Data Processing Agreement

Last updated: 25 August 2026

This Data Processing Agreement (the “Agreement” or “DPA”) is concluded between the Harmony Contracting Entity identified in the Order Form (the “Processor”) and the Customer (as defined in the Terms of Service), as the “Controller”, together with the Processor the “Parties”. Where no Order Form has been executed, the Harmony Contracting Entity is Harmony Labs Limited. The identity of the Harmony Contracting Entity does not affect the substantive obligations of the Parties under this Agreement.

§1. Definitions

The terms used in this Agreement have the following meanings:

Harmony — the platform that allows users to record, transcribe (from audio and video formats), unify, and analyze conversations across different communication platforms, available at heyharmony.com.

Harmony Group — Harmony Global Inc., a corporation incorporated under the laws of the State of Delaware, with its registered office at 8 The Green, Ste R, Dover, Delaware 19901, United States (“Harmony Global”); Harmony Labs Limited, a private company limited by shares incorporated under the laws of Ireland, with its registered office at 22 Northumberland Road, Ballsbridge, Dublin 4, D04 ED73, Ireland, registered with the Companies Registration Office under company number 811689 (“Harmony Labs”); and Harmony Brasil Ltda., a limited liability company incorporated under the laws of Brazil, with its registered office at Rua Iapó nº 62, Alphaville Graciosa, Pinhais/PR, CEP 83327-075, Brazil, enrolled with the CNPJ under number 64.767.289/0001-51 (“Harmony Brasil”), together with their respective affiliates.

Harmony Contracting Entity — the member of the Harmony Group identified as the contracting entity in the Order Form, which is the Processor under this Agreement.

EU Standard Contractual Clauses — the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.

LGPD — Brazilian Federal Law No. 13.709/2018 (Lei Geral de Proteção de Dados Pessoais), as amended.

ANPD Standard Contractual Clauses — the standard contractual clauses (cláusulas-padrão contratuais) approved by the Brazilian National Data Protection Authority (ANPD) in Resolution CD/ANPD No. 19 of 23 August 2024.

Intra-Group Transfer — a transfer of personal data between members of the Harmony Group, including the transfer from Harmony Labs or Harmony Brasil to Harmony Global for the purpose of hosting and operating the infrastructure on which Harmony runs.

GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), as supplemented by applicable national implementing legislation, including the Irish Data Protection Act 2018.

Applicable Data Protection Law — the GDPR and any other data protection or privacy legislation applicable to the Parties’ activities under this Agreement, including, where relevant, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and the LGPD.

Controller, Processor, Sub-processor, Data Subject, Personal Data, Processing, Personal Data Breach and Supervisory Authority — have the meanings given to those terms in the GDPR.

Agreement — this Data Processing Agreement, including its Annexes and Appendices.

Order Form — any order form executed by the Parties incorporating the Terms of Service and this Agreement, and identifying the Harmony Contracting Entity that is the Processor under this Agreement.

Terms of Service — the Harmony Terms of Service available at heyharmony.com/terms, which govern the relationship between the Controller and the Processor.

Special Categories of Personal Data — personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, together with genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a natural person’s sex life or sexual orientation, as defined in Article 9(1) of the GDPR.

International Transfer Appendix — the appendix setting out the safeguards adopted for transfers of personal data to third countries, including transfers carried out under an adequacy decision of the European Commission pursuant to Article 45 of the GDPR, under the EU Standard Contractual Clauses pursuant to Article 46 of the GDPR, and under the ANPD Standard Contractual Clauses, and setting out the safeguards applicable to Intra-Group Transfers, attached to this Agreement as Appendix 1.

§2. Subject matter of the Agreement

Pursuant to this Agreement, the Controller engages the Processor, in accordance with Article 28 of the GDPR, to process personal data on the Controller’s behalf to the extent specified in §3.

§3. Scope of processing

3.1. The subject matter of the processing under this Agreement is any personal data that the Processor processes on behalf of the Controller in connection with the performance of the Terms of Service, the Controller being the controller (or, where applicable, a processor acting on behalf of a third-party controller) thereof within the meaning of the GDPR.

