VigiLens - Data Processing Addendum Effective 2026-09-22 This Data Processing Addendum ("DPA") applies whenever you use VigiLens to hold or send information about your own clients. It forms part of the Terms of Service between you and JOLIVE Labs Inc. ("JOLIVE Labs", "we", "us"), and you do not need to sign it separately. It is written to be handed to a compliance reviewer. It describes what we do with your clients' information, what we will not do with it, who else touches it, how quickly we tell you if something goes wrong, and how you get it back or have it deleted. 1. WHO DECIDES WHAT You decide what client information goes into VigiLens and what is done with it. We act only on your instructions. In the language of the laws that apply: - Under PIPEDA and Quebec's Law 25, you are the organisation responsible for your clients' personal information. We process it for you. - Under the GDPR and UK GDPR, where they apply to you, you are the controller and we are the processor. - Under US state privacy laws, you are the business or controller and we are the service provider or processor. We handle your own account information (your name, firm, billing details and settings) as the organisation responsible for it. That is covered by our Privacy Policy, not by this DPA. 2. WHAT WE DO WITH CLIENT INFORMATION We process client information only to provide VigiLens to you, to keep it secure, and where a law requires it. Using the product is your instruction: storing a client, drafting a message, sending it, rendering a video, running your monitoring, and keeping the audit record are all processing you have asked for. If we believe an instruction from you breaks a data protection law, we will tell you rather than carry it out quietly. We do not: - sell client information, or share it for advertising; - use client information to train any artificial intelligence model, our own or anyone else's; - use client information for our own purposes, including product analytics that would identify a client; - let one firm see another firm's clients, voices, messages or videos. We may produce aggregated, de-identified statistics that cannot be traced back to any person, for example to understand overall load on our systems. 3. AI AND VOICE PROVIDERS Drafting a message sends the relevant context to our AI provider: the size of a market move, your firm name, and the client's first name, notes and survey answers you have recorded. Narrating a video sends the script to our voice provider. Both are bound as our subprocessors under section 7. Our AI provider does not use information sent through its interface to train its models, and holds it for a limited period for abuse monitoring only. If you would rather no client details reached an AI provider, you can write the messages yourself: the AI is a drafting aid, not a requirement. A cloned voice is created only with the express consent of the person whose voice it is, is tied to your firm, and is never offered to another firm. 4. CONFIDENTIALITY AND PERSONNEL Client information is confidential. Access is limited to people who need it to run or support the service, each bound by confidentiality obligations that survive their engagement with us. We do not read the contents of your client records, messages or notes except where you ask us to in support, where it is needed to investigate a fault or a security incident, or where a law requires it. 5. HOW IT IS PROTECTED We keep technical and organisational measures appropriate to the information involved. Today those include: - Encryption in transit (HTTPS) and encryption at rest for the database and stored files. - Per-firm isolation enforced by database security rules, so a request can only reach records belonging to the signed-in advisor, not only by application code. - Sign-in handled by a dedicated authentication provider using session cookies that are checked for revocation on each request, with a control to sign out every device at once. - An append-only audit log of communications that neither you nor we can alter after the fact. - Rate limiting on the interfaces that cost money or send email, to limit abuse. - Error monitoring configured without session recordings, with market-data credentials scrubbed before anything is reported. - Links sent to your clients are unguessable tokens, resolved server-side, and they stop working when a message is cancelled or an account is closed. Security measures change as products do. We may update them, provided the protection does not materially decrease. 6. IF SOMETHING GOES WRONG If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to client information you hold in VigiLens, we will notify you without undue delay and in any event no later than 72 hours after becoming aware of it. That 72 hours is deliberate. If you are a US broker-dealer or investment adviser, Regulation S-P requires you to have arrangements with your service providers to be told within that window so you can meet your own duty to notify affected people. Canadian advisors have parallel obligations under PIPEDA's breach reporting rules and Law 25. Our notice will describe what we know: the nature of the incident, the categories and approximate number of records involved where known, the likely consequences, and what we are doing about it. We will keep you updated as we learn more, and give you reasonable help with any notification you have to make. An initial notice is not an admission of fault. 