted to a third-party AI service for processing, the data sent may include: (a) voice recordings, audio clips or speech submitted by you; (b) images or image links submitted by you; (c) text prompts, instructions or queries submitted by you; (d) transcripts or converted representations of the above; (e) session metadata such as language selected, feature used, region identifier and timestamp; and (f) such other technical or contextual data as is strictly necessary for the specific AI function you have invoked to operate, limited to the minimum data required for that function. We do not transmit account credentials, payment information or unnecessary personal identifiers to third-party AI services for AI Processing purposes.

Transparency under the EU AI Act:

Pursuant to Article 50 of Regulation (EU) 2024/1689 (“the AI Act”), if Voice Soul’s AI-generated audio output could be mistaken for a real human voice, we label it as AI-generated, as required by Article 50 of the AI Act. We do not use AI practices that Article 5 of the AI Act prohibits, such as manipulative techniques that cause harm.

Since raw voice recordings and images are deleted immediately after your AI Output is generated, as described above, We do not use them to build test prompts, benchmark datasets or evaluation sets. Any quality, safety or abuse-prevention metrics we maintain (for example, error rates, latency, or the number of safety-filter triggers) are aggregated technical statistics and do not include your underlying voice recordings, images or transcripts.

Feedback, corrections, ratings, suggested translations, quality comments, support tickets and similar inputs may be used to evaluate, debug, improve and develop the Platform, Services and AI Outputs. You should not include Personal Data, Special Categories of Personal Data, confidential information or third-party information in feedback unless strictly necessary to resolve the issue. We recommend redacting or omitting such information where possible, as feedback may be retained, reviewed by personnel or service providers, and used to evaluate and improve the Platform, Services and AI Outputs.

Where Personal Data is used for model improvement, evaluation or quality review, We will do so only where permitted under this Policy, a relevant notice, user settings or Applicable Laws, and with heightened care for Sensitive Data, children’s data and similarly protected information.

We may use aggregated, anonymized, de-identified or non-personal information to improve, test and monitor the Platform, Services, AI Outputs, safety systems, performance, language quality, routing logic, abuse-prevention systems and user experience. We will use measures to make re-identification of an individual from such information unlikely, taking into account the means available to any person to reverse the anonymization or de-identification process.

Unless expressly disclosed in a consent notice, feature-specific notice or applicable setting, we do not use your voice recordings, images, prompts or other Content containing Personal Data to train third-party public foundation models. Where third-party AI vendors, translation providers, speech providers or computer-vision providers process Input Data, we use contractual restrictions or technical controls that limit their use of such Input Data to providing and supporting the relevant services, subject to the terms available from those providers and Applicable Laws.

The categories of third-party service providers that may receive your Input Data for AI Processing purposes include: (i) large language model (LLM) / foundation model providers that generate text, language or contextual responses; (ii) speech-to-text and text-to-speech engine providers that convert voice recordings to text and text to audio output; (iii) machine translation providers that translate content between languages; (iv) computer-vision and image-analysis providers that interpret images and generate image-related outputs; and (v) cloud infrastructure providers whose compute or storage resources host or route Input Data during processing. The list of such third-party service providers may be accessed here [K&K_HA1] with the specific purpose for which your Input Data is shared. We do not share your Input Data with these providers for their own marketing, profiling or model-training purposes beyond what is described in this Policy. Where we are permitted to identify a specific provider by name, details will be published on the Platform or notified to you in a feature-specific notice.

9. MODEL IMPROVEMENT, TRAINING AND EVALUATION

We distinguish between processing needed to provide the Service and processing for model improvement, evaluation or training. Service delivery processing includes receiving Input Data, routing it to appropriate Company systems or Third-Party Services, generating AI Outputs, maintaining session state, applying safety filters, performing abuse checks, calculating Coin deductions and resolving technical errors. Model improvement processing may include quality measurement, debugging, latency evaluation, safety testing, translation-quality review, speech-recognition assessment, image-processing assessment, prompt and response evaluation, and development of improved workflows or safety controls.

Location-related processing may include approximate location derived from IP address, device settings, selected region, language settings, app-store region or network information, and precise location, only where enabled by you and required by a feature. Location information may be used to configure language sets, regional experiences, feature availability, fraud-prevention controls, compliance settings, advertising attribution, Offer Wall eligibility and security measures.

You should not submit personal details, identity documents, payment information, passwords, health information, children’s information, precise location information, confidential business information, legal documents, medical documents or other sensitive content, unless strictly necessary for the specific Service, and unless you have the right and consent or another lawful ground recognised under Applicable Laws to do so. For example, an identity document is necessary only where a feature expressly requires identity verification, not for general translation or chat features. The Platform is not intended to be used as a repository for highly sensitive records unless a feature expressly states otherwise.

You must not record, upload, process or submit another person’s voice, image, likeness, biometric information, confidential information, personal information or sensitive information unless you have all notices, consents, permissions and lawful grounds required under Applicable Laws and the Terms and Conditions. Where permitted, you are responsible for obtaining all necessary notices, consents, and permissions before doing so. This restriction applies to recordings of conversations, images of individuals, images of documents, images containing personal details, workplace recordings, classroom recordings, medical, legal or financial information, and any Content where another person has a privacy or confidentiality interest.

Classification of Voice and Image-related Data

The Platform helps you read, translate and understand documents and text in various languages, depending on your subscription plan (free or premium), and processes your voice and images to generate translations, transcriptions, descriptions and contextual answers, and to run safety and fraud-prevention checks, not to identify you. The Platform does not have the ability to analyse, interpret, describe or comment on facial features, scenery or other visual characteristics depicted in an image, and will not respond to requests seeking such analysis. The Platform may process voice or image features to generate translations, transcriptions, descriptions, contextual answers, language outputs, safety filters, fraud-prevention checks, abuse-prevention signals or service-quality metrics. This does not constitute biometric data merely because it involves your voice or image: biometric data arises only where such data is subjected to specific technical processing for the purpose of uniquely identifying you, within the meaning of Article 4(14) GDPR/UK GDPR, which the Platform does not currently perform. The Platform does not currently include any feature that uses voice or facial characteristics to verify your identity or isolate individual behavioral metrics, and the Platform does not perform any facial recognition, facial analysis or extraction of facial characteristics from images. If such a feature is introduced in future, we will obtain your separate, explicit consent under Article 9(2)(a) GDPR/UK GDPR (or Article 6(7) FADP) before enabling it.

