PRIVACY POLICY

PRIVACY POLICY

Voice Soul is an AI-enabled voice, image and language assistance platform that enables users to record, upload, translate, process and receive audio, image-based, contextual and language-related outputs through artificial intelligence and third-party processing systems (the “Services”). The Services are owned and operated by Sohofi Global Technologies, a partnership firm based in India, with its registered office at Flat No. 203, 23/1, J R Makwoods Apartments, Old Mangammanapalya Road, Popular Colony, Mangammanapalya, Bengaluru, Bengaluru Urban, Karnataka, 560068 (“SOHOFI”, “Company”, “we”, “us” or “our”).

This Privacy Policy (“Policy”) explains how we collect, use, disclose, and protect your information when you use the Voice Soul mobile application, website, web application, APIs, interfaces, software, tools, content and related services (the “Platform”), and is tailored to address the requirements of the local data protection laws of the Middle East jurisdictions where we operate. For AI Processing features, Input Data is intended to be processed on a one-time, transient basis to generate the requested AI Output and is then deleted, de-identified or retained only in limited form as described in this Policy.

This Policy is provided electronically and should be read with the Terms and Conditions, consent notices, cookie notices, feature-specific notices and in-app disclosures. Nothing in this Policy limits any mandatory rights available to you under Applicable Laws.

In this Policy, “you” / “your” / “yourself” means the person using the Platform and/or the person on whose behalf you are acting. We process Personal Data, Sensitive Data, third-party information and other Information/Data only for the relevant features and purposes described in this Policy and in accordance with Applicable Laws.

Please read this Privacy Policy carefully before accessing or using the Platform. This Policy is provided for transparency and information purposes. It is not, by itself, a consent instrument, and reading, accessing or acknowledging it, or registering on or otherwise using the Platform, does not constitute your consent to the processing of your Personal Data for any purpose. Where consent is the applicable legal basis under the data protection law of your jurisdiction, we will separately obtain your free, specific, informed, unconditional, and unambiguous consent, by itemised consent notice, before processing your Personal Data for the relevant purpose. If you accept this Policy on behalf of another person, company or other legal entity, you represent and warrant that you have full authority to bind such person, company, or legal entity to this Policy.

This Policy describes our current data protection policies and practices and may be amended/updated from time to time. Any changes to this Policy will become effective upon posting of the revised Policy on the Platform or upon such other date as may be notified by us. We suggest that you regularly check this Policy to apprise yourself of any updates.

1. CONSENT

This Policy is a privacy notice provided to you in connection with our processing of your Personal Data under the data protection laws applicable in the jurisdiction from which you access the Platform, including the transparency and notice obligations under those laws. It describes our data practices so that you can understand how we process your Personal Data and make an informed decision about your use of the Platform. This Policy, by itself, does not constitute your consent to any processing that relies on consent as its lawful basis. We process Personal Data on the basis of your consent, the performance of the Terms and Conditions, compliance with a legal obligation, our legitimate interests, or another lawful basis recognized under Applicable Laws. If you do not agree with the disclosures in this Policy or an applicable consent notice, please do not proceed with the use of the relevant feature or Service. This Policy shall be deemed to be incorporated into the Terms and Conditions of the Platform and shall be read together with them.

Consent” means a freely given, specific, informed, unconditional, and unambiguous indication of your wishes by a clear affirmative action, signifying your agreement to the processing of your Personal Data for one or more specified purposes, consistent with the standard under Article 6(1), UAE PDPL, Article 4, Qatar PDPPL, and Article 24(1), Bahrain PDPL (which additionally requires consent from a person with full legal capacity, written, explicit and specific to the processing). Where the Oman PDPL requires consent, including before disclosure under Article 21, or before advertising or marketing material under Article 22, we obtain it in written or electronic form before the relevant processing commences.

Where consent is the basis on which we process your Personal Data, we will present you with a consent notice that: (a) itemizes each category of Personal Data, including any Sensitive Data, proposed to be processed under that consent; (b) specifies each purpose for which it is processed; (c) explains that you may withdraw consent at any time, as easily as you gave it; and (d) where processing is to be carried out by a Processor or third-party AI vendor on our behalf, identifies the categories of such recipients. Consent will not be bundled with acceptance of the Terms and Conditions or made a condition of a contract, including the provision of a Service, where that consent is not necessary for such performance, and we will not require you to consent to processing beyond what is necessary for the feature or Service you are using. Where Applicable Laws impose a higher consent standard for Sensitive Data, we will obtain that consent separately, through a dedicated consent notice distinguishable from this Policy, and will not treat acceptance of this Policy, app permissions or the Terms and Conditions as satisfying that standard.

We do not present consent requests as a single “accept all” or “agree and continue” choice covering unrelated processing activities, and we do not treat silence, inactivity, pre-ticked boxes or continued use of the Platform as an indication of consent. We instead present separate, itemized consent requests at the point where the relevant processing actually begins, rather than as a single blanket acceptance at account creation, including at: (i) account registration, for account-related communications and fraud/security logging incidental to account use; (ii) first use of a specific AI Processing feature, for transmission of your Input Data to the relevant AI Sub-processor; (iii) the cookie preference banner, for non-essential cookies and similar tracking technologies; (iv) a dedicated marketing opt-in, presented separately from every other consent request, for promotional communications; and (v) a dedicated in-app prompt, for any feature involving Sensitive Data or Biometric Data. We review these consent points periodically to ensure they continue to reflect where decisions about your Personal Data are actually made.

Where the Platform transmits your Personal Data to an AI Sub-processor as part of providing the core AI Processing functions described in this Policy, such transmission forms an integral part of the Service you have requested. Before you use a feature that involves transmission of your Personal Data to an AI Sub-processor for the first time, the Platform will, to the extent technically practicable and before such transmission commences: (a) inform you of the nature and categories of data to be sent; (b) identify the category of AI Sub-processor that will receive it; and (c) specify the purpose of such transmission. Where Applicable Laws require your consent for that transmission, including for Sensitive Data or Biometric Data, we will additionally obtain that consent by way of a separate, itemized consent notice before transmission commences, and will not activate the relevant feature until consent is given. Your Input Data will be sent to AI Sub-processors in the categories described in the AI Processing, Model Operations and Outputs Section of this Policy, solely to provide the relevant features to you. Creating an account or using the Platform generally does not, by itself, constitute your consent to such transmission.

You may withdraw consent at any time through the controls available for the relevant feature or by contacting us, as easily as you gave it. Such withdrawal will not affect the lawfulness of processing carried out before withdrawal, consistent with Article 6(2), UAE PDPL and Article 5(1), Qatar PDPPL, an undertaking we extend across all jurisdictions covered by this Policy regardless of whether local law expressly so provides, though it may limit the relevant Service, feature, Coin-related functionality, Offer Wall activity or Third-Party Service, and we may continue processing under an independent lawful basis or statutory compliance obligation where permitted. Withdrawing consent does not affect the continued provision of Services that do not depend on that consent, although the specific feature requiring it may become unavailable.

2. APPLICABILITY

This Policy applies to Information/Data collected through the Platform and Services, including account creation, app usage, voice-to-voice translation, the Image to Your Voice / Visual Story Converser (image-based question-and-answer), image-to-voice functionality, contextual image assistance, language mapping, location-based language configuration, customer support, Coins, Premium Membership Plans, advertisements, Offer Wall activities and Third-Party Services, across the Middle East and GCC jurisdictions where the Platform is available, including the UAE, Saudi Arabia, Qatar, Kuwait, Bahrain, Oman and Egypt, subject to mandatory local requirements and, for Saudi Arabia, Egypt and Turkey, the jurisdiction-specific Annexures. We comply with the stricter legal requirement that applies to you, regardless of jurisdiction. Availability in any jurisdiction subject to sanctions, export controls, cloud-provider or AI-vendor restrictions, including Iran and Iraq, is subject to those requirements, and the Company makes no representation that the Platform is available or lawfully accessible in any such jurisdiction.

This Policy does not apply to independent third-party applications, app stores, payment gateways, AI vendors, cloud providers, analytics providers, advertising partners, Offer Wall providers, survey providers, game providers, external websites or other Third-Party Services that process Information/Data for their own purposes. A third party that processes Information/Data on our behalf and for our benefit, without determining the purpose or manner of that processing, instead acts as a Processor.

Where we engage a third-party AI Sub-processor, cloud infrastructure provider, analytics provider or customer support platform to process Personal Data exclusively on our behalf and per our documented instructions, we remain responsible as Controller for all such processing. We will: (i) select Processors offering sufficient guarantees to implement appropriate technical and organizational measures; (ii) bind each under written contract to act only on our instructions, maintain confidentiality, and implement security obligations equivalent to our own; and (iii) monitor their ongoing compliance. Processors participating in the same activity without a written agreement allocating their respective obligations are treated as jointly responsible for compliance.

If you submit, upload, record or process Content, including any person’s voice, image, likeness, biometric information, personal information, confidential information, sensitive information, prompts, files, messages, image links or other materials through the Platform, you are responsible for ensuring that you have all rights, consents, notices, permissions and lawful grounds required under Applicable Laws and the Terms and Conditions.

3. DEFINITIONS

a) Applicable Laws” means all applicable laws, regulations, regulatory guidance, governmental directions, orders and legally binding requirements relating to privacy, data protection, cybersecurity, telecommunications, electronic transactions, consumer protection, AI governance, anti-cybercrime, cloud-computing, digital platforms and related matters in jurisdictions where the Platform or Services are offered, accessed or used, including without limitation:

i) in the UAE (mainland), Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) and Cabinet Decision No. 111 of 2023, as issued by the UAE Data Office;

ii) in Saudi Arabia, the Personal Data Protection Law (Royal Decree No. M/19, 2021, as amended by Royal Decree No. M/148, 2023) and its Implementing Regulations, enforced by SDAIA and fully in force from 14 September 2024;

iii) in Qatar, Law No. 13 of 2016 on Personal Data Privacy Protection (PDPPL) and the NDPO's regulatory guidance; in Bahrain, the Personal Data Protection Law (Law No. 30 of 2018) and its Regulations;

iv) in Oman, the Personal Data Protection Law (Royal Decree No. 6/2022) and its Executive Regulations (issued February 2024);

v) in Kuwait, the Data Privacy Protection Regulation (Decision No. 26 of 2024) applies only to CITRA-licensed telecommunications and IT service providers, a category of entities that does not include the Company in respect of its provision of a downloadable AI application. The applicable law is instead the Electronic Transactions Law No. 20 of 2014 and the Cybercrime Law No. 63 of 2015. The Company applies this Policy’s general standards to Kuwait-based Data Subjects as a matter of policy, and will reassess if its Kuwait activities expand into licensed services;

vi) in Turkey, Law No. 6698 on the Protection of Personal Data (KVKK, 2016), administered by the Personal Data Protection Authority (KVKK Board);

vii) in Egypt, the Personal Data Protection Law (Law No. 151 of 2020) and its Executive Regulations (Ministerial Decision No. 816/2025), with the one-year compliance grace period expiring November 2026, noting Personal Data may only be transferred outside Egypt following a separate PDPC licensing process that assesses the destination country’s adequacy and requires the data subject’s explicit consent; and

viii) in Iran and Iraq, no comprehensive data protection statute is yet in force (each has a draft law pending); privacy-related obligations instead derive from general electronic-transactions, cybercrime and constitutional provisions in each jurisdiction, together with Iran’s data-localisation requirement for the National Information Network and Iraq’s digital-platform licensing framework, and availability of the Platform in either jurisdiction is subject to applicable sanctions and export-control restrictions; and

ix) all other applicable cybersecurity, telecommunications, electronic transactions, consumer protection and AI governance laws in the relevant jurisdiction, together with Indian laws mandatorily applicable to the Company as its place of incorporation.

b) “Personal Data” or “Personal Information” means any data related to an identified or identifiable natural person, identifiable directly or indirectly through elements such as name, voice, image, identification number, electronic identifier, geographical location, or physical, physiological, economic, cultural or social characteristics, consistent with Article 1, UAE PDPL, Article 1, Qatar PDPPL, Article 1, Bahrain PDPL, and Article 1, Oman PDPL. This includes identifiers, contact details, device or online identifiers, usage and location-related information, voice, image, likeness, account information, payment-related metadata, prompts, Content and AI Outputs, and, per Article 1, UAE PDPL, Sensitive Personal Data and Biometric Data as defined below. Aggregated or anonymized information that cannot reasonably identify an individual is not Personal Data for purposes of this Policy, though de-identified or pseudonymized information may remain subject to Applicable Laws where it can reasonably be linked back to an individual.

c) Sensitive Personal Information” or “Sensitive Personal Data” means (i) under the UAE PDPL (Article 1), data directly or indirectly revealing a natural person’s family, ethnic origin, political or philosophical opinions, religious beliefs, criminal record, biometric data, or health, physical, psychological, mental, genetic or sexual condition, and Biometric Data resulting from technical processing of physical, physiological or behavioral characteristics enabling unique identification (e.g. facial images or voiceprints); (ii) under the Qatar PDPPL (Article 16), personal data of special nature, being data related to ethnic origin, children, health, physical or psychological condition, religious creeds, marital relations or criminal offences; (iii) under the Bahrain PDPL (Article 1), data revealing race, ethnic origin, political or philosophical opinions, religious beliefs, trade union affiliation, criminal record, or health or sexual status; and (iv) under other Applicable Laws, any additional categories designated as sensitive or subject to heightened protection.

d) Data Subject” means the identified or identifiable individual to whom Personal Data relates and includes, where applicable, a parent, lawful guardian or authorized representative.

e) Controller” means the natural or legal person, public authority, agency or other body, that alone or jointly with others, determines the purposes and means of processing Personal Data.

f) Processor” means a natural or legal person, public authority, agency or other body which is processing Personal Data on behalf of a Controller, including service providers, vendors, contractors and other processors engaged by us.

g) Processing” means any operation or set of operations, performed on Personal Data whether or not by automated means, such as collection, recording, storage, adaptation, alteration, use, disclosure, transmission, restriction, erasure or destruction.

h) Content” means audio, voice recordings, speech, images, image links, prompts, text, metadata, feedback, files, messages, names, likenesses, instructions and other material submitted, uploaded, recorded or transmitted through the Platform.

i) AI Outputs” means translations, audio responses, transcriptions, descriptions, contextual responses, language-related outputs, image-related outputs, text, voice outputs or other outputs generated or assisted by artificial intelligence, translation, speech, computer-vision or related systems.

j) AI Processing” means processing of Content, Personal Data, device information, technical data, prompts, voice recordings, images, metadata and other inputs by or through AI systems, machine-learning models, translation engines, speech systems, computer-vision systems, safety tools and related Third-Party Services. Unless stated otherwise, raw Input Data is intended to be processed temporarily for the requested Service.

k) Input Data” means prompts, audio, voice recordings, images, image links, text, instructions, metadata, files, feedback and other information provided to the Platform for processing by a Service or AI system. Input Data used to generate an AI Output is not retained as permanent history by default.

l) Model Improvement Data” means data used to monitor, test, evaluate, debug or improve the quality, reliability, safety, latency, usability or performance of the Platform, Services, AI Outputs and related systems. We seek to use aggregated, anonymized, de-identified or minimized data wherever reasonably practicable.

m) Human Review” means review by authorized personnel, contractors or service providers for limited operational, support, quality, safety, abuse-prevention, legal, security or rights-protection purposes, subject to safeguards. Human Review may not be available where raw Input Data has been processed transiently and deleted.

n) Biometric Data” means voiceprints, facial geometry, biometric identifiers, image-derived identifiers, speech-derived identifiers or other biological, physiological or behavioral characteristics that are used or capable of being used for identification, verification, authentication, classification or similar processing where regulated under Applicable Laws.

o) Cross-Border Transfer” means any processing, access, transfer, storage, hosting, support, remote access or disclosure of Information/Data in or from one jurisdiction to another, including through cloud infrastructure, AI infrastructure, vendor systems, support tools or globally distributed processing environments.

p) Localization Requirements” means legal or regulatory obligations requiring local storage, mirroring, access restrictions, regional routing, local hosting, local processing, restricted remote access or regionalized processing for certain Information/Data, systems, logs or services.

q) Coins”, “Offer Wall”, “Premium Membership Plan”, “Third-Party Services”, “User” and “Visitor” shall have the meanings assigned to them in the Terms and Conditions.

