V3 — 29 June 2026 (Platform Terms + Data Processing Addendum)
If you have executed an Order Form to purchase access to and use of The Jinn Labs Services and have not otherwise executed a separate written subscription agreement with us, then please read these Jinn Labs Platform Terms (these “Terms”, and together with any associated Order Form, this “Agreement”) carefully because they govern your use of any services provided to you by Jinn Labs Inc. (“Jinn Labs”). The Terms “Jinn Labs,” “We,” and “Us” refer to Jinn Labs, and the term “Customer” refers to you and any entity on behalf of which you are entering into this Agreement, as set forth on the applicable Order Form. Each a “Party” and together the “Parties”.
Jinn Labs offers a proprietary, cloud-based and edge-based theft-detection and retail-intelligence platform (the “Jinn Labs Platform”). Customers access the Jinn Labs Platform through the software application provided by Jinn Labs (the “Upload Tool”) and through Jinn Labs Hardware (defined in Section 3), which enable secure processing of video footage, point-of-sale data, and other audiovisual or transactional records (collectively, “Recordings”). The Jinn Labs Platform, the Upload Tool, the Jinn Labs Hardware, and any related software, APIs, and services are the “Jinn Labs Services”. The Jinn Labs Services analyze Recordings using artificial intelligence (computer-vision models, multimodal reasoning, and third-party generative-AI APIs) and may provide alerts, insights, recommendations, summaries, or other generated materials (“Generated Materials”). For quality assurance, Jinn Labs personnel may access and review Recordings, Customer Materials (as defined below), and/or Generated Materials in accordance with its privacy and data protection policies in order to provide, monitor, validate, secure, troubleshoot or improve the Jinn Labs Services.
2.1Right to Use. Subject to Customer’s compliance with this Agreement, Jinn Labs grants Customer a limited, non-exclusive, non-transferable (except as permitted by Section 12), non-sublicensable right, during the Term, solely for Customer’s internal business purposes and within the Licensed Volume set forth in the Order Form, to use the Upload Tool and the Jinn Labs Platform.
2.2Use Restrictions. Jinn Labs reserves all rights not expressly granted. Customer will not, and will not permit any person to, directly or indirectly: (i) use the Jinn Labs Services in violation of any law or third-party right; (ii) reverse engineer, decompile, disassemble, or modify the Jinn Labs Services; (iii) distribute, sell, sublicense, or otherwise transfer the Jinn Labs Services to any third party; or (iv) use the Jinn Labs Services, Generated Materials, or Confidential Information for benchmarking or competitive analysis, or to develop, commercialize, or sell any product, service, or technology that could compete with the Jinn Labs Services, including to develop AI or machine-learning models.
2.3Generated Materials. Subject to Customer’s compliance with this Agreement and to Jinn Labs’ retention of all Intellectual Property Rights in the Jinn Labs Services, Jinn Labs grants Customer, during the Term, a limited, non-exclusive, non-transferable, worldwide license to access and use the Generated Materials solely for Customer’s internal business purposes. Customer acquires no ownership interest in the Jinn Labs Services, the Generated Materials, or any underlying technology or intellectual property of Jinn Labs.
2.4Authorized Users. Customer will not allow any person to use the Jinn Labs Services other than its employees or individual contractors authorized by Customer and within the Licensed Volume (“Authorized Users”). Customer is responsible for all acts and omissions of its Authorized Users.
2.5Support. Jinn Labs will use commercially reasonable efforts to provide reasonable technical support consistent with its standard support practices.
2.6Ownership of Jinn Labs Services. As between the Parties, Jinn Labs solely owns all right, title, and interest, including all worldwide patent, copyright, trade-secret, and other intellectual property rights (“Intellectual Property Rights”), in and to the Jinn Labs Services and all interfaces, tools, methods, know-how, inventions, features, data models, AI/ML models and weights, data architecture, and—subject to Section 2.3—the Generated Materials, and all updates, enhancements, modifications, and improvements (the “Jinn Labs IP”).