3.2. The data referred to in §3.1 include, in particular, personal data of employees, associates of the Controller, persons authorized by the Controller to use Harmony, and end customers, being any individuals who contact or are contacted by the Controller using the services, or whose personal data is otherwise processed by the Controller through the services under the Terms of Service, such as:

(a) Identity Data: name, surname, middle name or patronymic, salutation;

(b) Contact Data: email address, phone number;

(c) Financial Data: information about financial transactions, such as bank account details, credit card information, and payment history;

(d) Voice recordings (audio files of conversations and content derived from them, including transcripts);

(e) Technical Data: information collected through automated means, such as IP addresses, device information, browsing history, and cookies;

(f) Employment Data: job title and employer information;

(g) Personal Preferences: preferences, interests, and characteristics, such as language preferences and marketing preferences; and

(h) other data resulting from the specifics of the services provided by the Processor, which the Controller uses under the Terms of Service.

3.3. The Processor will process all categories of personal data that the Controller provides to Harmony. Since the accumulation of personal data on the Processor’s servers occurs automatically during use of the service, the Processor does not have real-time control over how the Controller categorizes such personal data.

3.4. The Controller shall not submit Special Categories of Personal Data to the Processor, including data concerning health, unless the Order Form expressly permits the submission of such data or the Parties otherwise agree in writing. Where the Order Form is silent, no Special Categories of Personal Data may be submitted, and the categories listed in §3.2 are to be read accordingly. Where the submission of Special Categories of Personal Data is expressly permitted, the Order Form shall identify the categories concerned, the Controller remains responsible for establishing a legal basis under Article 9(2) of the GDPR (or Article 11 of the LGPD, where applicable), and the Processor shall apply the additional safeguards described in Annex II.

3.5. Biometric data and emotion inference. The Services process voice recordings as audio data for the purposes of transcription, summarisation, and analytical processing of conversational content.

(a) The Services do not process voice recordings to extract biometric identifiers for the purpose of uniquely identifying natural persons within the meaning of Articles 4(14) and 9 of the GDPR.

(b) The Services do not infer emotions or intentions of natural persons from biometric data within the meaning of Regulation (EU) 2024/1689. Where the Services derive sentiment, scoring or similar indicators, they do so from the text of transcripts and not from vocal, acoustic, prosodic or other biometric characteristics.

(c) Where the Customer requires processing that would constitute biometric identification or emotion recognition, such processing is outside the scope of the Services and requires separate written agreement between the Parties.

(d) The Processor will not materially diminish the position described in (a) and (b) during the term. Any material change will be communicated to the Controller in accordance with §7, and the objection and termination rights in §7.4 and §7.5 apply.

§4. Purpose, nature, and duration of the processing

4.1. The processing of personal data under this Agreement is performed in accordance with the documented instructions of the Controller, in line with Article 28 of the GDPR, for the purpose of the Controller using the services of the Processor under the Terms of Service, in particular: using Harmony, and handling requests and complaints related to the use of Harmony.

4.2. The execution of the Terms of Service and this Agreement, together with the Controller’s selection of the Processor’s services under the Terms of Service, shall be considered by the Parties as the documented instruction referred to in §4.1.

4.3. The data processed by the Processor will be processed during the term of the Terms of Service on a permanent or occasional basis, depending on the nature of the particular activity or service performed under the Terms of Service. Following termination or expiry of the Agreement, Harmony will make Customer Data available for export for 30 days and will permanently delete all Customer Data no later than 90 days after termination or expiry, except where retention is required by applicable law. Export is provided in accordance with the Terms of Service.

4.4. Within 90 days from the date of termination of this Agreement or receipt of a documented request for deletion of personal data from the Controller, the Processor shall: (a) delete the personal data from all storage media, programs, and applications, including any copies thereof; or (b) irreversibly anonymize the data covered by the deletion request, unless further processing is required by Union or Member State law.

4.5. Upon the Controller’s written request, the Processor shall confirm in writing that all personal data has been deleted or returned, except where retention is required by applicable law.

4.6. The Processor makes configuration options available to the Controller within the Services, including data retention settings and the selection of AI model providers, through which the Controller may customize the processing of Customer Data within the scope of the standard operation of the Services. The use of such configuration options by the Controller or its authorized Users constitutes a documented instruction within the meaning of this Agreement. Individual instructions going beyond the foregoing that require customization of the Processor’s standard service are binding only to the extent agreed in writing in an Order Form or a separate written amendment.

