Data Processing Addendum · Alebex
Legal / DPA

Data Processing Addendum

Processing-role, security, subprocessor, transfer, assistance, and deletion terms for Customer Personal Data

Version 2.0.0 / Effective August 18, 2026 / Public incorporated data-processing terms
Account-configured processing details

This DPA is designed for clickwrap and signed relationships. The Services, countries, data categories, retention settings, and customer roles shown in the Account or an Order Form supplement the schedules below. ALEBEX does not identify subprocessors in this public document; the current confidential list is available under the Subprocessor Information page.

01

Scope and roles

This ALEBEX AI Data Processing Addendum (“DPA”) forms part of the agreement between ALEBEX AI Corp. (“ALEBEX”) and Customer governing the Services (the “Service Agreement”). It applies where ALEBEX processes Customer Personal Data on behalf of Customer.

Depending on applicable law and the processing facts, Customer is the controller, business, organization, custodian, or equivalent role, and ALEBEX is the processor, service provider, contractor, vendor, agent, or equivalent role. Where Customer acts for an End Client, ALEBEX may be a subprocessor and Customer represents that it is authorized to appoint ALEBEX.

For personal information that ALEBEX collects and controls for its own account administration, billing, security, legal, website, and direct relationship purposes, ALEBEX acts as an independent controller or organization and the ALEBEX Privacy Policy applies. This DPA does not convert Customer into a controller of ALEBEX-controlled corporate information.

02

Processing details and documented instructions

The subject, duration, nature, purpose, data subjects, and data categories are described in Schedule 1, the Service Agreement, the Account, enabled Services, and any Order Form. Customer instructs ALEBEX to process Customer Personal Data to provide, secure, support, debug, monitor, bill, maintain, and operate the Services; generate Output; comply with law; enforce the Service Agreement; and perform other lawful documented instructions consistent with the Services.

The Service Agreement, Customer’s authorized Account configuration, API calls, settings, support requests, and lawful written instructions constitute documented instructions. ALEBEX may refuse, suspend, or require modification of an instruction that ALEBEX reasonably believes violates law, the Service Agreement, the AUP, the Communications Policy, the Country Requirements, security requirements, or service integrity.

ALEBEX will notify Customer where it believes an instruction violates applicable data-protection law, unless law prohibits notice. ALEBEX is not required to provide legal advice or independently determine Customer’s legal basis.

03

Customer obligations

Customer is responsible for the lawfulness, accuracy, minimization, collection, source, retention instructions, and permitted use of Customer Personal Data; identifying applicable legal roles; providing privacy notices; obtaining required consent or other lawful basis; responding to Recipients and data subjects; and ensuring its End-Client, employee, user, and Recipient terms authorize the processing.

Customer must not submit Restricted Data unless ALEBEX has approved or enabled the data category, purpose, safeguards, legal basis, and necessary contractual terms. Customer must configure retention, access, recording, transcription, and deletion settings appropriately and must not instruct ALEBEX to retain data longer than needed or lawfully permitted.

Customer must maintain reasonable security for its systems, devices, users, credentials, contact lists, CRM, integrations, and Customer Applications; use available multi-factor authentication for privileged access; promptly remove access; and notify ALEBEX of actual or suspected unauthorized access or misuse.

04

ALEBEX obligations

ALEBEX will process Customer Personal Data only for the purposes permitted by this DPA and the Service Agreement; ensure authorized personnel are subject to confidentiality obligations; implement reasonable administrative, technical, and physical safeguards appropriate to the Services and processing risk; and provide the assistance described below.

ALEBEX will not sell Customer Personal Data or share it for cross-context behavioral advertising, as those terms are defined under applicable United States state privacy laws. ALEBEX will not retain, use, or disclose Customer Personal Data outside the direct business relationship or for a commercial purpose other than providing and operating the Services, except as permitted by law and the Service Agreement.

ALEBEX will not use identifiable Customer Personal Data to train a general-purpose or shared AI model without Customer’s express opt-in. ALEBEX may use de-identified and aggregated information for security, fraud prevention, capacity planning, quality control, analytics, and service operation or improvement, provided ALEBEX applies reasonable controls against re-identification and does not use it to identify Customer, an End Client, or a data subject.

05

Security measures

ALEBEX will maintain a written security program containing measures reasonably appropriate to the nature and risk of the Services, including access controls, least privilege, available multi-factor authentication for privileged access, encryption in transit, secure storage, credential management, logging and monitoring where appropriate, vulnerability management, incident response, personnel confidentiality, and secure development practices.