2.7Protection of Know-How. Customer acknowledges that Jinn Labs’ methods, configurations, deployment techniques, and know-how are proprietary. Except to the extent necessary to facilitate the installation of the Jinn Labs Hardware (as defined below), Customer will not disclose, transfer, or make available any Jinn Labs know-how, Confidential Information, or Jinn Labs IP to any other vendor, integrator, or provider of competing or comparable products or services, and will not use any of the foregoing to assist any such third party.
2.8Apple App Store. This Section applies to any Jinn Labs mobile application (the “App”) that Customer acquires from the Apple App Store or uses on an iOS device. Apple has no obligation to provide maintenance or support for the App. If the App fails to conform to any applicable warranty, Customer may notify Apple, and Apple may refund the App purchase price to Customer (if any) and, to the maximum extent permitted by law, will have no other warranty obligation with respect to the App. Apple is not responsible for addressing any claims relating to the App or Customer’s possession or use of it, including (i) product liability claims, (ii) claims that the App fails to conform to any applicable legal or regulatory requirement, and (iii) claims under consumer protection or similar laws, and Apple is not responsible for the investigation, defense, settlement, or discharge of any third-party claim that Customer’s possession or use of the App infringes that party’s intellectual property rights. Apple and its subsidiaries are third-party beneficiaries of this Agreement and may enforce it against Customer. Customer represents and warrants that (i) it is not located in a country subject to a U.S. Government embargo or designated as a terrorist-supporting country and (ii) it is not listed on any U.S. Government list of prohibited or restricted parties. Customers will also comply with any applicable third-party terms of service when using the App.
3.1Hardware and Upgrades. Jinn Labs will provide the edge devices, tablets, and related equipment identified in the Order Form (the “Jinn Labs Hardware”) for use with the Jinn Labs Services during the Term at no separate charge, and will provide system upgrades (including device, camera-integration, and software upgrades) that Jinn Labs makes generally available, as part of the subscription. The Jinn Labs Hardware is provided on loan for use with the Jinn Labs Services and remains Jinn Labs’ property unless the Order Form expressly states it is sold to Customer.
3.2Technical Assessment; Right to Decline. Jinn Labs or its service provider will complete a technical assessment of the Customer site before installation of the Jinn Labs Hardware. Jinn Labs may decide, in its discretion, whether to proceed with installation following the assessment. If Jinn Labs does not proceed with the installation, or the installation is not successfully completed for any reason, Jinn Labs will refund any deposit paid by Customer within fifteen (15) days of Jinn Labs’ decision not to proceed.
3.3Installation Scope; NVR Work Excluded. Jinn Labs’ obligation is limited to the installation and onboarding of the Jinn Labs Hardware and Services. Any work relating to network video recorders, digital video recorders, cameras, or related recording infrastructure that is not Jinn Labs Hardware (including labor, equipment, configuration, upgrades, troubleshooting, or installation) (“NVR Work”) is solely between Customer and its technician/installer, is separately arranged and paid for by Customer, and is outside the scope of Jinn Labs’ obligations under this Agreement. Jinn Labs has no responsibility or liability for any NVR Work or related charges.
3.4Title; Risk of Loss; Return. Risk of loss for Jinn Labs Hardware in Customer’s possession passes to Customer upon installation at the Customer site by Jinn Labs or its service provider, as contemplated in Section 3.3. Upon expiration or termination of the Agreement, return of the Jinn Labs Hardware is Customer’s responsibility; Jinn Labs will provide a shipping box and prepaid label, and Customer will return the Jinn Labs Hardware in working condition (ordinary wear excepted).