10. VOICE, IMAGE AND LOCATION-RELATED PROCESSING

The Services may process voice recordings, speech, accents, dialects, language patterns, background audio, images, objects, text contained within images, places, signs, documents, metadata and location-related settings. Depending on the nature of the Content you choose to submit, such Information/Data may directly or indirectly identify you or another individual, or reveal personal, professional, cultural or other sensitive aspects of your life. SOHOFI recognises that such Information/Data deserves an appropriate level of confidentiality and protection. The Platform does not classify or process Content for the purpose of identifying Special Categories of Personal Data under the GDPR or UK GDPR, or Sensitive Personal Data under the FADP. However, Content you choose to submit for translation, transcription or other requested functionality may incidentally contain such data. As the Platform cannot detect or classify such data within your Content, whether to include it is a choice you make when submitting Content, and any such data will be processed solely to deliver the requested output, subject to the general security and confidentiality measures described in this Policy.

To protect users, maintain the integrity of the Platform and comply with Applicable Laws, SOHOFI may implement safety filters, content moderation measures, rate limits, usage limits, routing controls, feature restrictions, geo-configuration, child-safety protections, sensitive-content filters and other technical or organisational safeguards. These safeguards are designed to reduce misuse, promote responsible use of artificial intelligence, protect the rights of users and third parties, and support the secure operation of the Services. Accordingly, these safeguards may prevent, modify, delay, refuse or otherwise restrict the processing of certain Content or the generation of particular AI Outputs where reasonably necessary to achieve those objectives.

Where an automated decision or automated processing materially affects your account, access to the Platform, Coins, rewards, subscription status or other rights available to you under Applicable Laws, you may contact us using the grievance or support mechanisms described in this Policy. Where required under Applicable Laws, we will provide an appropriate opportunity to request human review of such decisions, subject to legal, security and technical considerations. In investigating such requests, we may review relevant logs, device information, transaction records, support communications, Content metadata and other information reasonably necessary to assess the matter.

The Platform may use automated systems to detect abuse, fraud, malware, unlawful or prohibited content, spam, manipulation of Coins or rewards, Offer Wall abuse, repeated payment failures, suspicious device behaviour, account compromise, policy violations, unsafe prompts, harmful AI Outputs or attempts to circumvent technical safeguards. Such systems are intended to protect the Platform, its users and third parties, and may affect the availability of particular features, the routing of requests, the generation or suppression of outputs, the suspension of rewards, security verification measures, account investigations or other enforcement actions where reasonably necessary.

Most AI Outputs are generated through automated processing without routine human involvement. However, authorised personnel or authorised service providers may conduct Human Review where reasonably necessary for customer support, troubleshooting, quality assurance, abuse investigations, safety assessments, model evaluation, fraud prevention, cybersecurity, incident response, legal compliance, grievance handling, enforcement of the Terms and Conditions or responding to lawful requests from competent authorities. Human Review is limited to feedback, support tickets or other Content you separately choose to submit, and to session metadata, safety-filter logs and technical records, rather than to the underlying voice recording or image itself.

11. HOW WE SHARE AND DISCLOSE YOUR INFORMATION

We may share Information/Data in the following ways, where permitted for the relevant purpose and subject to appropriate confidentiality, security, processor, transfer and purpose-limitation safeguards where required under Article 28 GDPR Data Processing Addendums (“DPAs”):

a) Affiliates and group companies: We may share Information/Data with our affiliates and group companies to operate, administer, support, secure and improve the Platform and Services, subject to contractual obligations requiring such affiliates and group companies to process the Information/Data only for the purposes described in this Policy and to maintain equivalent security and confidentiality safeguards.

b) Service providers and Processors: We may provide access to or share Information/Data with hosting providers, cloud providers, AI vendors, translation providers, speech-engine providers, computer-vision providers, analytics providers, security vendors, customer-support tools, email/SMS providers, payment support vendors, fraud-prevention vendors, auditors, professional advisers and other processors engaged to provide services on our behalf, in each case under a valid contract requiring such processors to act only on our instructions and to process Information/Data solely for the purposes described in this Policy.

c) App stores, payment providers and subscription partners: We may share Information/Data to process subscriptions, verify payments, issue refunds, resolve disputes, administer Premium Membership Plans and comply with payment-related requirements.

d) Advertising Partners and Offer Wall providers: We may share Information/Data to display, measure, attribute and verify advertisements, rewarded advertisements, surveys, games, installs, offers, eligibility, anti-fraud checks and Coin credits. Such partners may also process certain information as independent Controllers under their own policies. Where required by law, we will obtain separate consent for advertising-related profiling or tracking.

e) Third-Party Services selected or used by you: We may share Information/Data where you choose to access, connect, interact with or complete activities through a Third-Party Service linked to or integrated with the Platform.

f) Protection of our rights and interests: We may disclose Information/Data to prevent fraud or abuse, protect the security and integrity of the Platform, enforce the Terms and Conditions, protect rights and safety, or respond to misuse of the Services.

g) Business transfers: We may disclose or transfer Information/Data in connection with a merger, acquisition, investment, financing, restructuring, sale of assets, insolvency, reorganization or transfer of all or part of our business, subject to appropriate confidentiality and legal safeguards.

h) Legal purposes: We may disclose Information/Data where required or permitted by Applicable Laws, court order, governmental direction, legal process, investigation, cyber-security reporting obligation or to protect rights, property, safety, security or the public interest.

i) Any other person with your consent: We may share Information/Data with a specified recipient where you expressly instruct or authorize us to do so.