4. INFORMATION WE COLLECT

We collect only such Personal Data reasonably necessary for the purposes described in this Policy, the Terms and Conditions, consent notices or feature-specific notices. Depending on your use of the Platform, we may collect the following categories:

a) Information You Provide to Us

i) Account Information: Information about you that you provide to us when creating, maintaining or using an account, including name, username, account ID, profile information, email address, mobile number, language preferences, country or region selection, authentication information and any other information provided by you.

ii) Content and AI Processing Information: Voice recordings and speech you provide for translation or conversation; photos or images you capture or upload for the Image to Your Voice / Visual Story Converser; the text of any follow-up questions you ask; and the AI-generated translations, transcriptions and answers (AI Outputs) we return to you. Your voice recordings and images are not stored, they are processed in real time and deleted immediately after the relevant AI Output is generated.

iii) Communication Information: If you communicate with us, such as by email, in-app support, phone, grievance channels or other means, we may collect your contact information, communication content and related records.

iv) Payment, Subscription, Coins and Offer Wall Information: Premium Membership Plan selection, subscription status, invoice or transaction identifiers, payment-provider confirmations, refunds, Coin balances, usage deductions, reward history, Offer Wall status, attribution identifiers, anti-fraud checks, eligibility criteria, third-party verification status and related records.

v) Any Other Information: Additional Information/Data voluntarily provided in connection with the Platform or Services such as customer support communications, feedback, or survey responses, which shall be collected and used solely for the purposes described in this Policy.

b) Information We Collect Through Automated Means

When you use the Platform or Services, we may collect device identifiers, advertising identifiers (where permitted), app instance identifiers, IP address, operating system, browser type, app version, device model, network information, crash logs, diagnostics, cookies, SDK and analytics data, attribution information, app permission status and similar technical logs used to operate and secure the Platform, diagnose and fix technical issues, and improve features, performance and usage patterns. The Platform may request device permissions such as microphone, camera, photo library, file access, storage, location and notifications. You may enable, disable or modify such permissions through your device settings or Platform settings. If you disable a permission, the relevant feature may not function or may function only in a limited manner.

c) Information We Collect from Other Sources

We may receive Information/Data from app stores, payment providers, Advertising Partners, Offer Wall providers, survey providers, game providers, AI vendors, cloud providers, analytics providers, fraud-prevention providers, support tools and other Third-Party Services, where permitted under Applicable Laws and verified against compliance with secondary user choice metrics.

5. HOW WE USE YOUR INFORMATION

In processing your Personal Data, we adhere to the data protection principles under Article 5 of UAE PDPL, Articles 8(1) and 10 of Qatar PDPPL, and Article 3 of Bahrain PDPL: (i) processing lawfully, fairly and transparently; (ii) collecting only for a specific, clear and legitimate purpose, and not processing it incompatibly with that purpose save where the purpose(s) is/are closely related; (iii) limiting collection to what is necessary; (iv) keeping data accurate and up to date; (v) not retaining identifiable data longer than necessary, save in anonymized form; and (vi) applying appropriate technical and organizational security measures. We are responsible for, and able to demonstrate, our compliance with these principles.

Sr. No.

Purpose

UAE PDPL

Qatar PDPPL

Bahrain PDPL

a

a) To create, authenticate, maintain, secure and administer your account and provide account-related support.

Contract necessity (Article 4(9))

Lawful Purpose: providing the service requested (Article 4)

Contract performance (Article 4(1))

b

b) To provide and maintain the Services, including voice-to-voice translation, the Image to Your Voice / Visual Story Converser (image-based question-and-answer), image-to-voice functionality, contextual image assistance, language mapping, location-based language configuration and customer support.

Contract necessity (Article 4(9))

Lawful Purpose: operating the Services requested (Article 4)

Contract performance (Article 4(1))

c

To process Content, prompts, voice recordings, images, metadata and other inputs through AI, translation, speech, computer-vision and related third-party systems to generate AI Outputs on a one-time and transient basis.

Explicit consent (Article 6), given classification as Sensitive/Biometric data

Consent (Article 4), given processing of data of a special nature (Article 16)

Consent (Article 5), given processing of sensitive personal data

d

To allocate, deduct, verify and administer Coins, Usage Charges, Premium Membership Plans, subscriptions, Offer Wall rewards, refunds, disputes and account balances.

Contract necessity (Article 4(9))

Lawful Purpose: administering the payment and subscription relationship (Article 4)

Contract performance (Article 4(1))

e

To display, measure, attribute and manage advertisements, rewarded advertisements, Offer Wall tasks, surveys, games, promotions and other monetization features, subject to your choices and Applicable Laws.

Consent (Article 6)

Consent (Article 4)

Consent (Article 5)

f

To detect, prevent, investigate, monitor and respond to fraud, abuse, spam, impersonation, payment fraud, Offer Wall manipulation, security incidents, suspicious activity, malware, cyber-risk, infrastructure threats, account compromise, sanctions risk and other prohibited conduct.

Judicial/security-procedure necessity (Article 4(3)); protection of the Data Subject’s interests (Article 4(7))

Lawful Purpose: protecting the Controller’s and users’ security against fraud and abuse (Article 4)

Legitimate interest (Article 4(5))

g

To improve, maintain, test, monitor, debug and develop the Platform, Services, safety systems, language quality, translation accuracy, performance and user experience, using minimized or de-identified data where reasonably practicable.

Consent (Article 6)

Lawful Purpose: improving the quality of the Services (Article 4)

Legitimate interest (Article 4(5))

h

c) To communicate with you about account activity, service updates, security alerts, support, policy changes, subscriptions, rewards, offers, marketing communications and administrative matters, subject to your choices.

Contract necessity for service communications (Article 4(9)); consent for marketing (Article 6)

Lawful Purpose: operational account communications (Article 4); consent for marketing

Contract performance for service communications (Article 4(1)); consent for marketing

i

To comply with Applicable Laws, court orders, governmental directions, regulatory requirements, lawful interception obligations, national-security obligations, sanctions compliance, cybersecurity reporting, audit, taxation, accounting, record-keeping and law-enforcement requests.

Compliance with other UAE laws (Article 4(10))

Lawful Purpose: complying with legal obligations (Article 4)

Legal obligation or court order (Article 4(3))

j

d) To enforce the Terms and Conditions, this Policy and other applicable terms, and to establish, exercise or defend legal claims.

Legal claim or defense of rights (Article 4(3))

Lawful Purpose: enforcing contractual rights and defending legal claims (Article 4)

Legitimate interest (Article 4(5))

k

e) To create aggregated, anonymized or de-identified analytics, statistics and service-improvement insights that do not reasonably identify an individual.

Statistical-purpose necessity (Article 4(6)); outside PDPL scope once anonymized

Lawful Purpose: producing service-improvement analytics (Article 4)

Legitimate interest (Article 4(5))

Oman: Unlike the UAE, Qatar and Bahrain, Oman’s PDPL recognizes no “legitimate interest” or general contract-necessity basis; under Article 10, Personal Data may not be processed without the Data Subject’s express, written consent, and the Company accordingly relies on consent for each processing purpose listed above for Oman-based Data Subjects. A narrow set of purposes fall outside the PDPL’s scope entirely under Article 2, including processing necessary for national security or public interest, a legal obligation or court order, performance of a contract to which the Data Subject is a party, or protection of the Data Subject’s vital interest, and the PDPL, including its consent requirement, does not apply to processing falling within one of those exclusions.

Unless expressly disclosed in a consent notice, feature-specific notice or applicable setting, we do not use your voice recordings, images, prompts or Content containing Personal Data to train third-party public foundation models, and we do not retain raw Input Data for model training by default.

The Company may implement moderation, filtering, intervention, escalation, Human Review, regional routing or other review systems to comply with legal, regulatory, cybersecurity, public-interest, cultural or safety obligations and to protect users, third parties, the Platform, AI systems and the Company’s legitimate operational interests.

6. DISCLAIMER

WHERE THE PLATFORM PROVIDES VOICE, IMAGE OR LANGUAGE ASSISTANCE SUCH ASSISTANCE IS AN AUTOMATED AID AND NOT A GUARANTEED DESCRIPTION, TRANSLATION OR ASSESSMENT; IT IS NOT A SUBSTITUTE FOR PROFESSIONAL TRANSLATORS, INTERPRETERS, LAWYERS, DOCTORS, FINANCIAL ADVISERS, EMERGENCY SERVICES, GOVERNMENT AUTHORITIES OR OTHER QUALIFIED PROFESSIONALS. USERS REMAIN RESPONSIBLE FOR INDEPENDENT JUDGMENT AND HUMAN ASSISTANCE WHERE ACCURACY OR SAFETY MATTERS, AND THE PLATFORM MUST NOT BE RELIED UPON FOR REGULATED, SAFETY-CRITICAL, LIFE-CRITICAL OR HIGH-RISK DECISIONS.

AI OUTPUTS ARE GENERATED ALGORITHMICALLY AND MAY CONTAIN ERRORS, MISTRANSLATIONS, OMISSIONS, HALLUCINATIONS, INCORRECT IMAGE OR TEXT INTERPRETATIONS, MISSED NUANCES, BIAS, OFFENSIVE CONTENT OR OTHER LIMITATIONS, AND MAY VARY BASED ON MODELS, THIRD-PARTY SYSTEMS, LANGUAGE SETTINGS, PROMPTS, SAFETY FILTERS, NETWORK CONDITIONS, REGIONAL AVAILABILITY, DEVICE SETTINGS OR PRODUCT CONFIGURATION. YOU SHOULD VERIFY AI OUTPUTS BEFORE RELYING ON THEM.

7. AI PROCESSING, MODEL OPERATIONS AND OUTPUTS

The Platform is an AI-enabled service. When you use AI features, the following categories of data may be transmitted to Company systems and Third-Party Services to provide the Service: (a) voice recordings and audio clips; (b) images and camera inputs; (c) text prompts and typed inputs; (d) translations and transcriptions; (e) session metadata (such as language settings, device type and app version); and (f) Content you submit through the relevant feature. This processing may involve globally distributed cloud infrastructure and regional routing systems operated by Third-Party Services, whose categories include: (i) large-language-model and generative-AI providers; (ii) automatic-speech-recognition and text-to-speech vendors; (iii) machine-translation engine providers; (iv) computer-vision and image-analysis providers; (v) cloud-computing and storage infrastructure providers; and (vi) safety, moderation and abuse-prevention service providers. Where we are permitted to identify specific vendors, we will do so in the relevant in-app disclosure, feature notice or updated version of this Policy. Unless stated otherwise, this processing is intended to be one-time, session-based and limited to generating the AI Output requested by you.

When you speak into Voice Soul, or take a photo for the Image to Your Voice/ Visual Story Converser, that audio or image is held in temporary memory on our servers, or those of our AI providers, just long enough to generate your translation, transcription or answer. It is not written to permanent storage, and it is dropped immediately after we deliver the response to you, the only exception being that, within an active conversation, we keep it briefly so you can ask follow-up questions about that same recording or photo, after which it is dropped too. We do not use your voice recordings or images to train AI models, and there is no setting, on our side or yours, that keeps them for that purpose.

Certain AI functionalities may be restricted, modified, suspended or unavailable in specific jurisdictions due to Applicable Laws, telecommunications requirements, cybersecurity requirements, cloud-provider restrictions, sanctions, cultural or public-interest considerations, safety requirements, infrastructure limitations or operational requirements.

Since raw voice recordings and images are deleted immediately after your AI Output is generated, as described above, we do not use them to build test prompts, benchmark datasets or evaluation sets. Any quality, safety or abuse-prevention metrics we maintain (for example, error rates, latency, or the number of safety-filter triggers) are aggregated technical statistics and do not include your underlying voice recordings, images or transcripts.

Feedback, corrections, ratings, suggested translations, quality comments, support tickets and similar inputs may be retained, reviewed by personnel or service providers, and used to evaluate, debug, improve and develop the Platform, Services and AI Outputs. You should not include Personal Data, SPDI, confidential information or third-party information in feedback unless strictly necessary to resolve the issue. We recommend redacting or omitting such information where possible.

Where Personal Data is used for model improvement, evaluation or quality review, we will do so only where permitted under this Policy, a relevant notice, user settings or Applicable Laws, and with heightened care for Sensitive Data, children’s data and similarly protected information.

