Data Processing Addendum

Version 1.0 · September 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Datax Limited, a company incorporated in Hong Kong, trading as Subanana ("Processor", "we"), and the customer accepting it ("Controller", "you"), and applies where we process personal data on your behalf in providing the Subanana services (the "Services").

  1. Definitions

    "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Supervisory Authority" and "Personal Data Breach" have the meanings given in the EU General Data Protection Regulation (2016/679, "GDPR"). "Customer Data" means audio, video, transcripts, translations, summaries and related content you submit to the Services. "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor).

  2. Scope and roles

    You are the Controller of Personal Data contained in Customer Data; we are your Processor. This DPA applies to Processing of Personal Data subject to the GDPR, the UK GDPR, or comparable data-protection law. If you are yourself a processor for a third party, you warrant you are authorized to instruct us as set out here.

  3. Instructions

    We Process Personal Data only: (a) to provide, maintain and secure the Services; (b) as documented in the agreement and this DPA; and (c) on your further documented instructions given through the Services' controls. We will inform you if we consider an instruction infringes applicable data-protection law. We do not sell Personal Data, and we do not use Customer Data from business (team and enterprise) workspaces to train machine-learning models unless your organisation explicitly agrees.

  4. Details of processing

    The subject matter, duration, nature and purpose of Processing, and the categories of Data Subjects and Personal Data, are set out in Annex I.

  5. Confidentiality

    We ensure that persons authorised to Process Personal Data are bound by contractual or statutory confidentiality obligations, and that access is limited to what each role requires.

  6. Security

    We implement and maintain the technical and organisational measures described in Annex II, and may update them provided the overall level of protection is not reduced.

  7. Subprocessors

    You provide general authorisation for the subprocessors listed at subanana.com/legal/subprocessors, which states each subprocessor's role and location. We will update that page before engaging a new subprocessor. You may subscribe to change notices by emailing privacy@subanana.com. You may object on reasonable data-protection grounds within 14 days of notice; if we cannot offer a workaround, you may terminate the affected Services and receive a pro-rata refund of prepaid fees. We remain responsible for our subprocessors' performance.

  8. International transfers

    Customer Data is hosted in AWS's Singapore region. Where Personal Data subject to the GDPR is transferred to us in Hong Kong, or onward to subprocessors outside the EEA, the transfer is made under the SCCs, which are incorporated into this DPA by reference, with: Module Two applying; Clause 7 (docking) included; option 2 of Clause 9(a) (general authorisation, 14 days); Clause 17 governed by Irish law; and Clause 18 courts of Ireland. Annexes I and II of this DPA serve as Annexes I and II of the SCCs. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum (version B1.0) applies with the tables completed by the details in this DPA.

  9. Assistance

    Taking into account the nature of Processing, we assist you: (a) with Data Subject requests — the Services let you export and delete Customer Data directly, and we respond to requests forwarded to privacy@subanana.com within 7 days; (b) with your obligations under GDPR Articles 32–36, including data-protection impact assessments, at your reasonable request.

  10. Personal Data Breach

    We notify you without undue delay, and in any event within 72 hours of becoming aware, of a Personal Data Breach affecting your Personal Data, and provide the information reasonably required for your own notifications as it becomes available.

  11. Deletion and return

    You can delete projects and Customer Data in the Services at any time. On termination of the Services, or on written request, we delete Personal Data within 30 days, except copies we must retain under applicable law, which remain protected under this DPA until deleted. Export tools are available before deletion.

  12. Audit

    We make available information reasonably necessary to demonstrate compliance with this DPA, including our security documentation and, when available, independent audit reports (such as SOC 2) under confidentiality. Where required by applicable law and no report reasonably satisfies the requirement, you may conduct an audit at most annually, on 30 days' notice, during business hours, without disrupting operations, at your cost.

  13. Liability, term, order of precedence

    This DPA is effective while we Process Personal Data for you. Liability under this DPA is subject to the limitations in the main agreement. If this DPA conflicts with the main agreement, this DPA prevails for data-protection matters; the SCCs prevail over everything.

  14. Governing law

    This DPA is governed by the law governing the main agreement, except where the SCCs require otherwise.

Customer — sign here and email the document to privacy@subanana.com
Organisation: ______________________
Signature: ______________________
Name / title: ______________________
Date: ______________________
Datax Limited (trading as Subanana) — countersigned and returned within 5 business days
Signature: ______________________
Name / title: ______________________
Date: ______________________

Annex I — Details of Processing

Subject matterSpeech-to-text transcription, subtitle generation, translation, summarization and live captioning of Customer Data.
DurationThe term of the Services, plus the deletion period in Section 11.
Nature and purposeUpload, storage, automated transcription and language processing, editing, sharing at the Controller's direction, export.
Categories of Data SubjectsThe Controller's users; speakers and participants in uploaded or live audio/video; persons mentioned in content.
Categories of Personal DataAccount data (name, email, locale); voice recordings; transcript and translation text; any Personal Data contained in submitted content — content is determined by the Controller.
Special categoriesNot required by the Services; may be present in content at the Controller's discretion. Parties agree the Services are not intended for medical or other special-category records.
FrequencyContinuous, as initiated by the Controller.

Annex II — Technical and Organisational Measures

Annex III — Subprocessors

The current list, with each subprocessor's function and location, is maintained at subanana.com/legal/subprocessors and forms part of this DPA.