4.7. During the term of the Terms of Service and until deletion pursuant to §4.4, the Controller may export Customer Data at any time using the export functions provided within the Services.

§5. Rights and obligations of the Parties

5.1. The Controller undertakes that any personal data processed by the Processor under this Agreement shall be processed by the Controller: (a) on one of the legal bases set forth in Article 6 (and, for special categories of personal data, Article 9) of the GDPR; or (b) on behalf of another controller, in which case the Controller represents to the Processor that the data will be processed by such controller on one of the relevant legal bases under Article 6 (and, where applicable, Article 9) of the GDPR, and that the Controller is authorized to engage the Processor for the processing of such personal data.

5.2. The Processor undertakes to:

(a) cooperate with the Controller, to the extent reasonably possible, through appropriate technical and organizational measures, in responding to requests from data subjects in the exercise of the rights provided in Chapter III (Articles 12 to 23) of the GDPR, including confirmation as to whether personal data is being processed, access, rectification, erasure, restriction of processing, data portability, objection to processing, and the right not to be subject to a decision based solely on automated processing;

(b) assist the Controller in complying with its obligations under Articles 32 to 36 of the GDPR, in particular the obligation to ensure the security of processing, to notify personal data breaches to the competent supervisory authority and to data subjects, and to carry out data protection impact assessments and prior consultations where required;

(c) upon termination of the processing services and depending on the Controller’s decision, delete or return to the Controller all personal data and delete all existing copies thereof, unless mandatory provisions of law require the storage of personal data, in which case §4.4 of this Agreement shall apply;

(d) make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations of the Processor under the GDPR and to enable the Controller, or an auditor authorized by the Controller, to conduct and contribute to audits, including inspections, subject to §5.3 and §5.4 below;

(e) inform the Controller without undue delay if, in the Processor’s opinion, an instruction issued by the Controller violates the GDPR or other applicable laws;

(f) ensure that all sub-processors used by the Processor are bound to the same data protection obligations as the Processor under this Agreement;

(g) process data using the sub-processors included in the list maintained at security.heyharmony.com (the “Sub-processor List”), and inform the Controller of any changes in accordance with §7; and

(h) not use personal data processed under this Agreement to train artificial intelligence or machine learning models, whether the Processor’s own models or those of any third party, and maintain contractual commitments with its artificial intelligence sub-processors prohibiting such use and requiring zero data retention beyond the duration of the processing request.

5.3. The audit right referred to in §5.2(d) may be exercised during the Processor’s business hours (Monday through Friday, 9:00 to 17:00 local time, excluding public holidays), with at least one week’s prior notice and without unreasonable interference with the Processor’s operations. During the audit, the Processor shall provide the Controller with the information necessary to demonstrate compliance with the GDPR. Audits shall not be conducted more than once per calendar year and shall not exceed 3 business days. All costs associated with audits shall be borne by the Controller.

5.4. The limitations on frequency, duration, and cost in §5.3 do not apply where: (a) the audit follows a Personal Data Breach affecting the Controller’s personal data; (b) the audit is required by a Supervisory Authority or by Applicable Data Protection Law, including where the Controller is a financial entity subject to Regulation (EU) 2022/2554 and the audit right must extend to the Controller’s competent authority; or (c) the Processor is in material breach of this Agreement. In those cases the audit may be conducted on reasonable notice and at the Processor’s cost, and the relevant Supervisory Authority or competent authority may participate in or conduct the audit.

5.5. If deficiencies are identified during an audit, the Processor shall remedy them within the timeframe agreed by the Parties, having regard to the severity of the deficiency.

5.6. The Processor is authorized to engage sub-processors for the processing of personal data covered by this Agreement, including sub-processors located outside the European Economic Area, subject to §7 (sub-processors) and the international transfer safeguards in §5.7. Where the Processor is Harmony Labs or Harmony Brasil, Harmony Global acts as a sub-processor and provides the hosting and platform infrastructure on which Harmony operates.

5.7. International transfers. Customer Data is stored in the United States and, except as set out in §5.10, processed there, and may be processed by sub-processors in other jurisdictions to deliver specific services, including AI model processing. The countries in which Customer Data is stored, and the sub-processors involved, are identified in the Sub-processor List maintained at security.heyharmony.com. Transfers of personal data to a third country not covered by an adequacy decision of the European Commission are carried out under the international transfer safeguards set out in the International Transfer Appendix attached as Appendix 1 to this Agreement, which forms an integral part of this Agreement and applies to such transfers without further action by the Parties. Where personal data is transferred to a third country or international organisation that the European Commission has recognized as ensuring an adequate level of protection pursuant to Article 45 of the GDPR, such transfers are carried out under that adequacy decision without the need for any additional transfer mechanism.