The list of all such entities to whom the data may be shared may be accessed from here.[K&K_HA2]

We do not disclose Personal Data for unrelated monetary consideration. Where a Third-Party Service processes information for advertising, attribution, rewards or monetization, such processing will be governed by this Policy, the relevant third-party policy, your choices and Applicable Laws.

We will seek to ensure that vendor changes do not materially reduce the protection of Personal Data under this Policy. Where a change materially affects processing of Personal Data or requires notice or consent under Applicable Laws, we will provide notice or obtain consent as required.

We may change, add, remove, replace or reconfigure AI vendors, models, cloud providers, speech engines, translation engines, computer-vision tools, analytics providers, safety systems or other processing tools from time to time to improve functionality, safety, latency, availability, cost, language coverage, quality, reliability or legal compliance. Such changes may affect output quality, available features, regional availability, latency, retention, data flows and the categories of processors involved.

We may change vendors, models, cloud providers, speech engines, translation engines, computer-vision tools, analytics providers, safety systems or other processing tools from time to time. Where a material change requires notice or other action under Applicable Laws, we will take the required steps.

Where a provider acts as our Processor or service provider, we bind them via explicit contracts to impose obligations relating to confidentiality, purpose limitation, security, access controls, retention, incident notification, rights assistance, deletion or return of data, transfer safeguards and restrictions on unauthorized use of Input Data. We require that providers processing your Personal Data on our behalf maintain data protection standards that are at least equivalent to those described in this Policy and required by Applicable Laws, and do not use your data for their own independent purposes beyond delivering the agreed service.

Consistent with Article 28(3) GDPR/UK GDPR, our contracts with Processors require them, among other things, to: (a) process Personal Data only on our documented instructions (including regarding international transfers); (b) ensure persons authorized to process the data are bound by confidentiality; (c) implement appropriate technical and organizational security measures; (d) engage sub-processors only with our prior general or specific written authorization and impose equivalent data-protection obligations on any sub-processor by way of a contract; (e) assist us, taking into account the nature of the processing, in responding to data subject rights requests and in meeting our security, breach-notification and Data Protection Impact Assessment obligations; (f) delete or return all Personal Data at the end of the provision of services, unless retention is required by law; and (g) make available to us information necessary to demonstrate compliance and allow for, and contribute to, audits and inspections.

Providers may process Input Data, Content, metadata, device data, logs, AI Outputs or other Information/Data on our behalf or independently, depending on their role and terms. Transfers outside your country or region will be handled using safeguards or lawful transfer arrangements where required.

With respect to third-party AI service providers that receive your Personal Data for AI Processing purposes, we require, through contractual measures, that such providers afford a standard of protection at least equivalent to that set out in this Policy and required under Applicable Laws, including restrictions on using your Input Data for purposes other than providing the relevant service to us, obligations of confidentiality, appropriate security measures, and data-deletion or return obligations upon termination of the engagement. Where a provider operates under its own privacy framework that is independently certified or recognized as equivalent or higher, we may rely on that framework to satisfy this standard. We will take reasonable steps to assess and address any material shortfalls that come to our attention.

The Company may use AI vendors, translation providers, speech-processing providers, computer-vision providers, cloud infrastructure providers, analytics providers, safety-tool providers, moderation vendors, monitoring tools and other service providers to operate the Platform. These providers may process Input Data, Content, metadata, device data, logs, AI Outputs or other Information/Data on our behalf or as independent providers, depending on their role and contractual terms. The list of all such vendors and service providers may be accessed from here.[K&K_HA3]

12. HOW DO WE RETAIN YOUR INFORMATION

We retain Information/Data only for as long as reasonably necessary for the purposes for which it was collected or processed, unless longer retention is required or permitted by Applicable Laws, contractual or operational requirements, accounting, fraud prevention, security, dispute resolution, enforcement or legal claims.

Account, profile and contact information is generally retained while your account remains active and for a reasonable period thereafter. Coin, subscription, payment, Offer Wall and transaction records may be retained for accounting, tax, audit, anti-fraud, chargeback, refund, verification and legal purposes.

Your voice recordings and images are processed in real time solely to generate the requested translation, transcription or contextual response, and are deleted immediately once that AI Output has been generated and delivered to you. The only exception is that, within an active, ongoing conversation, a voice recording or image may be retained for the limited duration needed to support your follow-up questions about it; it is deleted at the end of that conversation. We do not retain your voice recordings or images for safety, debugging, fraud-prevention or model-training purposes. Text-based AI Outputs (such as a translation or answer) are likewise not retained as permanent history unless you save them, a feature provides for retention, or you submit them to us for support or feedback.

Raw voice recordings, images and prompts are not retained beyond the active conversation, as described above. Separately, session metadata, safety logs, abuse-prevention logs, Coin consumption records, model-routing records, quality metrics and error logs, none of which include your underlying voice recordings or images, may be retained for longer periods where necessary for security, fraud prevention, service integrity, accounting, legal compliance or dispute resolution, as set out below.

Without limiting the foregoing, we retain the following categories of Data for the periods indicated below, or until the purpose for which the data was collected is no longer being served, whichever is later, subject to any longer period required by Applicable Laws:

a. Account, profile and contact information: for the duration your account remains active, and for three (3) years following account closure or last login, for legal, security, fraud-prevention and dispute-resolution purposes;

b. Coin, subscription, payment metadata, Offer Wall and transaction records: for eight (8) years from the date of the relevant transaction, as required for accounting, tax, audit and anti-fraud purposes;

c. Voice recordings, images, prompts, transcripts and session Content not saved by you: deleted immediately after the relevant AI Output is generated and delivered to you; retained only for the duration of an active conversation to support follow-up questions, and deleted at the end of that conversation. Not retained for safety, debugging, fraud-prevention or any other purpose;

d. Metadata, safety logs, abuse-prevention logs, model-routing records and error logs: for twelve (12) months from creation, for security, fraud-prevention and service-integrity purposes; and

e. Support tickets, feedback and grievance records: for three (3) years from resolution, for quality-assurance and legal-compliance purposes.