We may use aggregated, anonymized, de-identified or non-personal information to improve, test and monitor the Platform, Services, AI Outputs, safety, performance, language quality, routing logic, abuse-prevention and user experience, using measures to make re-identification of an individual unlikely given the means reasonably available to reverse anonymization or de-identification.

We seek to use configurations, contractual restrictions or technical controls that limit third-party AI vendors’ use of Input Data to providing and supporting the relevant Services. Where a third-party AI vendor processes your Personal Data on our behalf, we require, through data processing agreements, that such vendor maintains technical and organizational measures, confidentiality obligations, purpose-limitation restrictions and data-subject rights-assistance commitments at least equivalent to the protections described in this Policy and required by Applicable Laws. We do not authorize AI Sub-processors to use your Personal Data for their own purposes beyond delivering the service.

The categories of third-party service providers that may receive your Input Data for AI Processing purposes include: (i) large language model (LLM)/foundation model providers that generate text, language or contextual responses; (ii) speech-to-text and text-to-speech engine providers that convert voice recordings to text and text to audio output; (iii) machine translation providers that translate content between languages; (iv) computer-vision and image-analysis providers that interpret images and generate image-related outputs; and (v) cloud infrastructure providers whose compute or storage resources host or route Input Data during processing. We do not share your Input Data with these providers for their own marketing, profiling or model-training purposes beyond what is described in this Policy. Where we are permitted to identify a specific provider by name, details will be published on the Platform here[K&K_HA1] or notified to you.[K&K_HA2]

8. MODEL IMPROVEMENT, TRAINING AND EVALUATION

We distinguish service-delivery processing from model improvement, evaluation or training. Service delivery includes receiving Input Data, routing it, generating AI Outputs, maintaining temporary session state, applying safety filters, performing abuse checks, regional routing, localization controls, calculating Coin deductions, resolving technical errors and limiting retention after processing.

Location-related processing may include approximate location derived from IP address, settings, selected region, app-store region or network information, and precise location only where enabled and required by a feature. Location may support language configuration, regional experiences, fraud prevention, compliance settings, attribution, Offer Wall eligibility and security.

You should avoid submitting unnecessary personal details, identity documents, payment information, passwords, health information, children’s information, precise location, confidential business or medical documents, or other sensitive content unless required and lawful (for example, identity documents are necessary only where a feature expressly requires identity verification, not for general translation or chat). The Platform is not intended as a secure vault or permanent repository for sensitive records.

Classification of Voice and Image-related Data

The Platform helps you read, translate and understand documents and text in various languages, depending on your subscription plan (free or premium), and processes your voice and images to generate translations, transcriptions, descriptions and contextual answers, and to run safety and fraud-prevention checks, not to identify you. The Platform does not have the ability to analyse, interpret, describe or comment on facial features, scenery or other visual characteristics depicted in an image, and will not respond to requests seeking such analysis. The Platform does not currently include any feature that uses voice or facial characteristics to verify your identity or isolate individual behavioral metrics, and the Platform does not perform any facial recognition, facial analysis or extraction of facial characteristics from images. If such a feature is introduced in future, we will obtain your separate, explicit consent before enabling it.

9. VOICE, IMAGE, BIOMETRIC AND LOCATION-RELATED PROCESSING

The Services may process voice recordings, speech, speech patterns, accents, dialect, language patterns, background audio, images, facial images, faces, facial geometry where generated by a feature, objects, text within images, image metadata, places, signs, documents, metadata and location-related settings. Depending on context and jurisdiction, voice recordings, speech patterns, facial images, image metadata, facial geometry or similar identifiers may constitute Biometric Data, Sensitive Data or other protected information under Applicable Laws.

Certain voice, image or biometric functionalities may require additional consent, separate notices, regional restrictions, localized processing, restricted retention, access controls or other safeguards depending on Applicable Laws, feature configuration, user location, cloud availability and the category of Information/Data involved. In jurisdictions where biometric data receives heightened statutory protection, including:

a) PDPL and SDAIA Implementing Regulations classify voiceprints and facial geometry as Sensitive Data only where processed to identify you; Voice Soul’s translation and Image to Your Voice / Visual Story Converser features do not do this, and if we introduce a feature that does, we will obtain explicit consent and any required SDAIA authorisation before enabling it for Saudi-based users).

b) UAE PDPL Cabinet Decision 111/2023 treats biometric identifiers as Sensitive Personal Data only where processed to identify you, which Voice Soul’s current features do not do) and Turkey (KVKK Article 6 classifies biometric data as a special category on the same identification-based test; if we introduce a feature that identifies you from your voice or face, we will obtain explicit consent before enabling it for UAE- or Turkey-based users),

c) Qatar, personal data of special nature under the PDPPL, as defined above, requires prior written authorization from the competent authority in addition to the data subject’s consent before such data may be processed,

d) Bahrain, Article 15 of the PDPL prohibits automatic processing of biometric data for identity verification without the PDPA’s prior written authorisation, obtained before such processing begins; unauthorised processing is a criminal offence under Article 58(1)(e). The Company will obtain this authorisation before enabling voice or facial biometric identification features for Bahrain-based users.

e) Oman, Article 5 of the PDPL prohibits processing of biometric, genetic or health data unless the Company first obtains a permit from the Ministry of Transport, Communications and Information Technology under the Executive Regulations, which the Company will obtain before enabling voice or facial biometric identification features for Oman-based users.

We will obtain the required consent, apply the required safeguards, and seek any required regulatory authorisation before enabling such features for users in those jurisdictions.

We may use safety filters, moderation rules, rate limits, routing controls, regional filtering, child-safety controls, sensitive-content filters, intervention, escalation or review systems and other safeguards. These controls may limit processing or AI Outputs where necessary or appropriate for legal, regulatory, cybersecurity, public-interest, cultural, safety, rights-protection, misuse-reduction or Platform-integrity obligations.

Where an automated process materially affects your account, access, Coins, rewards, subscription status or rights under Applicable Laws, you may contact us through the grievance mechanism. We will review such concerns in accordance with Applicable Laws and available safeguards.

The Platform may use automated systems to detect abuse, fraud, malware, unlawful content, manipulation of Coins, payment issues, suspicious device behavior, account compromise, unsafe prompts, harmful outputs or circumvention attempts. We do not make solely automated decisions producing legal or similarly significant effects on individuals, except where: (a) required or expressly permitted by Applicable Laws; (b) the Data Subject has given explicit consent; or (c) the decision is necessary for performance of a contract with the Data Subject. Where we do make such decisions, we implement the safeguards required under Applicable Laws, including: under the Saudi PDPL, the right to contest an automated decision; under the UAE PDPL, the right to request human review of decisions producing significant effects; and under Turkey’s KVKK, ensuring the decision does not produce an adverse legal effect without an available right to object. Human Review will be limited to personnel or service providers with a need to access relevant information for a permitted purpose, subject to safeguards. Where raw Input Data has been deleted after transient processing, review may rely on retained logs, metadata, support records or information separately provided by you.

10. HOW WE SHARE AND DISCLOSE YOUR INFORMATION

We may share Information/Data in the following ways, where permitted for the relevant purpose and subject to appropriate confidentiality, security, processor, transfer and purpose-limitation safeguards where required:

a) Affiliates and group companies: We may share Information/Data with our affiliates and group companies to operate, administer, support, secure and improve the Platform and Services, subject to contractual obligations requiring such affiliates and group companies to process the Information/Data only for the purposes described in this Policy and to maintain equivalent security and confidentiality safeguards.

b) Service providers and Processors: We may provide access to or share Information/Data with hosting providers, cloud providers, AI vendors, translation providers, speech-engine providers, computer-vision providers, analytics providers, security vendors, customer-support tools, email/SMS providers, payment support vendors, fraud-prevention vendors, auditors, professional advisers and other processors engaged to provide services on our behalf, in each case under a valid contract requiring such processors to act only on our instructions and to process Information/Data solely for the purposes described in this Policy.

c) App stores, payment providers and subscription partners: We may share Information/Data to process subscriptions, verify payments, issue refunds, resolve disputes, administer Premium Membership Plans and comply with payment-related requirements.

d) Advertising Partners and Offer Wall providers: We may share Information/Data to display, measure, attribute and verify advertisements, rewarded advertisements, surveys, games, installs, offers, eligibility, anti-fraud checks and Coin credits. Such partners may also process certain information as independent data fiduciaries/controllers under their own policies. Where required by law, we will obtain separate consent for advertising-related profiling or tracking.

e) Third-Party Services selected or used by you: We may share Information/Data where you choose to access, connect, interact with or complete activities through a Third-Party Service linked to or integrated with the Platform.

f) Protection of our rights and interests: We may disclose Information/Data to prevent fraud or abuse, protect the security and integrity of the Platform, enforce the Terms and Conditions, protect rights and safety, or respond to misuse of the Services.

g) Business transfers: We may disclose or transfer Information/Data in connection with a merger, acquisition, investment, financing, restructuring, sale of assets, insolvency, reorganization or transfer of all or part of our business, subject to appropriate confidentiality and legal safeguards.

h) Legal purposes: We may disclose Information/Data where required or permitted by Applicable Laws, court order, governmental direction, legal process, investigation, cyber-security reporting obligation or to protect rights, property, safety, security or the public interest.

i) Any other person with your consent: We may share Information/Data with a specified recipient where you expressly instruct or authorize us to do so.

We do not disclose Personal Data for unrelated monetary consideration. Where a Third-Party Service processes information for advertising, attribution, rewards or monetization, such processing will be governed by this Policy, the relevant third-party policy, your choices and Applicable Laws.

We may change, add, remove, replace or reconfigure AI vendors, models, cloud providers, speech engines, translation engines, computer-vision tools, analytics providers, safety systems or other processing tools from time to time to improve functionality, safety, latency, availability, cost, language coverage, quality, reliability or legal compliance; such changes may affect output quality, available features, regional availability, retention, data flows and the categories of processors involved. We will seek to ensure that such changes do not materially reduce the protection of your Personal Data under this Policy, and where a change materially affects the processing of your Personal Data or requires notice or consent under Applicable Laws, we will provide that notice or obtain that consent as required.

Where a provider acts as our Processor or service provider, we bind it via explicit contract to obligations covering confidentiality, purpose limitation, security, access controls, retention, incident notification, rights assistance, deletion or return of data, transfer safeguards, and restrictions on unauthorized use of Input Data, consistent with the equivalent-protection standard described elsewhere in this Policy.

Providers may process Input Data, Content, metadata, device data, logs, AI Outputs or other Information/Data on our behalf or independently, depending on their role and terms. Transfers outside your country or region will be handled using safeguards or lawful transfer arrangements where required.

The Company may disclose Information/Data where required or permitted for cybersecurity compliance, lawful interception obligations, anti-cybercrime obligations, national-security requests, sanctions compliance, governmental investigations, court proceedings, emergency response, prevention of unlawful activity or legally binding regulatory directions.

Disclosure obligations, government-cooperation requirements, review thresholds and available safeguards may vary across jurisdictions and may be subject to confidentiality, secrecy, national-security, public-order or similar restrictions under Applicable Laws.

11. CROSS-BORDER TRANSFERS

Information/Data may be processed, accessed, transferred, disclosed, hosted or stored in jurisdictions outside your country of residence, including jurisdictions that may have different levels of data protection, cybersecurity, government-access, cloud-computing or regulatory requirements.

Cross-Border Transfers may involve the Company, affiliates, cloud providers, AI infrastructure providers, speech-processing vendors, translation engines, computer-vision systems, analytics providers, security vendors, customer-support providers, professional advisers and globally distributed systems used to operate, secure, improve, support and provide the Platform and Services.

Where required under Applicable Laws, the Company will implement reasonable safeguards for international transfers, which may include contractual protections, technical controls, access controls, vendor due diligence, encryption or similar measures appropriate to the relevant transfer, feature, vendor, jurisdiction and risk. The following jurisdiction-specific requirements apply in addition to the general approach described in this section:

a) UAE PDPL and Oman PDPL: Both require transfers to be subject to a contractual framework providing an adequate level of protection, or to fall within a category approved by the competent authority; as neither the UAE Data Office nor Oman’s competent authority has yet published a relevant adequacy list, transfers from these jurisdictions are made on the basis of (i) a binding contractual framework with our service providers and vendors imposing PDPL-consistent obligations, and/or (ii) the Data Subject’s express consent (for the UAE, given consistently with the UAE’s public and security interest, under Article 22, UAE PDPL). We will update this Policy if either authority publishes a relevant adequacy list;

b) Saudi PDPL: Personal data may only be transferred outside Saudi Arabia where required to fulfil a contractual obligation to the Data Subject, where the Data Subject has consented, or where the transfer is necessary for the public interest, subject to SDAIA approval or applicable exception;

c) Qatar PDPPL: Article 15 imposes no general adequacy-based restriction on outbound transfers; rather, the Controller may not take any decision or measure limiting Cross-Border Data Flow unless the transfer would itself breach the PDPPL or is likely to cause serious damage to the Personal Data or the Individual’s privacy. Transfers from Qatar are accordingly permitted by default, subject to the PDPPL’s general processing safeguards (Articles 8 and 13) and any specific NDPO guidance;

d) Bahrain PDPL: Transfers outside Bahrain are permitted only to PDPA-assessed adequate jurisdictions, under appropriate safeguards (binding corporate rules or standard contractual clauses), or with the Data Subject’s specific consent. India sits on Bahrain’s PDPA Adequacy List (Resolution No. 42 of 2022), so transfers to India may proceed without prior PDPA authorization, provided the PDPL’s general processing principles are otherwise satisfied;

e) Kuwait DPPR: Any transfer of Personal Data outside Kuwait must be accompanied by disclosure of the receiving country and the technical and legal safeguards applicable to the transfer; and

f) Turkey KVKK: Cross-border transfers require an adequacy decision, an approved safeguard (a standard contract, binding corporate rules or comparable undertaking accepted by the KVKK Board), or a recognized exception under KVKK Article 9, as detailed in the Turkey Annexure to this Policy.

The Company will take steps to comply with the applicable transfer mechanism required in each jurisdiction.