5.8. Allocation of the restricted transfer. Notwithstanding §5.7, where the Processor is Harmony Labs and the Controller is established in the European Economic Area, the relationship between the Parties is an intra-EEA relationship: the provision of the Services by the Processor to the Controller does not itself constitute a transfer of personal data to a third country, and no standard contractual clauses and no representative under Article 27 of the GDPR are required on that leg. The restricted transfer arises instead on the Intra-Group leg between Harmony Labs, as data exporter, and Harmony Global, as data importer, which operates the infrastructure on which Customer Data is stored, and is governed by the EU Standard Contractual Clauses as set out in A1.6. Where the Processor is Harmony Brasil, the corresponding Intra-Group Transfer to Harmony Global is governed by the ANPD Standard Contractual Clauses as set out in A1.7. Where the Processor is Harmony Global and the Controller is established in the European Economic Area, the transfer from the Controller to the Processor is itself a restricted transfer, governed by the EU Standard Contractual Clauses concluded directly between the Parties, and A1.8 applies.

5.9. The Controller undertakes, in accordance with Articles 13 and 14 of the GDPR, to inform data subjects whose data the Controller will process through Harmony of the international transfers carried out under this Agreement.

5.10. Data location. Customer Data is stored on infrastructure operated by Harmony Global in the United States, irrespective of which Harmony Contracting Entity is the Processor. The Processor does not currently offer a choice of infrastructure region, nor storage of Customer Data within the European Union or the European Economic Area. Certain processing takes place within the European Union: speech-to-text transcription is performed by a sub-processor located in France, and the conversational AI companion layer operates on infrastructure located within the European Union. Other sub-processors may process Customer Data in further jurisdictions to deliver specific services, including AI model processing. The current list of sub-processors, the countries in which they process Customer Data, and the international transfer mechanism applicable to each is maintained at security.heyharmony.com.

5.11. Records of processing. The Processor shall maintain records of all processing activities carried out on behalf of the Controller, in accordance with Article 30 of the GDPR. Such records shall include: (i) the name and contact details of the Processor and of the Controller; (ii) the categories of processing carried out on behalf of the Controller; (iii) where applicable, transfers of personal data to a third country, including the identification of the recipient country and the safeguards adopted; and (iv) a general description of the technical and organizational security measures referred to in Article 32 of the GDPR.

5.12. Where the Controller or its authorized Users select an AI model or model provider whose processing takes place outside the European Economic Area, that selection constitutes a documented instruction of the Controller for the associated processing and for any related international transfer. The Processor shall ensure that an appropriate transfer mechanism within the meaning of Chapter V of the GDPR is in place for each such transfer, as identified in the sub-processor list at security.heyharmony.com.

5.13. The Controller hereby instructs the Processor to implement requests from data subjects concerning (a) the rectification of account or profile data, and (b) the deactivation or deletion of a user account and the data exclusively associated with it, independently and without prior consultation with the Controller, where the request is submitted directly to the Processor and the identity of the data subject has been verified by appropriate means, such as the email address associated with the user account. All other data subject requests are handled in accordance with §5.2(a).

5.14. Compliance with the obligations under this Agreement and Article 28 of the GDPR shall, as a rule, be demonstrated by the provision of an appropriate and up-to-date attestation or report issued by an independent body in connection with an IT security or data protection certification or audit. The audit rights in §5.2(d), §5.3 and §5.4 remain unaffected; however, inspections shall be carried out with due regard to the Processor’s legitimate interests, where possible primarily by way of written information or remote review, during normal business hours and without unreasonable interference with the Processor’s operations, and any third party appointed by the Controller to carry out an inspection may not be a competitor of the Processor and must first be bound in writing to confidentiality.

5.15. Where assistance provided by the Processor under §5.2 exceeds the assistance reasonably owed under this Agreement, in particular in connection with data protection impact assessments, prior consultations, or extensive regulatory or data subject matters attributable to the Controller’s specific circumstances, the Parties shall agree in advance on appropriate additional remuneration. Assistance following a personal data breach for which the Processor is responsible is never chargeable.