4.1Fees; Deposit; No Setup or Cancellation Fee. Customer will pay the fees set forth in the Order Form (“Fees”) without offset or deduction. There is no setup fee. Any deposit paid by Customer is applied to the first month’s subscription Fees (and is refundable only as provided in Section 3.2). By purchasing a subscription, Customer expressly authorizes Jinn Labs (or its third-party payment processor) to initiate recurring, non-refundable payments and charge it for such Fees. Jinn Labs (or its third-party payment processor) will charge Customer’s payment method (such as a credit card, debit card, gift card/code, or other method accepted) for such Fees each month on the applicable date (“Transaction”). In connection with Customer’s Payment, Jinn Labs may ask Customer to supply additional relevant information including credit card number, credit card expiration date and contact email and postal addresses for billing and notification (such information, “Payment Information”). Customer represents and warrants that it has the legal right to use all payment method(s) represented by any such Payment Information, and Customer authorizes Jinn Labs to provide its Payment Information to third parties to complete Customer’s Transaction. By initiating a Transaction, Customer agrees to the pricing, payment and billing policies applicable to such fees and charges, as posted or otherwise communicated by Jinn Labs.
4.2Term. The initial term commences on the Effective Date and continues for one (1) year (the “Initial Term”). Thereafter, the Agreement automatically renews for successive one-year periods (each a “Renewal Term,” with the Initial Term, the “Term”), unless either Party gives written notice of non-renewal at least thirty (30) days before the end of the then-current Term.
4.3Early Cancellation. If Customer cancels during the Initial Term, Customer will, at Customer’s election, either (i) pay One Hundred Fifty U.S. Dollars ($150) per month for each month remaining in the Initial Term, or (ii) return the Jinn Labs Hardware/system in working condition at Customer’s expense in accordance with Section 3.4. This Section 4.3 states Customer’s sole financial obligation for early cancellation during the Initial Term.
4.4Late Payment; Taxes. Late amounts accrue interest at 1.5% per month (or the highest lawful rate), and Jinn Labs may suspend the Jinn Labs Services until Customer pays the past due amounts; Customer will reimburse Jinn Labs for all related reasonable collection costs (including reasonable attorneys’ fees). Customer is responsible for all sales, use, and similar taxes, other than taxes on Jinn Labs’ net income.
5.1Data Permissions; Owner Responsibility. Customer represents that it is the owner or authorized operator of the Customer site and that it grants Jinn Labs permission to access and use all cameras connected to the site’s NVR and, where Customer opts in, the site’s point-of-sale data. Customer is solely responsible for how it uses the Jinn Labs Services and any Generated Materials, and for any decisions or actions it takes based on them; Jinn Labs provides the Jinn Labs Services as a tool for the operator. To the maximum extent permitted by law, Jinn Labs has no liability arising from its use, within the scope of the permissions Customer grants, of owner-permitted data for analysis, theft/shrink detection, employee-productivity insights, and improvement and training of Jinn Labs’ models.
5.2License to Jinn Labs. Customer grants Jinn Labs a worldwide, transferable, sublicensable license to: (i) use the Customer Materials (as defined below) to provide the Jinn Labs Services; (ii) develop de-identified data and insights (“Service Information”) and use it to improve the Jinn Labs Services; and (iii) use the Customer Materials to develop, improve, and train Jinn Labs’ proprietary AI models, products, and services. Subject to the foregoing, Customer owns all information, data, content, and materials provided through the Jinn Labs Services, including Recordings (the “Customer Materials”).
5.3Data Processing. Each Party will comply with the Data Processing Addendum attached as Exhibit B (the “DPA”), which is incorporated by reference.
6.1Termination for Cause. Either Party may terminate this Agreement on written notice if the other materially breaches and fails to cure within thirty (30) days after written notice (no cure period for breach of Sections 2 or 5.2 / Jinn Labs IP).
6.2Effect; Survival. On expiration or termination: (i) Customer ceases use of the Jinn Labs Services and returns the Jinn Labs Hardware per Section 3.4; (ii) all amounts due become payable (including any amount under Section 4.3); and (iii) each Party returns or destroys the other’s Confidential Information. Sections 2.2, 2.6, 2.7, 3.4, 4, 5, 6.2, 7, 8, 9, 10, 11, and 12 survive.