12. DATA LOCALIZATION AND REGIONAL PROCESSING

Certain jurisdictions may impose Localization Requirements, mirroring, restricted-access, local-hosting, regional routing, access-approval, cybersecurity-review or regional processing obligations for certain categories of Information/Data, logs, cloud workloads, AI Processing, telecommunications data or regulated services. By way of specific illustration:

(a) Saudi Arabia: SDAIA’s Implementing Regulations require that Personal Data of Saudi residents be stored and processed within Saudi Arabia unless an approved exception or transfer mechanism applies. Certain critical national data may be subject to additional localization obligations under the Saudi Cybersecurity Framework;

(b) UAE: The UAE PDPL requires that Sensitive Personal Data of UAE residents must be stored within the UAE unless a transfer is made under an approved safeguard, and certain telecommunications and financial data are subject to localization under sectoral regulations; and

(c) Kuwait: Ministerial Decision No. 6 of 2023 on Cloud Computing Services imposes storage restrictions for certain categories of government-related and regulated data, which may affect cloud-based AI Processing for users in Kuwait.

Where such localization obligations apply, the Company will implement the required technical, organizational or contractual measures to address them, including regional cloud configuration, localized processing, access restrictions, local support arrangements, data minimization, routing controls, retention controls, vendor commitments or feature restrictions, where required or operationally appropriate.

13. HOW DO WE RETAIN YOUR INFORMATION

We retain Information/Data only for as long as reasonably necessary for the purposes for which it was collected or processed, unless longer retention is required or permitted by Applicable Laws or for governmental/regulatory preservation, investigation, fraud-prevention, compliance, accounting, security, dispute-resolution or legal-claims purposes. Retention periods vary by category and jurisdiction. Under the specific requirements of Applicable Laws:

(a) Under the Saudi PDPL and SDAIA Implementing Regulations, Personal Data of Saudi residents will not be retained for longer than is necessary for the purpose of collection, and in no event for more than ten (10) years from the date of creation, unless the Data Subject has consented to a longer period or a specific law requires otherwise;

(b) Under the UAE PDPL and its Executive Regulations, Personal Data will be deleted or anonymised upon fulfilment of the collection purpose or expiry of the applicable retention period, and regulated data categories may be subject to specific retention periods set by the UAE Data Office or applicable sectoral laws;

(c) under Oman’s PDPL, Qatar’s PDPPL and Bahrain’s PDPL, Personal Data will be retained only for as long as necessary for the purpose of collection (subject, for Oman, to a longer period if required by law or agreed with the data subject), after which it will be deleted, anonymised, or securely archived in accordance with any applicable NDPO or PDPA guidance;

(d) where applicable telecommunications, financial or governmental regulations in any covered jurisdiction prescribe a minimum mandatory retention period, the Company will comply with that minimum period.

For AI Processing, retention varies by data type. Raw audio, raw images and prompts are processed transiently and are not retained beyond the session, as described below, while metadata, safety logs, abuse-prevention logs, Coin consumption records, model-routing records, quality metrics, error logs and support records may be retained for longer periods where necessary for security, fraud prevention, service integrity, accounting, legal compliance, dispute resolution or improvement of the Platform.

Without limiting the foregoing, we retain the following categories of Data for the periods indicated below, or until the purpose for which the data was collected is no longer being served, whichever is later, subject to any longer period required by Applicable Laws:

a. Account, profile and contact information: for the duration your account remains active, and for three (3) years following account closure or last login, for legal, security, fraud-prevention and dispute-resolution purposes;

b. Coin, subscription, payment metadata, Offer Wall and transaction records: for eight (8) years from the date of the relevant transaction, as required for accounting, tax, audit and anti-fraud purposes;

c. Voice recordings, images, prompts, transcripts and session Content not saved by you: deleted immediately after the relevant AI Output is generated and delivered to you; retained only for the duration of an active conversation to support follow-up questions, and deleted at the end of that conversation. Not retained for safety, debugging, fraud-prevention or any other purpose;

d. Metadata, safety logs, abuse-prevention logs, model-routing records and error logs: for twelve (12) months from creation, for security, fraud-prevention and service-integrity purposes; and

e. Support tickets, feedback and grievance records: for three (3) years from resolution, for quality-assurance and legal-compliance purposes.

We will update the periods above as our practices evolve and will notify you of any material change in accordance with the Update to the Privacy Policy Section of this document. De-identification or anonymization may not be reversible, and once information has been anonymized or aggregated it may not be possible to associate it with your account or respond to access, correction or erasure requests in relation to that anonymized or aggregated information.

Deletion may not immediately remove all backup copies, caches, logs, legal, security, payment or Offer Wall verification records, or data retained by independent Third-Party Services, but we apply deletion, de-identification, anonymization or retention controls consistent with Applicable Laws. Residual copies are deleted or overwritten within ninety (90) days under our backup and retention cycles, except where a longer period is required for legal, security, payment or dispute-resolution records as described above.

Consistent with the storage limitation principle under Article 5(7), UAE PDPL, Article 10, Qatar PDPPL, and Article 3(5), Bahrain PDPL, where you have not used your account for the inactivity period specified above, we will erase or anonymize your Personal Data upon lapse of that period, unless retention is required for a legal obligation, legal claims, or another permitted purpose, notifying you at least forty-eight (48) hours in advance so you may log in to prevent erasure if you wish.

When the purpose for which Personal Data was collected is no longer being served and retention is no longer necessary for any legal, safety, fraud-prevention, security, accounting or dispute-resolution purpose, we will delete, de-identify, anonymize or aggregate the data under Article 15, UAE PDPL, Article 5(3), Qatar PDPPL, and Article 23, Bahrain PDPL. Under those provisions, you may request erasure where, among other grounds: (i) it is no longer necessary for the purpose collected; (ii) you withdraw the consent on which processing was based; (iii) you object and there are no legitimate grounds for us to continue; or (iv) the data was processed in violation of Applicable Laws. We conduct periodic reviews to identify data that should be erased, and de-identification or anonymization is carried out using techniques designed to prevent re-identification, consistent with the Anonymization standard under Article 1, UAE PDPL. Once anonymized, the information is no longer treated as Personal Data under this Policy.

14. HOW WE PROTECT YOUR INFORMATION

We implement reasonable security practices and technical and organizational measures to protect Information/Data from unauthorized access, disclosure, alteration, destruction, loss, misuse and accidental damage, including access controls, authentication, encryption, logging, threat intelligence, vulnerability testing and management, intrusion detection, security-event monitoring, incident escalation and response, regionalized access and network monitoring, abuse detection, vendor controls, confidentiality obligations, data minimization, retention controls and periodic review.

No method of transmission, storage or processing is completely secure. You are responsible for maintaining account credentials, securing your device and notifying us of suspected unauthorized access or misuse.

Where a security incident or Personal Data breach triggers a reporting obligation, we will take the steps required by Applicable Laws, which may include notifying affected individuals and competent authorities. Breach notification is required within seventy-two (72) hours of becoming aware under the UAE PDPL (to the Data Office), the Saudi PDPL (to SDAIA, with affected Data Subjects notified without undue delay), the Oman PDPL (to the competent authority and affected persons), Bahrain’s PDPL (to the PDPA, unless the breach is unlikely to threaten data subjects’ rights, with affected data subjects also notified and failure to notify subject to administrative fines), and Turkey’s KVKK (to the Board); Qatar’s PDPPL requires notification to the NDPO and affected individuals without undue delay in accordance with NDPO guidance, without a fixed hour threshold. Where notification to affected individuals is required, we will provide it within the timeframe prescribed by the relevant Applicable Law.

AI-related security measures may include prompt-abuse monitoring, rate limiting, anomaly detection, access logging, vendor-access controls, restrictions on employee access to raw Content, and review of incidents involving unintended disclosure, prompt injection, model misuse, excessive data exposure or unauthorized access. Where required under Applicable Laws, including the Saudi PDPL Implementing Regulations, the UAE PDPL and Cabinet Decision 111 of 2023, the Oman PDPL Executive Regulations, Bahrain’s PDPL, and Turkey’s KVKK secondary legislation, we shall endeavour to conduct Privacy or Data Protection Impact Assessments before high-risk processing activities, including large-scale processing of Sensitive Data, biometric data, voice recordings or AI-driven automated decision-making, and use their findings to inform the safeguards applied.

Security measures may vary depending on infrastructure availability, cloud-provider capabilities, jurisdiction, feature availability, applicable legal requirements, Localization Requirements, regional access restrictions and the relevant threat environment.

You must not attempt prompt injection, model extraction, scraping, automated abuse, circumvention of safety filters, unauthorized access to AI systems or any activity intended to expose non-public Platform, model, security or user information.

15. THIRD-PARTY LINKS AND FEATURES

The Platform may include Third-Party Services, advertisements, rewarded advertisements, Offer Wall tasks, surveys, games, links, SDKs or integrations provided by third parties that may act as our processors or as independent providers depending on the feature and processing activity. When you interact with a Third-Party Service, the third party may collect information directly from you or your device, including device identifiers, IP address, advertising identifier, interaction data, reward eligibility and offer completion status. Their privacy policy and terms govern independent processing. We may receive confirmation, attribution, verification, anti-fraud and reward-status information from Third-Party Services to credit Coins, verify eligibility, prevent manipulation and resolve disputes.

The Platform may use cloud infrastructure, AI vendors, analytics providers, support tools, payment partners, Advertising Partners and other Third-Party Services located in India, Middle East jurisdictions, globally distributed cloud regions or other jurisdictions. Cross-Border Transfers will be undertaken in accordance with Applicable Laws and reasonable safeguards where required.

Where a feature permits you to save, download, export, share or reuse AI Outputs, you are responsible for reviewing those AI Outputs and handling any Personal Data, confidential information, third-party content or sensitive information lawfully.

Deletion or erasure requests will be assessed under Applicable Laws and may not affect AI Outputs already delivered or shared, information retained for legal, operational or security purposes, anonymized information, backups or caches awaiting deletion, or information retained by independent Third-Party Services.

Subject to technical availability and Applicable Laws, you may limit certain AI Processing through Platform, device, browser or account controls, including microphone, camera, photo, location, notification, advertising, cookie and marketing preferences.

16. USER RIGHTS AND CHOICES

Subject to Applicable Laws, users may have certain rights regarding their Information/Data. Such rights differ by jurisdiction and may be subject to verification, legal, operational, cybersecurity, fraud-prevention, public-interest, national-security, technical, confidentiality, rights-protection and other lawful limitations.

a) Access to information: to request confirmation of whether we process your Personal Data and access to information about such processing where provided by Applicable Laws.

b) Correction or updating: to request correction, completion or updating of inaccurate, misleading or incomplete Personal Data where provided by Applicable Laws.

c) Deletion or erasure: to request deletion, erasure or destruction of Personal Data in circumstances recognized by Applicable Laws, subject to permitted retention and lawful limitations.

d) Restriction, objection or cessation: to request restriction of processing, object to certain processing or request cessation of processing where such rights apply under Applicable Laws.

e) Copy or portability: to request a copy of certain Personal Data or portability in a structured format where Applicable Laws expressly provide such right and the same is technically feasible.

f) Automated-processing safeguards: to request applicable review, explanation or safeguards where a solely automated process produces legal or similarly significant effects concerning you and Applicable Laws provide such right.

g) Consent and preference choices: to withdraw consent where processing is based on consent and to manage non-essential marketing, notifications, cookies, advertising identifiers, app permissions and feature consents, subject to technical availability and lawful limitations.

You may submit a request by contacting the Grievance Officer / Data Protection Contact listed in the Contact Section of this Policy. We may verify your identity and may decline or limit a request where permitted by Applicable Laws, including where compliance would affect others’ rights, security, cybersecurity, fraud prevention, legal obligations, governmental requests, legal claims, confidential information, anonymized data or data processed transiently and not retained.

Where Platform, device, browser, consent-management or cookie-preference tools are available, you may use them to manage, review or withdraw consent, subject to technical availability and Applicable Laws.

Important: We will endeavor to respond to all valid requests within the timeframe of one month. If we are not able to process your request within that time, we will send a written explanation of the same, without any charge, unless the request is manifestly unfounded or excessive.

17. SENSITIVE PERSONAL INFORMATION AND CHILDREN’S PRIVACY

The Platform does not classify or process Content for the purpose of identifying Sensitive Data. Sensitive Data may include health, biometric, genetic, children’s, voice, facial-image, precise-location, identity or financial information and other categories recognized under Applicable Laws. Voice recordings, images, photographs, facial images, prompts or other Content you submit may incidentally contain such data depending on context. As the Platform cannot detect or classify such data within your Content, it is your responsibility not to upload or submit Sensitive Data, unless it is incidental to and necessary for the output you have requested. As we cannot classify such data, we are not able to apply data-specific additional safeguards to it; any such Content is processed solely for the purposes described in this Policy, subject to the general security and confidentiality measures described herein

The Platform is intended for individuals legally competent to use the Services and at least eighteen (18) years of age or the age of majority in their jurisdiction, whichever is higher, unless a specific Service lawfully permits otherwise. Under the Saudi PDPL, processing of a minor’s Personal Data (persons under eighteen (18)) requires lawful consent of a parent or legal guardian, and the Company will not knowingly collect or process the Personal Data of Saudi-based minors without such consent; the UAE PDPL, Oman’s PDPL and Bahrain’s PDPL likewise require parental or guardian consent for processing a minor’s Personal Data; under Qatar’s PDPPL, children’s data is treated as Personal Data of special nature and requires prior authorization from the competent authority in addition to guardian consent; and under Turkey’s KVKK, where the legal basis for processing is explicit consent, consent given by a minor must be supported by the consent of their legal representative.

We do not knowingly permit children to create accounts or use the Services unless permitted by Applicable Laws and supported by required parental or guardian consent or authorization. If we learn that a child’s Personal Data was collected without required consent, we will take appropriate steps to delete or restrict it, subject to legal and safety requirements.

Where Applicable Laws require enhanced safeguards for children, we will comply with those requirements, including restrictions on detrimental processing, profiling, tracking, behavioral monitoring or targeted advertising directed at children, to the extent applicable.

18. EXERCISING RIGHTS:

You can exercise privacy rights by submitting a request sohofi@sohofi-global.com or contacting the Grievance Officer / Data Protection Contact listed in the Contact Section. We may request information to verify your identity and may be unable to honor a request if verification is not possible.