§6. Reporting personal data breaches

6.1. The Processor undertakes, upon becoming aware of a personal data breach, to communicate it to the Controller without undue delay and in any case no later than 72 hours, in line with Articles 33 and 34 of the GDPR. This timeline is the default and may be modified by an Order Form.

6.2. The communication to the Controller shall include at least: (a) a description of the nature of the breach and, if possible, an indication of the categories and approximate number of data subjects affected, and the categories and approximate volume of records concerned; (b) a description of the likely consequences of the breach; and (c) a description of the measures applied or proposed by the Processor to address the breach, including measures to mitigate its possible adverse effects.

6.3. Notification to the competent supervisory authority and to data subjects under Articles 33 and 34 of the GDPR remains the responsibility of the Controller, except where otherwise agreed in writing. The Processor shall provide reasonable assistance to enable the Controller to comply with that obligation within the timeframes established by the GDPR and, where the LGPD applies, within the timeframes established by Article 48 of the LGPD.

§7. Use of sub-processors

7.1. The Controller hereby grants the Processor a general authorization to engage sub-processors in accordance with this §7. The list of sub-processors is maintained at security.heyharmony.com (the “Sub-processor List”). Where the Processor is Harmony Labs or Harmony Brasil, Harmony Global Inc. is named in the Sub-processor List as a sub-processor, together with its processing locations and the international transfer mechanism applicable to that leg. Any change to the Harmony Group entity providing hosting or infrastructure is subject to the notice and objection procedure in §7.2 and §7.4 on the same terms as any other sub-processor.

7.2. The Processor shall inform the Controller of any intended addition or replacement of a sub-processor, giving the Controller the opportunity to object. Notice shall be provided by email at least 30 days before engaging a new sub-processor.

7.3. The Processor may engage a replacement sub-processor without the advance notice required by §7.2 only where necessary to maintain continuity of the Services following the failure, insolvency, or termination of an existing sub-processor. In that case the Processor shall notify the Controller as soon as reasonably possible and in any event within five business days of the engagement, shall ensure that the replacement provides equivalent or better security terms, and the objection rights in §7.4 and §7.5 apply from the date of that notice.

7.4. The Controller shall raise any objection in writing or by documentary form within 30 days from receipt of the notice, providing the reasons for the objection. Failure to object within this period shall be considered consent to the change. The Controller undertakes not to object without valid reasons.

7.5. If the Controller objects to a new sub-processor, the Parties shall work together in good faith to resolve the objection for a period of 30 days from receipt of the objection. If no resolution is reached within that period, the Controller may terminate the affected Services without penalty on written notice to the Processor, and the Processor shall refund a pro-rata portion of prepaid fees for the unused portion of the Subscription Term.

7.6. The Processor shall, upon reasonable request, provide the Controller with confirmation that its agreements with sub-processors contain data protection terms substantially equivalent to those of this Agreement.

§8. Technical and organizational measures

8.1. The Processor shall ensure that any person acting under its authority who has access to personal data is bound by an obligation of confidentiality and shall not transfer, disclose, or share such data with unauthorized persons.

8.2. The Processor shall implement the technical and organizational security measures required under Article 32 of the GDPR, appropriate to the risks involved in the processing, in particular as set out in Annex II (Technical and Organizational Measures), which forms an integral part of this Agreement.

8.3. The Processor shall maintain documentation of the technical and organizational measures implemented to comply with the requirements of this Agreement and Applicable Data Protection Law.

8.4. The Processor may change or adapt the technical and organizational measures set out in Annex II during the term of this Agreement, provided that such measures continue to meet the statutory requirements and the overall level of protection is not reduced.

§9. Mutual exchange of information

9.1. The Parties undertake to notify each other of any suspected personal data breach without undue delay and to cooperate in good faith in accordance with the GDPR.

9.2. The Parties shall consult on the necessity and content of any communications to the competent supervisory authority or data subjects regarding personal data breaches.

9.3. Any information or notices exchanged between the Parties under this Agreement shall be sent to: (a) for the Controller: the email address associated with the Customer’s account, as set out in the Terms of Service; and (b) for the Processor: [email protected].