“Confidential Information” means information one Party provides that is designated confidential or reasonably should be understood to be confidential, including the Jinn Labs Services and all Jinn Labs IP and know-how. The Receiving Party will not use or disclose the Disclosing Party’s Confidential Information except as necessary to perform under this Agreement, and will not disclose it to any competing or comparable vendor (see Section 2.7); provided that Jinn Labs may use Customer Confidential Information in de-identified form to develop Service Information. Standard exclusions (information that is publicly known, already known, independently developed, or rightfully obtained) and compelled disclosure protections apply.
Each Party represents that it has authority to enter into this Agreement. Customer represents that Jinn Labs’ use of the Customer Materials will not violate law or infringe third-party rights, and that Customer has obtained all consents, permissions, notices, and licenses (including any required signage, employee-monitoring, biometric/privacy, and audio-recording notices/consents) necessary for Jinn Labs’ use of the Recordings and Customer Materials in connection with the Jinn Labs Services.
THE JINN LABS SERVICES ARE PROVIDED “AS IS,” AND JINN LABS DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT, AND ANY WARRANTY THAT THE SERVICES WILL BE ERROR-FREE OR UNINTERRUPTED. CUSTOMER ACKNOWLEDGES THAT GENERATED MATERIALS ARE PROVIDED FOR INFORMATIONAL PURPOSES ONLY; JINN LABS MAKES NO GUARANTEE THAT THE SERVICES OR GENERATED MATERIALS ARE ACCURATE OR WILL DETECT ALL EVENTS OR RESULT IN ANY REDUCTION OF THEFT OR CRIME. CUSTOMER’S USE OF AND RELIANCE ON THE GENERATED MATERIALS IS AT CUSTOMER’S OWN RISK.
EXCEPT FOR EXCLUDED CLAIMS (CUSTOMER’S BREACH OF SECTION 2 OR ITS PAYMENT OBLIGATIONS, OR EITHER PARTY’S INFRINGEMENT OF THE OTHER’S INTELLECTUAL PROPERTY RIGHTS), NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES, OR LOST PROFITS/REVENUE/DATA. JINN LABS’ TOTAL LIABILITY IN CONNECTION WITH THIS AGREEMENT WILL NOT EXCEED THE FEES ACTUALLY PAID BY CUSTOMER TO JINN LABS IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM. THESE LIMITATIONS ARE AN ESSENTIAL BASIS OF THE BARGAIN AND APPLY EVEN IF A REMEDY FAILS OF ITS ESSENTIAL PURPOSE.
Jinn Labs will defend Customer against third-party claims that Customer’s use of the Jinn Labs Services infringes such third party’s Intellectual Property Rights, and will indemnify against resulting damages/costs awarded or agreed in settlement, excluding claims arising from Customer’s breach, the Customer Materials or Generated Materials, Customer’s failure to use updates, third-party modifications, or combinations with non-Jinn-Labs materials. Customer will defend and indemnify Jinn Labs against claims that the Customer Materials (or Jinn Labs’ permitted use of them) infringe or violate third-party IP, publicity, or privacy rights or any law, or arising from Customer’s use of the Jinn Labs Services other than as permitted, from NVR Work, or from Customer’s failure to obtain required notices/consents. Standard notice, control, and cooperation conditions apply.
Neither Party may assign this Agreement without the other’s consent, except to a successor in a merger, acquisition, or change of control. This Agreement is the entire agreement and supersedes prior understandings; amendments must be in writing. The Parties are independent contractors. This Agreement is governed by the laws of the State of Washington, and the Parties consent to exclusive jurisdiction and venue in the state and federal courts located in King County, Washington. Notices must be provided in writing (email sufficient). This Agreement may be executed in counterparts, and electronic signatures and electronic acceptance (including click-to-accept) have the same effect as originals.
This Data Processing Addendum (including its Attachments) (“Addendum”) forms part of and is subject to the terms and conditions of the Jinn Labs Platform Terms (the “Agreement”) by and between Customer (“Customer”) and Jinn Labs Inc. (“Jinn Labs”).