We will endeavor to acknowledge and resolve requests within the timelines prescribed under Applicable Laws, subject to any permitted extension, fee, refusal or limitation. Under Article 18, Bahrain PDPL, where your request is incomplete we will notify you within ten (10) days to request the missing information and will respond, accepting or rejecting it with reasons, within fifteen (15) working days of receipt; under Article 23(1), Bahrain PDPL, requests for rectification, blocking or erasure will be answered within ten (10) working days, free of charge. Where a jurisdiction’s timelines are instead set by implementing regulations, including Qatar’s PDPPL (delegated to a Ministerial decision under Article 7) and the UAE PDPL (delegated to its Executive Regulations), we will follow those instruments once issued and, in the interim, endeavor to respond within the timelines above.

If we reject your request, we will notify you of our reasoned decision and, where applicable, your right to file a complaint with the competent regulator, the Data Office (Bureau) in the UAE (Article 24, UAE PDPL), or the competent Authority in Bahrain (Article 18(4), Bahrain PDPL), or, if dissatisfied, to lodge a complaint with a competent supervisory authority or approach another regulator, court or forum available under Applicable Laws in your jurisdiction.

19. USER RESPONSIBILITIES

You are responsible for ensuring that Personal Data you provide is accurate and lawful. You must not impersonate another person, submit false information, raise false grievances, or use the Platform for unlawful surveillance, unauthorized recordings, biometric misuse, illegal data collection, harassment, stalking, doxxing, identity theft, infringement of privacy or publicity rights, violation of privacy laws or other prohibited activity under the Terms and Conditions or Applicable Laws.

You agree that your use of the Platform, Content, AI Outputs, Coins, Offer Wall, advertisements and Third-Party Services shall remain subject to the Terms and Conditions, including provisions relating to user undertakings, prohibited conduct, disclaimers, limitation of liability and indemnification, to the maximum extent permitted under Applicable Laws.

20. PROHIBITED AI AND DATA USES

If Content, AI Outputs, account behavior, Offer Wall activity, payment activity or Platform use creates legal, security, safety, privacy, reputational, operational, regulatory, sanctions, cybersecurity or commercial risk, we may restrict processing, refuse outputs, suspend features, withhold rewards, preserve records where lawful, report unlawful activity, cooperate with authorities, implement regional filtering, block prohibited jurisdictions or take other action permitted under the Terms and Conditions and Applicable Laws.

You must not submit Content that includes malware, unlawful instructions, exploit code, phishing content, hate speech, child sexual abuse material, unlawful sexual, terrorist or violent content, threats, blackmail, extortion, unlawfully obtained Personal Data, unauthorized Sensitive Data, unlawful biometric data, unauthorized confidential information, political manipulation, disinformation, sanctions circumvention, unlawful surveillance instructions, unauthorized biometric analysis or other unlawful content.

You must not use the Platform to create or distribute deepfakes, misleading or unlawful synthetic media, disinformation, political manipulation, unlawful impersonations, deceptive audio, fraudulent translations, forged transcripts, fabricated evidence, unlawful surveillance materials, sanctions-circumvention materials, biometric identification tools, unauthorized biometric analysis or outputs that violate rights or Applicable Laws.

You must not use the Platform or AI Outputs to identify, profile, track, monitor, surveil, target, harass, deceive, defame, impersonate, manipulate or discriminate against any person, or infer sensitive characteristics of another person, except where expressly lawful and authorized.

21. UPDATE TO THE PRIVACY POLICY

The most current version of this Privacy Policy will govern our use of your Information/Data and can be found on our Platform. We reserve the right to update this Privacy Policy at any time. Where an update materially changes the purposes for which Personal Data is processed, the categories of Personal Data collected or shared, the retention periods, or your rights and choices, we will make the updated Policy available to you and notify you as required under Applicable Laws before the change takes effect. Where the change affects processing for which your consent was the basis, we will present a fresh consent notice and obtain your renewed consent before processing your Personal Data in that new or changed manner. Changes that do not materially affect your rights or the processing of your Personal Data may be communicated by posting the updated Policy on the Platform. We advise you to review this Policy at regular intervals. If you do not accept a material change, you may withdraw consent and discontinue use of the affected feature or Service, as described in the Consent Section of this Policy.

22. CONTACT

For questions, requests or inquiries regarding protection of your Information/Data or this Policy, including requests under European privacy or data protection laws, you can contact SOHOFI’s / Data Privacy Officer / Representative, where required:

Addressed To:

Data Privacy Officer

Name: Sohofi

Company: Sohofi Global Technologies

Address: Flat No. 203, 23/1, J R Makwoods Apartments, Old Mangammanapalya Road,

Popular Colony, Mangammanapalya, Bengaluru, Bengaluru Urban, Karnataka, 560068

E-mail: dpo@sohofi-global.com

Phone: [insert phone number, if applicable]

Egypt Representative

Name: [insert full legal name]

Address: [insert representative address]

E-mail: [insert email address]

Phone: [insert phone number, if applicable]

Turkey Data Controller Representative

Name: [insert full legal name]

Address: [insert representative address]

E-mail: [insert email address]

Phone: [insert phone number, if applicable]

Please keep in mind that email communication is not always secure. Include sufficient information to identify your account, country, request type and feature involved, but do not include unnecessary raw voice recordings, images, prompts or other sensitive Content unless required for the request.

For users located in Turkey: the Company is required to register with the VERİBİS registry of the Personal Data Protection Authority (KVKK Board) as a data controller and to publish its registration details. Details of the Company’s VERİBİS registration [insert VERİBİS registration number and link] are available through [insert link or contact]. As the Company is not established in Türkiye, Article 16 of the KVKK requires the Company to appoint a Data Controller Representative in Türkiye as part of its VERBİS registration; this requirement applies regardless of whether Sensitive Data is processed. The contact details of the Company’s Data Controller Representative in Türkiye will be made available through this Policy or other appropriate communication channels.

We will address your request in accordance with Applicable Laws and ordinarily free of charge, except where a fee or limitation is permitted by law. We may verify your identity before acting. If unsatisfied, you may lodge a complaint with a competent privacy, cybersecurity or regulatory authority or approach another competent regulator, court or forum available under Applicable Laws.

23. GOVERNING LAW AND JURISDICTION

This Policy and disputes relating to the Platform, Services, Coins, subscriptions, AI Outputs, advertisements, Third-Party Services or the relationship between you and the Company shall be governed by the laws of India for contractual and general legal matters, without regard to conflict-of-law principles. Nothing in this Policy limits non-waivable rights available under applicable privacy, cybersecurity, telecommunications, consumer-protection or related laws.

Subject to any non-waivable statutory, consumer, data-protection, cybersecurity, telecommunications or regulatory remedy available under Applicable Laws, disputes relating to this Policy shall be subject to the jurisdiction provisions in the Terms and Conditions. Nothing in this Policy limits non-waivable rights available under applicable privacy, cybersecurity, or telecommunications laws. Where specific local requirements, such as those detailed in the Egypt, Turkey or Saudi Arabia Annexures, mandate a particular legal outcome or process, those requirements take precedence.

It is pertinent to mention that the Annexures for the “Saudi Arabia”, “Turkey” and “Egypt” are supplemental to the main Policy. They will be reviewed and updated separately, when such review or update is warranted as per the amendment in the statute or the regulations in the jurisdiction they pertain to.


ANNEXURE

SAUDI ARABIA-SPECIFIC DATA PROTECTION PROVISIONS

To be appended to and read together with the Company’s Middle East Privacy Policy

Recitals

This Annexure supplements, and does not replace, the Company’s Middle East Privacy Policy (the “Main Policy”), and applies in addition to it wherever the Company processes personal data of Data Subjects located in the Kingdom of Saudi Arabia. In the event of any conflict between this Annexure and the Main Policy insofar as it concerns Saudi Data Subjects, this Annexure shall prevail. Terms defined in the Main Policy carry the same meaning here unless the context otherwise requires.

1. Definitions

In this Annex, unless the context otherwise requires:

a) “Kingdom” or “KSA” means the Kingdom of Saudi Arabia, including its territory and jurisdiction, as recognized under the applicable laws and regulations

b) PDPL” means the Personal Data Protection Law of the Kingdom (Royal Decree No. M/19, 9/2/1443H / 16 September 2021, as amended by Royal Decree No. M/148, 5/9/1444H / 27 March 2023), together with its Implementing Regulations and the Regulation on Personal Data Transfer Outside the Kingdom (the ‘Transfer Regulation’), each issued by SDAIA and fully in force since 14 September 2024, and any binding SDAIA rules or guidance thereunder, including the Rules Governing the National Register of Controllers.

c) “SDAIA” means the Saudi Data and Artificial Intelligence Authority, the Competent Authority for the PDPL. References to SDAIA include the National Data Management Office or any successor Competent Authority to which SDAIA’s functions may be transferred.

d) “National Data Governance Platform” or “NDGP” means SDAIA’s electronic platform for controller registration, breach reporting, Data Protection Officer notification, and related regulatory filings.

e) “Saudi Data Subjects” means individuals whose Personal Data are processed in KSA or in connection with Saudi Processing, including Saudi citizens, residents, and visitors.

f) “Saudi Processing” means processing of personal data to which the PDPL applies.

g) “Sensitive Data” for KSA means Personal Data revealing racial or ethnic origin; religious, intellectual, or political belief; data relating to security, criminal convictions, and offences; biometric or genetic data processed for the purpose of identifying a person; health data; and data indicating that one or both of an individual’s parents are unknown.

2. Saudi-Specific Legal Bases for Processing

Personal data of a Saudi Data Subject may not be processed, nor the purpose of processing changed, without the Data Subject’s explicit consent (given by the Data Subject or, where they lack legal capacity, their legal guardian, per the Implementing Regulations), except as set out below. Consent may not be made a condition of providing a service or benefit unless the benefit is directly related to the processing for which consent is sought (Article 7, PDPL), and may be withdrawn at any time (Article 5(2), PDPL).

Personal data may be processed without consent only where one of the following conditions is met under Article 6, PDPL:

(i) the processing serves the Data Subject’s actual interests where communicating with them is impossible or difficult (Article 6(1));

(ii) it is carried out under another law or in implementation of a prior agreement to which the Data Subject is a party (Article 6(2));

(iii) the Company is a public entity and the processing is required for security purposes or to satisfy judicial requirements (Article 6(3)); or

(iv) the processing is necessary for the Company’s legitimate interest, provided this does not prejudice the Data Subject’s rights and interests and no Sensitive Data is processed (Article 6(4)).

Where the Company collects Personal Data from a source other than the Data Subject, or processes it for a purpose other than that for which it was collected, it relies on one of the grounds in Article 10, PDPL: (a) the Data Subject’s consent; (b) data that is publicly available or collected from a publicly available source; (c) processing necessary to protect public health or safety, or the life or health of specific individuals; (d) data that will not be recorded or stored in identifiable form; or (e) circumstances where complying with the direct-collection or purpose-limitation requirement would itself harm the Data Subject or their vital interests.

The Company treats ‘legitimate interest’ under Article 6(4) and Article 10, PDPL as a narrow exception to the general consent requirement, not a standalone ground of equal standing to consent as under Article 6(1)(f) GDPR; it is unavailable for Sensitive Data and relied upon only following a documented assessment balancing the Company’s interest against the Data Subject’s rights.

Further, the Company acknowledges that Sensitive Data may not be used for marketing purposes under any circumstances as per Article 26 of the PDPL, and the unauthorized disclosure or publication of Sensitive Data carries enhanced administrative and criminal exposure under Article 35 of the PDPL. Voice Soul’s voice-to-voice translation and image-based features process voice and images to generate a translation or answer, not to identify you. This does not currently trigger the Sensitive Data classification under Article 1(11), PDPL, which applies only to biometric data processed for the purpose of identifying an individual. If we introduce a feature that identifies a Saudi Data Subject from their voice or face, we will treat that processing as Sensitive Data, obtain explicit consent, apply heightened safeguards, and, where processing is continuous or large-scale, conduct a Data Protection Impact Assessment before enabling it.

The Implementing Regulations, issued pursuant to Article 5(1) of the PDPL, define “explicit consent” as direct and unambiguous consent given by the Data Subject in a manner clearly indicating acceptance of the processing in a way that cannot be interpreted otherwise. Explicit consent is required for the processing of Sensitive Data and, under the Implementing Regulations, for decisions based solely on automated processing.

The basis relied on for each processing purpose in respect of Saudi Data Subjects is set out below:

Sr. No.

Purpose

Saudi PDPL Basis

a)

f) To create, authenticate, maintain, secure and administer your account and provide account-related support.

Consent (Article 5)

b)

g) To provide and maintain the Services, including voice-to-voice translation, image-to-voice functionality, contextual image assistance, language mapping, location-based language configuration and customer support.

Article 6(2); explicit consent (Article 5(1)) for AI-specific features involving Sensitive Data

c)

To process Content, prompts, voice recordings, images, metadata and other inputs through AI, translation, speech, computer-vision and related third-party systems to generate AI Outputs on a one-time and transient basis.

Explicit consent (Article 5(1)), given classification as Sensitive Data (Article 1(11))

d)

To allocate, deduct, verify and administer Coins, Usage Charges, Premium Membership Plans, subscriptions, Offer Wall rewards, refunds, disputes and account balances.

Consent (Article 5)

e)

To display, measure, attribute and manage advertisements, rewarded advertisements, Offer Wall tasks, surveys, games, promotions and other monetization features, subject to your choices and Applicable Laws.

Consent (Article 5)

f)

To detect, prevent, investigate, monitor and respond to fraud, abuse, spam, impersonation, payment fraud, Offer Wall manipulation, security incidents, suspicious activity, malware, cyber-risk, infrastructure threats, account compromise, sanctions risk and other prohibited conduct.

Legitimate interest (Article 6(4)), non-Sensitive Data only; otherwise consent

g)

To improve, maintain, test, monitor, debug and develop the Platform, Services, safety systems, language quality, translation accuracy, performance and user experience, using minimized or de-identified data where reasonably practicable.

Legitimate interest (Article 6(4)), non-Sensitive Data only; otherwise consent

h)

h) To communicate with you about account activity, service updates, security alerts, support, policy changes, subscriptions, rewards, offers, marketing communications and administrative matters, subject to your choices.

Article 6(2) for service updates; consent (Article 5) for marketing

i)

To comply with Applicable Laws, court orders, governmental directions, regulatory requirements, lawful interception obligations, national-security obligations, sanctions compliance, cybersecurity reporting, audit, taxation, accounting, record-keeping and law-enforcement requests.

Article 6(2) (pursuant to another law)

j)

i) To enforce the Terms and Conditions, this Policy and other applicable terms, and to establish, exercise or defend legal claims.