Schedule 2 describes baseline measures. Specific features, configurations, or customer commitments may be stated in an Order Form or security addendum. ALEBEX does not warrant that a measure eliminates every threat or that the Services satisfy a certification, industry standard, or customer-specific control unless expressly stated in a signed document.

06

Security Incidents

“Security Incident” means an actual breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by ALEBEX. Unsuccessful attempts, scans, pings, blocked attacks, or events that do not compromise Customer Personal Data are not Security Incidents.

ALEBEX will notify Customer without undue delay after confirming a Security Incident involving Customer Personal Data. Notice may be provided through the Account or to Customer’s designated security or administrator contact and will include information reasonably available and appropriate to the event. ALEBEX may provide information in phases as investigation continues.

ALEBEX will take reasonable steps to contain, investigate, remediate, and preserve evidence. Customer is responsible for notifications and responses arising from Customer systems, instructions, contact lists, Customer Applications, credentials, communications, or failure to obtain required rights, notices, consent, or lawful basis.

Customer must notify ALEBEX immediately, and no later than twenty-four hours after discovery, of any actual or suspected Security Incident involving Customer systems, credentials, Customer Content, Output, or use of the Services and must cooperate in containment, investigation, remediation, and legally required notification.

07

Subprocessors

Customer gives ALEBEX general authorization to engage subprocessors to provide the Services. ALEBEX will require subprocessors that process Customer Personal Data to protect it under obligations materially consistent with this DPA, taking account of the service provided. ALEBEX remains responsible for their processing to the extent required by applicable law and this DPA.

ALEBEX does not publish the full subprocessor list on the public website. Customer may request the current list through the ALEBEX AI Subprocessor Information page using a business email and legitimate business purpose. The list identifies relevant processor name, function, and general processing location, subject to confidentiality and security restrictions.

ALEBEX will provide reasonable notice of a material new subprocessor where required by applicable law or Customer’s signed agreement. Customer may object within fifteen days on reasonable documented data-protection grounds. The parties will seek a commercially reasonable alternative. If none is available, ALEBEX may terminate the affected Service or Customer may stop using it; this is Customer’s exclusive remedy for the objection.

08

Cross-border processing and international transfers

Customer authorizes processing in Canada, the United States, and other jurisdictions in which ALEBEX or authorized service providers operate, subject to the Service Agreement, enabled territories, and applicable law. Customer is responsible for providing required cross-border notices and obtaining required consent.

Where a transfer from the European Economic Area, Switzerland, or United Kingdom requires a transfer mechanism, the affected Services will not be enabled until the parties have completed an applicable transfer addendum, Order Form, or other lawful mechanism. The parties may incorporate the European Commission Standard Contractual Clauses or the applicable United Kingdom addendum by reference, with modules and annex information determined by the parties’ roles and Schedule 1.

ALEBEX may suspend a transfer or affected Service where law, a court, regulator, sanctions rule, carrier, or provider prevents the transfer or where the required mechanism is not in place.

09

Data-subject and privacy requests

Customer is responsible for responding to access, correction, deletion, portability, objection, restriction, opt-out, unsubscribe, do-not-call, consent-withdrawal, and complaint requests relating to Customer Personal Data. Customer should use available self-service and export tools before requesting ALEBEX assistance.

ALEBEX will provide reasonable assistance where required by applicable law and technically available, taking account of the nature of processing. ALEBEX may charge reasonable fees for assistance beyond included functionality unless the request results from ALEBEX’s breach. ALEBEX may verify request scope, identity, authority, and security before acting.

If ALEBEX receives a request directly concerning Customer Personal Data, ALEBEX may refer the requester to Customer unless law requires a direct response. Customer must provide timely instructions and must not require ALEBEX to disclose another customer’s information, confidential security information, or ALEBEX trade secrets.

10

Return, deletion, de-identification, and retention

During the Term, Customer may use standard export and deletion functionality. Upon termination or Customer’s lawful request, ALEBEX will return, delete, or de-identify Customer Personal Data according to the Service Agreement, Account functionality, and applicable law.

ALEBEX may retain information where required or permitted for backups, legal holds, security, fraud, billing, tax, audit, dispute, complaint, regulatory, service-integrity, and evidence-preservation purposes. Retained information remains protected and is not used for unrelated commercial purposes. Backup deletion may occur through ordinary rotation rather than immediate deletion.

Retention periods for enabled Services are stated in the Account, documentation, an Order Form, or Customer instructions. Customer is responsible for selecting a lawful retention period. ALEBEX may de-identify information instead of deleting it where legally permitted and reasonably necessary for security, fraud, analytics, or service operation.