We will update the periods above as our practices evolve and will notify you of any material change in accordance with the Update to the Privacy Policy Section of this document. De-identification or anonymization may not be reversible, and once information has been anonymized or aggregated it may not be possible to associate it with your account or respond to access, correction or erasure requests in relation to that anonymized or aggregated information.

Deletion may not immediately remove all backup copies, caches, logs, legal records, security records, payment records, Offer Wall verification records or data retained by independent Third-Party Services, but we will apply deletion, de-identification, anonymization or retention controls in accordance with Applicable Laws and our practices. Such residual copies will be deleted or overwritten within 90 (ninety) days in accordance with our backup and retention cycles, except to the extent a longer period is required for legal, security, payment or dispute-resolution records as described above.

Consistent with the storage limitation principle under Article 5(1)(e) GDPR/UK GDPR, where you have not used your account or the Platform for the inactivity period specified in the retention schedule above, we will erase or anonymize your Personal Data upon the lapse of that period, unless retention is required for compliance with a legal obligation, for the establishment, exercise or defence of legal claims, or for another purpose permitted under Applicable Laws. Before doing so, we will notify you at least forty-eight (48) hours in advance, using the contact details associated with your account, so that you may log in or otherwise use the Platform if you wish to prevent such erasure.

When the purpose for which Personal Data was collected is no longer being served and retention is no longer necessary for any legal, safety, fraud-prevention, security, accounting or dispute-resolution purpose, we will delete, de-identify, anonymize or aggregate Data in accordance with the storage limitation principle under Article 5(1)(e) GDPR/UK GDPR and our erasure obligations under Article 17 GDPR/UK GDPR. Article 17 requires us to erase your Personal Data without undue delay where, among other grounds, it is no longer necessary in relation to the purposes for which it was collected, you withdraw the consent on which processing was based (to the extent no other lawful basis applies), or you object to processing and no overriding legitimate grounds exist. We will conduct periodic reviews of retained Personal Data to identify data that should be erased in the ordinary course. De-identification or anonymisation, where applied, will be carried out using techniques designed to prevent identification of the data subject, having regard to the means reasonably likely to be used for re-identification, consistent with Applicable Laws and our internal retention practices; once anonymised, the resulting information will not be treated as Personal Data for the purposes of the GDPR, UK GDPR or FADP.

13. HOW WE PROTECT YOUR INFORMATION

We implement reasonable security practices and appropriate technical and organizational measures designed to protect Information/Data from unauthorized access, disclosure, alteration, destruction, loss, misuse and accidental damage. Measures may include access controls, authentication, encryption at rest via AES-256 and in transit via TLS 1.3 or similar safeguards, logging, vulnerability management, vendor controls, incident response, confidentiality obligations, data minimization, retention controls and periodic review. No method of transmission, storage or processing is completely secure. You are responsible for maintaining account credentials, securing your device and notifying us of suspected unauthorized access or misuse.

Where a security incident or personal data breach triggers a reporting obligation under Article 33 or 34 GDPR/UK GDPR, we will notify the competent supervisory authority, being, for users in the United Kingdom, the Information Commissioner’s Office (“ICO”), and for users in the EEA, the competent supervisory authority under Article 55 GDPR (for example, Ireland’s Data Protection Commission, Germany’s competent state-level data protection authority, France’s Commission Nationale de l’Informatique et des Libertés (“CNIL”)) without undue delay and, where feasible, not later than seventy-two (72) hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where notification is not made within seventy-two (72) hours, it will be accompanied by reasons for the delay. Our notification to the supervisory authority will describe, to the extent known at the time: (a) the nature of the breach, including where possible the categories and approximate number of Data Subjects and personal data records concerned; (b) the name and contact details of our Data Privacy Officer; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address the breach, including, where appropriate, measures to mitigate its possible adverse effects.

For users in Switzerland, the seventy-two (72)-hour benchmark above does not apply. Under Article 24 FADP, we will instead notify the Federal Data Protection and Information Commissioner (“FDPIC”) as soon as reasonably possible after becoming aware that a data security breach is likely to lead to a high risk to your personality or fundamental rights, describing the nature of the breach, its effects and the measures taken, and we will inform you, where necessary, for your protection or where the FDPIC so requires.

Where the breach is likely to result in a high risk to your rights and freedoms, we will also communicate the breach to you without undue delay, describing in clear and plain language the nature of the breach and the information set out above, using the same channels we use to contact you for the Services (for example, your registered email address or in-app notification), unless an exception under Article 34(3) GDPR/UK GDPR applies (such as our having applied appropriate technical protection measures, like encryption, rendering the data unintelligible).

AI-related security measures may include prompt-abuse monitoring, rate limiting, anomaly detection, access logging, vendor-access controls, restrictions on employee access to raw Content and review of incidents involving unintended disclosure, prompt injection, model misuse, excessive data exposure or unauthorized access.

You must not attempt prompt injection, model extraction, scraping, automated abuse, circumvention of safety filters, unauthorized access to AI systems or any activity intended to expose non-public Platform, model, security or user information.

14. THIRD-PARTY LINKS AND FEATURES

The Platform may include Third-Party Services, advertisements, rewarded advertisements, Offer Wall tasks, surveys, games, links, SDKs or integrations provided by third parties that may act as our processors or as independent providers depending on the feature and processing activity.