Legitimate interest (Article 6(4))

k)

j) To create aggregated, anonymized or de-identified analytics, statistics and service-improvement insights that do not reasonably identify an individual.

Legitimate interest (Article 6(4)); outside PDPL scope once anonymized

3. Processor Obligations

The Company will only select Processors that provide the necessary guarantees to implement the PDPL and its Regulations, and will monitor their compliance, without prejudice to the Company’s own responsibilities toward the Data Subject and SDAIA. Data processing agreements with Processors will address the matters required under the Implementing Regulations, including any subsequent sub-processor contracts.

4. Mechanism for Transfer of Personal Data Outside the Kingdom

The Company may transfer or disclose Personal Data outside the Kingdom only where permitted under the PDPL, its Implementing Regulations, the Regulation on Personal Data Transfer Outside the Kingdom (the “Transfer Regulation”), and any applicable guidance from the Competent Authority, and only where necessary for a lawful purpose under Article 29, PDPL, including to perform an obligation under an international agreement to which the Kingdom is a party, to serve the interests of the Kingdom, to perform or conclude a contract to which the Data Subject is a party, or for any other purpose permitted under the PDPL, its Implementing Regulations or the Transfer Regulation. The Company will ensure that: (i) the transfer does not prejudice the national security, vital interests or other significant interests of the Kingdom except where otherwise permitted; (ii) the data transferred is limited to the minimum necessary and complies with data minimization; (iii) the recipient jurisdiction provides an adequate level of protection as determined by the Competent Authority; and, (iv) as no adequacy list has yet been published, the Company implements appropriate safeguards recognized under the Transfer Regulation, including Standard Contractual Clauses, Binding Common Rules, approved certifications or codes of conduct, or any other recognized safeguard; (v) where required, it conducts and documents a transfer risk assessment, particularly for continuous or large-scale transfers of Sensitive Data, and implements measures to mitigate identified risks; (vi) the transfer does not adversely affect Data Subjects’ rights or reduce their level of protection under the PDPL; (vi) the Company maintains appropriate records of cross-border transfers and complies with applicable notification, documentation, registration and reporting obligations; and (vii) where a transfer relies on an exception including the Data Subject’s explicit consent, the Company ensures all conditions for that exception are satisfied, including informing the Data Subject of material risks and obtaining explicit, informed and documented consent where required.

Where the Company determines that the conditions permitting a transfer are no longer satisfied, or that the safeguards relied upon are no longer effective, it will suspend or cease the transfer without undue delay and take corrective measures necessary to ensure continued compliance with the PDPL, its Implementing Regulations, and the Transfer Regulation.

Exempted transfers: The Company may otherwise transfer or disclose Personal Data outside the Kingdom without the above safeguards only where the transfer (a) provides a direct benefit or service to the Data Subject without conflicting with their interests or expectations; (b) is non-recurring, limited in duration and Data Subjects, subject to Standard Contractual Clauses or an accredited recipient, and does not involve Sensitive Data; (c) is necessary for centralized operational processes (such as HR, billing or accounting) within the Company’s multinational group, subject to Binding Common Rules, Standard Contractual Clauses or an accredited recipient; or (d) is necessary for scientific research, limited to the minimum data required.

5. SDAIA’s Regulatory, Investigatory and Enforcement Powers

SDAIA, as Competent Authority and without prejudice to the Saudi Central Bank’s powers under Article 30(1), PDPL, is empowered under Article 30(4), PDPL to: (i) request documents and information from the Company; (ii) request other parties’ cooperation in its supervisory and enforcement functions; (iii) specify compliance-monitoring tools including the national register of Controllers; and (iv) provide Personal-Data-protection services through that register or other means, for a fee. SDAIA may delegate these duties under Article 30(5). Its appointed personnel have powers of control and inspection over PDPL violations, may seek criminal-investigation assistance, and may seize the means or tools used in a violation pending a decision, under Article 37, and SDAIA may extend its monitoring and enforcement tools to Controllers and Processors outside the Kingdom that process Saudi residents’ data, under Article 33(4). The Company will maintain a valid authorization mechanism and platform access to enable timely response to any SDAIA notification, investigation or indictment.

6. Controller Registration (National Data Governance Platform) and Local Representation

Under Article 30(4)(C), PDPL and the Rules Governing the National Register of Controllers, the Company will register as a Controller on SDAIA’s National Data Governance Platform where its main activity is based on Personal Data processing and collection, or where it processes Sensitive Data likely to entail a high risk to Data Subjects’ rights and freedoms (e.g. criminal data, genetic data, or racial or ethnic origin).

Registration is completed online, free of charge, through a designated authorized delegate. SDAIA will notify the Company at least thirty (30) days before its registration certificate expires, with a five (5) day grace period to submit a renewal request, and the certificate remains publicly accessible on the National Register for verification.

The Rules Governing the National Register of Controllers apply to Controllers established within the Kingdom. SDAIA has indicated separate registration rules for Controllers located outside the Kingdom, which will be issued in due course. Pending issuance, where the Company has no Kingdom establishment, it will appoint a Saudi-based representative for registration and regulatory-liaison purposes if and to the extent required by SDAIA, a role performing a regulatory point-of-contact function, without an independent statutory duty of expertise, independence, or reporting to the Company’s management.

The Saudi Representative shall:

(i) Act as the Company’s local point of contact for SDAIA and other competent authorities on PDPL matters;

(ii) Facilitate communications between the Company, SDAIA and Saudi Data Subjects regarding compliance;

(iii) Maintain records the Competent Authority requires it to hold or make available;

(iv) Assist the Company in responding to regulatory enquiries, inspections, investigations, audits, notices and enforcement actions;

(v) Support the Company’s Controller registration, regulatory filings, DPO notifications, breach notifications and other compliance requirements;

(vi) Promptly notify the Company of any communication or direction received from the Competent Authority or a Saudi Data Subject; and

(vii)Perform such other functions as may be prescribed under the PDPL, its Implementing Regulations, the Rules Governing the National Register of Controllers, or subsequent SDAIA guidance.

The appointment of a Saudi Representative does not transfer or diminish the Company’s responsibilities as Controller under the PDPL. The Company remains fully responsible for compliance with the PDPL, its Implementing Regulations, and all applicable obligations, and the appointment does not affect the Competent Authority’s ability to exercise its regulatory or enforcement powers against the Company.

7. Records of Processing Activities

Without prejudice to the Company’s destruction obligations under Article 18, PDPL, the Company will maintain records of its Saudi Processing activities, for the period required under the Implementing Regulations, available to SDAIA on request, containing at minimum: (i) the Company’s contact details; (ii) the purpose of processing; (iii) the categories of Data Subjects; (iv) any entity to which Personal Data has been or will be disclosed, including outside the Kingdom; and (v) the expected retention period under Article 31, PDPL.

8. Data Protection Officer

The Implementing Regulations, under Article 30(2), PDPL, identifies when the Company must appoint one or more Personal Data Protection Officers and set their responsibilities. Where appointed, the Officer is responsible for Personal Data protection within the Company, ensuring PDPL adherence, monitoring internal procedures, and receiving data-related requests, per the PDPL, its Implementing Regulations and SDAIA’s Rules for Appointing the Personal Data Protection Officer. The Officer may be a Company employee, an external service provider, or the Company’s appointed representative, and their details will be submitted to SDAIA through the National Data Governance Platform and kept current.

9. Personal Data Breach Notification

The Company will notify SDAIA of any breach, damage or illegal access to a Saudi Data Subject’s Personal Data (Article 20(1), PDPL), and separately notify the affected Data Subject where the breach would cause damage or prejudice their rights (Article 20(2)), within the timeframe SDAIA has specified as seventy-two (72) hours of becoming aware. The Company will maintain records of all breaches, whether or not notifiable, a tested breach-response plan, and contractual obligations requiring Processors to notify the Company of any breach without undue delay.

10. Retention and Deletion

Where Personal Data of a Saudi Data Subject is no longer necessary for the purpose for which it was collected, the Company will, without undue delay, cease collecting it and destroy previously collected data (Article 11(4), PDPL), save that it may retain data after that purpose ceases provided it no longer contains anything that could identify the Data Subject (Article 18(1), PDPL and Implementing Regulations).

The Company shall retain Personal Data beyond the purpose of its collection only where: (a) there is a legal basis for retaining it for a specific period, in which case the data shall be destroyed upon the later of the lapse of that period or the fulfilment of the collection purpose; or (b) the data is closely related to a matter pending before a judicial authority and its retention is required for that purpose, in which case the data shall be destroyed once the judicial procedures conclude as per Article 18(2) of the PDPL.

Upon destruction, the Company shall render the Personal Data unreadable and irretrievable across all systems, including backups, and shall notify any party with whom the data was shared and request corresponding destruction.

11. Cookies and Online Tracking

The PDPL does not contain standalone cookie-specific provisions. Cookies and similar tracking technologies that process Personal Data of Saudi Data Subjects fall within the PDPL’s broad definition of “Processing” (Article 1(5)) and are governed by the PDPL’s general consent and transparency requirements, this Policy and any guidance issued by the Competent Authority. Consistent with the PDPL, the Company will: (i) use cookies only for specified, explicit and legitimate purposes and collect only what is necessary and proportionate; (ii) obtain the Data Subject’s freely given, specific, informed consent (withdrawable at any time, without affecting the lawfulness of prior processing) before placing or accessing non-essential cookies, other than strictly necessary cookies used for operation, security, authentication, fraud prevention or network management, which may be used without prior consent where permitted; (iii) provide clear, accessible information on the types of cookies used, their purposes and retention periods, whether third parties may access them, and how preferences may be managed or withdrawn, through a cookie management mechanism available at any time; (iv) protect Personal Data collected through cookies with appropriate technical and organisational measures; and (v) ensure any disclosure or transfer of such data to third parties or outside the Kingdom complies with this Policy, the PDPL, the Implementing Regulations and the Transfer Regulation. Nothing in this clause limits Data Subjects’ rights under the PDPL, including to be informed, access, correct, complete, delete or withdraw consent regarding Personal Data processed through cookies.

12. Data Subject Rights and Complaints

Under Article 4, PDPL, Saudi Data Subjects have the right to: (i) be informed of the legal basis and purpose of collection of their Personal Data; (ii) access their Personal Data, subject to the restrictions in Articles 9 and 16(1)-(6); (iii) request a copy of their Personal Data in a readable and clear format; (iv) request correction, completion or updating of their Personal Data; (v) request destruction of their Personal Data when no longer needed, without prejudice to the Company’s retention obligations; (vi) withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 5(2)); (vi) lodge a complaint with SDAIA (Article 34); and (vii) apply to the competent court for proportionate compensation for material or moral damage resulting from a violation of the PDPL or its Regulations (Article 40).

The Company shall respond to a Data Subject request within the period and by the method set out in the Implementing Regulations as per Article 21 of the PDPL, currently thirty (30) days from receipt, extendable once by a further thirty (30) days with notice and justification to the Data Subject before expiry of the initial period.

Saudi Data Subjects should first raise a request or complaint with the Controller. If dissatisfied with the Company’s handling of a complaint, or if no response is received within the timeframe given above, a Data Subject may lodge a complaint with SDAIA, within ninety (90) days of becoming aware of the relevant matter as specified in the Implementing Regulations, or pursue other judicial remedies available under Saudi law, including a compensation claim under Article 40 of the PDPL.

13. Children and Minors

The PDPL does not fix a numerical age of majority for data protection purposes. Article 5(1) provides that the Implementing Regulations set out the terms for obtaining a legal guardian’s consent where a Data Subject lacks legal capacity, and Article 1(6) recognizes a legal guardian as a party from whom Personal Data may be collected on the Data Subject’s behalf. Consistent with the Main Policy’s general age threshold (18, or the local age of majority, if higher), the Company treats Saudi Data Subjects under eighteen (18) as requiring parental or guardian consent, and will not knowingly collect or process Saudi-based minors’ Personal Data without it. Before relying on guardian consent, the Company will take reasonable measures to verify the guardian’s authority, ensure their exercise of rights does not harm the minor’s interests, and enable the minor to exercise their own rights under the PDPL. Such measures may include requesting government-issued identification evidencing the guardian’s relationship to the minor, cross-checking the guardian’s details against the minor’s registered account information, and, where the minor reaches the age of majority, providing a means for the minor to review, confirm, or withdraw any consent previously given on their behalf.

14. Data Protection Impact Assessments

The Company will conduct a Data Protection Impact Assessment of its Saudi Processing for any product or service, based on the nature of its activities, under the PDPL and Implementing Regulations, which specify triggering scenarios including: (i) continuous or large-scale processing of data of Data Subjects who lack legal capacity; (ii) processing requiring continuous monitoring; (iii) automated-decision processing; or (iv) processing otherwise likely to negatively impact Data Subjects’ privacy, including large-scale processing of Sensitive Data, biometric data or voice recordings. A copy of the assessment will be shared with any Processor engaged in the corresponding processing.


ANNEXURE

Egypt-Specific Data Protection Provisions

(To be read together with, and form an integral part of, the Company’s Middle East Privacy Policy)

1. Introduction

a) This Annex applies where we process the Personal Data of individuals located in the Arab Republic of Egypt or where the processing is otherwise subject to the Egyptian Personal Data Protection Law No. 151 of 2020 (PDPL) and its Executive Regulations.

b) This Annex supplements our Privacy Policy and explains the additional rights, safeguards and obligations that apply to the processing of Personal Data in Egypt. If there is any inconsistency between the two insofar as PDPL-covered processing is concerned, this Annex prevails. Unless otherwise defined here, capitalized terms have the meanings assigned to them in the Privacy Policy.

2. Definitions

For the purposes of this Annex:

a) “PDPL” means the Egyptian Personal Data Protection Law No. 151 of 2020 and its Executive Regulations, together with any binding guidance issued by the Egyptian Personal Data Protection Centre (“PDPC”).

b) “PDPC” means the Egyptian Personal Data Protection Centre, the authority responsible for regulating and enforcing the PDPL.

c) “Egyptian Data Subject” means an individual whose Personal Data is processed in Egypt or whose Personal Data is otherwise subject to the PDPL.

d) “Egyptian Processing” means the collection, recording, storage, use, disclosure, transfer, deletion or any other processing of Personal Data that is subject to the PDPL.

e) “Transfer License” means a license issued by the PDPC authorizing the cross-border transfer, storage, remote access or other processing of Personal Data outside Egypt where required under Article 14 of the PDPL and the Executive Regulations.

f) “Transfer Impact Assessment (TIA)” means the documented assessment required before certain cross-border transfers to evaluate the risks associated with the transfer and the safeguards implemented to protect Personal Data.

g) “Egypt Representative” means the representative appointed by the Company in Egypt, as required under Article 4 and Article 5 of the PDPL because the Company is not established in Egypt and processes Personal Data of individuals located in Egypt, to act on the Company’s behalf in respect of Egyptian Processing.