§10. Liability

10.1. The Processor’s liability under this Agreement shall be subject to the liability limitations set forth in Section 14 of the Terms of Service, as may be modified by an Order Form.

10.2. Notwithstanding §10.1, claims involving breach of Applicable Data Protection Law, unauthorized disclosure or loss of personal data, or violation of data subject rights shall be subject to the enhanced liability cap set forth in Section 14.2 of the Terms of Service, as may be modified by an Order Form.

10.3. Subject to §10.1 and §10.2, the Processor shall remain fully liable for the acts or omissions of its sub-processors in respect of the processing of personal data on behalf of the Controller, as if such acts or omissions were its own.

10.4. Nothing in this Agreement limits the liability of either Party to a data subject or to a Supervisory Authority, or any liability that cannot be limited under Applicable Data Protection Law.

§11. Final provisions and termination

11.1. This Agreement is concluded for the duration of the Terms of Service and terminates automatically, without the need for additional declarations, upon termination or expiration of the Terms of Service.

11.2. This Agreement enters into force upon execution by both Parties or upon acceptance of the Terms of Service by the Controller, whichever is earlier.

11.3. Any amendment, supplement, or termination of this Agreement, on pain of nullity, shall be made in writing or by documentary form. The Parties agree to renegotiate this Agreement in good faith as part of any renegotiation of the Terms of Service.

11.4. The Controller may terminate this Agreement with immediate effect, without prior notice, upon the Processor’s failure to remedy, within a reasonable cure period of not less than 14 days from written notice, deficiencies identified during the audit referred to in §5.3, or any processing of personal data in violation of this Agreement or Applicable Data Protection Law.

11.5. Where the Processor reasonably believes, on objective grounds, that the Controller is processing personal data entrusted to the Processor in violation of §5.1, in particular by processing such data without the legal basis required under Article 6 (or, for special categories, Article 9) of the GDPR, the Processor shall notify the Controller in writing, setting out those grounds, and the Parties shall work in good faith to resolve the matter within 15 days of that notice. During that period the Processor may suspend the affected processing only to the extent necessary to avoid an imminent violation of Applicable Data Protection Law. The Processor may terminate this Agreement only if the matter remains unresolved at the end of that period, or where immediate cessation of processing is required by law or by a Supervisory Authority.

11.6. Appendix 1 (International Transfer Appendix) and Annex II (Technical and Organizational Measures) form an integral part of this Agreement.

11.7. In the event of any conflict between this Agreement and the Terms of Service in respect of data protection matters, this Agreement shall prevail. In the event of any conflict between this Agreement and an Order Form executed by the Parties, the Order Form shall prevail to the extent it expressly addresses the conflicting matter.

11.8. This Agreement is governed by the law specified in the Order Form for the Harmony Contracting Entity that is the Processor. Absent such specification, this Agreement is governed by the laws of Ireland, including the GDPR as applicable in Ireland and the Irish Data Protection Act 2018. The Parties submit to the exclusive jurisdiction of the courts specified in the Order Form or, absent such specification, of the courts of Ireland, for the resolution of any dispute arising out of or in connection with this Agreement. The governing law and forum of this Agreement do not affect the law elected under Clause 17 of the EU Standard Contractual Clauses or the forum elected under Clause 18(b), which in each case is Ireland, as set out in A1.6.

11.9. This Agreement may be executed and stored in electronic form on the Processor’s servers and sent to the email address provided by the Controller as a PDF, or signed in two counterparts, one for each Party.

11.10. This Agreement cannot be terminated separately from the Terms of Service. Termination or expiry of the Terms of Service results in the termination of this Agreement, which nevertheless remains in force until the deletion of Customer Data pursuant to §4.4 has been completed.

Appendix 1 — International Transfer Appendix

A1.1. Scope. This Appendix sets out the safeguards adopted for transfers of personal data to third countries under §5.7 of this Agreement, whether the transfer occurs between the Controller and the Processor, between members of the Harmony Group, or between a member of the Harmony Group and a sub-processor.

A1.2. Adequacy decision. Where transfers of personal data are made to a third country or international organisation that the European Commission has decided ensures an adequate level of protection pursuant to Article 45 of the GDPR, such transfers are carried out under that adequacy decision without the need for any additional transfer mechanism.