1. Subject Matter and Duration.
1.1.Subject Matter. This Addendum reflects the Parties’ commitment to abide by Data Protection Laws concerning the Processing of Customer Personal Data in connection with Jinn Labs’ execution of the Agreement. All capitalized terms that are not expressly defined in this Addendum will have the meanings given to them in the Agreement. If and to the extent language in this Addendum or any of its Exhibits conflicts with the Agreement, this Addendum shall control.
1.2.Duration and Survival. This Addendum will become legally binding upon the effective date of the Agreement. Jinn Labs will Process Customer Personal Data until the relationship terminates as specified in the Agreement.
2. Definitions. For the purposes of this Addendum, the following terms and those defined within the body of this
Addendum apply.
2.1.“Customer Personal Data” means Personal Data that Customer provides to Jinn Labs that Jinn Labs processes on behalf of Customer to provide the Services.
2.2.“Data Protection Laws” means the applicable privacy and data protection laws, rules and regulations to which the Customer Personal Data are subject. “Data Protection Laws” may include, but are not limited to, the California Consumer Privacy Act of 2018 (as amended by the California Privacy Rights Act) (“CCPA”) and similar U.S. state comprehensive privacy laws currently in effect; the EU General Data Protection Regulation 2016/679 (“GDPR”) and its respective national implementing legislations; the Swiss Federal Act on Data Protection; the United Kingdom General Data Protection Regulation; the United Kingdom Data Protection Act 2018 (in each case, as amended, adopted, or superseded from time to time).
2.3.“Personal Data” has the meaning assigned to the term “personal data” or “personal information” under
applicable Data Protection Laws.
2.4.“Process” or “Processing” means any operation or set of operations which is performed on Personal Data or sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
2.5.“Security Incident(s)” means the breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data attributable to Jinn Labs.
2.6.“Subprocessor(s)” means Jinn Labs’ authorized vendors and third party service providers that Process Customer Personal Data.
3. Processing Terms for Customer Personal Data.
3.1.Documented Instructions. Jinn Labs shall Process Customer Personal Data to provide the Jinn Labs Services in accordance with the Agreement, this Addendum, any applicable Order Form, and any instructions agreed upon by the parties. Jinn Labs will, unless legally prohibited from doing so, inform Customer in writing if it reasonably believes that there is a conflict between Customer’s instructions and applicable law or otherwise seeks to Process Customer Personal Data in a manner that is inconsistent with Customer’s instructions.
3.2.Authorization to Use Subprocessors. To the extent necessary to fulfill Jinn Labs’ contractual obligations under the Agreement, Customer hereby authorizes Jinn Labs to engage Subprocessors. Customers acknowledge that Subprocessors may further engage vendors.
3.3.Jinn Labs and Subprocessor Compliance. Jinn Labs shall (i) enter into a written agreement with Subprocessors regarding such Subprocessors’ Processing of Customer Personal Data that imposes on such Subprocessors data protection requirements for Customer Personal Data that are consistent with this Addendum; and (ii) remain responsible to Customer for Jinn Labs’ Subprocessors’ failure to perform their obligations with respect to the Processing of Customer Personal Data.
3.4.Right to Object to Subprocessors. Where required by Data Protection Laws, Jinn Labs will notify Customer via email prior to engaging any new Subprocessors that Process Customer Personal Data and allow Customer ten (10) days to object. If a customer has legitimate objections to the appointment of any new Subprocessor, the parties will work together in good faith to resolve the grounds for the objection.
3.5.Confidentiality. Any person authorized to Process Customer Personal Data must be subject to a duty of
confidentiality, contractually agree to maintain the confidentiality of such information, or be under an
appropriate statutory obligation of confidentiality.
3.6.Personal Data Inquiries and Requests. Where required by Data Protection Laws, Jinn Labs agrees to provide reasonable assistance and comply with reasonable instructions from Customer related to any requests from individuals exercising their rights in Customer Personal Data granted to them under Data Protection Laws.