When you interact with a Third-Party Service, the third party may collect information directly from you or your device, including device identifiers, IP address, advertising identifier, interaction data, reward eligibility and offer completion status. Their privacy policy and terms govern independent processing. We may receive confirmation, attribution, verification, anti-fraud and reward-status information from Third-Party Services to credit Coins, verify eligibility, prevent manipulation and resolve disputes.

The Platform may use cloud infrastructure, AI vendors, analytics providers, support tools, payment partners, Advertising Partners and other Third-Party service providers located in India, European Economic Area, the United Kingdom, Switzerland, or other jurisdictions.

Where Personal Data is transferred outside the European Economic Area, we rely on one or more of the following transfer mechanisms under GDPR Chapter V: (a) Standard Contractual Clauses adopted by the European Commission (currently, Commission Implementing Decision (EU) 2021/914); (b) transfers to recipients in countries for which the European Commission has issued an adequacy decision; or (c) other appropriate safeguards permitted under Article 46 GDPR.

Where Personal Data is transferred outside the United Kingdom, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, the UK’s own International Data Transfer Agreement, transfers to countries for which the UK Secretary of State has issued adequacy regulations, or other appropriate safeguards permitted under Article 46 UK GDPR, and, for transfers and reliance on Article 46 safeguards entered into after 5 February 2026, we apply the “data protection test” introduced by the Data (Use and Access) Act 2025, assessing whether the standard of protection for the transferred data in the destination country is not materially lower than the standard of protection under the UK data protection regime.

Note that India does not currently hold an EU adequacy decision. Thus, transfers to SOHOFI’s Indian infrastructure rely on Standard Contractual Clauses or equivalent Article 46 safeguards, backed by rigorous supplementary technical security measures, such as localised data partitioning.

Where an AI Sub-processor or other recipient is self-certified under the EU-U.S. Data Privacy Framework (or, for UK transfers, the UK Extension to the EU-U.S. Data Privacy Framework, known as the “UK-U.S. Data Bridge”), we may rely on the European Commission’s corresponding adequacy decision (and, for UK transfers, the UK Secretary of State’s adequacy regulations) as the transfer mechanism for that recipient, in place of or in addition to Standard Contractual Clauses.

Before relying on Standard Contractual Clauses or other Article 46 safeguards for a transfer outside the EEA or UK, we carry out a transfer impact assessment evaluating the law and practices of the destination country that are relevant to the transferred data, consistent with the approach recommended by the European Data Protection Board in its Recommendations 01/2020, and we implement supplementary technical, contractual or organizational measures (such as encryption, pseudonymization or access controls) where necessary to bring the level of protection up to the EU standard of essential equivalence.

Where Personal Data of individuals in Switzerland is transferred outside the Switzerland, we rely on lawful transfer mechanisms under the FADP, including: (a) transfers to countries recognized by the Swiss Federal Council as ensuring an adequate level of data protection, or where the destination country (including India) is not so recognized, (b) the Standard Contractual Clauses recognized by the Swiss Federal Data Protection and Information Commissioner (FDPIC), supplemented with Swiss-specific amendments where required; (c) binding corporate rules submitted in advance to the FDPIC; or (d) other safeguards permitted under Art. 16(2) FADP (including ad hoc contractual clauses or sufficient guarantees under international law).

Where a feature permits you to save, download, export, share or reuse AI Outputs, you are responsible for reviewing those AI Outputs and handling any Personal Data, confidential information, third-party content or sensitive information lawfully.

Deletion or erasure requests will be assessed under Applicable Laws and may not affect AI Outputs already delivered or shared, information retained for legal, operational or security purposes, anonymized information, backups or caches awaiting deletion, or information retained by independent Third-Party Services.

Subject to technical availability and Applicable Laws, you may limit certain AI Processing through Platform, device, browser or account controls, including microphone, camera, photo, location, notification, advertising, cookie and marketing preferences.

15. USER RIGHTS AND CHOICES

Subject to Applicable Laws, verification of identity and applicable limitations, you may have the following rights in relation to your Personal Data where EU/UK/Switzerland privacy or data protection laws apply:

a) Right to lodge a complaint

(i) You have the right at any time to lodge a complaint with the supervisory authority of the EU member state in which you are habitually resident, work, or where you believe an infringement has occurred. A list of EEA supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

(ii) If you are located in the United Kingdom, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s independent supervisory authority for data protection matters. The ICO can be contacted at https://ico.org.uk/make-a-complaint/ or by post at Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom.

(iii) If you are located in Switzerland, you have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC), the Swiss supervisory authority for data protection matters. The FDPIC can be contacted at https://www.edoeb.admin.ch/en/submitting-a-complaint or by post at Feldeggweg 1, CH-3003 Berne, Switzerland.

(iv) This right is without prejudice to any other administrative or judicial remedy available to you.

b) Right to information: To know how we collect, use, and share your personal data under Articles 13 and 14 GDPR/ UK GDPR and Articles 19-21 FADP. This policy, along with any notices we provide at the point of data collection, is intended to give you this information in a concise and transparent manner.

c) Right of access: You may request confirmation of whether we process your Personal Data and access to information about such processing under Article 15 GDPR. Where we transfer your Personal Data to a third country or international organization, you have the right to be informed of the appropriate safeguards relied on for that transfer under Article 46 GDPR/UK GDPR, in accordance with Article 15(2) GDPR/UK GDPR.

d) Right to rectification: You may request correction, completion or updating of inaccurate, misleading or incomplete Personal Data under Article 16 GDPR. Where we have disclosed your Personal Data to a recipient prior to your request, we will, in accordance with Article 19 GDPR/UK GDPR, communicate any rectification, erasure or restriction to that recipient unless this proves impossible or involves disproportionate effort, and we will tell you who those recipients are if you ask us to.

e) Right to erasure: You may request erasure or your Personal Data under Article 17 GDPR/UK GDPR where, for example: (i) it is no longer needed for the purposes we collected it; (ii) you withdraw consent and there is no other legal basis for processing; (iii) you object to the processing and we have no overriding grounds to continue; or (iv) it was processed unlawfully. This right is not absolute, and we may be required to retain data to comply with a legal obligation, defend legal claims, or for reasons of public interest, research, or freedom of expression.