A1.3. Standard contractual clauses. Transfers of personal data to a third country not covered by a European Commission adequacy decision, including the United States, are governed by: (a) the EU Standard Contractual Clauses, executed between the exporting member of the Harmony Group and the receiving sub-processor; (b) in the case of transfers to organizations in the United States certified under the EU-U.S. Data Privacy Framework, that framework; or (c) where a sub-processor does not offer the EU Standard Contractual Clauses, the most equivalent contractual safeguards offered by such sub-processor, with the Processor confirming that such safeguards provide a level of protection essentially equivalent to that required under the GDPR, together with any supplementary measures identified as necessary following a transfer impact assessment.

A1.4. Sub-processor transparency. The current list of sub-processors, their processing locations, and the international transfer mechanism applicable to each is maintained at security.heyharmony.com.

A1.5. Confirmation on request. Upon the Controller’s reasonable written request, the Processor shall confirm the international transfer mechanism in place for any specific sub-processor processing the Controller’s personal data.

A1.6. Intra-group transfers under the EU Standard Contractual Clauses. Harmony Labs, as data exporter, and Harmony Global, as data importer, have entered into the EU Standard Contractual Clauses, Module Three (processor to processor), in respect of personal data processed under this Agreement that is transferred to, stored in, or accessible from the United States. The following elections apply: (a) the optional docking clause in Clause 7 applies; (b) for the purposes of Clause 9, Option 2 (general written authorisation) applies, with the notice period set out in §7.2 of this Agreement; (c) the optional language in Clause 11(a) concerning an independent dispute resolution body does not apply; (d) for the purposes of Clause 17, the clauses are governed by the law of Ireland; (e) for the purposes of Clause 18(b), any dispute arising from the clauses shall be resolved before the courts of Ireland; and (f) Annex I is populated by §3 and §4 of this Agreement, Annex II by Annex II to this Agreement, and Annex III by the Sub-processor List, with the Irish Data Protection Commission identified as the competent supervisory authority in Annex I.C. The Controller is a third-party beneficiary of those clauses in accordance with Clause 3. Upon the Controller’s reasonable written request, the Processor shall make a copy of the executed clauses available to the Controller.

A1.7. Intra-group transfers from Brazil. Harmony Brasil, as data exporter, and Harmony Global, as data importer, have entered into the ANPD Standard Contractual Clauses in respect of personal data subject to the LGPD that is transferred to, stored in, or accessible from the United States. Harmony Global is identified in the Sub-processor List as the recipient of such transfers, together with the applicable transfer mechanism, and the disclosure and notification obligations in §7 and A1.4 apply to that leg on the same terms as to any other sub-processor.

A1.8. Representative in the Union. Where the Processor is Harmony Labs, the Processor is established in the Union and no representative under Article 27 of the GDPR is required. Where Harmony Global contracts directly with a Controller established in the European Economic Area and the processing falls within Article 3(2) of the GDPR, Harmony Global shall designate a representative in the Union in accordance with Article 27 of the GDPR and shall identify that representative in the Order Form and at security.heyharmony.com.

A1.9. United Kingdom. For transfers of personal data subject to the UK GDPR, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018 applies to the EU Standard Contractual Clauses referred to in A1.3 and A1.6. Tables 1 to 3 of that Addendum are completed by reference to §3, §4 and Annex II of this Agreement and the Sub-processor List, and for the purposes of Table 4 neither Party may end the Addendum as set out in Section 19 of the Addendum. References in the Clauses to the GDPR are read as references to the UK GDPR, the competent supervisory authority is the Information Commissioner, and the governing law and forum are those of England and Wales.

A1.10. Switzerland. For transfers of personal data subject to the Swiss Federal Act on Data Protection, the EU Standard Contractual Clauses referred to in A1.3 and A1.6 apply with the following amendments: references to the GDPR are read as references to the Swiss Federal Act on Data Protection; the competent supervisory authority is the Federal Data Protection and Information Commissioner; the term “member state” is not interpreted so as to exclude data subjects in Switzerland from enforcing their rights in their place of habitual residence; and, until the revised Act applies to legal entities, the Clauses also protect the personal data of legal entities.

Annex II — Technical and Organizational Measures

AII.1. The Processor implements the technical and organizational security measures required under Article 32 of the GDPR, appropriate to the risks involved in the processing.