3.7.Data Protection Assessment, Data Protection Impact Assessment, and Prior Consultation. Where required by Data Protection Laws, Jinn Labs agrees to provide reasonable assistance and information to Customer where, in Customer’s judgement, the type of Processing performed by Jinn Labs requires a data protection assessment, data protection impact assessment, and/or prior consultation with the relevant data protection authorities. Customer shall reimburse Jinn Labs for all non-negligible costs Jinn Labs incurs in performing its obligations under this Section.
3.8.Demonstrable Compliance. Jinn Labs agrees to provide information reasonably necessary to demonstrate compliance with this Addendum upon Customer’s reasonable request.
3.9.California Specific Terms. To the extent that Jinn Labs’ Processing of Customer Personal Data is subject to the CCPA, this Section shall also apply. Customer discloses or otherwise makes available Customer Personal Data to Jinn Labs for the limited and specific purpose of Jinn Labs providing the Jinn Labs Services to Customer in accordance with the Agreement and this Addendum. Jinn Labs shall: (i) comply with its applicable obligations under the CCPA; (ii) provide the same level of protection as required under the CCPA; (iii) notify Customer if it can no longer meet its obligations under the CCPA; (iv) not “sell” or “share” (as such terms are defined by the CCPA) Customer Personal Data; (v) not retain, use, or disclose Customer Personal Data for any purpose (including any commercial purpose) other than to provide the Jinn Labs Services under the Agreement or as otherwise permitted under the CCPA; (vi) not retain, use, or disclose Customer Personal Data outside of the direct business relationship between Customer and Jinn Labs; and (vii) unless otherwise permitted by the CCPA, not combine Customer Personal Data with Personal Data that Jinn Labs (a) receives from, or on behalf of, another person, or (b) collects from its own, independent consumer interaction. Customer may: (1) take reasonable and appropriate steps agreed upon by the parties to help ensure that Jinn Labs Processes Customer Personal Data in a manner consistent with Customer’s CCPA obligations; and (2) upon notice, take reasonable and appropriate steps agreed upon by the parties to stop and remediate unauthorized Processing of Customer Personal Data by Jinn Labs.
3.10.Service Optimization. Where permitted by Data Protection Laws, Jinn Labs may Process Customer Personal Data: (i) for its internal uses to build or improve the quality of its services; (ii) to detect Security Incidents; and (iii) to protect against fraudulent or illegal activity.
4. Information Security Program. Jinn Labs shall use commercially reasonable efforts to implement and maintain
reasonable administrative, technical, and physical safeguards designed to protect Customer Personal Data.
5. Security Incidents. Upon becoming aware of a Security Incident, Jinn Labs agrees to provide written notice without undue delay and within the time frame required under Data Protection Laws to Customer’s Designated POC. Where
possible, such notice will include all available details required under Data Protection Laws for Customer to comply with its own notification obligations to regulatory authorities or individuals affected by the Security Incident.
6. Cross-Border Transfers of Customer Personal Data.
6.1.Cross-Border Transfers of Customer Personal Data. Customer authorizes Jinn Labs and its Subprocessors to transfer Customer Personal Data across international borders, including from the European Economic Area, Switzerland, and/or the United Kingdom to the United States.
6.2.EEA, Swiss, and UK Standard Contractual Clauses. If Customer Personal Data originating in the European Economic Area, Switzerland, and/or the United Kingdom is transferred by Customer to Jinn Labs in a country that has not been found to provide an adequate level of protection under applicable Data Protection Laws, the parties agree that the transfer shall be governed by Module Two’s obligations in the Annex to the Commission Implementing
Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (“Standard Contractual Clauses”) as supplemented by Exhibit A attached hereto, the terms of which are incorporated herein by reference. Each party’s signature to this Agreement shall be considered a signature to the Standard Contractual Clauses to the extent that the Standard Contractual Clauses apply hereunder.