3. When We Process Your Personal Data

We process Personal Data relating to Egyptian Data Subjects only where permitted under the PDPL and its Executive Regulations. Where required under Articles 2 and 6, PDPL, we will obtain your express, informed and freely given consent, which may be obtained electronically through account registration, feature activation, consent prompts, device permissions or other lawful electronic methods, before processing your Personal Data, and you may withdraw it at any time using the available account controls or by contacting us, unless we are required or permitted by law to continue processing.

Processing Based on Consent; Processing Without Consent

Where permitted under Article 6, PDPL, we may process your Personal Data without your consent if necessary to perform a contract with you, conclude a contract in your favour, or bring or defend a legal claim; to comply with a legal obligation or an order issued by a competent investigative authority or judicial ruling; or to exercise our legitimate rights, provided this does not conflict with your fundamental rights and freedoms. Where none of these grounds applies, we will obtain your express consent before processing.

The basis relied on for each processing purpose in respect of Egyptian Data Subjects is set out below:

Sr. No.

Purpose

Egyptian PDPL Basis (Article 6)

a

k) To create, authenticate, maintain, secure and administer your account and provide account-related support.

Performance of a contractual obligation

b

l) To provide and maintain the Services, including voice-to-voice translation, image-to-voice functionality, contextual image assistance, language mapping, location-based language configuration and customer support.

Performance of a contractual obligation; consent for AI-specific features

c

To process Content, prompts, voice recordings, images, metadata and other inputs through AI, translation, speech, computer-vision and related third-party systems to generate AI Outputs on a one-time and transient basis.

Consent for the AI feature; not currently classified as Sensitive Data, since this processing generates translations and answers rather than identifying you or any Data Subject

d

To allocate, deduct, verify and administer Coins, Usage Charges, Premium Membership Plans, subscriptions, Offer Wall rewards, refunds, disputes and account balances.

Performance of a contractual obligation

e

To display, measure, attribute and manage advertisements, rewarded advertisements, Offer Wall tasks, surveys, games, promotions and other monetization features, subject to your choices and Applicable Laws.

Consent

f

To detect, prevent, investigate, monitor and respond to fraud, abuse, spam, impersonation, payment fraud, Offer Wall manipulation, security incidents, suspicious activity, malware, cyber-risk, infrastructure threats, account compromise, sanctions risk and other prohibited conduct.

Exercise of the Controller’s legitimate rights (4th ground)

g

To improve, maintain, test, monitor, debug and develop the Platform, Services, safety systems, language quality, translation accuracy, performance and user experience, using minimized or de-identified data where reasonably practicable.

Exercise of the Controller’s legitimate rights

h

m) To communicate with you about account activity, service updates, security alerts, support, policy changes, subscriptions, rewards, offers, marketing communications and administrative matters, subject to your choices.

Performance of a contractual obligation for updates; consent for marketing

i

To comply with Applicable Laws, court orders, governmental directions, regulatory requirements, lawful interception obligations, national-security obligations, sanctions compliance, cybersecurity reporting, audit, taxation, accounting, record-keeping and law-enforcement requests.

Legal obligation or order from investigative/judicial authority

j

n) To enforce the Terms and Conditions, this Policy and other applicable terms, and to establish, exercise or defend legal claims.

Initiation or defense of legal proceedings

k

o) To create aggregated, anonymized or de-identified analytics, statistics and service-improvement insights that do not reasonably identify an individual.

Exercise of the Controller’s legitimate rights; outside PDPL scope once anonymized

4. Sensitive Personal Data

a) Certain categories of Personal Data receive enhanced protection under Article 1 of the PDPL. Sensitive Personal Data means data revealing mental, psychological, physical or genetic health; biometric data; financial data; religious beliefs; political opinions; or security status. Data relating to a child is deemed Sensitive Personal Data in all cases, regardless of its content.

b) We do not collect, transfer, store, retain, process or make available Sensitive Personal Data without a license from the Center under Article 12 and Article 19, and, except where otherwise permitted by law, without your written and explicit consent.

c) Where a child’s Sensitive Personal Data is processed: if the child is under fifteen (15), we obtain explicit written consent (paper or electronic) from the parent or legal guardian before collecting or processing the data, specifying its time scope and withdrawable at any time; if the child is fifteen (15) or older but under eighteen (18), consent may be given by the child or by their parent or legal guardian, as applicable.

4.1. Voice, Image and Biometric Data

a) Some features of our Platform use artificial intelligence to process voice recordings, photographs, facial images or other visual or audio inputs.

b) Where such processing involves biometric data or other Sensitive Personal Data regulated under the PDPL, we will obtain your explicit consent before processing begins, presented separately from other permissions wherever required under the PDPL, after clearly explaining the specific AI feature requiring the information, why it is required, the categories of Personal Data involved, and how it will be used. This applies only where a feature is specifically designed to identify you from your voice or image; Voice Soul’s current translation and Image to your Voice / Visual Story Converser features are not designed to do this.

c) Where an AI feature is optional, you may choose not to provide your consent. Refusing consent for an optional feature will not prevent you from accessing other core Platform services unless the relevant processing is strictly necessary to provide those services.

5. PDPC Operating License

a) We will obtain and maintain a license or permit from the Personal Data Protection Center (“Center”) authorizing us to collect, store, and process personal data as a controller and/or processor, before commencing such processing, in accordance with Articles 4 and 5 of the PDPL and the Executive Regulations.

b) Our application for this license or permit will include, under Articles 21 and 35, Executive Regulations: (i) our commercial registration details, registered address, legal representative, organizational structure and contact information; (ii) the category of license or permit applied for; (iii) the nature and volume of Personal Data we intend to process; (iv) our proposed data retention periods; (v) the mechanism for obtaining data subjects’ consent and the means by which they may exercise their rights under Article 2, PDPL; (vi) the security procedures and technical measures we will apply, consistent with Center standards; (vii) the identity of our Data Protection Officer and confirmation of their independence; and (viii) technical information on our processing infrastructure, including relevant certificates and accreditations.

c) A license authorizes ongoing processing activities for a period of three (3) years, renewable. A permit authorizes processing for a specific, time-bound purpose for a period not exceeding one (1) year. We will apply to renew a license no less than three (3) months before its expiry, and a permit no less than one (1) month before its expiry, in accordance with the Executive Regulations.

d) We will not commence, or will suspend, any processing activity requiring a license or permit under the PDPL until that license or permit has been obtained.

e) Where our processing involves Sensitive Personal Data, we will obtain a separate license for the processing of Sensitive Personal Data, in accordance with Article 12 of the PDPL and the Executive Regulations, in addition to the Operating License.

6. Transferring Personal Data Outside Egypt

a) We may transfer, store, access or process your personal data outside Egypt only where permitted under the PDPL and its Executive Regulations.

b) Where the PDPL requires a license before Personal Data may be transferred outside Egypt or accessed from outside Egypt, we will obtain the necessary Transfer License from the PDPC before carrying out the transfer.

c) For the purposes of this Annex, a restricted transfer includes, where applicable under the PDPL and its Executive Regulations: (i) transferring Personal Data outside Egypt; (ii) allowing remote access to Personal Data from outside Egypt; (iii) storing Personal Data on servers located outside Egypt; or (iv) any other cross-border processing activity requiring prior approval under the PDPL.

d) We will not rely solely on contractual arrangements or other international transfer mechanisms where the PDPL requires a Transfer License.

6.1. Transfer License Applications

a) Where a Transfer License is required, our application to the PDPC will include the information and supporting documents required under the PDPL and its Executive Regulations, including: (i) the purpose of the proposed transfer; (ii) the categories of Personal Data involved; (iii) the recipient of the Personal Data; (iv) the safeguards implemented to protect the transferred data; and (v) a Transfer Impact Assessment where required.

b) Unless otherwise permitted under the Executive Regulations, we will not proceed with a restricted transfer until the applicable licensing requirements have been satisfied.

7. Transfer Impact Assessments

a) Before carrying out a restricted transfer that requires regulatory approval, we will conduct and document a Transfer Impact Assessment (TIA) where required under the PDPL and its Executive Regulations.

b) A TIA helps us evaluate whether Personal Data transferred outside Egypt will continue to receive an appropriate level of protection.

c) Where applicable, a TIA will consider the categories and volume of Personal Data being transferred, the purpose of the transfer and why it is necessary, the identity and legal status of the parties involved, the legal and regulatory framework of the recipient country (including laws relating to government access, surveillance and national security), the contractual, organizational and technical safeguards protecting the transferred data, and any remaining risks to the rights and freedoms of Egyptian Data Subjects together with additional safeguards implemented to reduce those risks.

d) We will review and update a TIA whenever there is a material change to the transfer, the recipient country, the processing activities or any legal requirement that may affect the level of protection provided.

8. Representative in Egypt

a) As the Company is not established in Egypt and processes Personal Data of individuals located in Egypt, Article 4 and Article 5 of the PDPL require us to appoint a representative in Egypt; this requirement applies regardless of whether Sensitive Data is processed. We will designate an Egypt Representative to act on our behalf.

b) The Egypt Representative may serve as a contact point for the PDPC and for Egyptian Data Subjects, a representative for PDPL-compliance matters, and a liaison for communications relating to our processing of Personal Data in Egypt.

c) Where required by law, the contact details of our Egypt Representative will be made available through our Privacy Policy or other appropriate communication channels.

9. Data Localization

a) Certain categories of Personal Data may be subject to data localization or local hosting requirements under the PDPL, its Executive Regulations or other applicable Egyptian sector-specific laws.

b) Where such requirements apply, we will take appropriate measures to comply, which may include storing Personal Data on servers located within Egypt, limiting remote access from outside Egypt, implementing regional hosting arrangements, restricting cross-border transfers, applying technical and organizational safeguards, and adopting any additional measures required by the PDPC or other competent Egyptian authorities.

c) Where localization requirements apply only to specific categories of Personal Data or regulated services, we will apply those requirements only to the extent required by applicable law.

10. Personal Data Breaches

a) We maintain appropriate technical and organizational measures to protect your Personal Data from unauthorized access, disclosure, alteration, loss or destruction. However, no security measure can guarantee absolute protection.

b) If we become aware of a Personal Data breach, we will respond promptly and take appropriate steps to contain, investigate and mitigate the incident.

c) Where required under the PDPL and its Executive Regulations, we will notify the PDPC within the prescribed timeframe, including where notification is required within seventy-two (72) hours of becoming aware of the breach.

d) Where required under the PDPL, we will notify you within three (3) working days from the date we notify the Center of the breach, in all cases, and inform you of the actions taken.

e) Our breach notification, where required, may include the nature of the breach, the categories and approximate number of affected individuals and records, the likely consequences of the breach, the measures taken or proposed to address it, and the contact details of our Data Protection Officer or Egypt Representative, where applicable.

11. How Long We Keep Your Personal Data

a) We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, taking into account legal and regulatory requirements, contractual obligations, dispute resolution, fraud prevention, cybersecurity investigations and other legitimate operational requirements, unless a longer period is required or permitted under the PDPL, its Executive Regulations or other applicable laws.

b) When Personal Data is no longer required, we will securely delete, anonymize or de-identify it in accordance with our retention practices and applicable legal requirements.

c) Where permitted under the PDPL, we may retain Personal Data for longer periods for legal proceedings, regulatory compliance, public interest archiving, or scientific, historical or statistical purposes, provided appropriate safeguards are implemented.

12. Cookies and Similar Technologies

a) Our Platform may use cookies, pixels, software development kits (SDKs), local storage and similar technologies to improve functionality, enhance security, analyse Platform performance and personalise your experience.

b) Where required under the PDPL and its Executive Regulations, we will obtain your prior, informed and freely given consent before placing or accessing non-essential cookies or similar technologies on your device.

c) Strictly necessary cookies that are essential for providing the services you request may be used without additional consent where permitted by law.

d) Where available, you may manage your cookie preferences through our cookie management tool or your browser settings. You may also withdraw your consent at any time, although doing so may affect the availability or functionality of certain features.

13. PDPL Compliance

a) We are committed to complying with the PDPL and its Executive Regulations, including any applicable implementation deadlines and regulatory requirements.

b) Where additional licenses, registrations, approvals or technical measures are required under the PDPL before we may lawfully process certain categories of Personal Data or carry out specific processing activities, we will take reasonable steps to obtain or implement them before commencing the relevant processing.

c) If a required approval, license or regulatory measure is not available by the applicable legal deadline, we may temporarily suspend the relevant processing activity or restrict the affected feature until compliance has been achieved.

d) Where reasonably practicable, we will continue to provide unaffected Platform features while the restricted processing remains suspended.

14. Your Right to Make a Complaint

a) If you have questions or concerns about how we process your Personal Data, we encourage you to contact us first so that we can investigate and respond to your concerns.

b) Where applicable, you may also contact our Data Protection Officer or Egypt Representative using the contact details provided in the Privacy Policy.

c) If you believe that your rights under the PDPL have been violated, you may submit a complaint to the PDPC or any other competent authority authorized under Egyptian law.

d) Submitting a complaint to us does not affect any rights or remedies available to you under the PDPL.

15. Governing Law

a) This Annex forms part of, and should be read together with, our Privacy Policy, and the processing of Personal Data to which it applies is governed by the PDPL, its Executive Regulations and other applicable laws of the Arab Republic of Egypt.

b) Nothing in this Annex limits or excludes any non-waivable rights, remedies or protections available to Egyptian Data Subjects under the PDPL or other applicable laws.

c) Nothing in this Annex limits the powers of the PDPC or any other competent authority responsible for enforcing the PDPL.

d) Any contractual disputes relating to this Annex shall be governed by the dispute resolution provisions set out in the Company’s Terms and Conditions, unless mandatory provisions of Egyptian law require otherwise or confer jurisdiction upon the competent courts or authorities of the Arab Republic of Egypt.