f) Right to restriction and objection: You may request restriction of processing or object to certain processing, including direct marketing, where such rights apply under Articles 18 and 21 GDPR respectively. We will bring your right to object to direct marketing to your attention explicitly, at the latest at the time of our first communication with you, and present it clearly and separately from other information, in accordance with Article 21(4) GDPR/UK GDPR. You possess an absolute right to object to direct marketing profiling at any time.

g) Right to data portability: You may request certain Personal Data you provided to us in a structured, commonly used and machine-readable format, where Applicable Laws provide such right under Article 20 GDPR.

h) Right in relation to automated decisions (Article 22 GDPR/UK GDPR): Where the Platform makes solely automated decisions (including profiling) that produce legal or similarly significant effects concerning you, such as account suspension, denial of access to features or Coin-related determinations, for users in the EEA, such a decision may only be made where necessary for a contract between you and us, authorized by EU or member-state law, or based on your explicit consent, and, in each case, you have the right to: (i) obtain human intervention; (ii) express your point of view; and (iii) contest the decision, under Article 22(3) GDPR. For users in the United Kingdom, following the entry into force of the Data (Use and Access) Act 2025 on 5 February 2026, Articles 22A-22D UK GDPR permit solely automated decision-making more broadly, subject to safeguards, and you have the corresponding rights to: (i) be informed of qualifying significant decisions, (ii) to make representations, (iii) to obtain human intervention and (iv) to contest the decision, under Article 22C UK GDPR. Additional safeguards apply where the decision involves special category data. We will identify the logic involved, the significance, and the envisaged consequences of such processing when you exercise this right. We do not currently make solely automated decisions of this nature by default, and we will inform you if this changes. Further, Article 21 of the FADP grants a parallel right to request that an individual decision not be taken solely on the basis of automated processing, and to have the decision reviewed by a natural person upon request.

i) Right to withdraw consent and manage choices: You may withdraw consent where processing is based on consent, under Article 7(3) GDPR, which can be executed at any point via explicit dashboard toggles and to manage non-essential marketing, notifications, cookies, advertising identifiers and app permissions.

j) Right to an effective judicial remedy: In addition to your right to lodge a complaint with a supervisory authority, you have the right to an effective judicial remedy before the courts of the EU member state, the United Kingdom or Switzerland (as applicable) where we are established or where you have your habitual residence, if you consider that your rights under this Policy or Applicable Laws have been infringed as a result of our processing of your Personal Data, under Article 79 GDPR/UK GDPR.

You may submit a request by contacting the Data Privacy Officer listed in the Contact Section of this Policy. We may verify your identity and may decline or limit a request where permitted by Applicable Laws, including where compliance would affect others’ rights, security, fraud prevention, legal obligations, legal claims, confidential information, anonymized data or data processed transiently and not retained.

Where Platform, device, browser, consent-management or cookie-preference tools are available, you may use them to manage, review or withdraw consent, subject to technical availability and Applicable Laws.

16. SENSITIVE PERSONAL INFORMATION

Sensitive Data may include health information, biometric data, genetic data, information revealing protected characteristics or beliefs and other categories recognized under Applicable Laws. Voice recordings, images, photographs, prompts or other Content may contain Personal Data or Sensitive Data depending on context. We process such information only for the purposes described in this Policy and where a specific condition in Article 9(2) GDPR (or equivalent provision of Applicable Laws) applies. Where we rely on explicit consent under Article 9(2)(a) GDPR, we will seek that consent separately and distinctly from general consent to this Policy. Where we rely on substantial public interest under Article 9(2)(g) or vital interests under Article 9(2)(c), we will apply the additional safeguards required by Applicable Laws.

We apply heightened security measures to Sensitive Data, including encryption in transit and at rest and access limited to personnel or service providers with a specific need to know. We do not use Sensitive Data to train third-party public foundation models, and we do not share Sensitive Data with Advertising Partners or Offer Wall providers for advertising or profiling purposes.

For users in Switzerland, sensitive personal data under Article 5(c) FADP is processed only where a lawful basis under Article 31 FADP applies, including explicit consent under Article 6(7) FADP, which we will seek separately and distinctly from general consent to this Policy, or another statutory justification recognized under the FADP, together with any additional safeguards required by Swiss law.

17. CHILDREN’S PRIVACY

The Platform is intended for individuals who are at least eighteen (18) years of age or the age of majority in their jurisdiction, whichever is higher, unless a specific Service lawfully permits otherwise. The applicable age of digital consent for processing based on consent varies by jurisdiction:

In the EEA, where users aged sixteen (16) or seventeen (17) seek to use the Platform, we note that several EU member states have set the age of digital consent below sixteen (16) (e.g. Austria at fourteen (14), France at fifteen (15)) under Article 8(1) GDPR. In all cases, where a user is below the applicable age of digital consent in their member state, we require verifiable parental or guardian consent before providing services involving the processing of Personal Information/Data.

In the UK, the age of digital consent is thirteen (13), as set out in Section 9 of the Data Protection Act 2018 (which modifies Article 8(1) UK GDPR). Where a UK user is under thirteen (13), we require verifiable parental or guardian consent before providing services involving consent-based processing of Personal Data.

We use age-verification measures appropriate to the risk of the processing activity and never run behavioral tracking mechanisms on accounts flagged as minor profile categories.

We do not knowingly permit children to create accounts or use the Services, unless permitted by Applicable Laws and supported by required parental or guardian consent or authorization. If we learn that a child’s Personal Data was collected without required consent, we will take appropriate steps to delete or restrict it, subject to legal and safety requirements.

Where Applicable Laws require enhanced safeguards for children, we will comply with those requirements, including restrictions on detrimental processing, profiling, tracking, behavioral monitoring or targeted advertising directed at children, to the extent applicable.