7. Audits and Assessments. Where Data Protection Laws afford Customer an audit or assessment right, Customer (or its appointed representative) may carry out an audit or assessment of Jinn Labs’ policies, procedures, and records relevant to the Processing of Customer Personal Data. Any audit or assessment must be: (i) conducted during Jinn Labs’ regular business hours; (ii) with reasonable advance notice to Jinn Labs; (iii) carried out in a manner that prevents unnecessary disruption to Jinn Labs’ operations; and (iv) subject to reasonable confidentiality procedures. In addition, any audit or assessment shall be limited to once per year, unless an audit or assessment is carried out at the direction of a government authority having proper jurisdiction.
8. Customer Personal Data Deletion. At the expiry or termination of the Agreement, Jinn Labs will delete all Customer Personal Data (excluding any back-up or archival copies which shall be deleted in accordance with Jinn Labs’ data retention schedule), except where Jinn Labs is required to retain copies under applicable laws, in which case Jinn Labs will isolate and protect that Customer Personal Data from any further Processing except to the extent required by applicable laws.
9. Customer’s Obligations. Customer represents and warrants that: (i) it has complied and will comply with Data
Protection Laws; (ii) it has provided data subjects whose Customer Personal Data will be Processed in connection with the Agreement with a privacy notice or similar document that clearly and accurately describes Customer’s practices with respect to the Processing of Customer Personal Data; (iii) it has obtained and will obtain and continue to have, during the term, all necessary rights, lawful bases, authorizations, consents, and licenses for the Processing of Customer Personal Data as contemplated by the Agreement; and (iv) Jinn Labs’ Processing of Customer Personal Data in accordance with the Agreement will not violate Data Protection Laws or cause a breach of any agreement or
obligations between Customer and any third party.
10. Account Data. Jinn Labs may Process Personal Data about Customer’s Authorized Users (as defined in the Agreement) (“Account Data”) in accordance with its Privacy Policy/Notice available at https://www.jinnlabs.ai/privacy, including for marketing purposes. Account Data is not Customer Personal Data.
11. Processing Details.
11.1.Subject Matter. The subject matter of the Processing is the Jinn Labs Services pursuant to the Agreement.
11.2.Duration. The Processing will continue until the expiration or termination of the Agreement.
11.3.Categories of Data Subjects. Data subjects whose Customer Personal Data will be Processed pursuant to the Agreement.
11.4.Nature and Purpose of the Processing. The purpose of the Processing of Customer Personal Data by Jinn Labs is the performance of the Jinn Labs Services.
11.5.Types of Customer Personal Data. Customer Personal Data that is Processed pursuant to the Agreement.
12. Contact Information. Customer and Jinn Labs agree to designate a point of contact for urgent privacy and security issues (a “Designated POC”). The Designated POC for both parties are: Customer Designated POC: As set forth in the Notices section of the Agreement.
Jinn Labs Designated POC: As set forth in the Notices section of the Agreement.
This Attachment A forms part of the Addendum and supplements the Standard Contractual Clauses. Capitalized terms not defined in this Attachment A have the meaning set forth in the Addendum.
The parties agree that the following terms shall supplement the Standard Contractual Clauses:
Supplemental Terms. The parties agree that: (i) a new Clause 1(e) is added to the Standard Contractual Clauses which shall read: “To the extent applicable hereunder, these Clauses also apply mutatis mutandis to the Parties’ processing of personal data that is subject to the Swiss Federal Act on Data Protection. Where applicable, references to EU Member State law or EU supervisory authorities shall be modified to include the appropriate reference under Swiss law as it relates to transfers of personal data that are subject to the Swiss Federal Act on Data Protection.”; (ii) a new Clause 1(f) is added to the Standard Contractual Clauses which shall read: “To the extent applicable hereunder, these Clauses, as supplemented by Annex III, also apply mutatis mutandis to the Parties’ processing of personal data that is subject to UK Data Protection Laws (as defined in Annex III).”; (iii) the optional text in Clause 7 is deleted; (iv) Option 1 in Clause 9 is struck and Option 2 is kept, and data importer must notify data exporter of any new subprocessors in accordance with Section 3.4 of the Addendum; (v) the optional text in Clause 11 is deleted; and (vi) in Clauses 17 and 18, the governing law and the competent courts are those of Ireland (for EEA transfers), Switzerland (for Swiss transfers), or England and Wales (for UK transfers).