11

Audit and compliance information

ALEBEX will make reasonably necessary information available to demonstrate compliance with this DPA, subject to confidentiality, privacy, security, privilege, trade-secret, service-provider, and service-integrity restrictions. ALEBEX may satisfy requests with policies, questionnaires, summaries, certifications, independent reports, or other documentation.

An on-site or direct audit is available only where required by applicable law and not reasonably satisfied by existing information. It must be limited to Customer Personal Data and relevant Services, conducted no more than annually unless a confirmed Security Incident or regulator requires otherwise, during normal hours, by an independent qualified auditor under confidentiality, without access to other customers or source code, and at Customer’s expense unless the audit identifies a material ALEBEX breach.

12

Canadian and United States privacy terms

For Canadian processing, ALEBEX will act as a service provider or agent where applicable, use personal information for the authorized purposes, protect it with safeguards appropriate to sensitivity, and assist Customer with access, correction, complaint, breach, and accountability obligations to the extent required and commercially reasonable.

For United States state privacy laws, ALEBEX acts as a processor, service provider, or contractor where applicable. ALEBEX will not sell or share Customer Personal Data; retain, use, or disclose it outside the direct business relationship or for a purpose other than specified business purposes, except as permitted by law; or combine it with personal data received from another person or collected through direct interaction, except as legally permitted to provide the Services.

Customer may take reasonable steps to confirm ALEBEX uses Customer Personal Data consistently with these restrictions. ALEBEX will notify Customer if it determines it can no longer meet a legally required restriction, and Customer may take reasonable and appropriate steps to stop and remediate unauthorized use.

13

Restricted Data and special regimes

This DPA does not by itself authorize health information subject to HIPAA, regulated financial data, payment-card data, biometric identification or voiceprints, student records, child data, criminal information, government-classified data, or another special regime. Such processing requires an enabled feature, confirmed legal roles, appropriate safeguards, and any additional agreement required by ALEBEX.

Customer must not rely on a general DPA as a business associate agreement, financial-services addendum, student-data agreement, biometric consent, or other specialized instrument. ALEBEX may require separate legal and security review and may refuse a data category or use.

14

Liability, priority, and duration

The exclusions and limitations of liability in the Service Agreement apply to this DPA. This DPA does not create a separate or additional liability cap. A customer or partner indemnity covering Customer’s data, instructions, legal basis, communications, or downstream users applies to this DPA.

This DPA controls over the Service Agreement for processing of Customer Personal Data. A signed data-protection addendum may modify this DPA only where it expressly identifies the change. The DPA begins when Customer accepts or signs it and continues while ALEBEX processes Customer Personal Data, including any lawful retention period.

15

Schedule 1 - Processing details

ItemDetails
Subject and purposeProvision, security, support, monitoring, billing, maintenance, approved improvement, legal compliance, enforcement, and operation of enabled ALEBEX Services.
DurationTerm of the Service Agreement plus lawful retention for backups, legal, security, billing, tax, audit, dispute, complaint, regulatory, and evidence-preservation purposes.
Data subjectsRecipients, customers, prospects, leads, users, employees, contractors, administrators, applicants, End Clients, Authorized Organizations, and other persons whose data Customer submits.
Data categoriesContact information; CRM and lead data; call and message content; audio and recordings; transcripts and summaries; scripts and knowledge; metadata; usage; configuration; support; security; and related operational records.
Sensitive or Restricted DataNot authorized unless ALEBEX enables or approves the data category, purpose, safeguards, legal basis, and any required addendum.
FrequencyContinuous or intermittent according to Customer’s use, API calls, Account settings, communications, and support requests.
Customer instructionsService Agreement, Account settings, API requests, enabled features, Order Forms, support requests, and lawful written instructions.
RetentionAs configured in the Services or stated in an Order Form or instruction, subject to lawful exceptions described in Section 10.
16

Schedule 2 - Baseline security measures

  • role-based access controls and least-privilege permissions;
  • available multi-factor authentication for privileged administrative access;
  • encryption in transit using current secure protocols and secure storage appropriate to the service;
  • credential, API-key, token, and secret management;
  • logging, monitoring, alerting, and evidence preservation appropriate to service risk;
  • vulnerability management, dependency review, patching, and secure development practices;
  • incident-response, escalation, and business-continuity procedures;
  • tenant separation and access restrictions appropriate to the service architecture;
  • personnel confidentiality and security awareness obligations;
  • subprocessor diligence and contractual data-protection obligations; and
  • backup, recovery, deletion, and retention controls appropriate to the service.