18. COOKIES AND SIMILAR TECHNOLOGIES

Cookies are small text files placed on your device by a website or application. Similar technologies include software development kit trackers (SDKs), pixel tags, web beacons, advertising identifiers (such as Apple IDFA and Google GAID), device fingerprinting techniques, local storage objects and session-state mechanisms. References to “cookies” in this Cookie Notice include all such similar technologies unless the context requires otherwise.

A. Cookie Notice

This Cookie Notice explains what cookies and similar tracking technologies the Platform uses, why we use them, and how you can manage your preferences. It should be read together with the Privacy Policy above. Where Applicable Laws including (a) Article 5(3) of the ePrivacy Directive as implemented in the relevant EU member state, (b) the UK Privacy and Electronic Communications Regulations 2003 (PECR), as amended by the Data (Use and Access) Act 2025, and (c) the corresponding transparency and fair-processing principles under the FADP for users in Switzerland, require your prior informed consent before we place non-essential cookies or similar trackers on your device, we will obtain that consent through an appropriate consent management mechanism before placing such trackers. Where your prior consent is required before a non-essential cookie or similar tracker is placed, we display a cookie banner offering three clear, equally prominent choices: (a) “Accept All”, to consent to every non-essential category described in the table below; (b) “Manage Preferences”, which opens a granular interface allowing you to switch each non-essential category on or off individually; and (c) “Reject Non-Essential”, by which only Essential/Strictly Necessary cookies are placed. No non-essential cookie is placed in a category for which you have not given consent, and your preferences are honoured for a period of twelve (12) months, after which you will be prompted to review and renew them, or may be changed at any time through the cookie preference centre.

For users in the United Kingdom, following the amendments made to Regulation 6 of PECR by the Data (Use and Access) Act 2025, certain cookies used solely for the purpose of collecting statistical information to improve the Platform, or to remember the appearance or functionality choices you have made, may be placed without your prior consent, provided you are given clear information about them and a simple means to opt out. Where we rely on this narrow exemption for a specific cookie, this is indicated in the cookie table below. We otherwise continue to seek your consent for analytics and similar cookies as a matter of policy.

B. Categories of Cookies and Tracking Technologies

We use, or permit third parties to use, the following categories of cookies and similar technologies on the Platform:

Category

Purpose

Consent Required?

Essential / Strictly Necessary

Enable core Platform functionality: authentication, session management, security, fraud prevention, load balancing and abuse detection. The Platform cannot operate without these.

No; exempt under ePrivacy Directive; disclosed here for transparency.

Analytics and Performance

Collect aggregated and, where necessary, device-level data on how users interact with the Platform: pages visited, features used, crash reports, error logs, session duration and similar metrics, to maintain and improve the Platform.

Yes; consent required before placement.

Advertising and Targeting

Measure, attribute and personalize advertisements, rewarded ads and Offer Wall tasks; track ad impressions, clicks, conversions and Coin credits; support frequency capping and anti-fraud checks. May involve cross-app or cross-device tracking via advertising identifiers.

Yes; consent required before placement; subject to your advertising-identifier preferences on your device.

Attribution and Install Tracking

Attribute app installs, re-engagements and in-app events to advertising campaigns to measure campaign effectiveness and allocate marketing spend.

Yes; consent required; may rely on device advertising identifier.

Third-Party SDKs and Integrations

Enable third-party features embedded in the Platform, including Offer Wall providers, survey providers, game providers, support chat tools and AI vendor SDKs. These providers may place their own trackers subject to their own privacy policies.

Yes; for non-essential SDKs; consent obtained before initialization.

C. How to Manage Your Cookie Preferences

You may manage or withdraw your consent to non-essential cookies at any time through: (a) the in-app consent management tool or cookie preference centre made available on the Platform; (b) your device or browser settings (noting that disabling cookies through browser settings may affect Platform functionality); or (c) the opt-out mechanisms provided by the relevant third-party providers. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. Essential cookies cannot be disabled as they are strictly necessary for the Platform to function. To exercise your cookie choices, withdraw consent or ask questions about this Cookie Notice, please contact us using the details in the Contact Section of this Policy.

19. EXERCISING RIGHTS:

You can exercise privacy rights by submitting a request through sohofi@sohofi-global.com or contacting the Data Privacy Officer listed in the Contact Section. We may request information to verify your identity and may be unable to honor a request if verification is not possible.

We will endeavor to acknowledge and resolve requests and grievances within the timelines prescribed under Applicable Laws (including, without limitation, one (1) month from receipt of a verified request under Article 12(3) GDPR/UK GDPR, extendable by a further two (2) months for complex or numerous requests), subject to any permitted extension, fee, refusal or limitation. For users in the United Kingdom, where we reasonably require further information from you to identify the scope of your request, the period between our request for that information and your response does not count towards this timeline, in accordance with Article 12A UK GDPR.

If dissatisfied, you may have the right to lodge a complaint with a competent supervisory authority or approach another competent regulator, court or forum available under Applicable Laws.

If we do not take action on your request, we will inform you without delay, and at the latest within one (1) month of receipt of the request, of our reasons for not taking action and of your possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy, in accordance with Article 12(4) GDPR/UK GDPR.

For users in the United Kingdom: Section 164A of the Data Protection Act 2018 requires us to operate an internal data protection complaints procedure. You may submit a complaint about our processing of your Personal Data through the Contact Section. We will acknowledge your complaint within thirty (30) days of receipt and, without undue delay, take appropriate steps to respond, including providing you with updates on progress where the complaint is not resolved promptly. We encourage you to raise your concern with us first, before contacting the ICO, so that we have the opportunity to resolve it directly.