AII.2. The current description of the Processor’s technical and organizational measures, including measures relating to: (a) pseudonymization and encryption of personal data; (b) ensuring the confidentiality, integrity, availability and resilience of processing systems; (c) restoring availability and access to personal data in a timely manner in the event of an incident; (d) regularly testing, assessing and evaluating the effectiveness of such measures; (e) access controls, logging and monitoring; and (f) personnel training and confidentiality obligations, is maintained at security.heyharmony.com and forms an integral part of this Annex II.

AII.3. The Processor shall not materially diminish the security measures described at security.heyharmony.com during the term of this Agreement. Material changes will be communicated to the Controller in accordance with §7.

AII.4. Where the Order Form expressly permits the submission of Special Categories of Personal Data under §3.4, the Processor shall apply the following additional safeguards: restriction of access to those categories to named personnel on a documented need-to-know basis; logging of all access to and export of such data; and encryption at rest using keys separate from those used for other Customer Data.

Annex E — Brazil (LGPD)

E.1. This Annex applies where the LGPD governs the processing, including where the Harmony Contracting Entity is Harmony Brasil. It supplements and does not replace the body of this Agreement.

E.2. Roles. Harmony acts as operador and the Controller acts as controlador within the meaning of Article 5 of the LGPD. References in this Agreement to Processor and Controller are read accordingly.

E.3. International transfers. Transfers of personal data out of Brazil are made on the basis of Article 33 of the LGPD, relying on the ANPD Standard Contractual Clauses as set out in A1.7 or on another mechanism permitted by Article 33. The Processor shall inform the Controller on request which mechanism applies to any given transfer.

E.4. Data subject rights. The Processor shall assist the Controller in responding to requests under Article 18 of the LGPD, including requests for confirmation of processing, access, correction, anonymisation, blocking or deletion of unnecessary or excessive data or data processed in breach of the LGPD, portability, information about the public and private entities with which data has been shared, information about the possibility of denying consent and the consequences of doing so, and review of decisions taken solely on the basis of automated processing.

E.5. Response times. The Processor shall provide the assistance referred to in E.4 within a period that enables the Controller to respond within the timeframes set by the LGPD. Unless the Order Form provides otherwise, the Processor shall respond to a request for assistance from the Controller within five (5) business days of receipt, and in any event within a period that enables the Controller to provide the confirmation of processing and access referred to in Article 19 of the LGPD within fifteen (15) days of the data subject's request.

E.6. Security incidents. The notification period in §6.1 of this Agreement applies and is shorter than the period contemplated by Article 48 of the LGPD, so that the Controller can meet its obligations to the ANPD and to data subjects under Article 48 and Resolução CD/ANPD nº 15/2024.

E.7. Records and reporting. The records maintained under §5.11 satisfy the requirement to maintain records of processing operations under Article 37 of the LGPD, and the Processor shall make them available to the Controller for the purposes of any report to the ANPD.

E.8. Country Addendum. Where the Controller contracts with Harmony Brasil, the Brazil Country Addendum to the Terms of Service applies and §11.8 of this Agreement is read accordingly.

E.9. Encarregado. The Processor has designated a person responsible for the processing of personal data (encarregado pelo tratamento de dados pessoais) within the meaning of Article 41 of the LGPD. The identity of the encarregado and the channel for contacting them are published at security.heyharmony.com and on the Processor's privacy page. Communications from data subjects and from the ANPD in respect of personal data processed under this Agreement may be addressed to that channel. The designation of an encarregado by the Processor does not discharge the Controller from any obligation to designate its own encarregado.

E.10. Cooperation with the ANPD. The Processor shall cooperate with the ANPD in the exercise of its powers under the LGPD. The Processor shall inform the Controller without undue delay of any request, order, or communication received from the ANPD that relates to personal data processed on the Controller's behalf, unless prohibited from doing so under applicable law, and shall provide the Controller with reasonable assistance in responding to it.

Signatures

The Processor (the Harmony Contracting Entity identified in the Order Form)

Entity (as identified in the Order Form):

☐ Harmony Global Inc. ☐ Harmony Labs Limited ☐ Harmony Brasil Ltda.

Signature: ______________________________

Name: ____________________________

Title: ____________________________

Date: ____________________________

The Controller (Customer)

Signature: ______________________________

Name: ____________________________

Title: ____________________________

Date: ____________________________