Annex I. Annex I to the Standard Contractual Clauses shall read as follows:
A. List of Parties
Data Exporter: Customer.
Address: As set forth in the Notices section of the Agreement.
Contact person’s name, position, and contact details: Customer’s Designated POC.
Activities relevant to the data transferred under these Clauses: The Jinn Labs Services.
Role: Controller.
Data Importer: Jinn Labs.
Address: As set forth in the Notices section of the Agreement.
Contact person’s name, position, and contact details: Jinn Labs’ Designated POC.
Activities relevant to the data transferred under these Clauses: The Jinn Labs Services.
Role: Processor.
B. Description of the Transfer:
Categories of data subjects whose personal data is transferred: The categories of data subjects whose personal data is transferred under the Clauses.
Categories of personal data transferred: The categories of personal data transferred under the Clauses.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: To the parties knowledge, no sensitive data is transferred.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis): Personal data is transferred in accordance with the standard functionality of the Jinn Labs Services, or as otherwise agreed upon by the parties.
Nature of the processing: The Jinn Labs Services.
Purpose(s) of the data transfer and further processing: The Jinn Labs Services.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Data importer will retain personal data in accordance with the Addendum.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: For the subject matter, nature, and duration as identified above.
C. Competent Supervisory Authority: The supervisory authority mandated by Clause 13. If no supervisory authority is mandated by Clause 13, then the Irish Data Protection Commission (DPC), and if this is not possible, then as otherwise agreed by the parties consistent with the conditions set forth in Clause 13.
F. Clarifying Terms: The parties agree that: (i) the certification of deletion required by Clause 8.5 and Clause 16(d) of the Clauses will be provided upon data exporter’s written request; (ii) the measures data importer is required to take under Clause 8.6(c) of the Clauses will only cover data importer’s impacted systems; (iii) the audit described in Clause 8.9 of the Clauses shall be carried out in accordance with Section 7 of the Addendum; (iv) the termination right contemplated by Clause 14(f) and Clause 16(c) of the Clauses will be limited to the termination of the Clauses; (v) unless otherwise stated by data importer, data exporter will be responsible for communicating with data subjects pursuant to Clause 15.1(a) of the Clauses; (vi) the information required under Clause 15.1(c) of the Clauses will be provided upon data exporter’s written request; and (vii) notwithstanding anything to the contrary, data exporter will reimburse data importer for all costs and expenses incurred by data importer in connection with the performance of data importer’s obligations under Clause 15.1(b) and Clause 15.2 of the Clauses without regard for any limitation of liability set forth in the Agreement.
Annex II. Annex II of the Standard Contractual Clauses shall read as follows:
Data importer shall use commercially reasonable efforts to implement and maintain technical and organisational measures designed to protect personal data in accordance with the Addendum.
Pursuant to Clause 10(b), data importer will provide data exporter assistance with data subject requests in accordance with the Addendum.
Annex III. A new Annex III shall be added to the Standard Contractual Clauses and shall read as follows:
The UK Information Commissioner’s Office International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (“UK Addendum”) is incorporated herein by reference.
Table 1: The start date in Table 1 is the effective date of the Addendum. All other information required by Table 1 is set forth in Annex I, Section A of the Clauses.
Table 2: The UK Addendum forms part of the version of the Approved EU SCCs which this UK Addendum is appended to including the Appendix Information, effective as of the effective date of the Addendum.
Table 3: The information required by Table 3 is set forth in Annex I and II to the Clauses.
Table 4: The parties agree that Importer may end the UK Addendum as set out in Section 19.