20. USER RESPONSIBILITIES

You are responsible for ensuring that Personal Data you provide is accurate and lawful. You must not impersonate another person, submit false information, raise false grievances, or use the Platform for unlawful surveillance, unauthorized recordings, biometric misuse, illegal data collection, harassment, stalking, doxxing, identity theft, infringement of privacy or publicity rights, violation of privacy laws or other prohibited activity under the Terms and Conditions or Applicable Laws.

If you submit, upload, record or process another person’s Personal Data, including voice, image, likeness, biometric information, confidential information or sensitive information, you represent that you have provided all notices and obtained all consents, authorizations and legal grounds required under Applicable Laws and the Terms and Conditions.

You agree that your use of the Platform, Content, AI Outputs, Coins, Offer Wall, advertisements and Third-Party Services shall remain subject to the Terms and Conditions, including provisions relating to user undertakings, prohibited conduct, disclaimers, limitation of liability and indemnification, to the maximum extent permitted under Applicable Laws.

21. PROHIBITED AI AND DATA USES

If Content, AI Outputs, account behavior, Offer Wall activity, payment activity or Platform use creates legal, security, safety, privacy, reputational, operational or commercial risk, we may restrict processing, refuse outputs, suspend features, withhold rewards, preserve records where lawful, report unlawful activity, cooperate with authorities or take other action permitted under the Terms and Conditions and Applicable Laws.

You must not submit Content that includes malware, unlawful instructions, exploit code, phishing content, hate speech, child sexual abuse material, unlawful sexual, terrorist or violent content, threats, blackmail, extortion, unlawfully obtained personal data, unauthorized Sensitive Data, unlawful biometric data, unauthorized confidential information or other unlawful content.

You must not use the Platform to create or distribute deepfakes, misleading synthetic media, unlawful impersonations, deceptive audio, fraudulent translations, forged transcripts, fabricated evidence, unlawful surveillance materials, biometric identification tools or outputs that violate rights or Applicable Laws.

You must not use the Platform or AI Outputs to identify, profile, track, monitor, surveil, target, harass, deceive, defame, impersonate, manipulate or discriminate against any person, or infer sensitive characteristics of another person, except where expressly lawful and authorized.

22. UPDATE TO THE PRIVACY POLICY

The most current version of this Privacy Policy document will govern our use of your Information/Data and can be found on our Platform (see “Privacy Policy” section). We reserve the right to update this Privacy Policy at any time. Where an update materially changes the purposes for which Personal Data is processed, the categories of Personal Data collected, the categories of third parties with whom Personal Data is shared, the data retention periods, or your rights and choices, we will make an updated copy of such Privacy Policy available to you and notify you before the change takes effect, using the same channels we use to contact you for the Services, consistent with the transparency obligations under Articles 12-14 GDPR/UK GDPR and the equivalent good-faith and transparency principles under the FADP. Where the change affects processing for which your consent was the basis, we will present a fresh consent notice and obtain your renewed consent before processing your Personal Data in that new or changed manner. Changes that do not materially affect your rights or the processing of your Personal Data may be communicated by posting the updated Policy on the Platform. We advise you to review the Privacy Policy at regular intervals. If you do not accept a material change, you may withdraw consent and discontinue use of the affected feature or Service, as described in the Consent Section of this Policy.

23. CONTACT

For questions, requests or inquiries regarding protection of your Information/Data or this Policy, including requests under European privacy or data protection laws, you can contact SOHOFI’s Data Privacy Officer, where required:

Addressed To:

Data Privacy Officer

Name: Sohofi

Company: Sohofi Global Technologies

Address: Flat No. 203, 23/1, J R Makwoods Apartments, Old Mangammanapalya Road,

Popular Colony, Mangammanapalya, Bengaluru, Bengaluru Urban, Karnataka, 560068

E-mail: dpo@sohofi-global.com

Please keep in mind that email communication is not always secure. Include sufficient information to identify your account, country, request type and feature involved, but do not include unnecessary raw voice recordings, images, prompts or other sensitive Content unless required for the request.

We will address your request in accordance with Applicable Laws and ordinarily free of charge, except where a fee or limitation is permitted by law. We may verify your identity before acting. If unsatisfied, you may lodge a complaint with a competent supervisory authority or approach another competent regulator, court or forum available under Applicable Laws.

24. GOVERNING LAW AND JURISDICTION

This Policy and disputes relating to the Platform, Services, Coins, subscriptions, AI Outputs, advertisements, Third-Party Services or the relationship between you and the Company shall be governed by the laws of India for contractual and general legal matters, without regard to conflict-of-law principles. Notwithstanding the foregoing, nothing in this clause limits or excludes: (a) the application of the GDPR and applicable EU member-state data protection laws to processing of Personal Data of individuals in the European Economic Area, which apply as mandatory provisions of law with extraterritorial effect under Article 3 GDPR and cannot be excluded or diminished by this choice of law; (b) the right of data subjects to exercise their GDPR rights before the competent supervisory authority or court in their member state of habitual residence; (c) the application of the UK GDPR and the Data Protection Act 2018 to processing of Personal Data of individuals in the United Kingdom, and the right of UK data subjects to exercise their rights before the Information Commissioner’s Office (ICO) or the competent UK court; (d) the application of the FADP to processing of Personal Data of individuals in Switzerland, and the right of Swiss data subjects to exercise their rights before the Federal Data Protection and Information Commissioner (FDPIC) or the competent Swiss court; or (e) any other mandatory right available to you under Applicable Laws that cannot lawfully be waived.

For the avoidance of doubt, the application of Indian law to this Policy does not reduce the level of protection afforded to data subjects in the European Economic Area, United Kingdom, or Switzerland below the applicable GDPR/UK GDPR/FADP standard.

Subject to any non-waivable statutory, consumer, data-protection or regulatory remedy available under Applicable Laws, disputes relating to this Policy shall be subject to the jurisdiction provisions in the Terms and Conditions. Nothing prevents you from exercising non-waivable rights before competent courts, authorities or supervisory bodies where Applicable Laws grant such rights.