16. Contact Information

a) If you have any questions about this Annex or how we process your Personal Data in Egypt, or if you wish to exercise your rights under the PDPL, you may contact us using the contact details provided in the Contact section of our Privacy Policy.

b) Where required under the PDPL or its Executive Regulations, you may also contact our designated Data Protection Officer or Egypt Representative using the contact details published in the Privacy Policy.

c) Please provide sufficient information to help us identify your request. To protect your privacy and security, we may request additional information to verify your identity before responding.

17. Changes to this Annex

a) We may update this Annex from time to time to reflect changes in applicable laws, regulatory guidance, our processing activities or our services.

b) Where required under the PDPL or its Executive Regulations, we will notify you of material changes using appropriate communication methods, including through our Platform or other reasonable means.

c) The latest version of this Annex will always be available together with our Privacy Policy.

Egypt Representative

Name: [insert full legal name]

Address: [insert representative address]

E-mail: [insert email address]

Phone: [insert phone number, if applicable]

Registered Data Protection Officer

Name: [insert full legal name]

Address: [insert representative address]

E-mail: [insert email address]

Phone: [insert phone number, if applicable]


ANNEXURE

TURKEY-SPECIFIC DATA PROTECTION PROVISIONS

(To be appended to and read together with the Company’s GDPR-Compliant Middle East Privacy Policy)

This Annexure supplements, and does not replace, the Company’s Middle East Privacy Policy (the “Main Policy”), and applies in addition to it wherever the Company processes Personal Data of Data Subjects located in the Republic of Turkey. In the event of any conflict between this Annexure and the Main Policy insofar as it concerns Turkish Data Subjects, this Annexure shall prevail. Terms defined in the Main Policy carry the same meaning here unless the context otherwise requires.

1. Definitions

In this Annex, unless the context otherwise requires:

· “KVKK” or “LPPD” means the Law on the Protection of Personal Data No. 6698, together with applicable secondary legislation, Board decisions, and guidance issued by the Turkish Personal Data Protection Authority.

· “Turkish Data Protection Authority” means the Personal Data Protection Authority established under Turkish law.

· “VERBIS” means the Data Controllers’ Registry Information System maintained under Turkish law.

· “Turkish Data Subjects” means individuals whose Personal Data are processed in Turkey or in connection with Turkish processing activities.

· “Turkish Processing” means processing of Personal Data to which Turkish law applies under this Annex.

2. Turkey-Specific Legal Bases for Processing

In respect of Data Subjects in Turkey, the Company relies on the processing conditions under Article 5(2), KVKK. Where none are satisfied, processing proceeds only on the Data Subject’s explicit consent, freely given, informed and specific to the purpose. The Company applies the “legitimate interest” ground under Article 5(2)(f) narrowly, not as a default fallback ground in the manner permitted under Article 6(1)(f) GDPR.

Personal Data may be processed by the Data Controller without seeking the Data Subject’s explicit consent only where: (i) it is expressly provided for by law; (ii) it is necessary for the protection of life or physical integrity of the person or another person who is unable to give consent due to physical disability or whose consent is not legally valid; (iii) processing of Personal Data of the parties to a contract is necessary and directly related to the establishment or performance of the contract; (iv) it is necessary for compliance with a legal obligation to which the Data Controller is subject; (v) the Personal Data has been made public by the Data Subject; (vi) data processing is necessary for the establishment, exercise or protection of a right; or (vii) processing is necessary for the Data Controller’s legitimate interests, provided this does not violate the Data Subject’s fundamental rights and freedoms.

The basis relied on for each processing purpose in respect of Turkish Data Subjects is set out below:

Sr. No.

Purpose

KVKK Basis

a

To create, authenticate, maintain, secure and administer your account and provide account-related support.

Contract necessity (Article 5(2)(c))

b

To provide and maintain the Services, including voice-to-voice translation, image-to-voice functionality, contextual image assistance, language mapping, location-based language configuration and customer support.

Contract necessity (Article 5(2)(c)); explicit consent (Article 6) for AI features

c

To process Content, prompts, voice recordings, images, metadata and other inputs through AI, translation, speech, computer-vision and related third-party systems to generate AI Outputs on a one-time and transient basis.

Article 6 Contract necessity (Article 5(2)(c)); not currently classified as special-category data, since this processing generates translations and answers rather than identifying you

d

To allocate, deduct, verify and administer Coins, Usage Charges, Premium Membership Plans, subscriptions, Offer Wall rewards, refunds, disputes and account balances.

Contract necessity (Article 5(2)(c))

e

To display, measure, attribute and manage advertisements, rewarded advertisements, Offer Wall tasks, surveys, games, promotions and other monetization features, subject to your choices and Applicable Laws.

Consent (Article 5(1))

f

To detect, prevent, investigate, monitor and respond to fraud, abuse, spam, impersonation, payment fraud, Offer Wall manipulation, security incidents, suspicious activity, malware, cyber-risk, infrastructure threats, account compromise, sanctions risk and other prohibited conduct.

Legitimate interest (Article 5(2)(f))

g

To improve, maintain, test, monitor, debug and develop the Platform, Services, safety systems, language quality, translation accuracy, performance and user experience, using minimized or de-identified data where reasonably practicable.

Legitimate interest (Article 5(2)(f))

h

To communicate with you about account activity, service updates, security alerts, support, policy changes, subscriptions, rewards, offers, marketing communications and administrative matters, subject to your choices.

Contract necessity (Article 5(2)(c)) for updates; consent (Article 5(1)) for marketing

i

To comply with Applicable Laws, court orders, governmental directions, regulatory requirements, lawful interception obligations, national-security obligations, sanctions compliance, cybersecurity reporting, audit, taxation, accounting, record-keeping and law-enforcement requests.

Legal obligation (Article 5(2)(ç))

j

To enforce the Terms and Conditions, this Policy and other applicable terms, and to establish, exercise or defend legal claims.

Establishment, exercise or protection of a right (Article 5(2)(e))

k

To create aggregated, anonymized or de-identified analytics, statistics and service-improvement insights that do not reasonably identify an individual.

Legitimate interest (Article 5(2)(f))

3. Special Categories of Personal Data

For the Republic of Turkey, ‘Special Categories of Personal Data’, as provided in conditions as enumerated in Article 6(3) of the KVKK shall additionally include race and ethnic origin, political opinion, philosophical belief, religion, sect or other belief, appearance and dress, membership of associations, foundations or trade unions, and criminal conviction and security measures data, in addition to health, sexual life, biometric and genetic data.

Personal data concerning health and sexual life may only be processed, without the Data Subject’s explicit consent, by persons subject to a secrecy obligation or competent public institutions and organizations, for the protection of public health, preventive medicine, medical diagnosis, treatment and nursing services, or the planning, management and financing of health-care services.

Processing special categories of Personal Data by the Data Controller is permitted only where: (i) the data subject has given explicit consent; (ii) it is expressly provided by law; (iii) it is necessary for the protection of life or physical integrity of the person or another person unable to give consent due to physical disability or whose consent is not legally valid; (iv) it relates to Personal Data made public by the Data Subject, and processing is consistent with the Data Subject’s intention to make it public; (v) it is necessary for the establishment, exercise or protection of a right; (vi) it is necessary for the protection of public health, preventive medicine, medical diagnosis, treatment and care services, or the planning, management and financing of health-care services, by persons subject to a legal duty of confidentiality or by competent public institutions; (vii) it is necessary for the fulfilment of legal obligations in employment, occupational health and safety, social security, social services, or social assistance; or (viii) it relates to current or former members and affiliates of foundations, associations and other non-profit organizations established for political, philosophical, religious or trade union purposes, or to individuals in regular contact with them, provided the processing complies with applicable legislation governing those organizations, is limited to their fields of activity, and does not involve disclosure to third parties.

4. Mechanism for Transfer of Personal Data Abroad

Transfers of Personal Data of Turkish Data Subjects outside Turkey shall require, as a threshold condition, that the underlying processing satisfy an applicable ground under Article 5 or Article 6 of the KVKK; a valid transfer mechanism under this Clause shall not, of itself, cure the absence of such a ground.

Subject to that threshold, such transfers shall be structured on a three-tiered hierarchy established under Article 9 of the KVKK:

· Tier 1 - Adequacy Decision: Where the Board has issued an adequacy decision covering the destination country, sector, or international organization, Personal Data may be transferred freely, without any additional safeguard, notification, or per-transfer Board approval. Adequacy decisions are published in the Official Gazette and re-assessed at least every four years.

· Tier 2 - Appropriate safeguards (in the absence of an adequacy decision), one of the following, each with a different approval/notification requirement under Article 9(4)-(5), KVKK: An ad hoc agreement (not classified as an international convention) between Turkish and foreign public institutions/organizations; binding corporate rules (“BCRs”) among group companies engaged in joint economic activity; the Board’s published standard contract, used without modification, requiring notification to the Authority within five (5) business days of signature only; or a written commitment letter containing adequate protection provisions.

· Tier 3 - Exceptional/incidental transfers: Where neither an adequacy decision nor an appropriate safeguard is available, transfer may occur only on an incidental basis (i.e., not regular, occurring once or a few times, not continuous, and not part of the Company’s ordinary course of business) and only where one of the following applies (Article 9(6), KVKK): The Data Subject has given explicit consent to the transfer, having been informed of the potential risks involved; the transfer is necessary for performance of a contract between the Data Subject and the Company, or for pre-contractual measures taken at the Data Subject’s request; the transfer is necessary for the establishment or performance of a contract between the Company and another person for the benefit of the Data Subject; the transfer is necessary for an overriding public interest; the transfer is necessary for the establishment, exercise, or protection of a right; the transfer is necessary to protect the life or physical integrity of a person who is unable to give consent; or the transfer is made from a publicly accessible registry, or a registry accessible to persons with a legitimate interest, subject to the access conditions of that registry.

· The Company shall ensure that the safeguards described above also apply to onward transfers of Personal Data already transferred abroad, and to transfers to international organizations (Article 9(8) KVKK).

5. Board’s Overriding Power to Restrain Transfer Despite Consent

Notwithstanding the Data Subject’s explicit consent or the existence of appropriate safeguards above, the Turkish Personal Data Protection Authority (“Authority”) retains an absolute statutory right under Article 9(9), KVKK to prohibit, restrict or immediately suspend any cross-border data transfer, exercisable at its sole discretion where it determines the destination country, the nature of the processing, or the transfer dynamics pose a serious risk of harm to Turkey’s national interests or to the Data Subject’s fundamental rights and freedoms. The Company explicitly acknowledges that no transfer mechanism utilized under this Agreement is self-executing or immune to such regulatory intervention. Consequently, upon receiving any official directive or suspension order from the Authority, the Company shall immediately cease the affected transfers and implement all necessary technical and administrative measures to secure the data within Turkey, without incurring liability to the counterparty for any resulting service disruptions.

6. Mandatory Data Controller Registry (VERBİS) and Local Data Controller Representative

Prior to processing Personal Data of Turkish Data Subjects, the Company (or, where established outside Turkey, its appointed Data Controller Representative, a Turkish legal entity or natural person) will register with VERBİS and maintain a Data Processing Inventory identifying the categories of Data Subjects and data, the purposes and legal bases of processing, and the technical and administrative measures adopted.

7. Personal Data Breach Notification

The Company will notify the Authority of any Personal Data breach concerning Turkish Data Subjects as soon as possible and in any event within seventy-two (72) hours of becoming aware, using the Authority’s prescribed Data Breach Notification Form together with reasons for any delay, regardless of the breach’s severity or risk profile. Affected Data Subjects will also be notified without undue delay, in the most appropriate manner, and the Company will maintain a Data Breach Response Plan naming a designated contact person.

8. Retention and deletion

Turkish Personal Data shall be retained only for as long as necessary for the relevant lawful purpose as mentioned in the application made to Data Controllers’ Registry Information System (VERBİS) under Article 16(3)(f), KVKK and any applicable retention obligation as stipulated by the Registry.

As a general rule, and independent of any cross-border transfer instrument, the Company shall erase, destroy, or anonymize Turkish Personal Data, ex officio or upon a Data Subject’s request, once the purpose for which it was processed no longer exists. Upon termination or expiry of the undertaking, submitted to the Personal Data Protection Board (the “Board”) and consequently approved by the Board, all transferred Personal Data and back-ups, the Data Controller shall delete, destroy, or anonymize the Personal Data in accordance with the Undertaking.

9. Cookies and online tracking

Where you are located in Türkiye, cookies and similar tracking technologies on our website and applications are governed by this Policy, which explains which cookies we use, which require your prior consent under Article 10, KVKK, and how to accept, reject or manage your preferences. Only cookies strictly necessary to deliver our services, or that you have specifically requested, may be used without consent. All others require your explicit consent, withdrawable at any time.

10. Data Subject Rights

Turkish Data Subjects have the right, under Article 11, KVKK, to request from the Company: confirmation of whether their Personal Data are processed; information as to how their Personal Data has been processed; to learn the purpose of processing and whether the Personal Data is used consistently with that purpose; to know the third parties, in Turkey or abroad, to whom their Personal Data is transferred; rectification of incomplete or inaccurate Personal Data; erasure or destruction of their Personal Data (Article 7); that any rectification, erasure or destruction be reported to third parties to whom the Personal Data was transferred; to object to a result produced against them solely through automated analysis of their Personal Data; and to claim compensation for damage arising from unlawful processing.

11. Complaints and remedies

Turkish Data Subjects must first submit a request to the Company under Article 13 KVKK to exercise their rights or raise concerns. The Company shall respond within thirty (30) days of the request. If the Company’s response is refused, found insufficient, or not provided within the specified period, the Data Subject may lodge a complaint with the Board within thirty (30) days of learning the Company’s response, or within sixty (60) days of the original request in any event. A complaint to the Board is inadmissible unless the Article 13 request has first been exhausted. Data Subjects may separately pursue judicial remedies, including a claim for compensation, under the general provisions of Turkish law.

12. Governing law

This Annex shall be construed in accordance with the KVKK/LPPD and mandatory Turkish regulatory guidance. Any inconsistency with Turkish mandatory law shall be resolved in favor of Turkish law for Turkish Processing.

Turkey Data Controller Representative:

Name: [insert full legal name]

Address: [insert representative address]

E-mail: [insert email address]

Phone: [insert phone number, if applicable]