7. WHO ELSE TOUCHES IT We use the providers below to run VigiLens. Each is bound by terms no less protective than this DPA, and each is used only for the purpose listed. - Google Cloud and Firebase: hosting, database, file storage, sign-in, and bot detection (United States) - Resend: sending email on your behalf (United States) - OpenAI: drafting message text and video scripts (United States) - Fish Audio (Hanabi AI Inc.): cloning and narrating voices recorded by you or your team (United States) - ElevenLabs: narration in the stock voices VigiLens provides (United States) - Amazon Web Services: rendering and storing finished videos (United States) - Upstash: rate limiting (United States) - Sentry: error monitoring (United States) - Stripe: subscription billing and payment processing (United States, Ireland and Canada) - Cloudflare: domain name services - Google Workspace: our support mailbox We remain responsible to you for what these providers do with client information. If we add or replace one, we will update this page and tell account holders by email before the new provider begins processing, giving you a reasonable opportunity to object. If you object on reasonable data protection grounds and we cannot offer an alternative, you may close your account and we will refund any prepaid, unused fees. Ask support@vigilensfinance.com to be notified of changes. 8. WHERE IT IS STORED, AND TRANSFERS Client information is stored and processed in the United States, and some providers may access it from other countries where they operate. Under Quebec's Law 25, an organisation must assess whether information transferred outside Quebec will receive adequate protection before transferring it, and must have an agreement in place. This DPA, together with the measures in section 5 and our contracts with the providers in section 7, is intended to be that agreement. We will give you the information you reasonably need to complete your own assessment. Where the GDPR or UK GDPR applies to a transfer, the parties agree the European Commission's Standard Contractual Clauses (and the UK Addendum) apply, with this DPA supplying the details they call for. 9. REQUESTS FROM YOUR CLIENTS Your clients' requests are yours to answer. Two of the common ones you can complete yourself, immediately, without contacting us: - Access and portability: Settings, Your data, exports everything in your account as a structured file. - Erasure: a client's page has a permanent delete that removes their record, their survey answers, their analyses, every message sent to them, and the drafts written for them. The audit log keeps that a message was sent and when, holding identifiers rather than names or message text, because you are required to keep a communications record. For anything else, including correction or restriction requests we would have to act on, tell us and we will help you respond within the time the law allows. If a client contacts us directly about information you control, we will point them to you and let you know. 10. GETTING IT BACK, AND DELETION You can export your data at any time while your account is open. When you ask us to close your account, we stop monitoring and sending, cancel anything scheduled, take your clients' links down, and hold the data for 30 days so the request can be undone. After that a scheduled job deletes your records, your files, the finished videos, and any voice clone created for you, and removes your sign-in. Backups made in the ordinary course are overwritten on their normal cycle. Anything a law requires us to keep, we keep only for that purpose and for no longer than required. 11. SHOWING OUR WORK On reasonable written request, no more than once a year unless a regulator or an incident requires otherwise, we will give you the information you reasonably need to confirm we are meeting this DPA. That will normally be written answers and any third-party reports our providers publish. If that is genuinely not enough for your obligations, we will agree an audit with you: during business hours, with reasonable notice, without disrupting the service or exposing any other firm's data, and at your cost unless it finds a material failure on our side. 12. HOW THIS FITS WITH EVERYTHING ELSE This DPA forms part of the Terms of Service. Where it conflicts with the Terms on the handling of client information, this DPA wins. The liability limits and exclusions in the Terms apply to this DPA, and to both parties together rather than separately. It starts when you first use VigiLens and lasts as long as we hold client information for you. Sections 4, 6 and 10 continue to apply afterwards for as long as they are relevant. We may update this DPA when the product, our providers, or the law changes. Material changes are announced to account holders, and the effective date at the top of this page always shows the current version. 13. CONTACT Questions about this DPA, requests for a signed copy, or notices under it: support@vigilensfinance.com. --- This document is provided for your compliance file. It is not legal advice, and it does not replace your own assessment of whether VigiLens is suitable for the information you hold.